Rotate your device to portrait

Ollin is designed to be held upright.

Privacy Policy

Last updated: July 17, 2026

The short version

  • We collect what you put into Ollin: your account, trips, bookings, group members, expenses, photos, checklists, and chat.
  • If you forward booking emails or connect your Gmail or Outlook (Pro), we store the raw email, use Anthropic's Claude to extract the booking details, and purge the raw content within 90 days.
  • By default we use only strictly-necessary cookies. In the EEA, UK, and Switzerland our product analytics is anonymous and cookieless until you opt in; elsewhere (including the US) it is on by default and you can opt out anytime in Settings or via “Your privacy choices” in the footer. We always honor Global Privacy Control and Do Not Track.
  • We never sell or share your personal information for advertising, and there are no ad trackers in Ollin.
  • Trip photos are stored privately and served through expiring signed links; photos on trips you make public are viewable by anyone with the share link.
  • If you use the optional Passport vault, your passport, Known Traveler, and loyalty numbers are encrypted (AES-256-GCM) before they're stored, and shared only with a travel partner you choose to link.
  • You can delete your account and everything in it any time from Settings in the app, or email hello@jaunttrips.com.

This summary is here to help you skim — the full policy below is what governs.

Who we are

Ollin is an AI travel planner and in-trip companion ("Ollin", "we", "us", "our"). Ollin is operated from the United States and is the controller of the personal information described in this policy. For anything privacy-related, reach us at hello@jaunttrips.com.

This policy explains what we collect, why, who we share it with, how long we keep it, and the choices and rights you have. We've added a plain-language note to most sections so you can skim.

Information we collect

Almost everything we hold is information you choose to put into Ollin:

  • Account information — your email address, display name, and profile photo (avatar), provided directly or by your sign-in provider (for example Google) through our authentication provider, Supabase.
  • Profile and preferences — your home city, home airport, base currency, and the travel preferences you save to personalize planning.
  • Trips and itineraries — destinations, dates, places, itinerary and reservation items, notes, votes, task assignments, and booking details you add or import, including confirmation numbers, costs, and (for cruises) cabin and occupant names.
  • Group members and invitations — when you invite someone to a trip by email, we store that email address (before they have an Ollin account) so we can deliver the invitation and connect them to the trip when they join. We also store friend connections you save.
  • Expenses and settlements — shared costs you log, currencies and exchange rates, and how costs are split and settled among the group.
  • Photos — pictures you upload to a trip, with any captions. Photos are stored in a private storage bucket and served through signed links that expire automatically, so they're viewable only by the trip's members — unless you make the trip publicly shareable (see How your information is shared). Note: we resize large photos but do not strip embedded metadata (such as EXIF location) from photos you upload, so avoid uploading photos whose metadata you don't want shared with the trip's members.
  • Checklists and packing lists — packing and to-do items you create for a trip.
  • Messages — in-trip group chat and your concierge ("Ask Ollin") conversations, which we store so they persist across your devices.
  • Passport vault (optional) — if you choose to use it, the travel identity numbers you save (passport number and expiry, Known Traveler / PreCheck number, and airline and hotel loyalty numbers). These are encrypted before storage — see Passport vault.
  • Travel partner — if you link a travel partner, we record that connection so your trips, packing lists, and Passport vault stay in sync between you (see How your information is shared).
  • Emails you forward or let us scan — described in Connected inboxes and email forwarding.
  • Limited usage, device, and log data — described in Cookies, analytics, and your choices, and in Security.

Aside from the Passport vault you choose to fill in, we do not ask for, and Ollin does not need, special-category data (such as health, religion, or precise background location). Please don't put sensitive personal information into trip notes or chat.

Connected inboxes and email forwarding

Ollin can turn booking confirmation emails into itinerary items in two ways: you can forward an email to your trip's private, per-trip import address, or — on the Pro plan, where enabled — connect your Gmail or Outlook account so Ollin periodically scans your mailbox for travel booking emails and imports them automatically.

When you use these features, we store the raw email — including its full text — in our database while we process it. We use Claude, an AI model from Anthropic, to read the email and extract booking details such as flights, hotels, reservations, confirmation numbers, and costs. Booking emails often contain personal information about other people — fellow travelers' names, loyalty numbers, phone numbers — so only forward or connect content you have the right to share.

Raw forwarded or scanned email content is kept only as long as needed for parsing and troubleshooting: we remove the raw email body after 30 days and delete the processing record entirely within 90 days. The structured booking details we extract stay on your trip until you delete them.

If you connect Gmail or Outlook, we request read-only mailbox access, search only for travel-related messages (using keywords like confirmation, reservation, booking, itinerary, and check-in), and your OAuth access and refresh tokens are encrypted at rest with AES-256-GCM. You can disconnect an integration at any time from within the app, which stops all scanning and removes the stored tokens.

Ollin's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to identify and import travel bookings into your trips — never for advertising — and we don't allow humans to read your email except with your explicit permission, where necessary for security, or to comply with law. We apply the same standards to Outlook data.

Passport vault

The Passport vault is an optional place to keep the travel identity numbers you reach for at booking and check-in: your passport number and expiry, your Known Traveler / PreCheck number, and airline and hotel loyalty numbers. You only ever store what you choose to type in, and you can edit or delete any entry — or the whole vault — at any time.

Because these are sensitive, we encrypt each number with AES-256-GCM before it's written to our database, so the stored value is ciphertext, never plaintext, and a database dump alone can't reveal it. In the app we show the numbers masked (for example, •••• 7709) until you reveal them. Access is limited by database row-level security to you and, if you link one, your active travel partner. We do not send your Passport vault to any AI model, advertiser, or booking partner.

Flight status and delay alerts

When you add a flight to a trip, Ollin can look up its live status to power gate, delay, and departure reminders. To do this our servers send the flight number and date to FlightAware's AeroAPI and store the status details (times, gates, terminals, delay minutes) on the trip. We send only the flight and date — not your name or account — and you can remove a flight, or turn its notifications off, at any time.

Destination briefings

For some destinations, Ollin generates a short, news-grounded "what to know right now" briefing (safety, events, and travel notes). Our servers fetch recent news headlines for the destination from GNews and pass them to Claude to summarize. We send only the destination name — never your identity — and a single briefing is cached and shared across everyone viewing that place, so this feature isn't tied to you personally.

How we use your information

We use your information to:

  • Provide Ollin — create and sync trips across your devices, enable group planning and voting, split expenses, store photos and checklists, and power group and concierge chat.
  • Power AI features — generate itineraries, answer concierge questions, build trip recaps, and parse booking emails (see AI processing).
  • Send transactional email — trip invitations and account-related messages — through Resend.
  • Send notifications you opt into — web push for trip countdowns, day-of itineraries, time-sensitive reminders, booking nudges, and group activity.
  • Process subscription payments and manage your plan through Stripe.
  • Keep Ollin secure and reliable — prevent abuse, rate-limit and debug our systems, and monitor service health.
  • Understand how the product is used, within the limits in Cookies, analytics, and your choices.
  • Comply with law and enforce our Terms of Service.

Where the law requires a legal basis (for example, in the EU/EEA and UK), we rely on: performance of our contract with you (to provide the service you ask for); your consent (for optional analytics, affiliate tracking, and push notifications); and our legitimate interests in keeping Ollin secure, reliable, and improving (balanced against your rights).

We do not sell your personal information, and we do not use it for third-party advertising.

AI processing by Anthropic Claude

Ollin's planning features are powered by Claude, an AI model provided by Anthropic, accessed over Anthropic's API. We send Claude only the content each feature needs: your trip details and saved preferences when generating an itinerary; your messages and relevant trip context when you chat with the concierge; your trip's highlights when creating a recap; and forwarded or scanned emails when extracting bookings. Email parsing in particular can include personal information about you and others contained in the email.

When the concierge needs current information, it may run a web search through Anthropic; in that case model-generated search queries (with a destination hint) are sent to Anthropic's search provider, but your identity is not.

Under Anthropic's commercial API terms, the inputs we send and the outputs we receive are not used to train Anthropic's models. This is a contractual commitment from Anthropic, not something Ollin enforces in code.

Service providers and sub-processors

We use a small set of providers (sub-processors) to run Ollin. Each one processes information only to provide its service to us, under contract:

  • Supabase — database, authentication, and file storage (United States).
  • Vercel — application hosting, plus privacy-friendly, cookieless aggregate web analytics.
  • Anthropic — Claude AI for itinerary generation, concierge chat, trip recaps, and email parsing; inputs and outputs are not used to train its models.
  • Stripe — subscription payments and billing. Your card details go directly to Stripe and never touch our servers.
  • PostHog — product analytics, hosted in the United States (cookieless and anonymous until you opt in in the EEA/UK/Switzerland; on by default with an opt-out elsewhere — see the cookies section).
  • Resend — transactional email delivery (we send from hello@jaunttrips.com).
  • Google — Maps and Places features (these run in your browser; see Maps, geocoding, and weather), and Google sign-in and Gmail import where you use them.
  • Microsoft — Outlook mailbox import, only if you connect an Outlook account.
  • FlightAware (AeroAPI) — live flight status for delay and gate alerts; we send a flight number and date, not your identity (see Flight status and delay alerts).
  • GNews — recent news headlines used to ground destination briefings; we send a destination name, not your identity (see Destination briefings).
  • OpenStreetMap — map tiles, and its Nominatim service for looking up place coordinates (we send place names, not your identity).
  • Open-Meteo — weather forecasts (we send coordinates and dates, not your identity).
  • Pexels and Unsplash — destination and cover imagery; we send only a destination search term, not your identity.
  • Travelpayouts, GetYourGuide, and Stay22 — affiliate/booking partners for outbound booking links. Most attribution rides the outbound link itself; the Travelpayouts measurement script follows your analytics choice — opt-in in the EEA/UK/Switzerland, on by default with an opt-out elsewhere (see Booking links and affiliate partners).
  • Upstash — rate-limiting infrastructure used to protect our inbound endpoints.

We keep this list current and will update this section as our sub-processors change.

Cookies, analytics, and your choices

By default, Ollin uses only strictly-necessary cookies and storage:

  • Supabase authentication cookies that keep you signed in.
  • Short-lived security cookies during sign-in, including a 10-minute cookie that protects the Gmail/Outlook connection handshake against forgery.
  • A per-session flag that remembers the launch splash has been shown, your saved analytics-consent choice, and a coarse, non-identifying region flag (derived from your approximate country) used only to set your default privacy posture.
  • Service-worker caches that let the app work as a PWA and load offline.

How our product analytics (PostHog) behaves by default depends on where you are. In the EEA, UK, and Switzerland it runs without cookies or device storage until you opt in: events are processed in memory only, are anonymous, and are not linked across sessions or to your identity. Elsewhere (including the US), analytics is on by default and you can opt out at any time — in Settings or via “Your privacy choices” in the footer. Separately, Vercel's web analytics collects aggregate, cookieless usage metrics that aren't tied to your identity, and a small amount of server-side telemetry (for example, errors and onboarding milestones) is recorded against your account so we can keep Ollin working and debug problems.

When analytics is active for you — whether you opted in, or it's on by default in your region — we set a first-party PostHog cookie and a localStorage identifier, and your usage is linked to your account (user id and email) so we can understand how Ollin is used across real journeys. Opting out at any time (in the app or the footer) withdraws this, switches analytics back to anonymous in-memory mode, and removes the identifier.

We honor Global Privacy Control (GPC) and Do Not Track browser signals: when your browser sends one, we treat analytics (and the affiliate measurement script) as denied everywhere, regardless of region, and the signal always overrides any choice stored on the device.

Ollin contains no advertising trackers, and we do not sell or share your personal information as those terms are defined by the California Privacy Rights Act (CPRA).

Maps, geocoding, and weather

Map display and place autocomplete are powered by Google Maps and Places where configured. These run in your browser, so when you view maps or type into place search, Google receives your IP address and what you type, under Google's privacy policy. If Google Maps isn't configured, we fall back to OpenStreetMap tiles, in which case OpenStreetMap's tile servers receive your request instead.

Looking up coordinates for place and destination names (geocoding) and fetching weather are done on our servers via OpenStreetMap's Nominatim and Open-Meteo, so those providers see only place names, coordinates, and dates — not your identity or IP.

Push notifications

If you opt in, Ollin can send web push notifications (for example, trip countdowns, day-of itineraries, booking nudges, and group activity). To deliver them, we store your browser's push subscription (an endpoint and encryption keys) and your notification preferences, including any quiet hours you set. We send notifications through your browser's push service. You can turn notifications off in the app or revoke the permission in your browser at any time.

Photo upload and sharing to Ollin

On supported devices, you can share a photo into Ollin from another app using your device's share menu, which uploads it to the trip you choose. Photos go to a private storage bucket and are served through expiring signed links. As noted above, we don't strip embedded metadata from uploaded photos, and photos on a trip you make public become viewable by anyone with the share link.

How your information is shared

Trips are shared with the people in them: group members can see the trip's itinerary, bookings, expenses, photos, checklists, and chat, according to their role (owner, editor, or viewer). If you create a shareable public trip link, anyone with that link can view what you've chosen to make public — but not private fields like confirmation numbers, costs, or owner details, which are deliberately excluded from public trip pages.

If you link a travel partner, the two of you share your trips and packing lists automatically, and each of you can see the other's Passport vault entries; this is the point of the feature. You can remove a travel partner at any time in Settings, which stops the sharing going forward.

Beyond the service providers listed above, we disclose information only if required by law or legal process, to protect the rights and safety of our users or the public, or — with notice to you where allowed — as part of a merger, acquisition, or sale of the business. We never sell your personal information.

Data retention

We keep your information for as long as your account is active, and then as described here:

  • Account, profile, trip, and photo data — kept until you delete the content or your account.
  • Passport vault entries — kept (encrypted) until you delete the entry or your account.
  • Raw forwarded or scanned email content — body removed after 30 days, processing record deleted within 90 days.
  • Billing records — retained by Stripe as required for tax and accounting purposes.
  • Backups — residual copies may persist in backups for a limited period after deletion before being overwritten.
  • Server logs and analytics events — retained per our processors' default retention periods.

Security

All traffic to Ollin is encrypted in transit (TLS). Mailbox OAuth tokens are encrypted at rest with AES-256-GCM. Trip data is protected by database row-level security so it's accessible only to the members of each trip. Trip photos live in a private bucket served via expiring signed links. Card details are handled entirely by Stripe and never reach our servers. We rate-limit sensitive endpoints (which involves briefly processing IP addresses) to prevent abuse.

No system is perfectly secure. If a breach ever affects your personal information, we'll notify you and the relevant authorities as required by law.

International data transfers

Ollin is operated from the United States, and your information is processed there. If you use Ollin from the EU/EEA, UK, or Switzerland, transfers to us and our processors rely on appropriate safeguards such as the Standard Contractual Clauses and, where applicable, our processors' participation in the EU-U.S. Data Privacy Framework.

Your rights and choices

Depending on where you live, you have some or all of the following rights: to access the personal information we hold about you, to correct it, to delete it, to receive a portable copy, to restrict or object to certain processing, and to withdraw consent at any time (for example, the analytics or push-notification opt-in). If you're in the EU/EEA or UK, you also have the right to lodge a complaint with your data protection supervisory authority.

If you're a California resident, you have the rights to know, delete, and correct your personal information, and to opt out of its sale or sharing — though we don't sell or share personal information in the first place. We will never discriminate against you for exercising your rights.

The fastest path for most of this is self-serve: you can delete your account from Settings in the app, which deletes your account, trips, photos, and mailbox integrations, and cancels any subscription. For anything else, email hello@jaunttrips.com — we respond to privacy requests within 30 days. We may need to verify your identity before acting on a request.

Children

Ollin is not directed at children, and you must be at least 16 to use it. We don't knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us and we'll delete it.

Changes to this policy

We'll update this policy as Ollin evolves. When we do, we'll change the date at the top, and for significant changes we'll notify you in the app or by email before they take effect.

Contact us

Questions, requests, or concerns about privacy? Email hello@jaunttrips.com and we'll be happy to help.

You can also reach us by mail at Ollin, 5411 S. Vine Street, Unit #3, Murray, UT 84107, United States.