Privacy policy
Effective
7 Wanders is operated by Pixel Benders LLC (operating as 7 Wanders), a Washington limited liability company based in Spokane, Washington, USA ("we," "us," "our"). This policy explains what 7 Wanders collects, why, and what your choices are.
What 7 Wanders collects
Account. Your email address, a user ID, and a display name when you sign in with Apple, Google, or email. The display name is the one Apple offers at sign-in or the one you type in, and it is shown to the people you share trips with. Used to operate your account, sync your trips, and identify you to your trip companions.
Trip content. Your itineraries, intake choices (destinations, dates, pace, budget), booking details you enter, expenses, and notes. Stored on your device first; synced to your account so your trips survive a lost phone. Attachment files you add (booking confirmations, tickets) sync to private storage on your account too, so they survive a lost phone with the rest of your trip; files over 3 MB stay on your device only.
Sharing. If you share a trip, the people you invite see that trip — its itinerary, bookings, expenses, and notes — along with your display name; those you make editors can change it. Nothing about a trip is visible to anyone else until you share it.
Diagnostics. Technical request records (status, latency, token counts) and minimal client events (an event name and an error code — no content). Used to keep the service working.
Product analytics. Anonymous counts of which screens, features, and controls get used. Events are names with coded values only — an item's kind, like "meal," or a day number — never your trip content: no destinations, venue names, dates, amounts, or free text. You control this with the "Share usage analytics" switch in the app's Settings: it's on by default, and you can turn it off any time. Crash reporting is separate and always on, so problems get fixed.
Usage. A daily count of your assistant requests, used to apply your plan's daily budget.
Purchases and Apple Ads attribution. Which subscription you bought and its renewal status, as reported by Apple — never your payment details. If you installed 7 Wanders after tapping an Apple Ads ad, and the "Share usage analytics" switch is on, Apple's attribution service tells us which campaign that was; this uses no advertising identifier and does not track you across other apps or websites. Both are processed for us by RevenueCat, our subscription-analytics provider, under your account's user ID.
Location — only when you tap for it. If you tap "Use my location" to fill in a trip's origin, we take a single one-time device reading to fill that field and do not store it beyond that field. If you tap the locate button on a trip map, your position is drawn on that map while you are looking at it — shown on your device only, and never stored or sent anywhere. 7 Wanders does not track your location in the background or continuously.
Shared links. If you import places from a link (a social-media post or a web page), we collect the link you shared, the publicly available information retrieved from it, and the places you choose to save from it. See AI processing for how a link is read and what we keep.
What 7 Wanders does not collect
- Background location: the app never tracks you in the background and never asks for always-on access.
- Photos: receipt scanning happens on-device; images never upload.
- Payment details: purchases go through Apple; we never see your payment information.
- Advertising identifiers: there are none in the app.
Sensitive information you might type in
7 Wanders doesn't ask for passport numbers, government IDs, payment card numbers, or health details, and no trip feature needs them. If you type something like that into your notes or booking details anyway, it's stored as part of your trip content — synced to your account, deleted with your account — and used only to show your trip back to you. Where you can, keep documents like passports in the apps that hold them and note just what you need (a confirmation code, a seat number).
AI processing
When you generate, refine, or ask about a trip, you're talking to an AI system, not a person. The relevant trip details and your question are sent to Google's Gemini API through 7 Wanders' server — the server holds the API key, and we don't store your prompts on the server or use them for anything except answering your request. Google processes those requests as our service provider under its Gemini API terms; see Google's terms for its own handling.
AI answers are suggestions for your trip. 7 Wanders makes no automated decision about you with legal or similar effects — no scoring, no profiling, no gatekeeping.
Day-by-day weather comes from Open-Meteo, requested with the trip's stop-city names and coordinates only — no account identifier is attached.
Place details and photos for the stops in your plan come from Google's Places API, queried through our server with the place name and city only — no account identifier is attached.
Flight options come from SearchApi, a flight-search provider we query through our server with just your search — origin and destination airports, dates, cabin, and traveler count. No account identifier is attached.
Third-party scraping services: When you share URLs from social media platforms or websites, we use third-party content extraction services to retrieve publicly available information (captions, thumbnails, video data, metadata) from those links.
How a shared link is read. The retrieved text (the post's title, caption, hashtags, creator handle and any transcript, clipped) is sent to Google's Gemini API through our server to pick out the places it names; those place names, with a city, are then matched through Google's Places API — the post text itself never goes to Google Places. For each link we keep one record, shared across everyone who imports the same link and not tied to your account: the link, the post's title, a short summary, the creator's handle, a copy of the thumbnail, and the places found with a short quoted line for each. We do not keep the full caption, the hashtags, the transcript, or the video. That record is kept for up to 90 days. Your own import request and its results are deleted about 24 hours after it finishes, or sooner if you delete it. The places you choose to keep are written into your saved lists, with the line from the post that named them, and stay yours like the rest of your trip content.
Service providers
- Supabase — database, authentication, and functions hosting (US region, us-east-2).
- Google (Gemini API) — AI responses, via our server as above.
- Google (Places API) — place details and photos for your itinerary, queried with the place name and city only.
- Google (Sign in with Google) — sign-in only; we receive your email and account identifier, nothing else.
- Open-Meteo — weather forecasts, city names and coordinates only.
- SearchApi — flight search results, queried with route, dates, cabin, and traveler count only.
- Third-party content extraction services — publicly available post content for links you share (queried with the link only; no account identifier).
- Apple — sign-in, push notifications, and all payments.
- Sentry — crash reporting.
- PostHog — product analytics.
- RevenueCat — subscription analytics and Apple Ads campaign attribution.
Retention and deletion
Delete your account any time in the app: Settings → Account → Delete account. This removes your sign-in and every trip stored on our servers; diagnostic records are unlinked from your identity, and your subscription record at RevenueCat is deleted. Trips saved on your device stay on your device — deleting the app removes them.
How long we keep things: your account and synced trip content are kept for as long as your account is active. When you delete your account, your data — attachment files in storage included — becomes inaccessible immediately, and we delete it from our systems within 30 days; residual copies may persist in encrypted backups for up to 90 days, after which they are purged. Diagnostic records are unlinked from your identity immediately on account deletion.
Shared-link records (see AI processing) are kept for up to 90 days and are not tied to your account; your own import requests are deleted about 24 hours after they finish.
Your choices
- Export your trips any time (trip.json or markdown) from the app.
- Delete your account in the app (above).
- Email us at support@7wanders.app to ask what we hold about you or to request deletion if you can't use the in-app path.
- Control location access in iOS Settings — the "Use my location" reading and the trip map's locate button only run when you tap them.
Email from 7 Wanders
Today, email from us is about your account only: sign-in, security, support replies, and anything Apple requires us to tell you about your subscription. There is no marketing list. If we ever start one, it will be separate, every message will have an unsubscribe link, and this policy will say so before it happens.
Children
7 Wanders is a travel-planning app for general audiences and is not directed at children. You must be at least 16 to create an account.
Security
Trip data syncs over HTTPS and is stored with per-user access controls (row-level security); AI provider keys live on our server, never on your device. No system is perfectly secure, and we don't claim this one is.
If a breach of our systems affects your personal information, we will tell affected users and any regulator we are required to notify.
Where 7 Wanders operates
7 Wanders' servers are in the United States (us-east-2). Wherever you use 7 Wanders from, your data is transferred to, processed, and stored in the US.
If you're in the EEA, UK, or Switzerland
Pixel Benders LLC is the controller of your personal data. We rely on these legal bases: performing our contract with you (operating your account, syncing and processing your trips, answering your requests); our legitimate interests (keeping the service secure and working — the diagnostics described above); and your consent where we ask for it, which you can withdraw at any time.
You have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to how we use it, and to complain to your local data protection authority. The in-app export and delete tools cover most of this instantly; for anything else, email support@7wanders.app and we'll respond to your request.
Changes
We'll update this page when the policy changes, note the effective date above, and keep prior versions available from this page.
Contact
Pixel Benders LLC (operating as 7 Wanders)
522 W Riverside Ave, Ste N, Spokane, WA 99201, United States
support@7wanders.app