Privacy Policy
Last updated 14 September 2026
Wander is a travel itinerary planner. This policy describes what it stores, what it sends elsewhere, and how to have it deleted. It is written to be read rather than skimmed, so it is specific about the parts that matter.
What Wander stores
- Your account. The email address you sign in with, and a display name. If you sign in with Google, the email address and name Google gives us. Passwords are handled by our authentication provider and are never visible to us.
- Your trips. Everything you put in them: trip names, destinations, dates, budgets and notes; activities with their times, places, coordinates, costs, booking references and notes; packing lists; and the requests and answers in that trip's Wander conversation.
- Who you share a trip with. The display name and email address of each person on a shared trip, so members can see who else is on it.
- Places on your globe. Places you save as somewhere you have been or want to go: the name, address and coordinates, and the journey it came from if it did. Only you can see them.
- Google Calendar access, only if you connect it. See the section below.
- Offline downloads, only when you request them. The itinerary, addresses, booking references, notes and packing list are saved in this browser on your device. Anyone who can use that browser can read them without signing in again. They are snapshots: later changes and access removals cannot reach a device while it is offline. Remove a copy from Downloaded trips or sign out of Wander to clear this browser’s downloads.
What Wander does not store
- Pictures you attach when planning. They stay in your browser, are sent once to be read, and are never written to our database.
- Your location. The route screen asks your browser for it to measure the way to a place. It is used for that request and not kept.
- Advertising or analytics data. There are no advertising cookies, no trackers and no analytics service. Your browser keeps your sign-in token, display preferences and any trips you explicitly download for offline access.
Google Calendar
Connecting a calendar is optional, is never part of signing in, and can be undone at any time. If you connect one, Wander asks Google for two permissions:
- Read your calendar (
calendar.readonly) — so it can show what you already have on during a trip and plan around it. - Manage events (
calendar.events) — so it can add your trip to your calendar when you ask, update those events when the trip changes, and remove them again when you ask it to.
Only a trip’s own dates are ever read. Every request is bounded by the start and end date of the trip you are looking at; Wander never asks for your calendar in general. From each event it reads the title, the start and end, the location and the description, and nothing else. Events that Wander itself wrote are filtered out of what it reads back.
Calendar entries are sent to our planning provider (OpenAI) when you use a feature that plans around them — creating a trip, asking for suggestions for a day, or asking the command bar to change something. That is how the wedding in your calendar ends up in your itinerary with its real address. If you would rather that did not happen, do not connect a calendar.
Writing is limited to events Wander created. Every event it adds carries a hidden marker naming the trip it came from. It only ever updates or deletes events carrying that marker; it does not touch anything else in your calendar.
The access it holds is a refresh token stored on our server, in a table that no user account can read — not even yours. It never returns to your browser after the moment Google issues it. Disconnecting deletes it and revokes it at Google in the same step.
Wander’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never used to train any model.
Who else sees your data
Wander has no employees reading your trips and sells nothing to anyone. It does rely on these services to work:
- Supabase — stores the database and runs sign-in.
- Vercel — hosts the application.
- OpenAI — turns your requests into plans. It receives what you type or attach, recent Wander conversation for that trip, the trip and its activities when you ask for a change, and calendar entries within the trip’s dates when a calendar is connected. It does not receive your email address or your account.
- Google Maps Platform — draws maps, searches for places, supplies place photos, ratings and reviews, and works out routes. It receives the place names you search for and the coordinates being shown.
- Unsplash and Wikimedia Commons — serve the photographs in journeys. Your browser requests each photograph from whichever of the two it came from when a journey page shows it.
- YouTube — only when you press play on a journey’s video. Until then only a still image is shown; pressing play loads YouTube’s privacy-enhanced player, and YouTube then receives that request.
Deleting things
- An activity or a trip — delete it in the app; it goes immediately, along with everything in it.
- A place on your globe — select it on the globe and remove it.
- The calendar connection — Account → Disconnect. The stored permission is deleted and revoked at Google straight away. Events already written to your calendar stay unless you remove them, which the trip’s Calendar panel will do for you.
- Your whole account — email REPLACE_WITH_YOUR_CONTACT_EMAIL from the address you signed up with. Everything is deleted within 30 days.
Children
Wander is not intended for children under 13, and accounts are not knowingly created for them.
Changes
If this policy changes in a way that affects what happens to your data, the date at the top changes with it.
Contact
Questions, or a deletion request: REPLACE_WITH_YOUR_CONTACT_EMAIL.