This is a working draft prepared for review. It has not yet been reviewed by an attorney and the operating entity is being formed. It will be finalized before turtlely opens to customers.
Privacy Policy
Draft · last updated July 16, 2026
turtlely helps trip organizers plan group travel and share it with their travelers. This policy explains what we collect, why, who processes it, and the choices you have. We wrote it to be read: if anything is unclear, ask us at the address at the bottom.
1. The two kinds of people who use turtlely
Organizers create accounts and enter trip information. Travelers just open a link an organizer shares with them: they never create accounts, sign in, or give us information to view a trip page.
2. What we collect from organizers
- Account details: name, email, password (stored by our authentication provider, never in plain text), and workspace name.
- Trip content: the itineraries, notes, dates, packing lists, and messages you write or generate.
- Roster information you enter about your travelers: names, roles, emergency contacts, and any dietary or medical flags you record. See section 3, this is the most sensitive data we hold and it is treated differently.
- Vendor relationship data: contacts, activity notes, and rates you record while planning.
- Access requests: if you ask for an invite, the name, email, organization, and note you submit.
3. Sensitive traveler information
Rosters often describe minors, and can include dietary and medical notes. We treat every roster as confidential:
- Roster data is never published to traveler share pages or anywhere public. Share pages contain the trip plan, never the people on it.
- Roster data is only visible inside the workspace of the organizer who entered it, and access is scoped server-side per workspace.
- Printable rooming lists and manifests render in the organizer's own browser; we do not email or distribute them.
- We never use roster data for any purpose other than showing it back to the organizer who entered it. It is never used for advertising, profiling, or training.
Organizers are responsible for having the authority and any consent needed to record traveler information, as described in our Terms of Service.
4. What we collect from travelers
Almost nothing. Traveler pages require no account and set no tracking or advertising cookies. If a traveler ticks items on a packing list, the ticks are stored in their own browser (localStorage) and never sent to us. Standard web server logs (IP address, request time) exist at our hosting providers for security and reliability, as with any website.
5. Children
turtlely accounts are for adults (18+). We do not knowingly collect information directly from children: information about minors reaches us only when an adult organizer enters it into a roster, and it is handled as described in section 3. If you believe a child's information was provided to us in error, contact us and we will delete it.
6. Who processes data on our behalf
We build on a small set of service providers, each used for one job:
- Supabase: database and authentication (account and trip data at rest).
- Railway and Cloudflare: application hosting, content delivery, and audio file storage.
- Anthropic: generates itinerary, guide, and podcast text from the trip details the organizer provides. Roster data is not sent to it.
- ElevenLabs: converts approved podcast scripts to audio.
- MapTiler and Google: map display and the venue database (venue information, not your travelers' information).
These providers process data under their own service agreements with us and do not get rights to use your content for their own purposes. We do not sell personal information, and we do not run third-party advertising or analytics trackers.
7. Cookies and local storage
We use what is needed to keep you signed in and remember your workspace preferences (authentication tokens and settings in your browser's storage). No advertising cookies, no cross-site tracking.
8. Retention and deletion
Trip content stays until you delete it or ask us to. Deleting a tour removes its share page immediately. You can request deletion of your entire workspace, including rosters and generated content, by emailing us; we will confirm completion. Backups age out on our providers' standard schedules.
9. Security
Access to workspace data is enforced server-side per workspace; traveler pages receive a sanitized copy of the trip that never includes roster, contact, or operator planning data; passwords are handled by our authentication provider; connections use HTTPS. No internet service can promise perfection: if we learn of a breach affecting your data we will notify you promptly at your account email.
10. Your rights
Email us to access, correct, export, or delete your information. Depending on where you live (for example California or the EU), you may have specific statutory rights to these things; we honor the requests regardless of where you live.
11. Changes
We will update this policy as the service evolves, and notify account holders of material changes by email or in the product before they take effect.
12. Contact
Privacy questions and requests: support@turtlely.org (address pending confirmation). The operating entity and mailing address will be listed here once the LLC is formed.