RoamWeek

Privacy Policy

Last updated: 2026-08-23

1. Who to contact

RoamWeek is an AI trip planning service operated from France. For anything about your data, including exercising the rights in section 8, write to privacy@roamweek.com. For anything else, support@roamweek.com. We answer within one month, which is the deadline the GDPR sets.

2. What we collect

  • Your account. Email address and a display name.
  • Your travel profile. Travel style, interests, budget level, pace, traveler type, and any dietary preferences or mobility notes you choose to write.
  • What you ask for. The text of every trip request you type. This is free text you wrote about your own trip, so it is the most personal column in our database and we treat it that way. It is stored once, against the trip it produced, and is used to regenerate or explain that trip.
  • What we produce. The generated itinerary, its days and activities, and any edits you make.
  • Your travel history. Destinations, ratings and notes you add, used to personalise later suggestions.
  • Usage and balance. How many trip plans you have left, how many you have generated, and a timestamped record of each generation. This record holds no prompt text.
  • Purchases. If you buy trip plans, we keep the amount, the currency, what it bought, and Stripe's identifiers for the payment. We never see or store your card number.
  • Technical data. Our host sees your IP address and request metadata, as any web server does.

3. Why we are allowed to process it

GDPR Article 13(1)(c) requires a lawful basis for each purpose. Ours are:

  • Performance of a contract for creating your account, generating and storing itineraries, publishing a trip when you press Share, and taking payment for trip plans. Without this data there is no service to provide.
  • Legitimate interest for keeping the service up, preventing abuse, and enforcing quotas. Our interest is not having the AI budget drained by automated traffic; the effect on you is a request count in a database.
  • Legal obligation for keeping records of money taken.

We do not sell your data or disclose it for advertising, we run no advertising, and we do not train any model on it. We disclose only what is needed to the processors listed below to provide and secure the service.

4. Who else sees it

These are every processor the application talks to. If we add another, this list changes in the same release.

WhoWhat forWhereWhat reaches them
SupabaseDatabase and authenticationEuropean UnionAccount email, display name, travel preferences, trips, activities.
AnthropicAI model providerUnited StatesYour travel preferences and the text of your trip request, sent on each generation.
VercelHostingUnited States and European UnionRequest metadata including IP address, for serving and securing the site.
StripePayment processingUnited States and European UnionYour email and billing details when you buy trip plans. Card numbers never reach us.
ResendTransactional email and operator notificationsUnited States and European UnionAccount email and basic account or purchase event details. Passwords, card numbers and travel prompts are never sent.
UnsplashDestination photographyUnited StatesA destination search term. No information about you is sent.
OpenStreetMap FoundationMap tilesUnited Kingdom and European UnionYour IP address and the map area you are looking at, requested by your browser.

Two of these are worth spelling out because they are easy to miss. Map tiles are fetched by your browser directly from the OpenStreetMap Foundation, which means it sees your IP address and the area of the map you are looking at, including on a shared trip page viewed by someone with no account. And your travel profile plus the text of your request go to Anthropic on every single generation, because that is what produces the itinerary.

5. Transfers outside the EU

Some of the processors above are in the United States. Those transfers rely on the Standard Contractual Clauses in each processor's data processing agreement, which is the mechanism Chapter V of the GDPR provides for regular, systematic transfers.

We say this precisely because the previous version of this page said something different. It asked you to consent to the transfer. Consent is the Article 49(1)(a) derogation, which exists for occasional and non-repetitive transfers, and every generation is a transfer, so it was the wrong instrument. Naming the real mechanism is both more accurate and better for you: it does not depend on a consent you could be nudged into.

6. Sharing a trip makes it public

Pressing Share on a trip publishes it at a link that anyone holding the link can open, with no account and no sign in. The shared page shows the trip title, destination, dates, the day by day plan, and your display name. It does not show your email, and it does not show the request you typed.

A link is a capability: anyone you send it to can send it on. Turn sharing off on the trip and the link stops working immediately.

7. Cookies and browser storage

  • Strictly necessary cookies keep you signed in. They are set by Supabase, our authentication provider. There is no analytics cookie, no advertising cookie and no tracking pixel, which is why you are not being asked to dismiss a banner.
  • Local storage. If you type a trip idea on the home page before you have an account, your browser saves that text under the key roamweek_pending_prompt so it is still there after you sign up. It is read once, then deleted. It never leaves your device until you sign in and generate. This is storage on your own device and we mention it because being small is not the same as being exempt.
  • Stripe. If you go to checkout, Stripe sets its own cookies on its own pages for fraud prevention.

8. Your rights, and how to use them

You can ask for a copy of your data, correct it, restrict or object to how it is used, take it elsewhere, or have it erased. Write to privacy@roamweek.com. You can also complain to the CNIL, the French supervisory authority, at cnil.fr.

Deleting your account. Profile, then Delete account. It asks you to confirm, and then it is done immediately and cannot be undone. It removes your account, your profile, every trip and its days and activities, your travel history, your remaining trip plan balance and your usage records. Any trip you had shared stops being reachable at the same moment.

One thing survives, and you should know which. The record of a payment stays, detached from you: amount, currency, what it bought and Stripe's identifiers, with no link back to a person. Keeping records of money taken is a legal obligation, which is the exception GDPR Article 17(3)(b) makes to erasure.

9. How long we keep things

  • Account, profile, trips and prompts: for as long as your account exists. Deleting the account deletes them the same day.
  • Usage records: 24 months, then removed. They hold a timestamp and a count, never prompt text.
  • Rate limit counters: 7 days.
  • Payment records: 10 years from the payment, which is the retention French accounting rules require.
  • Server logs: kept by our host on its own schedule for security and debugging, and not used for anything else.

10. Automated decisions

An AI model writes your itinerary. That is the product, and it is disclosed on the generate page before you use it. Nothing here makes a decision with a legal or similarly significant effect on you, so the Article 22 rules on automated decision making are not engaged. The model can be wrong, and the terms say so plainly.

11. Changes

If this policy changes materially, we email the address on your account before the change takes effect. The date at the top always reflects the current version.