Privacy Policy
Last updated: 19 September 2026
This policy explains what DreamTrips does with your personal data: what we collect, why, who else sees it, and how long we keep it. It describes the app as it actually works — not as a template says it might.
The short version: we keep as little as we can. Your home address, date of birth and passport number never leave your phone. Your card details never touch our systems. We do not sell your data, we run no advertising, and we do not train any AI model on what you tell us.
Who we are
| Controller | DreamTrips Legacy LLC |
|---|---|
| Address | 5700 Tennyson Pkwy, Suite 300, Plano, Texas 75024, USA |
| Privacy contact | privacy@dreamtrips.ai |
| Support | app.dreamtrips.ai/support |
The Service is the DreamTrips app for iOS and Android and the website at app.dreamtrips.ai. Access is limited to members of the DreamTrips travel club.
What stays on your phone
Your home address, date of birth and passport numberare stored only in your device's own storage. They are never transmitted to us and we could not produce them if asked. We use them to prefill booking forms, and they reach a travel provider only at the moment you make a booking that requires them.
Clear them any time in Settings → Clear device data, or by uninstalling the app.
What we keep on our servers
- Account: e-mail address, and if you provide them, first name, last name and phone number. Your membership level and eligibility, checked with the DreamTrips club.
- Preferences: language, chosen assistant persona, interests, travel pace, home currency.
- Trips: your saved itineraries and the chat history that produced them, including 96-pixel thumbnails of any photos you attached.
- Bookings: reference, status, dates, amount, the name and e-mail on the booking, and the IP address of the device you booked from (Inspira requires it to complete the booking). Never card details.
- Travel Wallet: the documents you upload — which may contain passports, visas, boarding passes and insurance certificates. Stored privately and served only to you.
- Passport country and expiry date if you enter them, so we can warn you before a border does. The passport number stays on your device.
- Luggage tracking link if you add one: the Apple "Share Item Location" URL for your tracker. Anyone holding that link can see where the tracker is, so we accept it only from
find.apple.com. Apple's shares expire on their own after about a week. Clearing the field here removes our copy — to cut the share off completely, stop it in Find My on your iPhone as well. - Push registrations: a device token per device you enable notifications on. Trip reminders go only to you; occasional service announcements from us go to every device that has notifications switched on. Turn them off in your phone's settings, or in the Travel Wallet, and the tokens are deleted.
- AI usage: which model answered, how many tokens and what it cost — to apply the fair-use limit.
- Technical logs when something fails, so we can fix it.
We run no advertising and no analytics product. There is no tracking SDK in the app. The map component sends its own usage telemetry to Mapbox, as their licence requires.
Why we may do this (legal bases)
| Purpose | Basis (GDPR Art. 6) |
|---|---|
| Running the app, planning, bookings, sign-in e-mails | Performance of a contract, 6(1)(b) |
| Location, microphone, camera, photo library, notifications | Your consent, given in the system prompt, 6(1)(a) — withdraw it in your phone's settings |
| Keeping the service secure, preventing abuse, applying fair use | Legitimate interests, 6(1)(f) |
| Fixing faults from error logs | Legitimate interests, 6(1)(f) |
| Keeping accounting and tax records | Legal obligation, 6(1)(c) |
The AI assistant
You are talking to an AI, not a person. Your messages, any photo you attach and — if you have location sharing on — your coordinates are sent to Anthropic to produce an answer.
Your conversations are not used to train any AI model, by us or by Anthropic. We deliberately keep passport numbers, dates of birth and payment data out of the assistant entirely.
There is one automated decision you should know about. Each account has a monthly fair-use allowance for AI. Once you pass it, the app keeps working but switches to a smaller, faster model until the calendar month resets. It affects answer quality only — never your bookings, your money or your access to the app. Write to us if you think it has been applied unfairly.
Who else sees your data
We do not sell your personal data and we do not share it for anyone else's marketing. Below is the complete list of who receives it and why.
Acting on our instructions (processors)
| Recipient | Purpose | Data |
|---|---|---|
| Anthropic, PBC (USA) | The AI assistant: interprets your questions and writes your itinerary | Chat text, attached photos, coordinates when location sharing is on, your first name and travel preferences |
| ElevenLabs, Inc. (USA) | Speech-to-text and text-to-speech | Voice recordings you make; the text of replies you play aloud |
| Google LLC — Cloud Text-to-Speech (USA) | Speech synthesis in some languages | The text of replies you play aloud |
| Google LLC — Places (USA) | Venue details and photos | Place names and coordinates |
| Google LLC — Firebase Cloud Messaging (USA) | Delivering push notifications | Device push token; the title and body of the notification |
| Mapbox, Inc. (USA) | Maps, place search and walking directions | Coordinates and search terms |
| Foursquare Labs, Inc. (USA) | Restaurant details, ratings and photos | Place names and coordinates |
| Vercel, Inc. (USA) | Hosting, and private file storage for Travel Wallet documents | All traffic to the Service; your uploaded document files |
| Turso / ChiselStrike, Inc. (USA) | The database holding every server-side record | Everything listed under “What we keep on our servers” |
| Resend / Plus Five Five, Inc. (USA) | Sending sign-in links, notifications and support replies | Your e-mail address and the message content |
Deciding for themselves (independent controllers)
| Recipient | Purpose | Data |
|---|---|---|
| Inspira Holidays | Hotel search and booking | Traveller name, e-mail, phone, nationality, dates, room choice; the IP address of your device when you search for and book hotels, which they use to check availability |
| Inspira Pay | Payment for hotel bookings, on their own hosted page | Your card details, which you enter on their page — never on ours |
| Guided Planet | Concierge service for members whose membership includes it | Your name, e-mail address, DreamTrips account ID and membership level — only when you open Concierge or sign in to it with your DreamTrips account |
| Duffel Technology Ltd (UK) | Flight search | Route, dates and passenger counts. No names — flight booking is not available in this release |
| Viator / Tripadvisor LLC (USA) | Attractions and tickets | Place and activity searches |
| Ticketmaster / Live Nation (USA) | Concerts, matches and shows | City and date searches |
| RapidAPI (USA) — aerodatabox | Live flight status: terminal, gate, delay | Flight number, date, departure airport |
| RapidAPI (USA) — visa-requirement | Visa rules for your destination | Your passport country of issue and destination country |
| Wikimedia Foundation, Inc. (USA) | Landmark descriptions and photos | Coordinates and landmark names |
| Open-Meteo (EEA) | Weather forecasts for the places in your trip | Coordinates and dates |
| DreamTrips travel club (dreamtrips.com) | Verifying your membership at sign-in | Your e-mail address and, if you sign in with a password, that password |
| Apple Inc. / Google LLC | App distribution and crash reporting | Device identifiers, crash data — governed by their own policies |
When you tap "open in Google Maps" or order a ride, we hand that app your start and destination — but only because you asked for it. We may also disclose data where the law requires it, or to our legal advisers.
Sharing a trip
If you turn on sharing for a trip, we create a long, unguessable link. Anyone with that link can see the itinerary — the places, days and notes — without signing in. It contains no account details and no booking references. Turn sharing off and the link stops working.
How long we keep it
| Account record | While your account exists. Erased the moment you delete it — immediately, in one transaction, with no grace period and no way to restore it. |
|---|---|
| Saved trips and chat history | Until you delete the trip or your account. Photos you attach are kept only as a 96-pixel thumbnail inside the saved conversation so the picture still appears when you reopen it; the full-size copy is never stored. |
| Travel Wallet documents | Until you delete the document or your account. The file itself is deleted from storage at the same time. Limit: 8 MB per document, 30 documents per account. |
| Booking records | Kept after account deletion in anonymised form only — the traveller name, e-mail and phone are erased and the record is unlinked from you. What remains is the reference, dates and amount, which accounting and tax law requires us to keep. |
| IP address stored with a booking | Deleted automatically 30 days after the booking was made — including bookings you never paid for — and immediately if you delete your account. |
| Voice recordings | We never store them. The audio goes to ElevenLabs for transcription; their own retention applies. |
| AI usage records | Model, token counts and cost per request, kept to apply the fair-use limit. Erased when you delete your account. |
| Technical error logs | 30 days, then deleted automatically. |
| Sign-in link | 15 minutes, single use. |
| Sign-in session | 30 days, or until you sign out. |
Where your data goes
We are based in the United States and most of the providers above are too. Where data about people in the European Economic Area or the United Kingdom is transferred out, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, or on the EU–US Data Privacy Framework where the provider is certified under it. Ask us at privacy@dreamtrips.ai and we will tell you which mechanism covers a particular provider.
Keeping it safe
Everything travels over HTTPS. Sign-in sessions use signed cookies that are restricted to our own site. Passwords, where you have one with us, are stored only as a scrypt hash — we cannot read them. Travel Wallet files are held in private storage and served only to the account that uploaded them. Access to production data is limited to the people who need it.
No system is perfectly secure. If we ever suffer a breach that puts your rights at risk, we will tell you and the relevant authority without undue delay.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to another provider. Where we rely on your consent, you can withdraw it at any time without affecting what we did before.
You do not have to ask us to delete your account — do it yourself in Settings → Delete account. It takes effect immediately. See exactly what is erased and what is kept. For anything else, write to privacy@dreamtrips.ai and we will answer within one month.
If you are in the EEA or the UK you may complain to your national data protection authority. You are welcome to come to us first — we would rather fix it.
If you are in California or another US state
We do not sell your personal information and we do not share it for cross-context behavioural advertising — under the CCPA/CPRA or any comparable state law. We do not use it to profile you for advertising. You have the right to know what we hold, to have it deleted, to correct it, and not to be treated differently for exercising those rights. Use the same address: privacy@dreamtrips.ai.
Storage on your device
We use only what the app needs to work: a sign-in cookie that lasts 30 days or until you sign out (plus, only while you use your DreamTrips account to sign in to a partner service such as Guided Planet, a second cookie that holds that request and is deleted when you finish or after 15 minutes), your preferences and language, the device-only data described above, and an offline cache so your Travel Wallet opens without signal. A functional cookie, dt_theme, remembers the look you chose so the app and partner services such as Concierge open in the same theme; it holds no personal data and lasts one year. There are no advertising or analytics cookies, so there is no consent banner to click. Signing out or deleting your account clears the offline cache and the device-only data.
Children
The Service is for adults. You must be 18 or older to use it, access is limited to verified club members, and it is rated 17+. We do not knowingly collect data from children. If you believe a child has an account, write to us and we will close it.
Changes
If we change this policy we will update the date above and, for anything material, tell you in the app before it takes effect.
Contact
DreamTrips Legacy LLC, 5700 Tennyson Pkwy, Suite 300, Plano, Texas 75024, USA. Privacy: privacy@dreamtrips.ai. Everything else: app.dreamtrips.ai/support.