Privacy Policy
Last updated: 27 June 2026
1. Data Controller
This Privacy Policy describes how personal data is processed in connection with TrailSnail ("we", "us"). The Service is currently operated as a personal, non-commercial project by a private individual based in Italy, who acts as the data controller under Article 4(7) GDPR.
Data Controller: Carlo Cannarsa, Italy
Contact: hello@trailsnail.app
Data Controller: Carlo Cannarsa, Italy
Contact: hello@trailsnail.app
2. Data we collect
Account data. When you sign up, your email address is stored. If you sign in via a social provider, the basic profile information that provider returns (name, avatar) is also stored. Passwords are managed by our authentication provider and are never accessible to us.
Trip data. Destinations, dates, group size, interests, pace, budget preferences, generated itineraries, the tours and points of interest you save, and any notes you add.
Technical data. Server logs are collected automatically for security, debugging and abuse prevention. They include your IP address, timestamps, the URL you requested and the user agent string sent by your browser. The user agent typically reveals your browser (e.g. Chrome, Safari, Firefox), operating system (e.g. macOS, Windows, iOS, Android) and general device type — for example a log line may contain "Macintosh" or "iPhone". It does not contain device serial numbers or precise hardware identifiers.
The authentication provider may also log the device and approximate location of each sign-in to power security notifications (e.g. "new sign-in from a Mac in Milan"). You can review this information in your Manage Account modal.
Rate-limit counters are kept short-term to enforce fair usage. We collect limited aggregated operational metrics that do not identify individual users and are used solely to monitor performance and improve the Service. We do not run advertising or behavioural-analytics trackers.
Preferences. Locale, region, currency and date-format choices you select in the "Language & Locale" settings, stored in cookies and mirrored to your account.
Trip data. Destinations, dates, group size, interests, pace, budget preferences, generated itineraries, the tours and points of interest you save, and any notes you add.
Technical data. Server logs are collected automatically for security, debugging and abuse prevention. They include your IP address, timestamps, the URL you requested and the user agent string sent by your browser. The user agent typically reveals your browser (e.g. Chrome, Safari, Firefox), operating system (e.g. macOS, Windows, iOS, Android) and general device type — for example a log line may contain "Macintosh" or "iPhone". It does not contain device serial numbers or precise hardware identifiers.
The authentication provider may also log the device and approximate location of each sign-in to power security notifications (e.g. "new sign-in from a Mac in Milan"). You can review this information in your Manage Account modal.
Rate-limit counters are kept short-term to enforce fair usage. We collect limited aggregated operational metrics that do not identify individual users and are used solely to monitor performance and improve the Service. We do not run advertising or behavioural-analytics trackers.
Preferences. Locale, region, currency and date-format choices you select in the "Language & Locale" settings, stored in cookies and mirrored to your account.
3. Whether providing data is mandatory
Providing your email address is necessary to create and maintain your account. Without it, you cannot use account-based features such as saving trips. Other information — including travel preferences, notes and itinerary details — is optional but may improve the planning experience.
4. Purposes and legal bases
We process personal data for the following purposes, on the legal bases shown (referring to Article 6 GDPR):
We do not sell your personal data. We do not use it to train AI models.
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Contract — Art. 6(1)(b) |
| Generating and saving itineraries | Contract |
| Account verification, password reset and security notifications | Contract |
| Important service updates | Contract / Legitimate Interest |
| Fraud prevention, rate-limiting, security monitoring | Legitimate Interest — Art. 6(1)(f) |
| Aggregated operational metrics to monitor performance | Legitimate Interest |
| Compliance with applicable laws | Legal Obligation — Art. 6(1)(c) |
| Marketing communications (if ever introduced) | Consent — Art. 6(1)(a) |
5. Email communications you may receive
We may send you the following operational emails through our authentication provider:
- Account verification (confirming your email at sign-up).
- Password reset, when you request one.
- Security notifications (e.g. new device sign-in).
- Important service updates that affect your data or your ability to use the Service.
6. Third-party processors
We share the minimum personal data necessary with the following processors. Where required by Article 28 GDPR, we have entered into appropriate Data Processing Agreements with them.
- Authentication and account management — email address, authentication identifiers, name and avatar (if provided via social sign-in). Provider: Clerk (United States; EU SCCs).
- AI day-plan generation — destination, travel dates and trip preferences, scoped to the session. Prompts are not used to train third-party models. Provider: Mistral AI (France, EU).
- Tour discovery — destination search only, via a public unauthenticated endpoint. No personal identifiers shared. Provider: GuruWalk (Spain, EU).
- Map tiles, geocoding and points of interest — search query and the IP address required to fulfil the request. Providers: OpenStreetMap, Nominatim, Photon, OpenFreeMap.
- Error tracking — anonymised technical crash reports (stack traces, browser/OS labels, request path). We actively strip Authorization / Cookie / API-key headers, request bodies, user email and IP address before events are recorded. Only an opaque internal user id may be attached — no name or contact information. Provider: self-hosted GlitchTip running on the same infrastructure as the Service (see below). This processor is optional and only active when a DSN is configured — disabled by default in development.
- Application hosting, database and cache — server logs (including IP address), account information, itineraries, saved places, preferences and short-lived rate-limit counters. The Service runs on containerised infrastructure (Postgres, Redis and the application server) operated directly by the Data Controller. No third-party database-as-a-service or backend-as-a-service processor holds this data. The underlying compute is provided by the hosting supplier listed below, which acts only as an infrastructure provider under GDPR Recital 26 and does not access application data in the ordinary course of business.
Current hosting supplier: to be updated when the Service is deployed publicly (e.g. Hetzner Cloud, Nürnberg — EU; or Netlify, US — EU SCCs). During private testing the application runs on hardware operated by the Data Controller in Italy.
7. Cookies
We use the following cookies — all strictly necessary or functional:
__session,__clientand related authentication cookies — authentication session.NEXT_LOCALE— your chosen UI language.NEXT_REGION,NEXT_DATE_FORMAT,NEXT_CURRENCY— formatting preferences.
8. Data retention
We keep your account and trip data for as long as your account is active. When you delete your account, associated personal data is deleted or anonymised within 30 days, unless a longer retention period is required by law (for example, for tax records).
Server logs are kept up to 90 days for debugging, security and abuse prevention. Rate-limit counters expire within minutes to hours.
Server logs are kept up to 90 days for debugging, security and abuse prevention. Rate-limit counters expire within minutes to hours.
9. Your rights
Under GDPR you have the right to:
To exercise any of these rights write to hello@trailsnail.app. We respond within 30 days, in line with Article 12(3) GDPR.
- access the personal data we hold about you (Art. 15);
- rectify inaccurate or incomplete data (Art. 16);
- request erasure of your data (Art. 17);
- restrict processing (Art. 18);
- data portability — receive a machine-readable export (Art. 20);
- withdraw consent at any time, where consent is the legal basis (Art. 7);
- lodge a complaint with your local data-protection authority (in Italy, the Garante per la Protezione dei Dati Personali).
To exercise any of these rights write to hello@trailsnail.app. We respond within 30 days, in line with Article 12(3) GDPR.
10. International transfers
Where personal data is transferred outside the European Economic Area, we rely on legally recognised transfer mechanisms, including the Standard Contractual Clauses approved by the European Commission and, where applicable, the EU–US Data Privacy Framework or other appropriate safeguards. Supplementary measures are adopted where required following the provider's transfer impact assessment.
11. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects within the meaning of Article 22 GDPR. The AI-generated itinerary suggestions are non-binding recommendations and can be freely modified, accepted or discarded by you.
12. Children
The Service is not intended for users under 18. We do not knowingly collect personal data from anyone below that age. This minimum age aligns with the full contractual capacity required under Italian law. If you believe we have inadvertently received data from a minor, contact us and we will delete it.
13. Security
We protect personal data using industry-standard measures: TLS in transit, encryption at rest at our database provider, role-based access control, row-level security on user data, regular dependency audits and rate limits on our APIs. No system is perfectly secure — but we work to minimise risk.
14. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service where appropriate, and reflected in the "Last updated" date above. The updated version will apply from its stated effective date.
See also the Terms of Service and Credits.