Privacy

Teepee is an invite-only trip planner for a small group of Travellers, not a public product. This page describes, plainly and specifically, what it collects about you and why — not a legal document, just an accurate account of what the system actually does. The Admin (Teepee's operator) has read it and is the person to ask if anything here is unclear.

What Teepee collects

  • Your Google profile and sign-in tokens. Signing in is Google sign-in only, so Teepee receives your name, email address and avatar image from Google, and stores the OAuth tokens Google issues for your session (the access token, refresh token, ID token, the granted scope, and a session token identifying your browser).
  • Everything you put in a Trip. Stops, Transport, Accommodation, Items, Costs, Notes, Journal entries and Checklists — the trip content you and the other Travellers on a Trip enter.
  • Your Globe. Markers — places you and whoever shares your Globe want to visit someday. This lives separately from any Trip, at the account level, not as part of a Trip's content.
  • A record of changes to a Trip. Creating, changing or deleting a Stop, Item, Transport, Accommodation, Chapter or Cost — or leaving a Note — is logged as an Activity: who did it, when, and for a change, which fields moved from what to what. This is the Trip's shared history, visible to the Travellers on that Trip.
  • Files you upload. Attachments such as tickets, confirmations and screenshots.
  • Push subscriptions. If you turn on the Digest on a Device, Teepee stores what that Device's browser gives it to deliver a push notification, plus a coarse device type ("iPhone", "Mac", and similar — derived once from the browser's user agent, never anything more specific), the timezone that Device last reported, and when it was last seen.
  • Error reports. When something in Teepee breaks — including a failure caught in your browser — it records the error message, a stack trace, the route it happened on, and your account id if you were signed in at the time. It is also written to Vercel's own runtime logs. The first time a given server-side failure is seen, its raw error message is pushed to every Admin's Device (if the Admin has one registered) — a repeat of the same failure only bumps a count, never pushes again, and a browser-reported failure is never pushed this way at all.
  • Access requests — including from people who never get an account. Teepee is invite-only: if you sign in with Google and your address is not on the invite list, sign-in is refused, and that refusal itself is recorded — your name, email, avatar, and how many times you've tried, exactly as Google's sign-in flow supplies them — so the Admin can see who has asked and decide whether to invite them. This is the most surprising thing on this page, so we are saying it plainly: Teepee can hold a record about you even if you are never granted an account. The Admin can approve a request (granting access) or dismiss it; a dismissed request is closed for good — it does not return to the Admin's queue, even if you sign in again.
  • Feedback notes. A remark you write to the Admin about Teepee itself (a defect, an annoyance, a suggestion) carries the note text plus the circumstances it was written in — the route, a page label, the Trip you were viewing (if any), your browser's viewport size and user agent, and your name. You see only your own notes in the app; only the Admin sees every author's notes.

Who it is shared with

Teepee is one small app, not an ad-funded product — nothing here is sold, and nothing is shared for marketing. The following named services are the ones Teepee's code actually contacts:

  • Google — sign-in. Your avatar image is also loaded straight from Google by whoever's browser is viewing it, so Google sees that request too, separately from sign-in itself.
  • Apple Push and FCM (Firebase Cloud Messaging) — deliver the Digest and other push notifications to your Devices.
  • OpenStreetMap (Nominatim) and CARTO — turn place names you enter into map coordinates, and draw the map tiles you see on the Summary, the Globe and the Day map.
  • Open-Meteo — a Stop's coordinates and a day's date, sent to fetch a weather forecast (or, for a date too far out to forecast, a typical reading from the same calendar date last year).
  • Frankfurter — currency codes (e.g. "AUD" → "EUR"), sent to fetch an exchange rate. No Trip content, just the currency pair.
  • Anthropic (Claude) — an optional AI assist, off unless the Admin turns it on. Teepee includes an AI assist for three things: suggesting activities, drafting a packing list, and parsing a pasted booking confirmation into a Transport or Accommodation. It only runs if the Admin has configured an API key for it — turning it on is a deployment setting, not a code change, so whether this is live can change without this page changing. When it is on, Teepee sends: a Stop's name and country, plus the titles of the Items already on that Stop (so it does not repeat them), for a suggestion; the Trip name with its Stops and dates, for a packing list; or, for parsing, the entire text you paste in — which can include names, addresses and booking or confirmation numbers, since it is whatever you pasted.
  • Cloudflare R2 — stores uploaded Attachments and Trip cover images.
  • Vercel — hosts the app, runs the database migration on a production deploy, and runs the Web Analytics described below.
  • Neon — hosts the database.
  • GitHub — the nightly database backup described under "How long it's kept" below is uploaded to GitHub as a GitHub Actions build artifact and stored there for up to 30 days: a complete copy of the database — every Trip, Note, email address, Access request and Error report in it. Who can download a GitHub Actions artifact is exactly who can read the repository it belongs to. That setting lives on GitHub, not in Teepee, and the Admin can tell you what it is today.

Analytics, advertising and trackers

There is no advertising in Teepee, and no third-party tracker in the ad-tech sense — no cross-site tracking, no ad targeting, no data broker, nothing sold. Teepee does use Vercel Web Analytics (part of the Vercel hosting above) for coarse, aggregate page views: which pages get opened, on what kind of device, plus referrer and coarse country — dimensions Vercel's own infrastructure adds, not anything read out of your account. It does not use cookies and does not build a personal profile. One redaction we do control: a Share link's URL carries a secret token as part of the address, so that token is stripped before the page view is sent to analytics — it still appears, unredacted, in an Error report if that specific page happens to throw (see "What Teepee collects" above). A Trip's id in a URL like /trips/… is deliberately not redacted from analytics, so usage can be broken down per Trip; a Trip id is useless to anyone without an account on that Trip. Beyond that one page-view counter, there is no other analytics.

How long it is kept

  • Database backups run nightly — the rollback path if a bug or a bad migration damages data. Each one is held on GitHub for up to 30 days as a build artifact. During that window the Admin also copies it to storage outside GitHub — this page makes no claim about how long that separate copy is kept.
  • Deleted files are not destroyed the instant you delete them: they are kept at least 35 days (so they still exist in any backup taken before the deletion), then removed the next time the Admin runs the cleanup — there is no scheduled job that does this on its own.
  • Error reports and Access requests are not deleted on a timer. An Admin can clear an error report once it is understood, and approve or dismiss an Access request — until then, both simply sit in the database (and so in the nightly backups above) like everything else.

Getting your data

There is no self-serve export yet — ask the admin and they'll send you a copy.