Privacy Policy
Effective 15 June 2026 · Version 1.1
This policy explains what personal data Giraffe (the "Service") collects, why, who it is shared with, and the rights a User has over it. The Service is operated by Dhanush Rakesh Parekh, an individual based in Bengaluru, India ("Operator", "we", "us"), who is the data controller / data fiduciary for that data. The Service is a free, experimental, non-incorporated project. The terms "Service", "Operator", "User", and "Provider Key" are used as defined in the Terms of Use.
The Operator collects the minimum data necessary to provide the Service. Questions may be directed to grievance@giraffe.land.
1. Scope
This policy applies to everyone who uses the Service. It is written to meet India's Digital Personal Data Protection Act, 2023 (DPDP), the EU and UK GDPR, and California's CCPA/CPRA. A User must be 18 or older (see Terms); the Operator does not knowingly collect data from anyone under 18.
2. Data we collect
- Account data: email address, name and identifier from the login provider (e.g. Google), and authentication session data.
- Profile and preferences: the travel preferences a User provides and — only where the User opts in — preferences derived from the User's public writing (see "Web enrichment" below). Controlled in Settings → Privacy.
- Trip data: the destinations, dates, plans, decisions, notes, threads, and cached references a User creates.
- AI usage metadata: token counts, the model used, and which agent ran, for transparency about BYOK usage (Section 4). The Operator does not store AI prompts and responses beyond what is saved into trip data.
- Uploaded files: PDFs, images, and other attachments. Files are processed to extract text and to generate search embeddings (via Voyage AI); the extracted text and embeddings are stored as part of the User's trip data and deleted with it.
- Technical data: IP address and basic device/browser information, used for security (not advertising or analytics profiling).
- Analytics: only where a User opts in to analytics cookies (see Cookie Policy).
Web enrichment (opt-in): With the User's explicit consent, the Service reads publicly available information the User points it to (such as the User's own public profiles or writing) to reduce manual entry, and extracts only travel-relevant preferences from it. It is off by default; the User actively enables it, the processing relies solely on the User's consent and stops on withdrawal, and the User may view, correct, and delete the derived preferences at any time in Settings → Privacy.
3. Purposes and legal bases
The Operator uses this data to provide and personalize the Service, to keep it secure, to debug and improve it, and to meet legal obligations. Under the GDPR, the legal bases are: performance of a contract (account and trip data), consent (cookies, analytics, web enrichment, and other optional features), and legitimate interests (security and prevention of abuse). AI suggestions are advisory and the User decides whether to act on them; the Operator does not make automated decisions that produce legal or similarly significant effects, and does not sell personal data.
4. How your AI provider processes your data (BYOK)
The Service is bring-your-own-key. When a User uses an AI feature, the content the User submits — the prompt and the relevant parts of the trip (destinations, dates, notes, and any attached files) — is sent directly to the AI provider the User has connected (for example, Anthropic, OpenAI, or a model accessed via OpenRouter), using the User's own Provider Key.
That provider processes this content under its own privacy terms, not this policy, and the Operator does not control how the provider retains, logs, or uses it. A User should review their chosen provider's privacy policy and any data-retention or model-training settings the provider offers. The Operator does not store the User's prompts or the provider's responses beyond what the User chooses to save into a trip, and never uses trip content to train any model.
5. Sub-processors
The Operator uses a limited set of service providers to run the Service. Each processes data only to provide its service to the Operator:
- Supabase — database, authentication, and file storage
- Upstash — Redis for rate-limiting and abuse protection (processes IP addresses)
- Fly.io — real-time collaboration sync, file extraction, and search workers
- Vercel — application and website hosting
- Cloudflare — DNS, CDN, email routing, image storage (R2), bot protection, and cookieless web analytics (aggregate usage only; no cookies, no cross-site or personal identifiers). Cloudflare is already the Service's infrastructure provider.
- Resend — transactional and reminder emails
- Sentry — error monitoring (configured to scrub personal data from error reports)
- Your chosen AI provider (e.g. Anthropic, OpenAI, or via OpenRouter) — processes your requests using your Provider Key; you hold the direct relationship with the provider (Section 4)
- Voyage AI — search/embeddings (funded by the Operator, not the Provider Key)
The Operator will update this list when it adds or changes a sub-processor and, for material changes, give notice in-app and by email at least 30 days in advance, so a User can object or close their account before it takes effect.
6. Storage location and international transfers
The Service's primary data is stored with Supabase in Mumbai, India. The EU and UK do not currently recognise India as providing an adequate level of data protection. For personal data of EU/UK Users, transfers out of the EEA/UK rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical measures (encryption in transit and at rest). The sub-processors above that are established outside the EEA rely on their own Standard Contractual Clauses or equivalent frameworks. Where a User connects an AI provider (Section 4), that transfer is one the User initiates with their own Provider Key. Enquiries may be sent to grievance@giraffe.land.
7. Retention
- Account and trip data: retained while the account is active.
- Derived profile preferences (web enrichment): retained for approximately 90 days; a User may delete any entry at any time.
- Security/audit logs (including IP/rate-limit data): retained up to 12 months, then irreversibly aggregated/anonymised so they are no longer personal data.
When a User deletes data or their account, the Operator removes it from active systems within 30 days; encrypted backups containing it are overwritten on the rolling backup cycle within approximately 90 days, after which no copies remain.
8. Your rights
Depending on jurisdiction, a User has rights to: access their data, correct it, delete it (right to erasure), export it (portability), restrict or object to certain processing, and withdraw consent. Under India's DPDP Act, a User also has the right to nominate another individual to exercise these rights on the User's behalf in the event of death or incapacity (to register a nominee, contact grievance@giraffe.land). California rights are described in Section 10.
9. Exercising your rights
Most rights are self-service and immediate in Settings → Privacy → My Data: view all data held, export it as JSON, correct the profile, delete specific preferences, or delete the account. Withdrawing a consent (analytics, web enrichment) is a single action in Settings → Privacy and is as easy as granting it; the Operator stops the relevant processing promptly, and withdrawal does not affect processing already carried out. For other requests — restriction, objection, or a complaint — email grievance@giraffe.land. The Operator responds within 30 days (GDPR) and, for grievances under DPDP, within the timeline required by law. For sensitive requests such as account deletion, the Operator may require identity re-confirmation.
10. California privacy (CCPA/CPRA)
In the past 12 months, the Operator collects these categories of personal information: identifiers (email, login identifier), internet/device activity (IP, basic device data), geolocation implied by trip destinations, and user content (trips, notes, files). Sources are the User and the User's login provider. The Operator uses this information only for the business purposes described in this policy. Any precise location or other sensitive personal information is used only to provide the Service, not to infer characteristics about the User.
The Operator does not sell or share personal information (as those terms are defined under the CCPA/CPRA) and never has. California Users have the rights to know, access, correct, delete, limit the use of sensitive personal information, and non-discrimination for exercising these rights, and may make a "Shine the Light" request. Exercise any of these via grievance@giraffe.land.
11. Children
The Service is for adults (18+). The Operator does not knowingly collect data from anyone under 18 and will delete such data if discovered. To report use by a minor, contact grievance@giraffe.land.
12. Cookies
The Service uses a minimal set of cookies, with analytics strictly opt-in and no advertising cookies. See the Cookie & Tracking Policy.
13. Data protection measures
The Operator uses encryption in transit and at rest, application-layer encryption for the Provider Key, strict access controls, and security scanning. See the Security Practices.
14. Data breach
If a breach affects personal data, the Operator will notify the relevant authority and affected Users where and as required by applicable law (within 72 hours of awareness under the GDPR, and per the DPDP timeline in India), by in-app notice and email, where the risk to the User is high.
15. Grievance Officer and escalation
Dhanush Rakesh Parekh — Grievance Officer & Data Fiduciary grievance@giraffe.land · Bengaluru, Karnataka, India (full postal address available on request)
Indian Users may also lodge a complaint with the Data Protection Board of India. EU/UK Users may contact their local data-protection authority (or the UK ICO). The Operator does not currently meet the thresholds requiring a Data Protection Officer; if that changes, this policy will be updated.
16. Changes to this policy
The Operator may update this policy. For material changes, the Operator will provide at least 30 days' notice (in-app and email) and keep prior versions available. Continued use after the effective date constitutes acceptance.
17. Contact
Privacy and grievances: grievance@giraffe.land · General help: support@giraffe.land