AwayDaysBack to product

Privacy policy

Your travel data should work for you—and stay under your control.

This policy explains how AwayDays handles account information, Gmail data, travel memories, connected-provider results, voice sessions, and the choices available to you.

Effective July 18, 2026

Google user data is used only for user-facing AwayDays features. It is never sold, used for advertising, credit decisions, or generalized AI model training.

1. Information AwayDays receives

Google identity

When you sign in, AwayDays receives your Google account identifier, verified email address, display name, and profile image. Sign-in does not include Gmail access.

Gmail Travel Memory

If you separately connect Gmail read-only, AwayDays searches for likely travel confirmations from the last five years. The current query targets reservation-category messages and subjects mentioning flights, hotels, itineraries, bookings, reservations, or tickets.

AwayDays may read the selected message body and relevant PDF or image attachments to extract travel facts. It cannot send, edit, delete, label, or otherwise modify Gmail.

Other product data

We process trip requests, confirmed preferences, itinerary choices, approvals, provider results, voice transcripts supplied through the configured voice service, operational events, and support communications needed to provide the product.

2. What is stored

DataPurposeRetention
Google identity and sessionsAuthenticate your account and protect private workspaces.Sessions expire after 30 days; account data remains until account deletion.
Encrypted Gmail OAuth tokensRun user-initiated selective imports without asking for consent on every request.Until you disconnect Gmail, revoke access at Google, the token becomes invalid, or you delete your account.
Travel memoryShow reviewable travel facts and build recommendations from facts you confirm.Until account deletion. Disconnecting Gmail stops future access but does not silently erase reviewed memories.
Gmail provenanceLet you verify an extracted fact against its source.Gmail message ID, subject, sender, normalized facts, and a short evidence excerpt are retained with the memory. AwayDays does not store the complete raw mailbox or a full raw message archive.
Import and action audit dataDiagnose imports, prevent duplicate actions, and reconcile known or unknown outcomes.Until account deletion or an earlier operational deletion schedule is introduced and disclosed.

3. How Google user data is used

  • Find likely travel confirmations at your request.
  • Extract explicit flight, hotel, rail, car, restaurant, and event facts.
  • Present every imported memory for confirmation or rejection.
  • Build a private preference profile only from confirmed memories.
  • Rank user-visible travel recommendations and prepare user-visible actions.

Rejected and unreviewed memories do not influence recommendations. Google user data is not used for advertising, resold, used to determine creditworthiness, or used to train a generalized model.

4. Optional processors and transfers

The Gmail connection screen lets you choose whether relevant content may be sent to optional processors. If you do not opt in, the corresponding processor is not used for Gmail import.

  • OpenRouter: relevant email text may be sent for structured extraction through providers configured to deny data collection and require zero-data-retention routing. AwayDays sends a pseudonymous user identifier rather than your account identifier.
  • LandingAI: relevant difficult PDFs and images may be sent for document parsing and structured extraction within the displayed credit budget only after Zero Data Retention is enabled for the production organization.
  • Infrastructure and security providers: hosting, database, logging, and security services may process the minimum data required to operate AwayDays.

These transfers are only for prominent user-facing AwayDays features and only with your in-product consent. Production processors must be configured or contractually required not to use Gmail data for advertising or generalized model training.

5. Security

Gmail tokens are encrypted at rest. AwayDays uses server-side OAuth code exchange with PKCE and signed state, HTTP-only session cookies, same-origin protections for state-changing requests, schema validation, provider allowlists, and approval boundaries for consequential actions. No security measure eliminates every risk; we review controls as the product moves to production.

6. Your controls

  • Connect Gmail separately from Google sign-in.
  • Choose whether OpenRouter or LandingAI may process Gmail content.
  • Confirm or reject each imported memory.
  • Open the original Gmail message for verification.
  • Disconnect Gmail, which revokes or removes local OAuth access and stops future imports.
  • Delete your AwayDays account and associated stored data through the account menu.
  • Revoke AwayDays directly from your Google Account security settings.

See Data Controls for the exact steps.

7. Google API Limited Use

AwayDays’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Changes

If our handling of Google user data materially changes, we will update this policy and present a new in-product notice or consent before using the data for the new purpose.

Questions or privacy requests

Email shanmukhsain@gmail.com. Account holders can also use the in-product Privacy & data controls.