Privacy
Last updated 26 September 2026
PinXMap is a trip planner. It stores what you put into a trip so that it is there tomorrow and so the people you share it with can see it. That is the whole purpose of the data it holds. There are no adverts, no analytics, no trackers, and nothing is sold or shared for marketing.
The short version.
- Without an account, your trip never leaves your device — it lives in your browser and no server has a copy. The map and the search still talk to their own services, as any map does.
- With an account, we store your email and whatever you put in your trips.
- Booking references never leave your device via the AI features — they are removed in your browser before anything is sent.
- Your booking reference is private to you until you choose, per booking, to share it with the trip.
- Nobody outside a trip can read it. That is enforced by the database, not by the app hiding buttons.
Using PinXMap without an account
You can plan a whole trip without signing up, and that is the default: the
map, the search and the planner open immediately. While you do that,
the trip exists only in your own browser, in
localStorage. It is not sent anywhere, it is not readable by
us, and it is not backed up. Clearing your browser data deletes it.
Two things still reach other servers in this mode, because they have to for the map to work at all: map tiles and place searches. Those are described under Other services below.
If you later create an account, the trip in your browser is offered to that account and uploaded then — at that point, and not before.
What is stored when you have an account
| What | Why it exists |
|---|---|
| Your email address, and a password that is stored hashed, never in readable form | To sign you in, confirm the address, and let you reset a forgotten password. |
| A display name, if you set one | So people on the same trip can see who picked which place. Readable only by people you share a trip with. |
| Your trips — name, dates, and which cities | The trip itself. |
| Places you save — name, category, coordinates, website and any notes, plus which day and time you put them on | The map and the itinerary. |
| Bookings — flights, stays, shows, attractions: the mode, a service or booking number, a traveller name if you enter one, and each leg's places, dates and times | To place them on the map and on the right day. |
| Booking references, kept in a separate table from the rest of the booking | See Booking references — these get stricter treatment than anything else here. |
| Who you share a trip with, and each person's role on it | To decide who may read and who may edit. |
| Your plan, its expiry date if it has one, and a monthly count of AI actions used | To apply the allowance. It is a count, not a copy of what you asked. |
Your browser also keeps a few small preferences locally — which itinerary view you last used, whether you dismissed a banner, and a cached copy of the trip you last opened so it works offline. Signing out deletes the cached trip and the draft from that browser.
Booking references
A booking reference and a surname is often enough to view, change or cancel a booking on an airline or hotel site. It is treated accordingly:
- It is stored in its own table, separate from the rest of the booking, with its own access rule — because the rule the rest of the trip uses would have exposed it to everyone on that trip.
- Only the person who entered it can read it, unless they choose per booking to share it with the trip.
- Only the person who entered it can change or un-share it — not the trip's creator, and not an administrator, though an administrator can read it, as noted below.
- It is never sent to the AI. See below.
The AI features, and what is sent
Three features use Anthropic's Claude models. They are the only time your content is sent to an AI service, and each sends a specific, limited thing.
Search
Free for everyone, including people with no account. Your search phrase is sent so it can be turned into a place and a set of map filters. Your trip is not sent with it.
Concierge chat
Your message is sent, along with a summary of the trip so the answer is about your trip rather than a generic one: the trip name, the dates, where you are staying, your saved places, and your booked journeys. Booking references and traveller names are not part of that summary — journeys are sent as places and times only.
Reading a confirmation email
You paste an email and the itinerary is read out of it. Before anything is sent, your own browser removes:
- the booking reference, which is detected and filled into the form locally;
- card numbers;
- email addresses;
- phone numbers where a label marks them as such;
- any run of nine or more digits — account, loyalty, passport and similar numbers.
What is sent is the travel itself: airports, dates, times, a service number. We do not store the pasted text — it is used to fill the form and then discarded. You see everything that was read before anything is saved.
Anthropic processes this on our behalf to return a result. Their handling of API data is described in the Anthropic Privacy Policy.
Other services involved
PinXMap runs on services that necessarily see some data in order to work. We do not send them anything beyond what the feature requires.
- Supabase stores the database and runs sign-in. Everything in the table above lives there. Their privacy policy.
- Cloudflare serves the site and runs the three small functions the AI features call. Your IP address is visible to it as part of serving any request, and is used as the key for rate limiting so one visitor cannot exhaust the service; we do not keep it. Their privacy policy.
- Stadia Maps serves the map tiles. Loading a map reveals your IP address and which part of the world you are looking at to them, in the same way as any map on the web. Their privacy policy.
- OpenStreetMap services provide the place search and the address lookups, and the map data itself. Running a search or saving a booking reveals your IP address and what you searched for to them. Their privacy policy.
- Anthropic, for the three AI features described above, and only when you use them.
There is no advertising network, no analytics product and no third-party tracker on this site. There are no cookies used for tracking. Signing in keeps a session token in your browser's local storage so you stay signed in; that is the only comparable thing here, and signing out removes it.
Who can see your trips
People you invite, and nobody else. Access is decided by the database on every single request, not by the app hiding buttons — a request made outside the app meets exactly the same rule.
- Invite someone and they can read the trip; whether they can edit depends on the trip creator's plan and on their own.
- Deleting a place or a booking is limited to whoever added it, plus the person whose trip it is. No plan grants power over another traveller's entries.
- Booking references are the exception described above and are not visible to the trip at all unless shared.
- Administrators of the service can access trip data for support and maintenance, including booking references. We would rather state that than imply a limit the database does not enforce. What an administrator cannot do is change a reference or alter who it is shared with — that stays the owner's alone.
Keeping and deleting things
Trips are kept until they are deleted. Deleting a trip removes its places, its bookings, its references and its membership list, for everyone.
You can delete your whole account from inside the app — Account → Delete my account. It tells you first how many trips will go and how many people lose access to them, and it asks you to type your email address, because there is no undo.
Deleting your account removes:
- your email address, your password and your display name;
- every trip you created, with its places, bookings, day plan and booking references — for everyone on that trip, not only for you;
- your booking references everywhere, your picks, and your membership of trips other people created.
One thing is kept on purpose: places and bookings you added to other people's trips remain on those trips, no longer attributed to anybody. Removing them would damage a plan that is not yours to edit — the organiser would lose the restaurant you found, with no explanation. They carry no personal data of yours once your name is off them.
You can ask us at any time for a copy of what is stored about you, for a correction, or for deletion. Most of it you can already see and change in the app itself, which is usually faster.
Children
PinXMap is not directed at children under 13 and we do not knowingly collect their information. If you believe a child has created an account, contact us and it will be removed.
Changes to this policy
If this changes in a way that affects what is collected or who it is shared with, the date at the top changes and the change is noted in the app's changelog. Continued use after a change means the new version applies.
Contact
Questions, requests for a copy of your data, corrections, or account deletion: support@pinxmap.com