Your data
Privacy Policy
This policy explains what Tripuppy collects when you explore cities, save discoveries, and plan a journey — and what we do with it.
Last updated September 2, 2026
Who we are
Tripuppy is a city-first travel discovery and planning service. We help independent travelers understand a city before they visit it. We are not a booking marketplace, and we do not process payments for travel.
This policy applies to the Tripuppy website and related product surfaces, including city pages, journeys, shared trips, sign-in, and feedback.
Information we collect
We collect only what we need to run the product and improve it.
- Account information. If you sign in, we receive your email address and the sign-in method you choose (email and password, a magic link, or Google).
- Journey information. Places, neighborhoods, and experiences you save; trips you create; notes; and whether a trip is private or shared.
- Feedback. The subject, category, message, and the page you were on when you wrote to us. If you are signed in, we associate the conversation with your account.
- Usage information. Pages viewed, cities searched or opened, and product actions such as saving an item or sharing a trip. We do not send email addresses, passwords, or similar secrets into analytics.
- Technical information. A random visitor identifier stored in your browser, approximate acquisition source (such as a campaign or referring site), and standard request data needed to operate the service.
You can explore cities without an account. Saves and trips can stay in this browser until you choose to sign in.
How we use it
We use information to:
- Provide discovery, city pages, journeys, planning, and sharing.
- Keep you signed in and return you to the page you came from.
- Respond to feedback and improve the product.
- Understand how people use Tripuppy, in aggregate, so we can make it clearer.
- Keep the service secure and prevent abuse.
We do not sell your personal information. We do not use it to advertise third-party products to you.
Analytics
On the live site, Tripuppy records product events and page views so we can see what helps travelers understand a city. Events are sanitized: fields that look like email addresses, passwords, or tokens are dropped.
We use Google Analytics (GA4) with anonymized IP addresses. Local development does not send events to Google Analytics. A first-party analytics endpoint also receives the same sanitized events so we can understand the product without relying only on a third party.
Accounts
Authentication is provided by Supabase. If you continue with Google, Google shares the account details needed to sign you in. We do not receive your Google password.
Staff roles, when they exist, live in account metadata used only to operate the product — not in public profiles.
Journeys and sharing
Your journey is private by default. A trip becomes visible to others only if you explicitly enable sharing. Anyone with the share link can then view that itinerary.
Treat a shared link like a public page. Unshare or stop circulating the link if you no longer want it seen.
Feedback
Messages you send through Feedback are read by the Tripuppy team so we can reply and improve the product. Include only what you are comfortable sharing.
AI trip arranging
If you use “Arrange my trip,” we send the trip you are working on — titles, days, and saved items — to an AI provider so it can propose an order. Do not put secrets or sensitive personal details in trip notes if you plan to use this feature.
When the AI service is not configured, Tripuppy falls back to a simple neighborhood heuristic on your device. That draft stays in the product; it is a suggestion, not a booking.
Third parties
We rely on a few processors to run Tripuppy:
- Supabase, for authentication and stored account and journey data.
- Google, for optional Google sign-in and Analytics.
- OpenAI, only when you request an AI-arranged itinerary and that feature is enabled.
- Our hosting provider, to serve the website.
Each of those services processes data under its own terms and privacy policy.
How long we keep it
Account and cloud journey data last as long as your account is active. Local journey data lasts until you clear it from the browser. Analytics events are kept long enough to understand product use and then discarded or aggregated.
Feedback conversations are kept so we can continue a thread and learn from it. If you want a conversation removed, ask us through Feedback.
Your choices
- Explore without creating an account.
- Sign out at any time from your account menu.
- Keep trips private, or share a link only when you choose.
- Clear this browser’s local storage to remove a local-only journey.
- Use browser controls to block analytics cookies. Some measurement will then be incomplete.
- Ask us, through Feedback, to correct or delete personal information we hold in the cloud.
Children
Tripuppy is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us through Feedback and we will delete it.
Changes
If this policy changes in a material way, we will update the date at the top of this page. Continued use of Tripuppy after an update means you accept the revised policy.
Contact
Questions about privacy belong in Feedback— the same channel the team uses to talk with travelers. You can also read our Terms of Service.