Privacy Policy
Last updated: July 30, 2026
This Privacy Policy explains how Runes ("Runes", "we", "us") collects, uses, and shares information when you use our travel-planning service. By using Runes you agree to this policy.
Information we collect
- Account information — your email and any profile details you provide (display name, home city, travel style, interests, dietary preferences).
- Trip data — the trips and itineraries you create, and your messages to Navi, our AI assistant. On the mobile app, some of this trip data is also stored on your device for offline access — including co-travelers' display names and shared expense records. This can include information about people in your travel party who don't use Runes themselves.
- Payment information — handled by Stripe. We do not store your card details; we keep only a Stripe customer reference and your subscription status.
- Usage analytics — aggregate, privacy-friendly usage data (see Analytics below).
How we use your information
We use your information to provide and improve the service: generating itineraries tailored to your preferences, powering the Navi assistant, processing subscriptions, and maintaining your account.
AI processing and service providers
To deliver Runes we share limited information with trusted providers who process it on our behalf: Supabase (database and authentication), Stripe (subscription payments on the web) and Apple and Google (in-app purchases on mobile), our AI provider — OpenRouter, which routes each request to the underlying model (currently Google Gemini) — to generate itineraries and Navi responses, Google Places (to find and autocomplete the destinations and places you type, from the text you enter), Mapbox (to estimate travel times and distances between your stops — used only when enabled), WeatherAPI (per-day forecasts for your destination and dates), Resend (to send our emails — invitations, reminders, data exports, and sign-in messages — so it receives the recipient's email address), Cloudflare (which delivers and protects the site, and so handles your network traffic and IP address, and runs the anti-abuse Turnstile checks on our public forms), Sentry (error monitoring, with personal data scrubbed), and Plausible (analytics). These providers are bound to use the data only to provide their services to us.
To produce your itineraries and Navi replies we send the AI provider your trip details, the travel preferences on your profile (including any dietary or accessibility notes you enter), and your Navi messages. This information is used only to return your result — it is not used to train AI models, and it is not retained by the provider beyond what is needed to serve the request.
Affiliate links
Runes includes booking links to third-party travel partners. If you click a link and make a booking, we may earn a commission at no extra cost to you. When you follow such a link, the partner's own privacy policy governs the information you provide on their site.
Cookies and analytics
We use Plausible Analytics, which is cookieless and does not collect personal data or track you across websites. To keep you signed in we store your session in your browser's local storage, not in a cookie — so Runes doesn't use tracking or advertising cookies.
Data retention and your choices
We keep your information for as long as your account is active. You can edit your profile, delete your trips, and request deletion of your account by contacting us. Deleting your account removes your personal data, subject to records we must retain for legal or accounting reasons.
Children
Runes is not directed to children under 13, and we do not knowingly collect information from them.
Changes and contact
We may update this policy from time to time; material changes will be posted here. Questions? Contact us at privacy@runesplan.com.