TraveladoSign in

Privacy Policy

Effective date: June 12, 2026

Travelado (“we,” “our,” or “us”), a product of Typeone LLC, operates the Travelado web application at travelado.ai and the Travelado iOS application (together, the “Service”). Travelado is a trip-operations app: you forward travel confirmation emails to a personal @travelado.ai address or upload documents, and the Service extracts booking facts, builds per-traveler trip timelines, detects gaps and deadlines, and sends you notifications.

This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data. By using Travelado, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use of the Service. For a plain-language summary of how your data is stored, encrypted, and deleted, see Your data & security.

1. Information We Collect

1.1 Account Information

When you create a Travelado account, we collect your email address and a display name. Travelado signs you in with a magic link sent to your email — we do not collect or store passwords.

1.2 Travel Documents and Forwarded Emails

The core of the Service is the travel documents you give us. When you forward a confirmation email to your personal @travelado.ai address or upload a document, we collect:

  • The forwarded email, including its sender, subject, body, and attachments.
  • Documents you upload directly (e.g., PDF confirmations, tickets, itineraries).

The original document is retained so you can always see the source of every extracted fact. Your forwarding address is unguessable and only works for building your trips.

1.3 Extracted Booking Data

We process your documents to extract structured booking facts, which may include:

  • Flight, hotel, transport, and activity details (times, locations, providers).
  • Confirmation codes and booking references.
  • Traveler names as they appear on bookings.
  • Deadlines such as check-in windows and cancellation cutoffs.

Every extracted fact keeps a link to the document it came from, so you can verify anything the AI produced.

1.4 AI Processing and Chat History

Documents are processed by Anthropic's Claude AI models to extract booking facts and check your trips for problems. If you use the AI trip assistant, we store your chat history so the assistant can maintain context. Your data is not used to train AI models. We use Anthropic under a commercial API agreement; Anthropic does not train on API data by default. Anthropic processes data pursuant to its own Privacy Policy.

1.5 Trip Membership and Sharing Data

When you create, join, or are invited to a trip, we store trip membership records (which accounts belong to which trips, and in what role) so we can enforce access control and deliver trip-related notifications to the right people.

1.6 Device and Notification Data

If you enable push notifications on iOS, we store a device push token so we can deliver alerts to your device. We also collect limited technical information (such as app version) for debugging and support.

1.7 Usage Data

We collect basic usage information to operate and improve the Service, including AI token-usage records associated with your account (used for plan limits and cost monitoring). This usage data does not include advertising identifiers and is not shared with advertisers.

1.8 Cookies

The web application uses only essential cookies and browser storage needed to keep you signed in. We do not use advertising or cross-site tracking cookies.

1.9 What We Do Not Collect

  • Passwords — sign-in is by email magic link only.
  • Payment card numbers — if and when paid billing launches, payment details will be handled by a payment processor, not stored by us.
  • Precise device location — we do not access GPS data.
  • Advertising identifiers or cross-app tracking data.

2. How We Use Your Information

  • To authenticate you and maintain your account.
  • To provide the core features of the Service: ingesting documents, extracting booking facts, building per-traveler trip timelines, detecting gaps and deadlines, and answering questions via the AI assistant.
  • To send you notifications about your trips (email and push), such as detected gaps, approaching deadlines, and trip activity.
  • To share trip content with the trip members you invite (see Section 3.1).
  • To enforce plan limits and monitor service costs (e.g., AI token usage).
  • To respond to support requests sent to support@travelado.ai.
  • To secure the Service and prevent abuse.
  • To comply with applicable laws and regulations.

3. How We Share Your Information

We do not sell, rent, or trade your personal information. We do not show ads. We share data only in these circumstances:

3.1 With Trip Members

Trips can be shared with people you invite. Members of a trip can see that trip's content — its timeline, documents, extracted booking facts, and traveler details on that trip. Access is enforced in the database itself (row-level security keyed to trip membership). Do not add documents to a shared trip that you do not want its members to see.

3.2 Service Providers

We use the following providers to operate Travelado. Each processes data only to provide its service to us:

  • Supabase — database, authentication, and document storage (encrypted at rest with AES-256, TLS in transit; SOC 2 Type II).
  • Cloudflare — inbound email routing for your @travelado.ai address and storage of raw inbound email (AES-256 at rest).
  • Anthropic — AI processing of document content and assistant chats (not used for AI training).
  • Resend — transactional email delivery (magic links, notifications).
  • Apple — push notification delivery to the iOS app.
  • Vercel — web application hosting.

3.3 Legal Requirements

We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of Typeone LLC, our users, or the public.

3.4 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred. We will provide notice before your data becomes subject to a different privacy policy.

4. Data Storage and Security

  • Documents and trip data are stored with Supabase; raw inbound email is stored with Cloudflare. Both encrypt data at rest with AES-256 and in transit with TLS.
  • Access to trip data is enforced with database row-level security keyed to trip membership — there is no code path that shows your trip to a non-member.
  • Travelado staff do not browse customer data; operational access is limited to debugging with your consent.
  • API keys and secrets are stored server-side and never embedded in client applications.

No system is completely secure, and we cannot guarantee absolute security. Because sign-in is tied to your email, we recommend protecting your email account with two-factor authentication. To report a security issue, contact security@travelado.ai.

5. Data Retention and Deletion

  • You can delete any document (and its extracted facts) from the app at any time. Deleted documents are removed from view immediately and permanently erased from storage within 30 days.
  • You can delete your entire account from Settings. Account deletion removes your documents, stored files, raw forwarded emails, trips you own, AI chat history, push tokens, and your profile.
  • Trips you own that have other members can be transferred to another member before deletion, so companions don't lose their plans.
  • Raw forwarded emails are purged as part of deletion; they are not retained after your account is deleted.
  • We may retain limited records where required by law (for example, records of a deletion request).

Deletion is permanent.

6. Your Rights and Choices

6.1 Access and Portability

You can view your documents, extracted facts, and trip data directly in the app. You may request a copy of the personal data we hold about you by contacting support@travelado.ai.

6.2 Correction

You can update your account information in Settings and edit or correct trip data in the app, or contact us for help.

6.3 Deletion

Use per-document deletion or account deletion in Settings (see Section 5), or contact support@travelado.ai. We will process deletion requests within 30 days.

6.4 Notifications

You can disable push notifications in your device settings. Transactional emails essential to the Service (such as sign-in magic links) cannot be disabled while you hold an account.

7. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: request disclosure of the categories and specific pieces of personal information we collect and how they are used and shared.
  • Right to Delete: request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: we do not sell your personal information or share it for cross-context behavioral advertising, so no opt-out is needed.
  • Right to Non-Discrimination: we will not discriminate against you for exercising any of these rights.

To exercise your California rights, contact support@travelado.ai. We will respond within 45 days as required by law.

8. European and UK Privacy Rights (GDPR / UK GDPR)

If you are located in the European Economic Area or United Kingdom, you have rights under GDPR / UK GDPR, including access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent.

8.1 Legal Bases for Processing

  • Contract performance: processing necessary to provide the Service you signed up for, including processing the documents you submit.
  • Legitimate interests: improving the product, preventing abuse, and ensuring security.
  • Legal obligation: compliance with applicable law.
  • Consent: where you have specifically opted in.

8.2 International Transfers

Your data may be transferred to and processed in the United States. Where such transfers occur, we rely on appropriate safeguards, including Standard Contractual Clauses where applicable.

To exercise your GDPR rights, contact support@travelado.ai. You also have the right to lodge a complaint with your local data protection authority.

9. Children's Privacy

Travelado is not directed to children under the age of 13 (or 16 in the EEA), and we do not knowingly collect personal information from children. Note that travel documents you submit may contain the names of minor travelers in your party; this information is provided by you, processed only to build your trip, and protected like all other trip data. If you believe a child has provided us with personal information directly, contact support@travelado.ai and we will promptly delete it.

10. Third-Party Links and Services

The Service may reference or link to third-party services (such as airline or hotel websites). This Privacy Policy does not apply to those third parties, and we encourage you to review their privacy policies. We are not responsible for the privacy practices of third-party services.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the Service or by email at least 14 days before the change takes effect. Continued use of Travelado after that period constitutes acceptance of the updated policy. The effective date at the top of this page reflects the most recent revision.

12. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy:

See also: Terms of Service · Your data & security