Privacy
Teepee is an invite-only trip planner for a small group of Travellers, not a public product. This page describes, plainly and specifically, what it collects about you and why — not a legal document, just an accurate account of what the system actually does. The Admin (Teepee's operator) has read it and is the person to ask if anything here is unclear.
What Teepee collects
- Your Google profile and sign-in tokens. Signing in is Google sign-in only, so Teepee receives your name, email address and avatar image from Google, and stores the OAuth tokens Google issues for your session (the access token, refresh token, ID token, the granted scope, and a session token identifying your browser).
- Everything you put in a Trip. Stops, Transport, Accommodation, Items, Costs, Notes, Journal entries and Checklists — the trip content you and the other Travellers on a Trip enter.
- Your Globe. Markers — places you and whoever shares your Globe want to visit someday. This lives separately from any Trip, at the account level, not as part of a Trip's content.
- A record of changes to a Trip. Creating, changing or deleting a Stop, Item, Transport, Accommodation, Chapter or Cost — or leaving a Note — is logged as an Activity: who did it, when, and for a change, which fields moved from what to what. This is the Trip's shared history, visible to the Travellers on that Trip.
- Files you upload. Attachments such as tickets, confirmations and screenshots.
- Push subscriptions. If you turn on the Digest on a Device, Teepee stores what that Device's browser gives it to deliver a push notification, plus a coarse device type ("iPhone", "Mac", and similar — derived once from the browser's user agent, never anything more specific), the timezone that Device last reported, and when it was last seen.
- Error reports. When something in Teepee breaks — including a failure caught in your browser — it records the error message, a stack trace, the route it happened on, and your account id if you were signed in at the time. It is also written to Vercel's own runtime logs. The first time a given server-side failure is seen, its raw error message is pushed to every Admin's Device (if the Admin has one registered) — a repeat of the same failure only bumps a count, never pushes again, and a browser-reported failure is never pushed this way at all.
- Access requests — including from people who never get an account. Teepee is invite-only: if you sign in with Google and your address is not on the invite list, sign-in is refused, and that refusal itself is recorded — your name, email, avatar, and how many times you've tried, exactly as Google's sign-in flow supplies them — so the Admin can see who has asked and decide whether to invite them. This is the most surprising thing on this page, so we are saying it plainly: Teepee can hold a record about you even if you are never granted an account. The Admin can approve a request (granting access) or dismiss it; a dismissed request is closed for good — it does not return to the Admin's queue, even if you sign in again.
- Feedback notes. A remark you write to the Admin about Teepee itself (a defect, an annoyance, a suggestion) carries the note text plus the circumstances it was written in — the route, a page label, the Trip you were viewing (if any), your browser's viewport size and user agent, and your name. You see only your own notes in the app; only the Admin sees every author's notes.
Analytics, advertising and trackers
There is no advertising in Teepee, and no third-party tracker in the ad-tech sense — no cross-site tracking, no ad targeting, no data broker, nothing sold. Teepee does use Vercel Web Analytics (part of the Vercel hosting above) for coarse, aggregate page views: which pages get opened, on what kind of device, plus referrer and coarse country — dimensions Vercel's own infrastructure adds, not anything read out of your account. It does not use cookies and does not build a personal profile. One redaction we do control: a Share link's URL carries a secret token as part of the address, so that token is stripped before the page view is sent to analytics — it still appears, unredacted, in an Error report if that specific page happens to throw (see "What Teepee collects" above). A Trip's id in a URL like /trips/… is deliberately not redacted from analytics, so usage can be broken down per Trip; a Trip id is useless to anyone without an account on that Trip. Beyond that one page-view counter, there is no other analytics.
How long it is kept
- Database backups run nightly — the rollback path if a bug or a bad migration damages data. Each one is held on GitHub for up to 30 days as a build artifact. During that window the Admin also copies it to storage outside GitHub — this page makes no claim about how long that separate copy is kept.
- Deleted files are not destroyed the instant you delete them: they are kept at least 35 days (so they still exist in any backup taken before the deletion), then removed the next time the Admin runs the cleanup — there is no scheduled job that does this on its own.
- Error reports and Access requests are not deleted on a timer. An Admin can clear an error report once it is understood, and approve or dismiss an Access request — until then, both simply sit in the database (and so in the nightly backups above) like everything else.
Getting your data
There is no self-serve export yet — ask the admin and they'll send you a copy.