Privacy Policy
Last updated: July 12, 2026
AreYouInTown ("we", "us") helps you see when your travel plans overlap with friends' plans. This policy explains what we collect, why, and how you can control it. Questions? Email hello@areyouintown.com.
What we collect
- Account info: your name and email address. If you sign up with a password we store only a one-way hash of it, never the password itself. If you sign in with Google we receive your name and email from Google.
- Travel info you enter: trips (city, region, country, optional dates and notes), your home city, wishlist countries, countries and places you've already been, and who you choose to share each trip with (friends and groups).
- Connections: the friends you add and the groups you create.
- Google Calendar data (only if you connect it): see the dedicated section below.
- Google Contacts data (only if you connect it): see the dedicated section below.
- Forwarded booking emails (only if you use that feature): when you forward a booking confirmation to our import address, we read it to detect the trip details, which includes sending the message text to our AI provider (see below).
- Basic usage data: login sessions (a cookie to keep you signed in) and privacy-respecting analytics about page visits.
How we use it
- To create your trips and detect when they overlap with a friend's.
- To notify you and the matching friend about an overlap, on the site and by email.
- To show your trips and travel history to the friends you choose to share them with.
- To keep your account secure and the service running.
We do not sell your data, show you ads, or use your data to train advertising or AI models.
Google Calendar, Google Contacts, and Limited Use
Connecting Google Calendar is optional. If you connect it, we request read-only access (the calendar.events.readonly scope) for one purpose: to scan your upcoming calendar events (roughly the next 12 months) and suggest trips you can add to AreYouInTown.
- We read event titles, locations, and dates only to detect a city and travel dates. You review every suggestion before anything is saved.
- To work out the city and dates from an event, the event's title, location, and dates are sent to our AI provider, Anthropic (the Claude API), which returns the trip details. Anthropic acts only as our service provider: under its commercial terms it does not use this data to train or improve its models, and it does not retain it beyond what is needed to return a result. We never send your Google data to any other AI service.
- We store a Google refresh token so we can run the scan when you ask. We do not keep a copy of your raw calendar.
- You can disconnect at any time from the Trips page; that revokes our access and removes the stored token.
Connecting Google Contacts is optional. If you connect it, we request read-only access (the contacts.readonly scope) for one purpose: to show your contacts so you can choose which of them to invite to AreYouInTown.
- We read contact names and email addresses only to display them for you to pick from. We fetch them on demand and do not keep a copy of your contact list.
- We only send an invitation to the specific contacts you select; we never message your contacts otherwise.
- We store a Google refresh token so we can fetch contacts when you ask. You can disconnect at any time from the Friends page, which revokes our access and removes the stored token.
For both Calendar and Contacts: we never sell Google user data, never transfer it to data brokers or advertisers, and never use it for advertising or lending. We use it only to provide the features described above. We do not transfer it to any third party except the service providers needed to run those features (our hosting provider, our database provider, and the AI provider named above), or where required by law.
Neither raw nor derived Google user data is used to develop, improve, or train generalized AI or machine learning models, by us or by any service we send it to. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing and storage
Your trips are visible only to the friends and groups you choose. We use trusted service providers to run the app, including Vercel (hosting and analytics), Neon (database), Resend (email), and Anthropic (AI trip detection). Data is stored on their secure infrastructure.
How we protect your data
All traffic to and from AreYouInTown is encrypted in transit (HTTPS/TLS), and data stored in our database is encrypted at rest by our database provider. Google access and refresh tokens are held as secrets in our hosting environment and are never exposed to the browser or to other users. Access to production systems is limited to the app maintainer, protected by a password-protected account with two-factor authentication. Passwords, when used, are stored only as one-way hashes.
Keeping and deleting your data
We keep your data while your account is active. You can delete individual trips at any time, and you can disconnect Google Calendar or Google Contacts at any time, which immediately deletes the stored Google token and any data derived from that connection that you have not chosen to save as a trip. To delete your whole account, use Delete my account on the Account page: it permanently removes your trips, matches, connections, and any stored Google tokens straight away. You can also email hello@areyouintown.com and we will do it for you. We do not keep backup copies of Google user data after deletion.
Children
AreYouInTown is not directed to children under 13, and we do not knowingly collect their data.
Changes
If we change this policy we will update the date at the top of this page. Significant changes will be communicated in the app or by email.