Legal

Privacy notice

As of September 2026

This is a courtesy translation. The German version is the legally binding one — it is the text this notice is owed in, and the one that governs if the two ever disagree.

1. Controller

The controller for the processing of personal data within the meaning of Art. 4(7) GDPR is:

Martin Lux Büchlweg 16 82041 Oberhaching Deutschland

Email: martin.lux0102@gmail.com

No data protection officer has been appointed, as the conditions of Art. 37 GDPR and § 38 BDSG are not met.

2. Your rights

You have the right at any time to

  • access the data stored about you (Art. 15 GDPR),
  • have inaccurate data corrected (Art. 16 GDPR),
  • have your data erased (Art. 17 GDPR),
  • have processing restricted (Art. 18 GDPR),
  • data portability (Art. 20 GDPR), and
  • object to processing based on a legitimate interest (Art. 21 GDPR).

You may withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR). Independently of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR); the competent authority is the one where you habitually reside or the one for the controller.

An informal message to the email address above is enough to exercise these rights.

3. Opening the application and server log files

When this application is opened, our hosting provider processes technically necessary data, in particular the IP address, the date and time of the request, the page requested, the volume of data transferred, the referrer and details of the browser and operating system.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the stable, secure operation of the application and in preventing misuse. This data is not combined with other data sources.

4. User account and sign-in

To use the service you create an account. In doing so we process your email address, a password and, optionally, a display name. The password is stored by our authentication service exclusively as a cryptographic hash; the plain text is never known to us.

Alternatively you can sign in with your Google account. In that case we receive from Google the details required for signing in, in particular your email address. Your Google password is not transmitted to us.

The legal basis is Art. 6(1)(b) GDPR, as the processing is necessary to provide the service you have requested.

5. Storage in your browser (§ 25 TDDDG)

So that you stay signed in, the application stores a session token in your browser's local storage. It is removed when you sign out.

This storage is strictly necessary for you to be able to use the service and is therefore permitted without consent under § 25(2) no. 2 TDDDG. The legal basis for the subsequent processing is Art. 6(1)(b) GDPR.

We do not use cookies or comparable technologies for analytics, tracking or advertising, and we embed no analytics services, social media plug-ins or external fonts.

6. Travel data and travel preferences

For each trip we store the details you enter: title, destination, country, dates, trip type, number of travellers, stops with their coordinates, and the suggested and saved places to stay, activities and day plans.

You can also record travel preferences: pace, budget level, interests, food preferences, preferred types of accommodation, maximum daily driving time, whether and with children of what age you are travelling, things you would like to avoid, and a free-text field for notes on mobility.

This data is associated with your account and is not visible to other users within the application. The legal basis is Art. 6(1)(b) GDPR.

7. Mobility notes and details about children

Please note: the free-text mobility field is voluntary. What you enter there may allow conclusions to be drawn about your health and may therefore constitute a special category of personal data within the meaning of Art. 9 GDPR. The same applies to the ages of accompanying children, which concerns the data of a minor.

Where you have provided them, both are transmitted to Anthropic PBC together with your other preferences when a trip plan is created (see section 9). To the extent that this is data under Art. 9 GDPR, we base the processing on your explicit consent under Art. 9(2)(a) GDPR, which you give by entering the information voluntarily and starting the plan. You can withdraw that consent at any time by clearing the field.

If you do not want this transmission, leave the mobility field empty and do not enter the ages of accompanying children. Planning works without these details; the suggestions will simply fit less precisely.

8. Place search via Google Places

When you enter a destination or have a trip plan created, we transmit the search term and, where applicable, the coordinates of the destination concerned to the Google Places service operated by Google Ireland Limited, in order to identify real places, accommodation and activities.

If you have written something in the "Preferences for this trip" field, that text is also sent to Google as a search term — it is the only way to find places that match what you asked for rather than general sights. What you write there therefore leaves our server; please do not enter anything there that Google should not learn. The field is optional and planning works without it.

The request is made exclusively via our server; your IP address is not transmitted to Google. Your saved travel preferences and your account data are not transmitted. Responses are cached by us for up to 30 days in order to limit the number of queries.

The legal basis is Art. 6(1)(b) GDPR.

9. AI-assisted trip planning

When you have a trip plan created, we transmit the trip's key details (title, destination, country, dates, trip type, number of travellers, stops, your own notes on the trip), the travel preferences you have recorded including the details named in section 7, and the place suggestions found beforehand, to Anthropic PBC, and have an AI model produce suggestions for accommodation, activities and a day plan from them.

Your name, your email address and your account identifier are not transmitted.

The legal basis is Art. 6(1)(b) GDPR, as this processing is part of the function you requested; for data under Art. 9 GDPR, Art. 9(2)(a) GDPR additionally applies. Planning is always started by you and does not happen automatically.

There is no automated decision-making within the meaning of Art. 22 GDPR: the suggestions are non-binding, have no legal effect on you, and can be accepted, changed or discarded by you.

10. Planning together and invitations

You can share a single trip, or your whole account, with another person. Someone who accepts an invitation to a trip can see and change that trip and can invite others in turn. Someone who accepts an invitation to your account can see and change every trip you own, including ones you create later. Your travel preferences stay private either way. Sharing works in one direction only: the person you invite does not thereby share their own trips with you.

Your display name is visible to the people you share with, so that it is clear who has access. The legal basis is Art. 6(1)(b) GDPR.

An invitation is a link. For each one we store whether it is for a trip or for the account, who created it, the expiry date, the time of withdrawal where applicable, and — only if you have the invitation sent by email — the recipient's email address as you entered it. Of the link itself we store only a cryptographic hash, not the link.

If you have the invitation sent by email, we transmit the email address you entered, your display name (or, failing that, your email address), the title of the trip concerned and the invitation link to Resend, Inc., which sends the message. If you pass the link on yourself instead, no email address is transmitted and none is stored.

The legal basis for sharing is Art. 6(1)(b) GDPR. We base the processing of the recipient's email address on Art. 6(1)(f) GDPR; the legitimate interest is in delivering the invitation you initiated. We send no reminders and no advertising to that address. Please enter only addresses belonging to people who will be expecting such a message.

11. Recipients

We do not pass your data on for advertising purposes and do not sell it. To provide the service we use the following processors:

Lovable (Lovable Labs Incorporated)

Hosting of the application and operation of the database and authentication (Lovable Cloud, technically based on Supabase). Account, trip and preference data is held here.

Registered office: EU and/or USA

Google Ireland Limited

Place search via the Google Places API and, where Google sign-in is used, authentication.

Registered office: Ireland; processing by Google LLC in the USA is possible

Resend, Inc.

Sending the invitation emails. The recipient address you entered and the content of the invitation are transmitted.

Registered office: USA

Anthropic PBC

AI-assisted creation of suggestions for accommodation, activities and day plans.

Registered office: USA

Beyond this we pass data on only where we are legally obliged to do so.

12. Transfers to third countries

With the processors named above, processing outside the EU or the EEA — in particular in the United States — cannot be ruled out. Such transfers are based on the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR, unless the provider concerned can rely on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework of 10 July 2023.

Despite these safeguards it cannot be entirely ruled out that US authorities may access transmitted data.

13. Retention

We store account, trip and preference data for as long as your account exists. If you delete a trip, its stops, accommodation suggestions, activities and day plans are removed with it. On your request we delete your account together with all associated data.

Cached place search responses expire after 30 days at the latest. They are not associated with your account. Server log files are kept by our hosting provider only for a short period. Statutory retention obligations remain unaffected.

14. Data security

Transmission is encrypted throughout, via HTTPS/TLS. Access to trip and preference data is secured at the database level: preferences can be reached only by the account they belong to, and a trip only by its own account and the accounts it has been shared with under section 10. Access keys for the services named above are held exclusively server-side and do not reach your browser. We also take appropriate technical and organisational measures under Art. 32 GDPR.

15. Changes to this privacy notice

We adapt this notice when the application or the legal situation changes. The version published on this page applies.

The provider details are in the legal notice.