PRIVACY
Travel plans are personal. We treat them that way.
This policy explains what Ashore stores during trip import, execution setup, planning, and sharing; who can see it; and the choices available to travelers and companions.
Information Ashore handles
Ashore stores the structured information used to operate a trip: destinations, dates, traveler names, itinerary items, notes, estimated costs, booking-readiness labels, import metadata, recommendations, reactions, questions, and recent owner-only undo checkpoints. The booking importer processes uploaded or pasted source material without retaining the original file or raw source text after the request completes. In trip planning and chat, Ashore saves extracted document text and source names privately with your planning session so you can ask follow-up questions. Original uploaded files are not retained.
Private execution records can include tasks, vendor names, contact and booking permissions, budget and deposit limits, refundability and alternate-time rules, booking windows, retry and audit events, confirmation codes, prices, cancellation terms, and evidence sources. This execution record is not included in guest trip pages or guest API responses.
Companions can contribute reactions, reaction reasons, and recommendations without an account. AI planning questions require a completed account introduction. Ashore assigns the browser a random participant identifier so changing a reaction does not inflate group totals.
Owner and participant cookies
Ashore uses essential HTTP-only cookies. Account cookies keep you signed in until you sign out or the session expires. Older, unclaimed trips can use an owner capability cookie; once a trip belongs to an account, that account is required for owner access. A separate participant cookie remembers a companion’s reactions. These cookies are not advertising trackers. Trip-owner and participant cookies are retained for up to one year unless cleared earlier. Legacy planning cookies last up to 90 days.
An owner may create a one-time recovery link for a new browser. Its secret stays in the URL fragment and is returned only once; Ashore stores a cryptographic hash and creation time. Successful recovery consumes the key and rotates owner access, invalidating the prior owner cookie and replacing any previous account association.
Google accounts
Creating plans or booking trips requires a Google account and a short Ashore introduction. Supabase Auth verifies your Google identity and stores your account identifier, name, and email. Ashore uses that identity to save and reopen your plans and bookings across devices. Signing in can associate unclaimed trips proven by this browser’s owner cookies with your account. Signing in does not give Ashore access to your inbox.
Your introduction is stored in Supabase under your account. It can include a preferred name, usual departure city or airport, travel interests, and how you heard about Ashore. These questions may be skipped. We save progress when you continue, so you can finish later or on another device. Travel answers can become editable defaults for future trips; the details you give for a specific trip take priority. Referral answers help us understand how people find Ashore and are not sent to the planning model. You can edit your introduction from Account; account deletion removes this customer profile.
Signing out removes account and trip-owner cookies from this browser, along with locally remembered planning and booking details. It does not delete trips saved to your account. To delete your account, open Account and choose Delete account. After confirmation, Ashore disconnects linked Gmail accounts, removes cards from your trip wallets, and deletes your account, saved trips, chats, imported content, shared links and travel preferences. If a booking or call is in progress, it must finish or be resolved first. A connected-service failure leaves deletion paused and lets you retry from Account. Contact Ashore Support if you need help.
Account deletion does not cancel reservations, recall delivered messages, or delete payment providers’ transaction history. We retain a minimal deletion receipt containing technical account and trip identifiers and timestamps to prevent delayed background tasks from restoring erased data. It contains no chat, imported document, name or email address.
Sharing and visibility
Anyone who receives a trip’s guest link can view its shared itinerary, traveler names, group reaction totals, booking-readiness labels, and recommendations. Guest and friend-link responses do not include the planner’s reusable travel profile or dietary restrictions.
A guest can create a separate, editable copy of a shared trip. A copy keeps the itinerary but receives fresh identities and does not include the original profile, dietary restrictions, traveler list, recommendations, reactions, reaction reasons, or claimed reservations.
How information is used
- Import, generate, refine, save, and display structured itineraries.
- Create and maintain private execution tasks within traveler-defined boundaries.
- Record approvals, retries, booking windows, and reservation evidence without equating an attempt with success.
- Answer questions about a shared trip and summarize group preferences.
- Keep reactions and recommendations consistent across participants.
- Protect owner-only editing and operate, secure, and improve the service.
Ashore processes limited connection information, such as an address supplied by the hosting network, to prevent automated abuse and excessive model usage. Production rate-limit counters use salted cryptographic hashes rather than storing raw client addresses and expire from active use after their short request window.
Ashore does not sell trip or profile data and does not use it for third-party behavioral advertising.
Service providers and external links
The trip planner uses OpenRouter and its configured model providers to interpret your preferences and generate suggestions, with public web research for practical details. Planning sessions can include companion ages, room arrangements, access needs, and the optional explanations you supply. Planning conversations are saved privately with that trip and can be cleared from conversation history. Live voice conversations use OpenAI; dictation uses the configured transcription provider. Ashore does not retain microphone recordings. These details and conversations stay out of the separate shared-plan view. You can delete a planning session from Trip details; inactive sessions expire after 90 days.
While preference memory is on, Ashore can remember a directly supplied departure airport and personal travel tastes for future trips, along with the words they came from. A usual airport is separate from a last-used suggestion. One-trip exceptions, document speakers, dates, trip budgets and other travelers’ details are not automatically added to your profile. Open Your travel defaults in Trip details to edit, remove or pause this memory. Preferences follow your account. Older browser-only preferences can be imported through that control.
Use my location is optional and only requests location when you click it. For nearby-airport suggestions, the coordinates are rounded before being sent to Ashore and Google Maps. Ashore does not save the device coordinates or turn that location into a home airport. You can enter an airport or city instead.
A production deployment may use hosting, database, and AI-model providers to process trip data on Ashore’s behalf. When model-backed planning is enabled, the relevant trip context and prompt may be sent to that configured model provider. Payment credentials and identity documents should never be submitted to the planner.
Files, pasted conversations, and readable Google Docs or Sheets links that you add to planning are treated as private trip sources. When you send an attachment in chat or use it to start a plan, its extracted text becomes part of the context processed through OpenRouter and its configured model providers. The separate web research step receives a public travel question rather than your documents or full conversation.
If a shared ChatGPT or Claude page requires you to interact before importing, you can open a temporary browser hosted by Browser Use. That provider processes the shared page and your interactions in that window. Ashore requests no saved login profile, recording, proxy or automatic CAPTCHA solving for this flow. You complete any required verification yourself and choose when to import the visible conversation. The window closes after import or cancellation and expires after five minutes. Only imported conversation text and its source link are saved with your trip.
Connecting Gmail is optional. Composio manages the Google connection and its authorization tokens for your planning owner identity. The connection requests read-only access: Ashore cannot send, edit or delete your mail through this feature. You enter a search and choose which emails to import; Ashore saves only those selected emails as trip sources. Disconnecting stops future access but does not remove copies you already imported. You can remove an unsent source, clear the conversation and its sources, or delete the planning session. You can connect several Google inboxes, choose which one to search, and disconnect each separately. Deleting one planning session does not disconnect Gmail from your other sessions under the same planning identity. A Gmail connection made before signing in may need to be connected again under your account.
Ashore displays Google Maps place information and, when you open Google reviews, requests a small live review sample for that place. Review text is not saved in your trip or sent to Ashore’s AI review analysis. Reviewer images load from Google when displayed. Google Maps features and content are subject to the Google Maps Additional Terms of Service and Google Privacy Policy. Opening a place or route in Google Maps leaves Ashore.
Retention, access, and deletion
Trip records remain available so planners and companions can return to them. Undo checkpoints are bounded and older checkpoints are discarded as newer planner changes replace them. A planner can permanently delete a trip through Trip settings. That removes the stored itinerary, private execution plan and evidence, active recovery-key hash, profile snapshot, companion-feedback ledgers, recommendations, and undo history, and existing planner, guest, calendar, recommendation, recovery, and execution links stop working.
For access or correction help, or if owner access has been lost, contact Ashore Support. Ashore may retain limited records when reasonably necessary for security, legal obligations, or abuse prevention.
Security and changes
Owner edit tokens are stored as cryptographic hashes, production database access is server-mediated, and private trip surfaces opt out of indexing and caching. No online service can promise perfect security; report a suspected access issue promptly through Support.
If this policy changes materially, the effective date and content on this page will be updated before the new terms apply.
Contact
For privacy requests or questions, use the current contact listed on the Support page.