Skip to main content

Privacy Policy

Last updated 24 September 2026

The short version. HuddleGo stores the trips you plan and the preferences you submit so your group can plan together. Your trip content is sent to Anthropic’s Claude to generate itineraries. We don’t sell your data, we don’t run advertising trackers, and you can delete your account and everything in it from Settings at any time. The detail below explains exactly what that means.

1. Who we are

HuddleGo is operated by Nomadic AI LLC, [REGISTERED ADDRESS]. For the purposes of the UK and EU GDPR we are the data controller for the information described here. You can reach us about anything on this page at hello@huddlego.io.

2. What we collect

Account details
Your email address and password (passwords are hashed by our authentication provider — we never see or store the plain text), your display name, and an optional profile photo. If you sign in with Google we receive your email address, name and profile picture from Google, and nothing else.
Trip content
Destinations, dates, budgets, group size and trip goals; the preferences each member submits (pace, budget, interests, dietary requirements and accessibility needs); chat messages; expenses and who paid; votes; packing lists; and anything you type into the Hana assistant.
Files you upload
Documents you add to a trip — which people commonly use for passport scans, insurance and booking confirmations. These are stored in a private bucket and served only through links that expire shortly after they are issued. They are readable by the members of that trip and by nobody else.
Location
Two different things, both optional. If you turn on live location on a trip map, your browser shares your position with the other members of that trip while the map is open; we do not store a history of it. Separately, our hosting provider tells us the approximate city a request came from, which we use only to bias destination autocomplete toward where you are. We never ask for background or continuous location.
Usage and diagnostics
A count of AI operations per day, so we can apply fair-use limits; aggregate, cookie-free page analytics; and error reports when something breaks. Error reports can include the page you were on and a technical stack trace.
Payment details
If and when paid plans are available, card details go directly to Stripe and never touch our servers. We store only Stripe’s customer and subscription identifiers and whether your plan is active.

3. Why we use it, and our lawful basis

  • To provide the service — creating trips, merging preferences into an itinerary, delivering chat and votes, splitting expenses. Lawful basis: performance of a contract.
  • To send trip email — invitations, “someone joined”, “your itinerary is ready”, and a reminder if you have joined a trip but not yet submitted preferences (at most two, ever, per trip). Lawful basis: legitimate interests — making group planning actually work.
  • To keep the service secure and available — rate limiting, abuse prevention, error monitoring. Lawful basis: legitimate interests.
  • To take payment, where you have bought a paid plan. Lawful basis: performance of a contract.

We do not use your trip content for advertising, we do not sell or rent personal data to anyone, and we do not build advertising profiles.

4. How AI is used

Generating an itinerary sends the relevant trip content — destination, dates and the group’s submitted preferences — to Anthropic’s Claude API. Messages you send to the Hana assistant, and photos or social links you import, are sent the same way. Anthropic processes this on our behalf as a service provider under their commercial terms, which do not permit using it to train their models.

Itineraries are generated text. They can be wrong about opening hours, prices, travel times or whether somewhere still exists — check anything that matters before you rely on it.

5. Who else can see your information

Other people on your trip

This is a group product, so it shares by design. Everyone in a trip can see the trip’s content, the display names and profile photos of the other members, the preferences each person submitted, chat messages, expenses, and any documents uploaded to that trip. Votes are the exception — they are tallied anonymously.

Other members cannot see your email address, your billing details, or any trip you have not invited them to. If you share a trip’s public link, anyone holding that link can see a read-only summary of the trip without signing in.

Service providers

These companies process data on our behalf, each limited to what its job needs:

Supabase
Database, authentication and file storage · EU/US
Vercel
Application hosting and privacy-friendly analytics · US
Anthropic
AI itinerary generation, Hana assistant, imports · US
Resend
Transactional email delivery · US
Google Maps Platform
Maps, place details and photos · Global
OpenStreetMap (Nominatim)
Converting place names to coordinates · EU
Komoot (Photon)
Destination autocomplete · EU
Sentry
Error and crash reporting · US/EU
Stripe
Payment processing (only if you subscribe) · US/EU

Some are based outside the UK and EEA. Where that is the case, transfers rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses.

We will also disclose information where the law requires it, and we may transfer it as part of a merger or acquisition — in which case we will tell you before it happens.

6. How long we keep it

  • Your account and trips — until you delete them. Deleting your account removes your profile and the trips you created, unless another member is still using a trip, in which case ownership passes to them and your personal details are removed from it.
  • AI usage counters — trimmed automatically; they exist only to enforce daily limits.
  • Error reports — retained by our monitoring provider on a rolling basis, then deleted.
  • Payment records — kept as long as tax and accounting law requires, typically six or seven years.

7. Your rights

If you are in the UK or EEA you have the right to access a copy of your data, to correct it, to have it erased, to restrict or object to how we use it, to data portability, and to withdraw consent where we relied on it. You can exercise most of these immediately: edit your profile in Settings, and delete your account and its data from the same page.

For anything else, email hello@huddlego.io and we will respond within one month. If you think we have handled your data badly you can complain to your local supervisory authority — in the UK, the Information Commissioner’s Office at ico.org.uk.

8. Cookies

We use cookies that are strictly necessary to run the service: they keep you signed in and protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies. Our analytics is aggregate and cookie-free, which is why you are not being asked to accept anything.

Your browser also stores a few small preferences locally — your chosen theme and language, and unsent drafts so you don’t lose work. That data stays on your device and never reaches us.

9. Children

HuddleGo is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal information, email us and we will delete it.

10. Security

Traffic is encrypted in transit and data is encrypted at rest. Access to trip data is enforced in the database itself — row-level security means a request for a trip you are not a member of returns nothing, regardless of what the application code does. Uploaded documents sit in a private bucket reachable only through short-lived signed links, and sensitive profile fields such as your email address are not readable by other members even through our own API.

No system is perfectly secure. If we discover a breach affecting your personal data we will notify you and the relevant regulator as the law requires.

11. Changes

If we change this policy materially we will update the date at the top and, for significant changes, tell you by email or in the app before they take effect.