Privacy Policy
Last updated: July 14, 2026
This page is maintained by the operator of WhereIveBeen ("we", "us") to answer common privacy questions about the app. It is not a certification and not legal advice.
1. Who we are
WhereIveBeen is a small personal project available at whereivebeen.xyz. For any privacy question or request, contact us at privacy@whereivebeen.xyz.
2. Data we collect
- Account: email address, hashed password (or Google account identifier if you sign in with Google), display name.
- Profile: optional home town (converted to approximate coordinates), preferred traveler type, map color preferences.
- Travel data: the places you mark as "been", "want", or "not been", and any AI itineraries you generate and save.
- Technical: minimal request logs (timestamps, IP address, user agent) kept short-term for security and abuse prevention.
We do not knowingly collect payment information, precise device location, or biometric data.
3. How we use your data
- Provide the core features (authentication, saving your maps, generating itineraries).
- Personalize AI trip suggestions using your traveler type and wishlist.
- Keep the service secure and debug errors.
We do not sell or share your personal data with advertisers, and we do not use it to build cross-site advertising profiles.
4. Legal bases (GDPR / UK GDPR)
- Contract (Art. 6(1)(b)): creating your account and delivering the features you request.
- Legitimate interests (Art. 6(1)(f)): keeping the app secure and preventing abuse.
- Consent (Art. 6(1)(a)): where you explicitly opt in (e.g. saving optional profile fields).
5. Subprocessors
We use the following providers to operate the app. Each processes only what is needed for its function:
- Lovable Cloud — hosting, database, authentication, server functions.
- Lovable AI Gateway / OpenAI — generating AI trip itineraries from the prompts you submit.
- OpenStreetMap Nominatim — geocoding the home town you optionally enter.
6. Cookies & local storage
We use only strictly-necessary storage: an authentication token stored in your browser so you stay signed in, and small UI preferences (e.g. selected tab). We do not run analytics or advertising trackers. See our Cookie Policy for the full list.
7. Retention
Your data is retained while your account exists. When you delete your account from the Profile page, your profile, visits, and itineraries are removed immediately and your authentication record is deleted through the platform's admin API. Short-term request logs age out automatically.
8. Your rights
Depending on where you live (EU/UK GDPR, California CPRA, or elsewhere), you have some or all of the following rights:
- Access — download a copy of your data (Profile → "Download my data").
- Rectification — edit your profile fields directly.
- Erasure / deletion — delete your account (Profile → "Delete account").
- Portability — the export is provided in machine-readable JSON.
- Objection / restriction — email us and we'll act on the request.
- Withdraw consent — at any time, without affecting prior processing.
- Lodge a complaint with your local supervisory authority (EU/UK).
- California residents: right to know, delete, correct, and non-discrimination. We do not "sell" or "share" personal information as those terms are defined by the CPRA.
Requests: privacy@whereivebeen.xyz.
9. International transfers
Our providers may process data outside your country of residence, including in the United States. Where required, transfers rely on standard contractual clauses or equivalent safeguards provided by those vendors.
10. Children
The service is not directed to children under 16, and we do not knowingly collect data from them.
11. Changes
We may update this policy. Material changes will be reflected in the "Last updated" date at the top.
12. Contact
Questions or requests: privacy@whereivebeen.xyz.