Legal
Privacy Policy
Last updated: October 6, 2026
Embarka uses the information you give us to plan trips, save itineraries and let you work on them with others. This page describes what the app actually does with that information.
What we collect
- Account details: your email, sign-in information and profile details. We also collect your email if you join the waitlist.
- Planning details you choose to add: home city, destinations, dates, traveler names and ages, children’s birth month and year, expected due month and year, accessibility or dietary needs, booking notes, chat messages, screenshots and saved travel preferences.
- Card and membership details: card issuer and product, points balance, portal redemption rate, annual credits and their usage, membership organization and level, and reciprocal programs. These forms do not ask for card numbers, expiry dates or security codes.
- Trip memories: photos you upload, captions and the date taken when available. We remove embedded image metadata before storing the photo and save the date taken separately.
- Usage details: app events, account and trip identifiers, and AI usage counters. We use account identifiers or IP addresses for request rate limits in server memory.
- We use cookies to keep you signed in. Browser storage holds drafts, preferences, checklist progress and the email awaiting sign-in verification.
Please do not submit passport numbers, full payment-card numbers or identity documents. Card product names, points balances and ordinary booking details are fine. Our automatic checks look only at text, so they cannot reliably catch an identity document inside an image.
Embarka is for adults planning trips. Parents and guardians may add details about children traveling with them, and a saved child traveler is not a separate account. Children may not create accounts.
Who processes it
We use these service providers to run Embarka:
- Supabase: Handles sign-in and stores account, profile, trip, collaboration, analytics and feedback records, plus uploaded photos and screenshots.
- Anthropic: Processes the planning text you submit, relevant profile and trip context, chat requests and uploaded itinerary screenshots to produce AI suggestions or extract itinerary text.
- Google Maps and Places: Receives place searches and locations for maps, geocoding, driving estimates and place photos.
- Google and Apple sign-in: Handle sign-in when you choose them and share account information with Supabase.
- Google Fonts: Serves fonts when you open an exported HTML itinerary.
- Open-Meteo: Receives destination searches, coordinates and dates to return weather information.
- Resend: Delivers app emails when configured, including recipient addresses and the message content.
- Vercel Analytics and Speed Insights: Measure usage and performance. App events can include account or trip identifiers and details about the action taken.
- Sentry: When configured, receives restricted error details. Session replay is turned off; turning it off does not remove records the provider already holds.
- Vercel hosting: Runs the website and API, processing requests and uploaded content.
- Telegram: When configured, receives privacy-operation alerts with shortened request identifiers and counts.
Sending information to these providers means it does not stay only inside Embarka. How long providers keep it, and whether it can be used for model training, depends on our arrangements with each provider. This page does not promise a particular setting.
Share only what your plan needs, especially when describing children or health and accessibility needs. AI context can include family needs, card and membership details, saved travel preferences, shared trip notes and reviews.
Booking links open partner sites. Booking.com links pass through Awin and may include hotel searches and travel dates. Viator links include activity searches and, when configured, an affiliate identifier. Those sites receive your request when you follow a link.
If you use location access during profile setup, we send your coordinates to Google to find your home city and save the coordinates with your profile. In the day view, your device position is used on your device to estimate travel to the next stop.
Sharing and feedback
- Anyone with a shared review link can see the itinerary shared through it.
- Invited collaborators get access that matches their role, including viewing trip photos. Anyone with an enabled recap link can see its trip name, dates, destinations, photos and captions.
- Feedback can include your description, the page URL, a trip identifier and screenshots.
- Feedback screenshots are stored privately. Only you and authorized Embarka staff can view them, through short-lived links. When screenshot uploads are unavailable, the feedback form accepts text only.
- Some screenshots sent with older feedback may still be reachable through their original links. Email us if you are concerned about one.
Avoid putting sensitive details in feedback or screenshots.
Deleting trips
Trip owners can delete a trip from the dashboard. Records linked to the trip by our database deletion rules are removed with it. This does not guarantee erasure of provider logs, backups, feedback uploads or saved learnings.
Deleting your account
- When online deletion is available, you can send a verified deletion request from the Account privacy screen. If it isn't available, email team@embarka.ai from your account email and we'll handle the request. Confirming the request is not the same as confirming the deletion.
- When automated processing is on, deletion runs after a 72-hour waiting period, and you can cancel from that screen until then. Requests that involve content in other people's trips are reviewed by a person first.
- Otherwise, our team reviews and approves each request.
- Deletion removes trips you own (and collaborators' access to them), your personal records, and comments and proposals you wrote on shared trips.
- If your request involves content in another owner's trip or a shared plan, a person reviews that part before it is removed.
- Provider records, backups and copies outside Embarka are handled separately.
- Our internal targets are to acknowledge a request within two business days and complete it within 30 days. These are targets, not guaranteed deadlines.
How long we keep things
| Information | Kept for |
|---|---|
| Private feedback screenshots | 30 days |
| Diagnostic analytics events | 365 days |
| Completed deletion receipts | 365 days, counted after the completion notice is sent and the contact email is cleared |
| Saved profiles and trips you still use | Kept so you can reuse them. They are not automatically expired. |
Nothing in this table is deleted before its period ends. To remove something sooner, delete it from your account or email us. These periods cover records in Embarka. Provider logs and backups follow their own schedules.
Seeing or correcting your information
To request access to, a copy of, or a correction to your personal information, email team@embarka.ai from your account email. We will verify your identity before handling the request.
Contact
For privacy questions or deletion requests, email team@embarka.ai. Do not include passwords, payment numbers or identity documents in your message.