Privacy Policy
Last updated 1 September 2026
This describes what MelonTech AI collects when you use Imprint Travel, why, and who else touches it. We do not sell your data, we do not run advertising, and we do not use your trips, notes or messages to train AI models.
1. What we collect
- Account details. Your display name, email address and profile picture, as your sign-in provider gives them to us — Google, Microsoft, or the address and password you registered. We never see your password.
- Your travel records. Flights, hotels, car hire and other bookings, trips and itineraries, places, budgets and expenses, documents you upload, and the confirmation emails you forward.
- What you write and post. Notes, published posts, questions, answers, comments, tags, photographs, and the messages you send.
- Social connections. Who you follow, friend requests, and who is on a trip with you.
- Device tokens, if you allow notifications — an identifier for an app install, so a gate change or a message can reach it.
- Location only when you send it: sharing a place or a live location in a chat stores a coordinate. We do not track your location in the background.
- Usage and cost telemetry. Counts of billable operations — a search, an import, a map load — recorded against your account so we can see what the service costs to run. It is counters, not a log of what you looked at.
- Technical data that any web service receives: IP address, browser or device type, and timestamps, in server and CDN logs.
2. Forwarded email, and how it is read
Mail sent to trips@imprint-travel.com is stored in our cloud storage, then read by a language model that extracts the booking — the airline, the flight number, the dates, the confirmation number — and writes it into your account. The message text or attachment is sent to that model to do it.
Two protections matter here. Attribution happens before the reading: mail from an address no account has confirmed is logged and discarded without ever going to a model, so a stranger’s travel details are never parsed or stored. And an address is only attributed once its owner has clicked a confirmation link sent to it, so nobody can point your mail at their account.
You can see every forwarding address on your account, and remove one, in the app’s settings. Removing it stops attribution from then on.
3. Why we hold it
To run the service you asked for: to file your bookings, build your itineraries, track a flight you saved, show your posts to the people you published them to, deliver your messages, and bill a subscription. To keep the service safe — handling reports, stopping abuse and preventing one account reaching another’s data. To keep it working, through error logs and the cost counters above. And to meet legal obligations, such as keeping records of a payment.
Where the law requires a legal basis, ours is the performance of our contract with you for everything the product does, our legitimate interest in security and in keeping the service running, your consent for notifications and location, and legal obligation for financial records.
4. Who else processes it
We use these providers to deliver the product. Each receives only what its job needs, and none of them is permitted to use your data for their own purposes.
- Amazon Web Services — hosting, databases and file storage, in the United States. Also the mail service that receives your forwarded confirmations and sends ours.
- Google (Firebase) — sign-in and identity, and Android push notifications.
- Google Maps and Places — searching for a place, its details and its photographs. A place you search for is sent to Google.
- OpenRouter, and through it DeepSeek and Google Gemini — reading a forwarded or uploaded booking. Only the booking document is sent, and only when you forward or upload one.
- FlightAware and FlightRadar24 — flight schedules, status and positions. They receive a flight number and date, not your identity.
- TripAdvisor — hotel details and photographs.
- Apple — iOS push notifications, and purchases made in the iOS app. Google Play for purchases made in the Android app.
- Stripe — payments made on the web. Card details go to Stripe and never reach our servers.
- Wikipedia — city photographs, where a place has no other picture.
We also disclose data where the law compels it, and to protect someone’s safety. If the business is ever sold or merged, your data moves with it, and we will say so before it does.
5. What is visible to other people
A published post is public with no account. Its text, photographs, place cards, tags, your display name and your profile picture are readable by anyone at a permanent address, and served to search engines. Its comments are public too.
A shared trip is visible to everyone invited to it, including its album, its bookings and its dates. Your profile — name and picture — is visible to people who find you in search, receive a friend request from you, or read something you posted.
Everything else is private to your account: your trips, your notes, your flights, your Passport, your imports and your messages. We do not publish anything by default; every public surface is one you chose.
6. Cookies and on-device storage
We use no advertising cookies and no third-party analytics trackers. The app stores a few things in your browser to work: your sign-in session, and small preference keys for theme, language and units. Chat keeps unsent messages in your browser’s local database so they survive a lost connection, and sends them when you are back.
Clearing site data signs you out and discards those preferences and any unsent message.
7. How long we keep it
Your records stay while your account is open, because the point of the product is to keep them. Deleting a trip, note, post or booking removes it from the app. Photographs and files in a shared trip album are kept while the album exists and are moved to colder storage after 90 days rather than deleted, so an old thread does not lose its pictures.
Closing your account deletes your records, your content and your uploads. What survives is bounded and listed: database backups age out within 7 days, server logs within 14, and a raw copy of any booking confirmation you forwarded within 90. Messages you already sent stay in the threads you sent them to, and a copy someone else already saved of something you published is not ours to delete. The whole list is on Delete your account.
8. Your rights
You can access, correct, export or delete your data. Most of it you can change or delete in the app directly. You can delete your account yourself, from the app: Passport → Settings → Account → Delete account, which removes it immediately. Delete your account sets out the steps, exactly what goes, what is kept and for how long.
If you cannot sign in, or you want an export or a specific piece of data removed rather than the whole account, write to support@imprint-travel.com from the address on your account, or use the support form. Either way we action it within 30 days.
Depending on where you live you may also have the right to object to or restrict certain processing, to withdraw consent — turning off notifications, removing a forwarding address — and to complain to your local data protection authority. We do not sell personal information and we do not share it for cross-context behavioural advertising.
9. Children
Imprint Travel is not for children under 13, or under 16 where local law sets that floor, and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.
10. Where your data lives
Our servers and storage are in the United States, and the providers above may process data elsewhere. If you are in the UK, EEA or another region with transfer rules, the transfer relies on the standard contractual clauses or an equivalent mechanism in our agreements with those providers.
11. Security
Traffic is encrypted in transit and data is encrypted at rest. Credentials and API keys are held in a managed secrets store rather than in configuration, every private endpoint requires a verified identity token, and access is scoped to your own account.
No service is perfectly secure, and we will not pretend otherwise. If a breach affects you, we will tell you and the relevant authority as the law requires.
12. Changes
We will update this page when the product changes, and the date at the top says when. For a material change — a new processor, a new category of data — we will give notice in the app or by email. The Terms of Service and the content standards sit alongside this document.
13. Contact
MelonTech AI, operator of Imprint Travel — support@imprint-travel.com.
Questions about any of this
Write to support@imprint-travel.com. The other documents are Terms, Privacy, Pictures & content and Delete your account.