PRIVACY
Travel plans are personal. We treat them that way.
This policy explains what Ashore stores during trip import, execution setup, planning, and sharing; who can see it; and the choices available to travelers and companions.
Information Ashore handles
Ashore stores the structured information used to operate a trip: destinations, dates, traveler names, itinerary items, notes, estimated costs, booking-readiness labels, import metadata, recommendations, reactions, questions, and recent owner-only undo checkpoints. Uploaded or pasted source material is processed to extract that structure; the current importer does not retain the original file or raw source text after the request completes.
Private execution records can include tasks, vendor names, contact and booking permissions, budget and deposit limits, refundability and alternate-time rules, booking windows, retry and audit events, confirmation codes, prices, cancellation terms, and evidence sources. This execution record is not included in guest trip pages or guest API responses.
Companions can contribute reactions, reaction reasons, questions, and recommendations without an account. Ashore assigns the browser a random participant identifier so changing a reaction does not inflate group totals.
Owner and participant cookies
Ashore uses essential HTTP-only cookies. An owner capability cookie lets the planner reopen and edit a trip. A separate participant cookie remembers a companion’s reactions. These cookies are not advertising trackers and are currently retained for up to one year unless cleared earlier.
An owner may create a one-time recovery link for a new browser. Its secret stays in the URL fragment and is returned only once; Ashore stores a cryptographic hash and creation time. Successful recovery consumes the key and rotates owner access, invalidating the prior owner cookie.
Sharing and visibility
Anyone who receives a trip’s guest link can view its shared itinerary, traveler names, group reaction totals, booking-readiness labels, and recommendations. Guest and friend-link responses do not include the planner’s reusable travel profile or dietary restrictions.
A guest can create a separate, editable copy of a shared trip. A copy keeps the itinerary but receives fresh identities and does not include the original profile, dietary restrictions, traveler list, recommendations, reactions, reaction reasons, or claimed reservations.
How information is used
- Import, generate, refine, save, and display structured itineraries.
- Create and maintain private execution tasks within traveler-defined boundaries.
- Record approvals, retries, booking windows, and reservation evidence without equating an attempt with success.
- Answer questions about a shared trip and summarize group preferences.
- Keep reactions and recommendations consistent across participants.
- Protect owner-only editing and operate, secure, and improve the service.
Ashore processes limited connection information, such as an address supplied by the hosting network, to prevent automated abuse and excessive model usage. Production rate-limit counters use salted cryptographic hashes rather than storing raw client addresses and expire from active use after their short request window.
Ashore does not sell trip or profile data and does not use it for third-party behavioral advertising.
Service providers and external links
A production deployment may use hosting, database, and AI-model providers to process trip data on Ashore’s behalf. When model-backed planning is enabled, the relevant trip context and prompt may be sent to that configured model provider. Payment credentials and identity documents should never be submitted to the planner.
Opening a place or route in Google Maps leaves Ashore and is governed by Google’s own terms and privacy practices.
Retention, access, and deletion
Trip records remain available so planners and companions can return to them. Undo checkpoints are bounded and older checkpoints are discarded as newer planner changes replace them. A planner can permanently delete a trip through Trip settings. That removes the stored itinerary, private execution plan and evidence, active recovery-key hash, profile snapshot, companion-feedback ledgers, recommendations, and undo history, and existing planner, guest, calendar, recommendation, recovery, and execution links stop working.
For access or correction help, or if owner access has been lost, contact Ashore Support. Ashore may retain limited records when reasonably necessary for security, legal obligations, or abuse prevention.
Security and changes
Owner edit tokens are stored as cryptographic hashes, production database access is server-mediated, and private trip surfaces opt out of indexing and caching. No online service can promise perfect security; report a suspected access issue promptly through Support.
If this policy changes materially, the effective date and content on this page will be updated before the new terms apply.
Contact
For privacy requests or questions, use the current contact listed on the Support page.