Privacy Policy
Last updated: [pending — set on first save]
This describes what data Nabu collects, why, and what we do with it.
Data we collect
When you sign up:
- Email, name, password (hashed with bcrypt — we never store the plaintext).
- Optional profile fields: phone, gender, nationality, passports & residencies, date of birth, location, interests, bio, profile photo.
When you use the service:
- Trip plans you create (destinations, dates, preferences, generated itineraries).
- Edits, ratings, and feedback you give on activities.
- Web requests (IP address, user agent) for security and rate limiting. The IP is hashed (SHA-256) before storage.
Why we collect it
- To run the service: generate itineraries that match your preferences.
- To improve personalisation: build a "travel persona" from your trips and feedback so future itineraries fit you better.
- To prevent abuse: rate limit, detect anomalies, support investigations.
- To communicate: account emails (verification, password reset, completed itineraries) and — only if you opted in — product updates.
Sub-processors
- Railway — application hosting, PostgreSQL, and private Redis rate limiting
- Resend — transactional email delivery
- UploadThing — image upload and CDN
- Whop — ticket purchase processing
- Sentry — error monitoring (no PII in stack traces)
- Anthropic, OpenAI, Google — AI providers we send your prompt and (where enabled) web-search context to.
Your rights
You can:
- Export your data — download everything we hold about you as JSON, from your profile page.
- Delete your account — from your profile page. We scrub personal fields.
- Correct or update any profile field at any time.
- Opt out of product-update emails at any time.
Retention
- Account data: kept while your account is active. Deleted accounts have PII scrubbed within 30 days.
- Trip data: kept while your account is active so collaborators retain access to shared trips.
Contact
Privacy questions: hello@itsnabu.com