Privacy Policy
Last updated August 13, 2026
Long Traveler is planning and follow-along software for long trips, at longtraveler.com. It is a product of Zobot LLC (“we”, “us”), of 2275 Huntington Drive #382, San Marino, CA 91108-2640, United States, which is the data controller for everything described here. This policy explains what we collect, why, where it lives, and the rights you have over it. The short version: we collect what the product needs to work, we use only essential cookies, we run no third-party analytics or advertising, and we never sell your data.
To delete your data — one photograph, everything we received from Facebook or Instagram, or your whole account — see Data Deletion & Your Privacy Rights, which sets out the instructions, the deadlines we answer on, and how to appeal if we refuse.
1. What we collect
- Account details — your name and email address, held by Clerk, our authentication provider, and the trip roles attached to your account.
- Trip content — the itineraries, reservations, notes, expenses, stories and photographs you or your trip’s admins put in.
- Photo metadata — when you upload photographs we read and keep their embedded EXIF data, including the time and GPS location they were taken, because placing each photo on the right day and map pin is the feature. See section 4.
- Social posts added to a trip — when someone adds a public Facebook, Instagram or TikTok post’s link to a trip, we keep that link and the details the platform publishes with it (caption, author’s public name, date, thumbnail address). We do not copy the photograph or video itself. If you connect a Facebook or Instagram account, we also hold the account identifier, name and email address Meta gives us — nothing more, and we never post as you. See how to delete it.
- Technical records — server logs (IP address, request, time) kept for security and debugging, and the storage used by your uploads, measured against your plan’s quota.
2. What we do not do
- No advertising, and no data sold or rented to anyone.
- No third-party analytics or tracking scripts.
- No profiling and no automated decisions with legal effect.
3. Cookies
We use essential cookies only: the session cookies our sign-in provider (Clerk) needs to keep you signed in and to protect against forgery. There are no advertising or analytics cookies, which is why our cookie notice only informs — under EU law, essential cookies need no consent, and we have nothing else to ask consent for. Your browser’s local storage holds small interface preferences (for example, a collapsed panel) on your own device; we do not read them server-side. If we ever add non-essential cookies, we will ask for consent first.
4. Photographs and location
Photo EXIF data — including GPS coordinates — is retained and used to place each photograph on a trip day and a map, and may be reverse-geocoded into a place name. Who can see a photograph is controlled by the trip’s admins: each photo is visible to a trip’s followers only when an admin makes it so. If you do not want location kept, strip EXIF before uploading; captions and placement can then be set by hand.
5. Who can see what
Trip content is private to that trip’s members. Followers see the follow-along view only; financial records are excluded from follower sessions on the server, not merely hidden. We look at your content only when needed to operate the Service, to investigate abuse, or because you asked us to.
6. Where your data lives
The Service runs on Amazon Web Services in the United States (us-east-1), with the database hosted by Neon and authentication by Clerk. Photographs and uploads are stored in private storage and served through expiring signed URLs. Email you send us (hello@ / support@) is received and stored by AWS SES. If you use the Service from outside the United States, your data is processed in the United States.
7. AI features
Some features (place research, story drafting, trip review) send the relevant trip content to Amazon Bedrock to generate text. That content is processed to produce the result and is not used by us to train models.
8. Retention and deletion
We keep your content while your account exists. Delete a record and it leaves the Service at once; our database backups keep a rolling seven-day recovery window and then age out on their own. When you delete a photograph, the stored image file is kept in private storage rather than destroyed in the same click — a safeguard against an accidental tap, since a lost row is recoverable and a lost photograph is not. Ask us and we will purge the file; deleting your account always does.
To delete your whole account and its content, write to hello@longtraveler.com — we acknowledge within 10 business days and complete the deletion within 30 days, except records we must keep by law. Full instructions, including what survives and why, are on Data Deletion & Your Privacy Rights.
9. Your rights
Wherever you live — and specifically if you are in the EU/EEA, the UK, or California — you may ask us for a copy of your data, ask us to correct it, export it, or delete it, and you may object to a use of it. Write to hello@longtraveler.com; we answer within 30 days. If you are in the EU/EEA you also have the right to complain to your local data-protection authority. Your rights are set out in full, by region and with the deadlines and appeal routes that apply, on Data Deletion & Your Privacy Rights.
10. Children
The Service is not directed at children and may not be used by anyone under 16.
11. Changes
If this policy changes materially we will give notice in the product or by email before the change takes effect, and this page always states its last-updated date.
12. Contact
Privacy questions and requests: hello@longtraveler.com. The data controller is Zobot LLC, and you can write to us by post at:
Zobot LLC
2275 Huntington Drive #382
San Marino, CA 91108-2640
United States