Rustichello plans trips and writes travel memoirs from your photographs. This page says, plainly, how your personal data is treated while it does that.
Rustichello operates the service and is the data controller for your personal data. To reach us, write to hello@rustichello.co or use the contact page.
Last updated: 24 September 2026.
The promises
Your personal information is never sold, shared or tracked. No advertising, no data brokers, no tracking cookies, no profile of you passed to anyone — ever.
We store only what is needed to do the job you asked for: the trip details you type, the photographs you choose for a memoir, and an email address if you create an account or ask for your memoir link by email.
You control everything that goes into a memoir. You pick the photographs and notes, and both paths are first-class. With maximum privacy, photographs come to Rustichello only to read their time and place and assemble the memoir. They are never shown to the writing model: captions use your notes and photo numbers. The direct old-photo reconstruction route uses richest captions, so downscaled copies are shown to the writing model; the planned-trip builder offers both paths. In either path, photographs are never used for training. Copies uploaded through the memoir builder's staging step are deleted after a completed build.
Before anything is uploaded, your browser reads the date and, where your camera saved one, the location stamped inside each photograph, and uses them to sort the photographs into the days of your trip. That reading happens on your own device. The memoir builder sends us no coordinates from your photographs: what leaves your browser is the grouping, which photographs belong to which day, and for each photograph the stop of your itinerary it was nearest to, with how far from that stop it was taken, rounded to a tenth of a kilometre and capped at 25 km, so a photograph taken far from the trip says only that, and a yes/no for whether the photograph's day was a day of the trip at all. Never the coordinate itself, and never the time it was taken. A photograph small enough to be uploaded untouched still travels with whatever its own camera wrote inside it, exactly as you took it.
One button deletes everything — trips, memoirs, preferences, account — from your own screen, immediately. No email to support, no waiting period. You can export a full copy of your data first, also with one tap.
Payments are handled by Stripe. We never see or store card numbers.
To enforce the one-itinerary anonymous allowance, we set one strictly necessary, signed cookie containing only a random identifier and allowance count. It contains no trip, account, Traveller DNA or persona data, is not used for tracking or advertising, expires after five years, and can be removed in your browser settings.
We count visits to the site ourselves. There is no Google Analytics, no advertising pixel, no third-party script and no analytics cookie. Nothing we use to count visits ever contacts anyone but us. (Paying is the one place your browser goes elsewhere, and it goes to Stripe's own checkout page, which you can see in the address bar.)
Rustichello is the data controller for the data above. The legal basis is simple: we process what is needed to deliver what you asked for (performance of a contract), and anything optional — like the photo-vision choice — only with your consent, which you can withdraw at any time.
Counting visits
We keep a count of how the site is used, so we can tell a quiet day from a broken one. A visit made without signing in is anonymous by construction rather than by promise. A visit made while signed in carries a one-way account code as well, and the bullet below says so in full.
Your IP address and your browser's user-agent string are never stored in these records. They are combined into a one-way code, and only the code is kept.
The key that makes that code changes every day. The same browser on two different days produces two unrelated codes, so for a visit that is not signed in we cannot follow anyone from one day to the next, even if we wanted to. That is a property of the maths, not a policy we apply.
Signed in is different, and here is the plain version. A visit made while you are signed in also carries a one-way code for your account, and that one does not change from day to day. So we can see when one of our own members comes back. We keep it for one reason: it lets us match visits to the itineraries and memoirs that were made, which is how we tell whether the site is working. It is still a one-way code, never your email address and never your account number, and it is on your visits only while you are signed in.
A record holds the page address, the time, whether the request succeeded, how long it took, and broad categories: phone or tablet or computer, browser family, operating system family, and whether the caller looked like an automated crawler.
If you arrive from a link, we keep the website name you came from, never the full address of the page you were on. If a link carries campaign tags, we keep those tags. No other part of the web address is kept.
Your country comes from a header our network provider adds, and only when it is present. We never guess a location from an IP address.
The page itself tells us how long it was open, how far down it was read, and which buttons were pressed. That happens in one small message when you leave the page. It sets no cookie and creates no identifier of its own.
If you are signed in, the record notes that fact and a one-way code for your account. Your email address and your account number are never in it.
These records are deleted after 400 days.
While your trip is being written
The itinerary and memoir prose are written by our in-house developed concierge and ghostwriting harness, utilising frontier model and intelligence providers acting as our processors — they receive your trip inputs, plus downscaled copies of your photographs only if photo-vision is on, and do not train on any of it. Venue facts come from Google Maps and weather from forecast services; each receives only the minimum needed (destination, coordinates, dates). Everything travels encrypted, and anything stored is encrypted at rest.
Some of these providers (hosting, AI, payments) run in the United States, so your data can cross borders: those international transfers are covered by the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.
Retention — how long things stay
Photographs staged for a memoir are deleted after a successful build. Abandoned or failed staging is deleted when the next stage or build request runs after the staging retention window, which is 24 hours. A finished memoir lives at a private, unlisted link until you delete it — anyone holding the link can view it, so share it as carefully as the memoir itself. Account data is erased the moment you delete the account. Routine server logs are kept for at most 30 days. Operational generation logs keep only bounded metadata such as whether a model answered or the offline planner was used, a short audit id, pseudonymous account/device id, token and cost totals, and provider error categories. They do not include names, emails, photographs or generated prose. Whatever usage statistics we keep are anonymous counts that identify no one. The visit records described under "Counting visits" are kept for 400 days and then deleted.
Your rights
If you are in the UK or EU (GDPR) or California (CCPA/CPRA), your rights to access, correction, erasure, restriction and portability are served instantly by the controls above — or email us and it is done for you within 30 days. If you are unhappy with an answer you may complain to your supervisory authority (in the UK, the Information Commissioner's Office).
The service is not directed at children under 16.
If how we handle your data ever materially changes, the app will say so before it takes effect, and this page and its date will change.