Privacy Policy
Last updated 1 September 2026
This is a draft, written for an early-stage product with a small number of users. It has not been reviewed by a lawyer. It describes what the software actually does today, which is the part that matters most.
1. Who runs this
Wayfare is an independent project, operated by Flutter Horizon — a registered sole proprietorship based in British Columbia, Canada. That is a business name, not a corporation: one person runs it, and there is no team behind it.
Questions, complaints, or requests about your data: hello@thewayfare.app
2. The short version
Wayfare is built so that most of it works without an account and without sending anything to a server. If you never sign in, your trips stay in your own browser and we have no copy of them.
An account exists so that some things can work — syncing between devices, storing photos, publishing a trip, and receiving forwarded booking emails. Those, by their nature, involve sending data to servers.
We do not sell data. We do not run advertising. We do not track you across other websites.
3. What stays on your device
When you use Wayfare without signing in, everything you create is stored in your browser's own storage (IndexedDB):
- Trips, destinations, days and stops
- Notes, ratings, arrival times
- Budgets and expenses
- Checklists
- Reservations parsed from a confirmation you paste or upload
None of this reaches us. You can export it to a file at any time, and clearing your browser's data will delete it — permanently, because there is no copy.
Some features work signed out too, and do reach a server even without an account: the map, place search, and the AI features that read a pasted itinerary or a booking confirmation all send what you type or paste to the provider that handles them (Google or Google Gemini — see section 5) so they can respond, whether or not you are signed in. None of it is stored as "your" data unless you are signed in.
4. What we store when you sign in
Signing in creates an account and enables syncing. From that point, the data listed above is also stored on our servers, in a Postgres database hosted by Supabase, so that it is available on your other devices.
We also store:
Account data — your email address, and if you sign in with Google, the name and profile image Google provides. Handled by Supabase Auth.
Photos — images you attach to a trip, in private object storage. Your browser strips all EXIF metadata from a photo before it ever leaves your device, including GPS coordinates — the file we receive has none, and we have checked this directly against the actual output, not just assumed it. The location a photo was taken is captured separately and kept in our database, tied to your account, never to the photo file itself, and is never included in a published photo.
Reservations — when you upload or forward a booking confirmation, we store what was extracted: carrier or property name, confirmation number, an access PIN where the confirmation states one, the names of everyone traveling on that booking (not just you), dates, times, and addresses.
Trip companions — if you name other people on a trip, for splitting costs or as passengers on a booking, those names are stored the way you typed them. We have no relationship with, and no way to contact, anyone you name this way.
Forwarded email text — the text of messages you forward to your trip address is retained for 30 days so that you can check what was extracted, then deleted automatically. We do not keep the raw message beyond that. The structured details already extracted from it (above) are not affected by this and are kept until you delete the trip or reservation.
Location, when you offer it — if you use the "log where I am" feature, the coordinates you capture are stored with that stop. This only happens when you explicitly ask for it, and the browser asks your permission first. Declining changes nothing else.
5. Third-party services
Wayfare depends on services run by others. Here is what goes to each and why.
Supabase — database, authentication and file storage. Holds everything in section 4. The database is hosted in Canada.
Vercel — hosting. Every request is processed by Vercel's own servers in the United States before reaching Supabase, regardless of where your account's data ultimately lives. Vercel keeps standard server logs, which include IP addresses, for a short time.
Google Gemini — used to read the text of an itinerary you paste, a booking confirmation you send, a single place you ask it to describe, or a day you ask it to review, and to suggest places when you ask it to. The full text of whatever document you send is passed to Google for processing exactly as written, including any other travelers' names or details it contains. Photos are never sent. Your private notes are never sent. We do not use your data to train any model, and Google's API terms state that data sent through the paid API is not used to train their models.
Resend — receives the booking confirmations you forward or the emails your trip address collects, and hands them to us for processing. Wayfare does not currently send you any email through Resend or otherwise — no confirmations, no notifications.
Google Maps Platform — the interactive map, the static map images on published trip pages, place search (what you type while searching for a place is sent to Google as you type it), place details and photographs when you tap a place on the map, address or coordinate lookup, and routing (the coordinates of a day's stops, to draw the path between them). Results are cached on our servers for up to 30 days before we ask Google again for the same thing. Clicking a directions link also opens Google's site with the two coordinates in the URL. Nothing else is shared, and their privacy policy applies from that point.
6. What we do not do
- No advertising, and no advertising trackers.
- No selling or renting of data.
- No analytics that follow you across other sites.
- No profiling and no automated decisions with legal effect.
- No use of your trips to train machine-learning models.
7. Publishing
A trip is private until you publish it. Publishing makes a page anyone can read at a public address.
When you publish, these are excluded by default, and stay off unless you turn them on:
- Your notes on stops, which you can turn on for all of them at once or one at a time
- Accommodation stops
- Your photos, which you can publish one at a time or all at once — you are shown exactly which photos are about to become public, and what they show, before the first one goes live
Turning any of these on or off takes effect immediately, whether or not the trip is currently published, and never requires taking the whole page down first.
Always excluded, with no setting to turn them on: every expense and budget figure, who paid or owes whom, booking confirmation numbers and PINs, GPS coordinates recorded during your trip or embedded in a photo, and the original text of anything you imported or forwarded.
Unpublishing removes the page immediately, including any published photos, and takes it out of the sitemap. Search engines may keep a cached copy for a while; that is outside our control.
8. How long we keep things
- Trip data — until you delete it, or delete your account.
- Forwarded email text — 30 days, then deleted automatically.
- Cached results from Google (map, search, place details, photos) — up to 30 days, then refreshed the next time they're needed.
- Usage and diagnostic records kept to prevent abuse (how many requests an account or address has made on a given day, and browser error reports) — 30 days, then deleted automatically.
- Deleting a trip — the trip stops appearing in your list right away, with a few seconds to undo it. After that, its photos are removed from storage and its forwarded-email text is cleared immediately.
- Deleting your account — email hello@thewayfare.app and we will delete everything associated with it. There is no self-service button yet; there will be.
Your local browser data is not affected by any of this. It is yours and it stays until you clear it.
9. Your rights
Wherever you live, you can ask us to show you what we hold about you, correct it, delete it, or give it to you in a portable form. Email hello@thewayfare.app.
The export feature already gives you your own data as a file, without asking anyone.
If you are in the EEA or UK, the GDPR applies. Our legal bases are: performing the service you asked for (your trips), your consent (location, sending documents for processing, publishing), and legitimate interest (keeping the service running and preventing abuse). You may complain to your national data protection authority.
If you are in California, the CCPA applies. We do not sell or share personal information as those terms are defined there.
If you are in Canada, PIPEDA applies, and you may complain to the Office of the Privacy Commissioner.
10. Where your data is
Your account data is stored in Canada. Every request, including from outside Canada, is first handled by servers in the United States before reaching that database.
11. Cookies
We use one thing, and it is not for tracking: a session cookie that keeps you signed in. There are no advertising cookies and no third-party trackers.
Your browser also stores your trips locally, which is not a cookie but is worth knowing about — it is described in section 3.
12. Children
Wayfare is not intended for people under 16, and we do not knowingly collect their data. If you believe a child has given us information, email us and we will remove it.
13. Security
Access to your data is enforced at the database level, so one account cannot read another's rows. Photos you have not published live in private storage, reachable only through short-lived signed links. A photo you publish is deliberately the opposite: it is copied into public storage so that anyone with the link can read it, which is what publishing it means. Secrets stay on the server. Traffic is encrypted.
We are honest about the limits: this is a small project without a security team. If you find a problem, please tell us at hello@thewayfare.app rather than publishing it, and we will fix it.
14. Changes
If this policy changes in a way that matters, we will say so in the app before it takes effect. The date at the top is always the date of the last change.