Golden Tempo Travel is operated by Golden Tempo LLC, a New Jersey limited liability company ("we," "us"). This policy explains what we collect, how we use it, who we share it with, and the choices you have. It is written to match what the product actually does. Questions or requests: [email protected].
1. Information we collect
Account information. Your email address, an optional display name, your language preference, and — if you sign up with a password — the password stored only as a bcrypt hash (we cannot see your actual password). If you sign in with Google or Apple, we store your email and the provider's account identifier so we can recognize you next time; SSO-only accounts have no password at all.
Trips and planning content. Trips, itineraries, saved places, accommodations and transport segments, booking checklists, packing lists, budgets and expenses, price alerts (route, dates, and baggage preference), and trip share/invite records.
AI conversations. When you are signed in, your conversations with the planning assistant are saved so you can pick up where you left off. Images you attach are not stored — they are sent to the AI provider to generate a response, and only an "image attached" marker is kept in the saved conversation. Conversations you have while signed out are not saved at all.
Traveler preferences and profile notes. Preferences you set (budget, pace, interests, home airport) and a short, AI-maintained set of profile notes about how you like to travel (for example "travels with two kids," "vegetarian"), built from your planning conversations so future trips are personalized. The AI is instructed not to record sensitive information (such as health, religion, or politics) unless you explicitly ask it to remember something. You can view and edit these preferences in the app, and they are deleted with your account.
Usage events. A first-party log of product events (account created, trip saved, booking link clicked, AI session token counts, and similar). Each event carries your internal account ID, an event type, an optional trip ID, and limited technical metadata — by design it contains no email address, no IP address, no browser user-agent, and no free text. It lives in our own database; we use no third-party analytics services. A small set of events (such as landing-page clicks) can be recorded without any account attached.
Server logs and security data. Like nearly every web service, our servers keep standard request logs — timestamp, request path, response status, and your IP address — used for security, debugging, and abuse prevention, and routinely rotated. We also keep short-lived, in-memory counters keyed by IP address to rate-limit abuse (login lockouts, daily AI-usage caps, sign-up caps); these are never written to the database and disappear on restart. Our edge network provider (Cloudflare) also processes your IP address and requests to route traffic and block attacks.
Email delivery records. When we send you email (verification, password reset, price alerts, trip reminders, co-planning invites), your email address is processed by our transactional email provider for delivery. Links in verification and reset emails use single-use, expiring tokens that we store only as cryptographic hashes.
2. How we use information
- To provide the Service: store your trips, generate itineraries, run searches, send the emails you request or subscribe to.
- To personalize: apply your saved preferences and profile notes to future planning conversations.
- To keep the Service safe and affordable: rate limiting, abuse prevention, debugging, and cost monitoring.
- To understand product usage in aggregate, using our own pseudonymous event log.
- We do not use your data for third-party advertising, and we do not sell it.
3. AI processing (please read this one)
The planning assistant is powered by Anthropic's Claude models, called from our servers. When you use it, we send Anthropic: your conversation messages, any images you attach, your current trip context, your saved traveler preferences and profile notes, and the results of searches the assistant runs on your behalf. Long conversations are also summarized by an AI model so they can continue past length limits, and after planning sessions an AI model may distill durable travel preferences from the conversation into your profile notes.
We use Anthropic's commercial API. Under Anthropic's commercial terms, API inputs and outputs are not used to train Anthropic's models by default. Anthropic's own usage policies apply to this processing: see anthropic.com/legal.
4. Service providers we share data with, and why
We share data only as needed to answer your requests or run the Service — never for the providers' own marketing:
| Provider | What they receive | Why |
|---|---|---|
| Anthropic | Planning conversations, attached images, trip context, preferences (see Section 3) | AI itinerary generation |
| Google Places | Place and destination search text | Finding and verifying places |
| Duffel | Airports, dates, passenger counts | Flight search |
| Ticketmaster | City and date window | Local events lookup |
| Open-Meteo | Destination name/coordinates and dates | Weather forecasts |
| Groq (or your browser's built-in speech service) | Voice-dictation audio, only while you use the microphone | Speech-to-text |
| Google / Apple | Standard sign-in flow data, if you choose SSO | Account sign-in |
| Resend | Your email address and message content | Delivering the emails described above |
| Cloudflare | IP address and request traffic | Edge network, TLS, and attack protection |
| Sentry | Technical error reports (error message and request metadata such as a request ID — not your account profile) | Error monitoring |
These lookups are made server-side; search providers do not receive your email address or account identity from us. Results you choose to keep become part of your trip data.
Voice dictation is optional. If you tap the microphone, audio is transcribed either by your browser's built-in speech service or by our transcription provider, then discarded — we never store your audio.
Beyond these providers, we do not share personal data with third parties except: with your direction (share links, invites, booking handoffs), to comply with law or valid legal process, to protect the Service and its users from fraud or abuse, or as part of a business transfer (in which case this policy would continue to apply to your data until changed with notice).
5. Affiliate and outbound links
Booking handoff links (for example Booking.com or Ferryhopper) open the provider's own site and may include an affiliate identifier so the provider can credit us if you book. Once you leave Golden Tempo Travel, the provider's own privacy policy applies. We record that a booking link was clicked (see usage events); we never receive your payment or booking details.
6. Sharing, invites, and export links
- Share links: anyone with a share link can view the latest version of that trip until you revoke the link (you can revoke it in the app).
- Co-planner invites: sent by email with a single-use, expiring invite token (stored hashed on our side). Co-planners can view and edit the trip; your display name is visible to them.
- Export and calendar links: signed links that expire after one hour; anyone with the link can access the export while it is valid.
7. Cookies and local storage
We use your browser's storage for: your session token (so you stay signed in), a local cache of your trips (so they stay viewable offline), and small preferences like language and last-viewed trip. We set no advertising cookies, no cross-site trackers, and no third-party analytics scripts. Cloudflare may set strictly-necessary technical cookies for security. You can clear all locally stored data by signing out and clearing your browser's site data.
8. Data retention
- Account, trip, preference, and conversation data: kept while your account exists.
- Unfinished planning conversations: automatically deleted after about 60 days of inactivity.
- Email verification/reset/invite tokens: single-use and short-lived; stored only as hashes.
- Server request logs: kept short-term for security and operations, then rotated.
- Database backups: we keep a rolling window of recent daily backups (roughly the last ten days). Deleted data leaves the backup rotation as those backups age out.
- Usage events: pseudonymous by design (internal account ID only). After you delete your account they are retained as aggregate product statistics, but no longer link to any identifiable account record — the account they pointed at no longer exists.
9. Deleting your account
You can delete your account yourself in the app (Account settings → Delete account; password confirmation required unless you signed up via SSO). Deletion immediately and permanently removes your account, trips, itineraries, conversations, preferences and profile notes, alerts, notifications, share links, and sessions from our live database. Copies in rotating backups age out as described above. You can also email us to request deletion.
10. Security
Honestly stated: passwords are stored as bcrypt hashes; email-borne tokens (verification, reset, invites) are stored only as SHA-256 hashes; sessions use random, expiring tokens; export links are signed and expire after an hour; all traffic is encrypted in transit (TLS); production access is limited to the operator. We deliberately collect little (no payment data, no precise location tracking, no ad IDs) because the best protection for data is not holding it. No online service can promise perfect security — if we learn of a breach affecting your data, we will notify you as required by law.
11. Your rights and controls
Built into the app, today:
- Delete your account (and all your data) — Account settings.
- Sign out of your other devices — Account settings.
- Edit or delete any trip, conversation, or preference, including the AI-maintained profile notes.
- Email controls: verification and reset emails are transactional; price alerts stop when you delete the alert; trip reminders and weekly digest emails have opt-outs in Account settings and a one-click unsubscribe link in every such email.
- Revoke share links and remove co-planners.
By email ([email protected]): you can request a copy of your data, correction, or deletion, and we will act on it within 30 days.
If you are in the EEA, UK, or a jurisdiction with similar laws: we process your data to perform our contract with you (providing the Service), for our legitimate interests (security, abuse prevention, product improvement using pseudonymous events), and with your consent where required (non-essential emails). You have rights of access, rectification, erasure, portability, restriction, and objection, and the right to complain to your local supervisory authority. We are a small US company and have not appointed an EU/UK representative.
California residents: we do not sell or "share" personal information as defined by the CCPA/CPRA, and we honor access and deletion requests from anyone, regardless of where you live.
12. International transfers
We are US-based, and your data is processed and stored in the United States (our own database servers, plus the US-based providers listed above). If you use the Service from outside the US, you understand your data is transferred to and processed in the US, where privacy laws may differ from those in your country.
13. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, contact us and we will delete it.
14. Changes to this policy
We may update this policy as the product evolves. Material changes will be posted here with a new effective date, and we will make reasonable efforts to notify you in the app or by email. Continued use after a change means you accept the updated policy.
15. Contact
Golden Tempo LLC (New Jersey, USA)
[email protected]