Skip to content

Legal

Privacy policy

What is collected, why, on what legal basis, who else touches it, how long it is kept, and how to get it out or have it erased. Nothing is sold, to anyone, ever.

Updated 4 Oct 2026about 11 minutes

  1. 1.The short version
  2. 2.Who is responsible for your data
  3. 3.What is collected
  4. 4.Why, and on what legal basis
  5. 5.The route generator, and what a model sees
  6. 6.Who else touches it
  7. 7.Where it goes
  8. 8.How long it is kept
  9. 9.What you can require of us
  10. 10.If you are in the United States
  11. 11.Children
  12. 12.Security, and what happens if it fails
  13. 13.Changes to this policy

1.The short version

We collect what the product needs to work: your account, the trips you build, and enough technical logging to fix what breaks. We do not sell personal data, we do not run advertising, and nothing here follows you to other websites.

Two measurement tools count what gets used on this site and where people give up on it. Say yes and both run. Say no and neither does. Until you answer either way, one of them runs in a mode where it stores nothing on your device and sends no identifier, and that is the only thing on this site that happens before you have decided. Refusing takes one tap, Cookie settings in the footer changes the answer whenever you like, and nothing else on any page belongs to anybody else.

One more note, because a link in an advert is the only way we can tell which adverts work. If the link you followed carried a campaign name, or you came from a search engine or a social site, this site keeps a few fixed words saying which, such as a channel and a campaign. It never keeps a click id, your address or the page you came from. Until you say yes it lives in the page's memory only, and a reload forgets it. If you sign up or pay, the words are written on your account and on the payment. If you said no, none of it is kept or sent.

Separately from those two tools, and only while you are signed in, we note on our own servers which day you opened a trip and which parts of it you used. It is how we find out whether anyone comes back to a trip they built, and so what is worth fixing. It stores nothing in your browser, so the cookie notice does not apply to it, and the table below gives its basis and how long it is kept.

If any of that changes, this page changes before it does, and you get an email, not a quiet edit.

2.Who is responsible for your data

The controller is the person named below: one self-employed individual with a Lithuanian individual activity certificate, not a company. Small enough that a request about your data is read by the person who wrote the code that holds it.

There is no data protection officer, because the scale does not require one under Article 37. Write to the address below and you reach the person who would be it.

VAT
Not registered for VAT
Email
hello@outrouted.com

3.What is collected

Eight kinds of thing, and nothing that is not on this list.

  • Account: name, email address, a hash of your password (never the password), your plan, your display preferences, and the home country you set for visa checks.
  • Trips: the countries, cities, dates, party, budget and pace you enter, the routes generated from them, and any notes you write into a trip. If you make a share link, anyone who holds it can read the trip without an account; your booking references and booking links stay out of it unless you turn them on for that link.
  • Billing: plan, period, amounts, invoices, and the card's brand, expiry and last four digits. Never the card number, which goes to Stripe and never reaches us.
  • Technical: IP address, approximate country from the network edge, user agent, request timing and error traces. The country is what decides whether you are shown euros or dollars, kilometres or miles, before you have told us anything.
  • Correspondence: whatever you write to us, and our replies.
  • Where you came from: a few fixed words saying which campaign link or kind of site brought you, such as a channel, a campaign name and, for a friends link, which group. Never a click id, your address, or the page you came from. Written on your account when you sign up, and on the payment when you pay.
  • An address for “tell me when it is ready”: if you type one into a search, whether or not you have an account. It is used for one message saying your routes are ready, with the link to them, and for nothing else. It is kept with that search, which lasts 24 hours, and goes when the search is cleared away.
  • Which trips you open: while you are signed in, the day you opened a trip you own or were invited to, and which of its parts you used that day, such as stops, days, stay, budget, weather, tasks, print, export or share. Kept against your account on our own servers. Never what you typed, where you were or which device you used, and nothing is set in your browser for it.

5.The route generator, and what a model sees

Route generation sends a large language model the inputs of the trip and asks it for a structure: which places, in what order, how many nights each. Those inputs are the countries, dates, party size, budget, pace, interests, the city you start from and the pool of candidate places. If you gave the ages of the people travelling, they go too. So do the places you pinned, with the label and note you gave each one.

Anything you wrote in your own words goes as well: the note in the planner, and your answers to the questions we ask before a search. It is sent as written, in a block marked as yours, and the model is told to treat it as information about the trip and not as instructions. It reaches the provider, so leave out what you would not want a processor to read. The questions before a search, the write-up of a route you build and a re-plan use the same inputs. Your name, email and account are not part of that request.

The model's answer is then checked, not trusted: places outside the candidate pool are dropped, a night split that does not add up is re-spread by our own code, and every number a person sees is computed here. The provider processes the request on our instruction under a contract that forbids using it to train their models.

This is not automated decision-making in the Article 22 sense. Nothing about it produces a legal effect on you or decides anything about you as a person. It suggests an itinerary, and you rearrange it.

6.Who else touches it

Every processor below is bound by a contract, may use your data only on our instruction, and may not use it for anything of their own. The last group is different and worth reading separately: they are asked for something by your browser, so they see your IP address the way any website you visit does.

The two measurement vendors sit between those two groups, which is why they are the only things on this site you are ever asked about. They are contracted the same way, and they are also Google and Microsoft, whose own policies govern what else they may do with what a tag collects. Both are configured here with advertising storage refused and ad personalisation off. Say no and neither one runs; before you have answered, Google's tag runs in a state that stores nothing, which the cookie policy sets out exactly.

The last row is on the list for what it is not. Booking.com, LOT Polish Airlines, Ferryhopper and EconomyBookings are paid links on the home page, and the logos beside them are files served from here, not creatives fetched from an affiliate network, so reading that page tells none of them anything at all. Press one and you are on that provider's site from that moment, under their own privacy and cookie policies, and what happens there is between you and them. What comes back to us is a count of clicks and sales in the network's dashboard, with nothing in it that identifies a person.

WhoWhat forWhat they get
CloudflareHosting, the database, and the network edge everything arrives throughEverything, as the infrastructure it runs on
StripePayments, invoices, card handlingName, email, card, amounts, and the fixed words for which link brought you
Google (Continue with Google)Signing in with a Google account, only if you press that buttonYour browser goes to Google's own sign-in page, so Google sees your IP address and which of its accounts you pick, as it does for any site with that button. We send it our app's id, the return address and a one-time code. It sends back your email address, whether it has verified that address, and your name. We keep the email and the name on your account. We ask for nothing else of yours (no contacts, mail or files), and no Google password or token is stored
ResendSending account email, and the message that your routes are readyName, email, the message. For a ready message, the address you typed and the link to your routes
OpenAIChoosing places, order and nightsTrip inputs and the candidate pool, including the note, ages and pinned places you wrote. No account identifiers
Nuitee (liteAPI)Hotel search prices and flight searches that inform planning, and hotel photographs, fetched by our server rather than by youDates, place or flight route, party size and requested currency. No guest details for a booking.
SerpApiFlight searches that inform planningRoute, dates, airports. Nothing about you
FrankfurterExchange rates for showing prices in your currencyA currency pair. Nothing about you
LocationIQ, Geoapify, geocode.maps.coTurning a typed place into coordinatesThe text you typed. Nothing about you
OpenFreeMap, OpenStreetMap, Amazon S3Map tiles and terrain, requested by your browserYour IP address and which tiles you looked at
PexelsDestination photography, fetched by our server rather than by youNothing about you. Your browser never contacts them
NASA POWERWhat the weather is usually like at a stop, in the month you are goingA coordinate. Nothing about you
Google AnalyticsCounting pages. Storing anything only if you agreedThe page you are on, where you arrived from, which campaign link brought you as a fixed word, a rough location from your IP address. On a share, invitation, password reset or verification page, and on a page of routes you have been mailed a link to, the secret part of the address is replaced before it is sent
Microsoft ClarityHow a page is used, only if you agreedMovements, clicks and scrolls. Typing is masked before it leaves your browser. It is not run at all on a share, invitation, password reset, verification or mailed routes page
Booking.com, LOT Polish Airlines, Ferryhopper, EconomyBookingsBooking, if you follow one of the paid links on the home pageNothing while you read the page. Your own visit to them once you press one

7.Where it goes

The infrastructure is Cloudflare's global network, so data is processed wherever that network handles the request rather than pinned to one country. Several processors above are United States companies. Both facts mean transfers out of the EEA happen, and neither is hidden behind a sentence about “our European hosting”.

Those transfers run on the European Commission's Standard Contractual Clauses within each provider's data processing agreement, with the supplementary measures those agreements set out. Where a provider is certified under the EU–US Data Privacy Framework, that applies too. You can ask for the specifics of any one of them.

8.How long it is kept

Retention is in the table above, purpose by purpose, because a single sentence about keeping things “as long as necessary” tells a reader nothing. The two that override everything else:

  • Delete your account and everything personal is erased within 30 days, including from backups as they roll over.
  • Invoices survive that, because accounting law requires them to be kept for 10 years. They hold what was sold, to whom, and for how much, not your trips.

9.What you can require of us

All of Chapter III of the GDPR, and none of it costs anything: a copy of your data, correction of what is wrong, erasure, a machine-readable export, restriction of processing, objection to anything based on legitimate interest, and withdrawal of any consent you gave, with withdrawing exactly as easy as giving it.

Export and deletion are both buttons in Account, so you do not have to ask. Ending a share link is a button too, on the trip itself: it stops the address working at once, it is free whether or not the trip is covered, and a new link is a new address that starts with booking references left out. For anything else, write to us and you will get an answer within 30 days, usually much sooner. If you are not satisfied, you can complain to the Lithuanian supervisory authority, or to the one where you live.

Export your data
Account → Data, no request needed
Delete everything
Account → Delete, no request needed
Switch off a share link
On the trip: Share → Stop sharing, free at any plan
Anything else
hello@outrouted.com
Complain about us
State Data Protection Inspectorate (VDAI)

10.If you are in the United States

The GDPR treatment above is what everybody gets; this section is the part US state privacy laws phrase differently. We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is no advertising tag on this site and no data broker in the list above. So there is nothing to opt out of, which is why you will not find a “Do not sell my information” link: it would be a link to a page saying no.

Your browser's Global Privacy Control signal is honoured anyway. If it is set, anything optional is refused before you are asked, and you would have to opt in deliberately to change that.

California residents can request the categories collected, the purposes, the categories of recipients, a copy, correction and deletion, and cannot be treated worse for asking. Residents of other states with comparable laws have comparable rights. The route is the same as everyone else's: write to us.

Marketing email would be opt-in and every message would carry a working unsubscribe link that we act on immediately. Today there is no marketing email at all.

11.Children

The service is not for under-16s and we do not knowingly collect anything from one. No part of it is directed at children, and nothing here profiles anybody for advertising.

If you believe a child holds an account, write to us and it will be removed, not investigated slowly.

12.Security, and what happens if it fails

Passwords are stored as salted hashes and never in a form anybody can read. Sessions are signed, http-only and revocable everywhere at once. Traffic is encrypted in transit. Third-party keys stay on the server and are never handed to a browser. The site sets a content security policy: a script may come from this origin or from three named others (Cloudflare's human check, Google's measurement tag and Microsoft's), and a browser blocks anything else. Pictures and map tiles may come only from the hosts in the list above.

None of that makes a breach impossible. If one happens and it puts you at risk, you will hear it from us, and the supervisory authority will hear it within 72 hours, as Articles 33 and 34 require. Found a hole? Tell us before you tell anyone else and you will be credited.

13.Changes to this policy

If we start using your data for something this page does not describe, you get an email before it takes effect, not after, and where the new use needs consent it does not start until you have given it.

Something unclear, or worded so it could be read two ways? Write to hello@outrouted.com and we will fix the wording rather than explain it privately once.