At a glance: Trip planning sends your prompt and selected preferences to our server and relevant service providers. The web app uses product analytics and stores some data in your browser. Operational records and cached attractions can persist on the server. Basic web trip generation does not require an account.
1. Information processed
Your trip request can include destinations, dates, adult counts, children’s ages, pet details, activity and food preferences, and any profile context you choose to supply. Free-text prompts and imported profiles can contain personal information you enter; avoid including passport numbers, payment details, or other information the planner does not need.
The web app can request browser location permission. If you grant it, the app can use coordinates as planning context. If location is unavailable, the backend can send your IP address to ipapi.co to estimate your region. Hosting and analytics providers also process network and browser information when you access the service.
If you use account-backed profile, feedback, or group-trip features available in your client, the backend can store the data you provide for those features, including account identifiers and shared trip information.
2. How we use this information
We use trip inputs to interpret your request, resolve destinations, obtain weather and place details, generate itinerary and safety suggestions, and build rule-based packing recommendations. We use operational and usage data to investigate errors, measure generation speed, and understand which features people use.
The current search telemetry records a prompt-length bucket rather than the full search text. Selected trip attributes, including destination, duration, and traveler counts, can appear in analytics or operational records. This does not mean trip inputs stay on your device: the planning service and AI providers process the request.
3. Storage and retention
The browser stores trip results, recent destinations, packing progress, custom items, preferences, and imported profile data. Some records have expiration rules, while others remain until you clear them. Starting another trip does not erase all browser data.
The backend can retain operational metrics, errors, cached attraction records, and data associated with optional profile, feedback, or group-trip features in Supabase. These records are not all discarded after a response. Clearing browser data or uninstalling a native app does not delete server records or copies already processed by third-party services.
Retention differs by record type and provider. We do not promise a single deletion period for all data. Contact the project owner using the links below with a question about stored information or a deletion request.
4. Service providers and external links
Providers receive the information needed for the feature you use, along with connection data associated with their requests. The active AI model and fallback provider can change.
- OpenAI, Google Gemini, and Anthropic: trip prompts, constraints, relevant profile context, and planning data for parsing, itinerary or safety generation, and fallback processing.
- Nominatim / OpenStreetMap: destination queries for geocoding.
- Visual Crossing and Weather.gov: destination coordinates and relevant dates for weather information, depending on the request.
- Google Places and Google Maps: attraction queries, place details, photos, and ordered route locations. Embedded maps also make requests from your browser.
- ipapi.co: IP address for approximate-region lookup when browser location is unavailable.
- Railway, Cloudflare, and Supabase: application hosting, delivery and security, and backend storage. Cloudflare can also provide site performance telemetry.
- PostHog: product analytics as described below.
- Retailers: clicking a shopping link opens an external search using the packing item’s search terms. The retailer handles any account, payment, or purchase information you provide there.
Native builds can additionally use Apple services such as Maps or WeatherKit. External providers apply their own data-handling practices; this page does not replace their policies.
5. Analytics and shopping links
The current web app initializes PostHog analytics when its production key is configured. It captures page views, interactions, browser/session identifiers, and selected trip attributes such as destination and traveler counts. PostHog persistence uses browser local storage. Input masking is configured for session recording; recording availability depends on the analytics configuration.
The current native implementation sends analytics only when its analytics setting is enabled and a provider key is configured. It uses an installation identifier and event properties such as prompt-length and child-age buckets. The web and native implementations do not have identical controls.
Packing lists can include retailer search links and an affiliate disclosure. We do not process purchases in the planner. Retailers and other external sites apply their own policies when you follow a link.
6. Children’s information
SproutRoute is for adults planning trips. Adults can provide children’s ages to tailor activities, packing, and car seat guidance. Those ages form part of the planning request and may be included in locally saved or optional account-backed trip/profile data. Do not include a child’s name or other identifying details unless the feature needs them.
7. Security
The hosted service uses HTTPS. Backend credentials remain server-side, and protected operational dashboards require authentication. Browser storage depends on the security of your browser and device. These measures do not eliminate all security risk.
8. Your choices
- Limit what you enter in prompts and imported profiles.
- Use browser permissions to control precise location access. Denying that permission does not itself disable IP-based region lookup.
- Clear SproutRoute site data in your browser to remove local records. Using the app again can create new records.
- Use the analytics setting where your native build provides it. The current web interface does not provide an equivalent in-app analytics toggle.
- Use available profile deletion controls or contact the owner about server-held information. Deleting local data does not remove server records.
9. Updates
We will update this page as the product’s data handling changes. The date above identifies this revision.
10. Contact
For questions about SproutRoute data handling, use the contact options on Nitish Prasad’s portfolio and identify the feature and approximate date involved. Do not send passwords or API keys.