planitshare.app/

Privacy Policy

Last updated: October 2, 2026

PlanItShare (planitshare.app) is operated by Miltos Vafiadis, an individual based in Greece, as an independent, non-corporate project. This policy explains what personal data the app collects, why, and what rights you have under the EU General Data Protection Regulation (GDPR).

1. Who controls your data

The data controller is Miltos Vafiadis, resident in Greece, contactable at privacy@planitshare.app or by post at Paralia Fourkas, Halkidiki 63077, Greece. Because PlanItShare is run by an individual rather than a company, this is also the person legally responsible for how your data is handled. The lead supervisory authority is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, dpa.gr).

2. Information we collect

  • Account data: email address, display name, and password (stored and hashed by our authentication provider, Supabase — we never see your plaintext password).
  • Trip and expense data you enter directly: trip names, dates, itinerary items, locations, a plan's price, booking link and cancellation terms, expense amounts, currencies, categories, and notes.
  • What you say about a plan on a trip you're on: your vote on an option or a booking — yes, fine either way, or rather not. Votes are shown with your name to the other people on that trip, and to nobody else; they are never sent anywhere, never used to train or prompt an AI model, and you can withdraw yours at any time. Deleting your account deletes your votes.
  • Confirmation emails you forward or paste in: the raw content of booking confirmations (flights, hotels, activities), which may include other travelers' names if they appear in the email.
  • Group and invitation data: who you invite to a trip, and the email address you invite them at.
  • Travel document details, only if you choose to enter them: the issuing country of the passport you plan to travel on, and its expiry date. We never ask for and never store a passport number, the name on the document, or a scan of it. These two fields exist solely so the Ground Truth tool can tell you whether your passport has enough validity left for a destination's entry rule. They are readable only by you — not by other members of your trips or groups — and you can clear them at any time from the tool.
  • Preferences: language, currency, date format, and theme, stored in a cookie and, once signed in, against your account.
  • Signup source: if you arrive through one of our own shared links (for example a social-media post of ours) and create your account during that same browser session, we record once, at signup, the link's tag — the platform and campaign name — and the referring page. It tells us which of our posts bring new members; nothing is recorded for visits that don't sign up.
  • Feature usage: which of the app's tools you open and use (for example that you opened Been There Done That, ticked a country, or ran a flight search between two airports), and when. This is a count of what happened, never its content — not which country, not your quiz answers, not what a search returned. We use it only to see which features people use and to decide what to keep improving; it is visible to the operator alone and is deleted after 180 days.
  • Technical data: IP address and basic request logs, kept only as long as needed for security and abuse prevention (e.g. bot protection on signup and comment forms).

3. Why we process your data

We process your account, trip, and expense data because it's necessary to provide the service you've signed up for (GDPR Art. 6(1)(b), contract performance). We process technical/security data (like bot-protection checks) under our legitimate interest in keeping the service usable and abuse-free (Art. 6(1)(f)). Where we ask for explicit consent — for example, before an anonymous visitor's browser session is used to let them track their own pending blog comment — we rely on Art. 6(1)(a). We may also send you operational notices by email about your account and the features you hold — for example a role you asked for, or a change to a tool you use — under the same legitimate interest (Art. 6(1)(f)); these are not marketing and you cannot be sent promotional email without separate consent.

4. AI-assisted features

When you forward or paste a confirmation email into the app, its content is sent to Anthropic's Claude API to automatically extract structured trip details (dates, locations, confirmation numbers) so we don't make you re-type them. Anthropic acts as our data processor for this and for the features below, under a data processing agreement.

A few other features send a question to the same model, from our server, only when you use them:

  • The B-Side (suggestions for a trip): the destination you chose, the month or dates, who is travelling (for example "a couple"), how far you're willing to go, your answers to its taste questions, and your trip brief if you write one.
  • Bring It Home (things to take home from a place, in beta): the place you chose, the trip's dates, your three answers about how you'll carry things, the names of the trip's cities inside that place, and your note about who it's for if you write one.
  • The Retro Phrasebook: a phrase you add, so it can be translated into other languages.

None of them sends your name, email address, passport or travel documents, or your bookings.

  • Anthropic's API does not use data submitted through the API to train its models (unlike consumer chat products).
  • Anthropic retains API inputs only briefly for abuse and safety monitoring, then deletes them, per its own API terms.
  • This processing happens outside the EEA (Anthropic's infrastructure is US-based); it's covered by Standard Contractual Clauses as the transfer safeguard.
  • What you send is used only to answer that request — extracting your trip details, or producing the suggestions or translation you asked for — never to train or fine-tune any model on our behalf, and never shared with other PlanItShare users except as the trip details, suggestions or lists that appear on a trip you share with them.

5. Sharing with other users

PlanItShare is built around shared trips. Once you add a plan or expense to a trip, the other members of that trip can see it — that's core to how the app works, not an incidental disclosure. Don't add anything to a shared trip that you wouldn't want your travel companions to see.

You can also add other users as "buddies". A buddy request shows the other person your name; if they accept, you each see the other's name and email address, and you appear in each other's quick picks when adding people to a trip or an expense group, and when linking household records — where a request between buddies does not need the separate confirmation code. Nothing else is shared, and nothing joins automatically: adding a buddy to a trip still sends an invitation they accept or decline. Either of you can end a buddy connection at any time from your profile, which removes you both from each other's picks.

If you use "Been There Done That", the places you record stay private to your account. You can separately opt in to a buddies scoreboard: while it is on, your buddies who have also opted in can see your display name, your visited-country count and the matching percentage, and your per-collection tallies (how many entries of each collection you have ticked, shown when they compare charts) — never your map, and never which countries, cities or places they are. You only see the numbers of buddies who share theirs. Switching the toggle off removes your numbers from their view immediately.

If you comment on a blog post while signed in, your display name is shown with your comment to everyone who reads the post. A comment left without an account shows the name you type, or "Anonymous".

6. Service providers we use

  • Supabase — database, authentication, and file storage.
  • Vercel — hosting the app and its API, and Vercel Analytics, a cookieless count of page views with no per-visitor identifier (roughly a month of history).
  • Anthropic (Claude API) — reading forwarded/pasted confirmation emails, and the answers behind The B-Side, Bring It Home and The Retro Phrasebook's translations (see §4).
  • Resend — transactional email (invitations, password resets, confirmations).
  • Cloudflare Turnstile — bot/abuse protection on signup and comment forms.
  • Mapbox — map rendering and address suggestions for itinerary locations (the text you type in a location box is sent to it to find matches).
  • Google Maps Platform — finding a place by name when you use "Search Google" in a location box; only the text you typed is sent, and only the chosen place's name, address and coordinates are kept on your plan.
  • FlightAware (AeroAPI) — flight status for the "Will It Be Late?" tool; only a flight number and a date are sent, never your name, booking reference or trip. We keep each estimate — for the departure and, where one was shown, the arrival — and, the next day, the flight's actual departure and arrival delays, for 180 days to measure how accurate the tool is.
  • Transport for London (TfL open data) — London stations, and the lines and stops of a London journey, when you use "Plan it with TfL" on a city transport plan (or "Next departures now" during the trip); only the station names you type, the two ends of the journey and its time are sent, never your name, trip or booking. Powered by TfL Open Data. Contains OS data © Crown copyright and database rights 2016 and Geomni UK Map data © and database rights [2019].
  • SL, Stockholm's public transport, through Trafiklab (Samtrafiken, Sweden) — stations in Stockholm County and Uppsala, and the lines and stops of a journey there, when you use "Plan it with SL" on a city transport plan (or "Next departures now" during the trip); only the station names you type, the two ends of the journey and its time are sent, never your name, trip or booking. Based on information retrieved from Trafiklab.se.
  • Transport for NSW (the New South Wales Government, Australia) — stations in New South Wales, and the lines and stops of a journey there, when you use "Plan it with Transport for NSW" on a city transport plan (or "Next departures now" during the trip); only the station names you type, the two ends of the journey and its time are sent, never your name, trip or booking, so nothing that identifies you goes to Australia. Source: Transport for NSW, licensed under CC BY 4.0.
  • opentransportdata.swiss (the Open Data Platform Mobility Switzerland) — stations in Switzerland, and the lines and stops of a journey there, when you use "Plan it with SBB" on a city transport, train, bus or boat plan (or "Next departures now" during the trip); only the station names you type, the two ends of the journey and its time are sent, never your name, trip or booking. Source: opentransportdata.swiss.
  • Île-de-France Mobilités (the Paris region's transport authority, France), through its PRIM platform — stations in Île-de-France, and the lines, stops and fares of a journey there, when you use "Plan it with Île-de-France Mobilités" on a city transport plan (or "Next departures now" during the trip); only the station names you type, the two ends of the journey and its time are sent, never your name, trip or booking. Contient des informations de Calculateur Île-de-France Mobilités, présentement mises à disposition aux conditions de la « Licence Mobilités ».
  • OneMap (the Singapore Land Authority, Singapore) — stations, station exits and bus stops in Singapore, and the lines and stops of a journey there, when you use "Plan it with OneMap" on a city transport plan (or "Next departures now" during the trip); only the station names you type, the two ends of the journey and its time are sent, never your name, trip or booking, so nothing that identifies you goes to Singapore. Contains information from OneMap, made available under the terms of the Singapore Open Data Licence version 1.0.
  • Open-Meteo (OpenMeteo GmbH, Switzerland) — the weather forecast shown on a trip's days, on its Prep page and on your Home page, from five days before a trip, and a day's hour-by-hour forecast when you open it; only the coordinates of places on a trip day — where it ends, and on a travel day the places it passes through — taken from the trip's booked plans and rounded to about 1 km, are sent, from our server, never your name, trip, dates or booking. Weather data by Open-Meteo.com, licensed under CC BY 4.0.

Each of these providers only receives the data needed to perform its specific function and is contractually restricted from using it for its own purposes.

7. International data transfers

Some of the providers listed above may process data outside the European Economic Area — Anthropic, Vercel, Google Maps Platform, and FlightAware are all United States companies. Where that happens, the transfer is covered by Standard Contractual Clauses or an equivalent safeguard recognized under GDPR Chapter V.

8. Data retention

We keep your account and trip data for as long as your account is active. Forwarded emails that couldn't be automatically filed remain in your personal "unfiled" inbox until you file or dismiss them. Audit log entries for sensitive actions (expense edits/deletes, role changes, invitations) are retained for accountability purposes even if the underlying record is later changed. You can close your account yourself from Settings — this disables it immediately and queues permanent deletion, which we complete shortly after (you'll get an email when it's done). Trips and data that are entirely yours are deleted outright; a trip you shared with others is kept for them, with a new organiser (in the app: "trip leader") assigned from its remaining members. Expenses, settlements and comments you contributed to a shared trip or the blog are kept too, since removing them outright would corrupt other members' shared expense history or break the conversation around them — but your name is replaced with "Deleted user" on all of them. You can delete your own comments before closing your account. Once deletion is complete, your personal data is removed except where we're required to keep it (e.g. financial records subject to a legal retention period, or audit trail entries about actions you took while a member of someone else's trip).

Two things are deleted on a schedule regardless of your account: feature-usage records (section 2) after 180 days, and the content of any email forwarded to us from an address that isn't linked to an account — such an email is never filed anywhere, the sender gets an automatic reply saying so, and its content is discarded after 30 days (only the sending address, subject line and date are kept, so we can see how often it happens).

9. Security

Access to your data is enforced at the database level through row-level security policies scoped to your account, not just application-level checks. Traffic to the app is encrypted in transit. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable, proportionate measures for an application of this size.

10. Your rights

Under GDPR, you have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. You can already update your profile details and preferences directly from your account settings, and you can close your account yourself from Settings — see §8 for exactly what that deletes and what is kept for other members. For access, export, restriction, or objection requests, email us — see §14 — and we'll handle it manually; we aim to respond within a month, as GDPR requires. You also have the right to lodge a complaint with the Hellenic Data Protection Authority, or with the supervisory authority in your own EU country of residence.

11. Cookies and local storage

We use a few first-party cookies: one remembers your language, currency, date format, and theme preferences; one records your device's time zone so that "today" in your trips is your today rather than the server's; and your sign-in session has its own. If you arrive through one of our own shared links, a temporary cookie notes which link brought you — it expires when you close your browser, and what it holds is saved to your account only if you sign up during that same visit. We don't use third-party advertising or tracking cookies.

12. Children, and people who travel with you

PlanItShare isn't directed at children and you must be 18 to create an account. If you believe someone under 18 has created one, contact us and we'll remove it.

Adults do, however, travel with children — and since a young child has no email address, no app can invite them anywhere. So an account holder can add people to a "household": a partner, a child, anyone they handle the travel preparation for. Usually those people are not users, have no account, and never sign in.

For each household member we store the name you give them, an optional date of birth, a relationship label you choose, and one or more passports — each as an issuing country and an expiry date. We do this so the app can answer the same questions for them that it answers for you: is this passport valid long enough for this destination, does this country require a visa, and does a trip need a consent letter for a minor travelling without both parents.

Deliberately not collected: passport numbers, the name printed on the document, issue dates, photographs, or any other identity-document field. The app does not need them to answer those questions, so it does not ask for them. The date of birth is optional; without it the app asks you whether the consent-letter item applies instead of working it out.

Household data is visible only to the account holder whose household it is, and to the person it is about if they have linked their own account (below). When you bring someone on a trip, the other travellers see their NAME and nothing else — not their date of birth, not their passports, not whether their passport clears. What the trip organiser sees on the before-you-go checklist is that an item has been answered, never the document behind it.

An adult on a household can be linked to their own PlanItShare account. The account holder sends a request naming them; the other person accepts or declines it themselves, and nothing happens unless they accept. Where the two accounts do not already share a trip or an expense group, accepting also requires a confirmation code that the account holder passes on separately — so a request sent to a mistyped address cannot be acted on by whoever receives it. The request records that person's email address against the household record, in the same way a trip invitation does, and expires after 14 days.

Linking hands the records over rather than sharing them. Once someone accepts, any passports the household was holding for them move into that person's own account, are deleted from the household, and the account holder can no longer see them or add new ones. From then on, that person can see that the household keeps a record under their name and can end the link at any time; ending it does not move the passports back, because by then they belong to the person they are about. If they are also a member of a trip the household added them to, that trip shows them once rather than twice — the only thing it learns is that two entries it could already see are the same person.

You are responsible for the data you enter about other people, including your own children, and for having the authority to enter it. Linking is offered only for people who are not recorded as being under 18. Deleting a household member deletes their passports with them and removes them from every trip they were added to. Deleting your account removes the whole household. If you are the parent or guardian of someone in your household and want their data removed, you can do it yourself at any time, or contact us and we'll do it.

13. Changes to this policy

If this policy changes materially — for example, a new category of data we collect, a new recipient we share it with, or a new purpose we use it for — we'll update the date at the top of this page and email registered users at least 30 days before the change takes effect. Continuing to use PlanItShare after that date counts as accepting the update; if you'd rather not, you can delete your account before the change takes effect (see §8).

14. Contact us

Questions or requests about your data: privacy@planitshare.app.