legal
Cookie Policy
The short version: no advertising cookies, no analytics cookies, no tracking pixels. Here is the long version anyway.
Last updated 5 August 2026
1. Why you are not seeing a cookie banner
United States law does not require consent before storing cookies. What it does require is that we tell you what we store and that we not sell your information without giving you a way out. This website stores nothing for advertising, runs no analytics, and we do not sell or share personal information — so there is nothing to opt out of, and the storage listed below is either needed to keep you signed in or is a preference you set yourself.
The same conclusion happens to hold for visitors in the EEA and UK, where consent is required for non-essential storage: this site sets none, so no banner is owed there either. If that ever changes, this page changes and a proper consent choice comes with it.
Note that this page is about the website and the web app. The iOS app is a different matter: it carries crash reporting and product analytics, which do not use cookies but do collect something. What they collect, and what they do not, is set out in section 3 of the Privacy Policy.
2. What the marketing site stores
Nothing. The landing page you arrive on sets no cookies and writes nothing to your browser storage. The waitlist form posts your email address to our server and stores nothing locally.
3. What the web app stores
The app at /app keeps a small amount of data in your browser so it can work. None of it is shared with third parties for advertising.
Strictly necessary
| Name | Purpose | Lifetime |
|---|---|---|
| Supabase session token | Keeps you signed in and authorises requests to our database. Set by our authentication provider under a name beginning sb-. | Until sign-out or expiry |
| onboarding_completed | Remembers that you finished the intro so it is not shown again on every visit. | Until cleared |
Preferences you set
| Name | Purpose |
|---|---|
| appLanguage | The language you chose |
| tripSortOption, tripShowPastTrips | How your trip list is sorted and filtered |
| sawDayReorderHint, swipeHintSeen_* | Records that you have seen a one-off hint, so it stops appearing |
| all_trip_llm_jobs | Tracks planning jobs already running, so a reload does not start them twice |
| tripbuddy-covers (IndexedDB) | Caches trip cover images already downloaded, so they do not have to be fetched again |
4. Third parties that see something
- OpenStreetMap — map tiles are fetched by your browser directly from OpenStreetMap servers, so they receive your IP address and the area of the map you are looking at whenever a map is on screen. They set no cookies for us.
- Google — only if you choose to sign in with Google. Google then sets its own cookies under its own policy. If you sign in with an emailed code instead, Google is not involved.
- Cloudflare — our host sets no cookies on this site as it is configured today; we checked. Its bot-protection cookie __cf_bm only appears when bot management is switched on, which it is not, and cf_clearance only if you are ever shown a security challenge. Neither is used for advertising or analytics.
Trip photography and place details are fetched by our own server, not your browser, so those providers never see your device or IP address.
5. How to clear or block it
Every browser lets you view and delete site data — usually under Settings, then Privacy. Clearing it will sign you out and reset your preferences. If you were using TripBuddy without an account, clearing it will also remove trips that were only held in that anonymous session.
Blocking all storage for this site will prevent sign-in from working at all, because the session token has nowhere to live.
6. Questions
Write to ali@tripbuddyai.com. See also the Privacy Policy.