Privacy Policy

Last updated: 25 Oct 2025

At teravia, we collect the minimum data needed to operate our maps, AI inspiration, and poster features. This Policy explains what we collect, why, and your choices.

1) What we collect

  • Usage & diagnostics. Basic event logs (e.g., feature used, timestamp, request size, success/error) to keep the service reliable.
  • Rate-limiting identifiers. For anonymous users we may store a hashed identifier (e.g., IP hash) to enforce daily limits. For signed-in users we store your user ID for the same purpose.
  • Content you provide. Trip parameters (destination, days, notes) you type to generate AI ideas or posters.
  • Images & attribution data. For place thumbnails from Wikimedia/Commons we cache a copy and store author/license/file-page URLs required for attribution.
  • Cookies/Local Storage. We use strictly-necessary cookies/local storage to keep lightweight preferences (e.g., dismissing a Terms modal) and session tokens for anonymous sessions.
  • Date of birth & age status. If you create an account, we collect your date of birth (DOB) to verify you are at least 16. We also store a derived boolean (age_verified). DOB may be masked in the UI by default.
  • Private social signals. Your Connections (mutual only) and your private Collections of trips. These are not publicly displayed beyond a single “Connections · {count}” number on your profile.
  • Subscription & billing metadata. Plan (e.g., Free/Plus), Stripe customer/subscription IDs, current_period_end, cancel_at_period_end, and usage quotas. We do not store full card details.

2) How we use data

  • Operate the app (maps, AI inspiration, poster generation, caching thumbnails).
  • Enforce fair-use limits and protect against abuse (spam, scraping, fraud).
  • Improve quality and reliability (diagnostics, aggregate analytics).
  • Show required image licenses/credits where applicable.
  • Provide private features: Connections (mutual only) and your personal Collection.
  • Personalize silently using your own private signals (connections/collections), without public leaderboards.
  • Manage subscriptions (auto‑renew status, end‑of‑period access) via Stripe.

3) AI providers & third parties

We use third-party services to deliver features:

  • AI models to generate itinerary text. Prompts you send may be processed by the model provider to return results.
  • Map tiles & Wikimedia for basemaps and place thumbnails; we may cache thumbnails and associated license metadata.
  • Stripe (payments) to process subscriptions. We share minimal identifiers (e.g., customer/subscription IDs) and do not store full card details.

These providers receive only the data needed to perform their function. Their privacy practices apply when they process your data.

4) Legal basis & purposes (if you’re in the EEA/UK)

  • Performance of a contract (providing the service you request).
  • Legitimate interests (security, abuse prevention, service analytics, required attribution).
  • Consent (where required, e.g., optional cookies or marketing if introduced later).
  • Compliance with legal obligations (tax/accounting records for subscriptions and payments).

5) Retention

  • Anonymous rate-limit records are kept for the rolling window needed to enforce limits (e.g., daily) and then pruned or aggregated.
  • Session outputs (AI ideas/posters) may be stored with your session ID so you can view/download them.
  • Cached thumbnails and attribution metadata may be retained to comply with license terms.
  • Subscription and billing records are retained for the period required by accounting/tax laws.
  • On account deletion, we cancel billing immediately and delete or anonymize personal data. Where image licenses require attribution, we may retain attribution records and cached thumbnails.
  • Aggregated analytics may be retained without identifying information.

6) Sharing

  • We do not sell your personal data.
  • We share data with processors (hosting/database, analytics, AI, maps, payments) strictly to operate the service, under appropriate agreements.
  • We may disclose information if required by law or to protect the rights and safety of users or the service.
  • Examples of processors include Supabase (hosting/database), Stripe (payments), and image/storage providers.

7) Your choices & rights

  • You can use teravia without creating an account. If you later create one, you may request access, correction, or deletion as applicable.
  • You can clear local browser storage/cookies related to teravia at any time (may affect session continuity).
  • EEA/UK residents: you may have rights to object, restrict processing, data portability, and lodge a complaint with your local authority.
  • You can show/hide DOB in the UI; DOB may be masked by default.
  • You can turn off auto‑renew; access continues until the listed end date.
  • You can delete your account; we cancel billing immediately and remove/anonymize your data.

8) Security

We use reasonable technical and organizational measures (encryption in transit, access controls). No system is 100% secure; please report issues to hello@teravia.app.

9) Children

teravia is not directed to individuals under 16. We block account creation for users under 16. If you believe we collected data from someone under 16, contact us to remove it.

10) International transfers

We may process data in countries different from yours. We use safeguards such as standard contractual clauses where required.

11) Changes to this Policy

We may update this Policy periodically. Material changes will be reflected by updating the “Last updated” date.

12) Contact

Email: hello@teravia.app


Also see our Terms of Service and Acceptable Use.

← Back to teravia