← Rustichello

# Privacy Policy

Rustichello turns your trip photographs into a written memoir. That means we handle
photographs, the locations and times stored inside them, and the few preferences you
type. This policy says exactly what happens to each of those, where it goes, how long it
stays, and how to get it back or get rid of it.

Last updated: 8 August 2026.

## Who is responsible

Rustichello is the data controller for the personal data described here, under the UK
GDPR and the EU GDPR.
The operator of record and its registered address are stated on our contact page.
Questions, requests and complaints go to **privacy@rustichello.co**, and we answer
within 30 days.

If you are in the UK or EU and are not satisfied with our answer, you may complain to
your supervisory authority (in the UK, the Information Commissioner's Office).

## What we collect, and why

You can use the planning and memoir flow without an account. Nothing below is collected
until you actually do the thing that produces it.

| What | When | Why (legal basis) |
| --- | --- | --- |
| Destination, dates, party size, interests | You type them into the planner | To generate your itinerary — performance of a contract |
| Photographs you upload, and the EXIF inside them (capture time, GPS coordinates, camera) | You choose photographs for a memoir | To place each photograph on the trip's timeline and write the memoir — performance of a contract |
| Short video clips | Only in a group memoir, if a contributor adds one | Same as photographs |
| Email address | Only if you ask us to email your memoir link, or you create an account | Consent (memoir email) / contract (account) |
| Password | Only if you create an account | Stored as a PBKDF2-SHA256 hash with a per-user salt, never in readable form |
| Step count | Only if you turn on real step data. Off by default | Consent. This is health data and we ask for it separately |
| Anonymous usage events | Every generation | Our legitimate interest in knowing whether the product works. See "Analytics" below |
| A device-generated referral code and, optionally, a "carry code" | Only if you use those features | Consent |

We do **not** sell personal data, do not share it with data brokers, do not run
advertising, and do not profile you for advertising. We use no third-party advertising or
tracking cookies. The site keeps a small amount of state in your browser's local storage
(your draft trip, your device's referral code, whether you have visited before) — that
stays on your device and disappears when you clear site data.

## Analytics: what is deliberately *not* recorded

Usage events record the shape of a session, never who you are: which destination and
intensity were chosen, how many days and photographs, how long generation took, what
the AI call cost, and coarse interaction counts (how many clicks and how much time
passed between landing and pressing "build") — counts only, never what was clicked or
typed. Free text you write about yourself is recorded only as a true/false
flag that you supplied some. Email addresses are never written into this stream — they
live only in the email list, separately, and are separately deletable.

## Automated processing (AI)

To write your itinerary and memoir prose we send the trip inputs to **Anthropic** (the
Claude API) for processing. For a memoir, you choose how photographs are handled:

* **Richest captions (default):** we send downscaled copies of your photographs —
  never the originals — so the model can see what each photograph actually shows.
  That is how captions describe your real pictures and how a photograph that doesn't
  belong to the trip gets flagged to you instead of silently guessed at.
* **Maximum privacy:** switch the photo-vision option off and your photographs never
  leave the service. Captions are worded from the stop numbers and short notes you
  attach to each photo instead. The same choice applies to memoirs built from a past
  trip's photos.

Either way, the only text that reaches the model is what you typed into the trip.
Anthropic acts as our processor and does not train models on this data. There is no
automated decision-making
that produces legal or similarly significant effects about you.

If the AI service is unavailable, or a spending cap is reached, generation falls back to
an offline generator on our own servers and nothing leaves it.

## Who else processes your data

| Processor | What they receive | Where |
| --- | --- | --- |
| Render (hosting) | All requests to the service | United States |
| Anthropic (Claude API) | Trip inputs; downscaled photographs ONLY if you keep the photo-vision option on | United States |
| Amazon S3 / Cloudflare R2 (object storage) | Your finished memoir file, staged uploads | United States or European Union, depending on the bucket |
| Google Maps Platform | The destination text you type and the trip's area coordinates — for geocoding, timezone, travel times, and finding the real, open venues your itinerary is built from | Global |
| OpenWeather | Coordinates and dates only | European Union |
| Resend | Your email address and the memoir link, only if you ask for the email | United States |
| Stripe | Payment details, only if and when you buy something. We never see or store card numbers | United States / European Union |

### International transfers

Some of these processors are in the United States, so your data is transferred outside
the UK and EEA. Those transfers rely on the UK International Data Transfer Addendum and
the EU Standard Contractual Clauses, alongside the technical measures described under
"Security".

## Storage and retention

- **Staged uploads** (photographs held between upload and build) are deleted as soon as
  your memoir is built — typically within minutes.
- **Your finished memoir** is one self-contained file, with the photographs embedded in
  it, stored at a long random address that is not listed or indexed anywhere. It stays
  until you delete it. Anyone holding the link can view it, so treat the link the way you
  would treat the memoir itself, and delete it when you have finished sharing.
- **Account data** (email, trips, itineraries, memoirs) is kept while the account exists
  and erased when you delete the account.
- **Email list entries** are kept until you unsubscribe.
- **Anonymous usage events** are kept for up to 24 months and contain no identifiers.
- **Server logs** (IP address, path, status, timing — used for rate limiting, abuse
  prevention and debugging) are kept for up to 30 days.
- **Carry codes** hold only a sanitised taste profile, with no identifiers, and are
  deleted when you delete the code.
- **Password-reset and email-confirmation links** are stored only as a one-way hash,
  never in a form that could be used to open your account. A reset link lasts an hour, a
  confirmation link 48 hours, and each works once. Resetting your password signs out
  every other device.

## Your rights

You have the right to access, correct, delete, restrict and object to our processing of
your personal data, and to receive it in a portable format. Where we rely on consent you
can withdraw it at any time, without affecting what happened before.

You can exercise these yourself, immediately.

**On the website, where there is no account:**

- **Delete a memoir** — the "Delete this memoir" control beside the share link, which
  calls `POST /web/memoir/delete`. Holding the link is the authorisation.
- **Delete what the app has learned about you** — the "Delete everything" control in the
  Traveler DNA panel. That profile lives in your browser; deleting it removes it, and
  `POST /web/dna/delete` removes any carry code you created.
- **Unsubscribe and erase your email** — `POST /web/subscribe/delete` with your address,
  or the unsubscribe link in any email we send.

**If you have an account (the API and mobile app):**

- **Access and portability** — `GET /api/account/export` returns everything held against
  your account, as JSON.
- **Erasure** — `POST /api/account/delete` erases the account, its trips, itineraries,
  memoirs and any contributed media, plus any email-list entry under the same address.
  It cannot be undone.

Or write to **privacy@rustichello.co** and we will do it for you.

### If you are in California

The CCPA and CPRA rights to know, delete, correct, and opt out of the "sale" or "sharing"
of personal information are served by the same routes above. We do not sell or share
personal information as those terms are defined, and we offer no financial incentives in
exchange for it.

## Children

The service is not directed at children under 16 and we do not knowingly collect their
personal data. If you believe a child has given us personal data, write to
privacy@rustichello.co and we will erase it.

## Security

- Everything travels over TLS. The service sends HSTS and a strict Content-Security-Policy.
- Passwords are hashed with PBKDF2-SHA256 (200,000 iterations, per-user salt) and are not
  recoverable by us or anyone else.
- Object storage is encrypted at rest.
- Memoir links use long random identifiers that cannot be guessed or enumerated.
- Operator analytics and the email list sit behind a separate operator token and are
  closed to the public by default.
- Rate limits and spending caps apply to every endpoint that costs money to run.

No system is perfectly secure. If a breach affects your rights we will notify the
relevant supervisory authority within 72 hours and tell you directly where required.

## Changes

If we change how we handle your personal data we will update this page and change the
date at the top. Material changes are announced in the app before they take effect.

## Contact

**privacy@rustichello.co**