Effective date: July 26, 2026
Controller or business: NUDOOO LLC, a California limited liability company
This Privacy Policy explains how Platix ("Platix," "we," "us," or "our") collects, uses, discloses, and retains personal information when you use the Platix website, trip-planning workspace, maps, public content, blogs, comments, collaboration tools, and related services (collectively, the "Service").
Platix is a travel inspiration, organization, and planning service. It is not a medical, financial, legal, emergency, insurance, immigration, or other professional-advice service. Please do not submit medical records, payment-card numbers, passport numbers, government identifiers, or other highly sensitive information to Platix.
1. Scope
This Policy applies to personal information processed by Platix through the Service, support communications, and related operations.
It does not govern a third party's independent processing, including travel providers, websites you visit through links, Google, OpenAI, Supabase, or other providers acting under their own terms and privacy policies.
2. Information we collect
The information we collect depends on how you use the Service.
Account and profile information
We may collect:
- Email address
- Display name
- Avatar or profile image
- Internal account and authentication identifiers
- Sign-in provider and OAuth-related information
- Authentication session and refresh tokens
- Account settings and account status
- The Terms and Privacy Policy versions presented to you, their content hashes, your acceptance or acknowledgment time, and the acceptance source
If you use Google sign-in, the Service may store Google provider access or refresh tokens when needed for enabled account features. Those tokens are restricted from normal client access.
Travel content
We collect content you create, upload, save, or receive through the Service, including:
- Trip titles, summaries, dates, destinations, routes, days, stays, and activities
- Place names, addresses, map coordinates, Google Place IDs, and place details
- Trip and place notes, tags, avoidances, and planning constraints
- Booking-related fields you choose to enter
- Saved places and collections
- Photos, captions, alt text, file metadata, and media ownership records
- Fork and source relationships between trips and collections
- Visibility and search-publication status
Designated private booking fields may be used for reservation reference numbers and costs. Do not enter access codes, payment-card data, passport data, government identifiers, or other information that is not necessary for planning. Authorized collaborators with editing access may be able to view private booking fields. Platix removes booking details from public and other read-only trip responses, but you should still review and remove private information before making a trip public.
Travel preferences and memory
Platix may store preferences you provide or facts inferred from your interactions to personalize travel planning, such as:
- Home base
- Travel style and pace
- Budget level
- Preferred transportation
- Interests and avoidances
- Dietary preferences
- Accessibility needs
- Other travel-planning notes
- Memory labels, values, confidence, source, and lifecycle status
Dietary or accessibility information can reveal sensitive health-related information. Provide it only when you want it used for travel planning. Do not provide medical records, diagnoses, medication details, or information requiring a health-care provider.
You can review and remove individual remembered facts through available account controls. You can also delete your account.
Prompts, chats, and AI records
We collect prompts, chat messages, selected trip or collection context, and AI responses when you use AI features.
For reliability, security, cost monitoring, debugging, and quality review, we may also store AI-run records that include:
- Input messages
- System and filled prompts
- Context and request data
- Model responses
- Model and provider
- Token usage, latency, cost estimates, and prompt fingerprints
- Guard evaluations, errors, and workflow status
- Related user, trip, collection, session, or surface identifiers
Do not include highly sensitive or regulated information in an AI prompt. Relevant prompt and context data may be sent to an AI service provider as described below.
Collaboration and sharing information
We collect information needed to provide collaboration and access controls, including:
- Invitee email address
- Invitation token and status
- Viewer or editor role
- Inviter and accepting-user identifiers
- Invitation delivery status
- Access grants and removal history
- Share and change events
If you invite someone, you represent that you have a legitimate reason to use their email address for the invitation.
Public and community information
Depending on your choices, we collect and display:
- Public trips and collections
- Public profile display name and avatar
- Comments and replies
- Reactions, saves, bookmarks, and fork activity
- Blog-comment name, body, status, and timestamps
- Public-content source links and attribution
Public content can be viewed, copied, linked, indexed where separately approved, or retained by others. Unlisted or link-accessible content may be viewed by anyone who obtains the link.
Contact and support information
When you contact us, we may collect:
- Name
- Email address
- Account identifier if signed in
- Message contents
- Message status and metadata
- Related email-delivery records
Contact messages are stored in our database and may also be sent to support@platix.io so a team member can respond.
Usage, analytics, and technical information
We may collect:
- IP address and request timing
- Browser or device user-agent information
- Request IDs, server logs, error logs, and security events
- Anonymous analytics identifier stored in local storage
- Analytics session and page-view identifiers
- Application version
- Account identifier when signed in
- Event type, product surface, and source
- Trip, collection, place, or scope identifiers associated with an event
- Search query text
- Place name, address, provider ID, and map coordinates
- Map viewport and interaction metadata
- Tutorial status and dismissed or completed steps
- Authentication redirect path stored locally in your browser
Current first-party interaction events include map searches, map place selections, marker interactions, and product-starter interactions.
Platix asks for your consent before any analytics run. Until you choose, no Google Analytics script is loaded, no analytics cookie is set, and no first-party analytics identifier or event is created. Declining is recorded and respected; you can change your mind at any time, and withdrawing consent is as easy as giving it. This consent covers both Google Analytics and the first-party product analytics described above, because both store identifiers on your device. If you consent and later sign in, Platix may associate the consenting browser's anonymous analytics identifier with your account so product activity can be understood across the sign-in boundary. It does not cover the authentication cookies needed to sign in and stay signed in, which are strictly necessary for the Service you requested and are not optional.
To evidence that choice, Platix records a consent receipt containing only the decision, the consent version it was given against, the time, how it was given, the application version, and a randomly generated receipt identifier used solely to link a later change of mind to the same device. The receipt deliberately does not include your IP address, browser user agent, referring page, page address, or location, and the receipt identifier is separate from any analytics identifier.
With your consent, Platix may retain sanitized text from searches of public content and your My Trips library to understand travel demand and improve search quality. Search-demand records are stored separately from general interaction analytics and do not include an account ID, email address, browser or analytics identifier, session ID, request ID, trip ID, IP address, or browser user agent. Before storage, Platix attempts to redact obvious email addresses, phone numbers, web addresses, UUIDs, tokens, and secret-like text. Search text can still identify someone through what they type, so Platix treats these records as restricted analytics data. Raw sanitized searches are ordinarily retained for up to 90 days. Only query groups that meet a minimum frequency threshold are included in monthly demand aggregates, which are ordinarily retained for up to 24 months. Search continues to work when analytics consent is declined; in that case, Platix does not create these search-demand records.
With your consent, Platix uses Google Analytics 4 to understand how visitors find and navigate the Service, including which referrers, search results, and articles bring people to the site. Google Analytics sets its own identifiers and processes IP address, page address, referrer, and general device and approximate location information under Google's terms. Google Analytics is loaded directly through the gtag.js measurement library; Platix does not use Google Tag Manager.
Platix limits what is sent to Google Analytics. Page addresses are reported without query strings or URL fragments, and invitation links are reported in a redacted form, so authentication tokens and invitation tokens are not shared. Platix does not enable Google Signals, does not link Google Analytics to Google Ads, and does not use Google Analytics for advertising or cross-context behavioral advertising.
Location information
Platix processes travel locations you enter, search, save, select, or include in a trip. This can include precise map coordinates for a place or route.
Platix does not currently collect continuous device GPS location as part of the implemented web product. If we add device-location collection, we will provide a contextual notice and request any consent required by law before collection.
Information from other sources
We may receive information from:
- A collaborator who invites or mentions you
- An authentication provider
- Google Maps and Places
- Public place and travel-information sources
- A support or email-delivery provider
- Security, fraud-prevention, or infrastructure providers
3. How we use information
We use personal information to:
- Create and manage accounts and authentication
- Provide trips, collections, maps, saved places, media, collaboration, comments, and sharing
- Generate, edit, review, and explain travel plans with AI
- Personalize travel planning using saved preferences and memory
- Respond to contact, support, bug, and partnership messages
- Deliver account, password, invitation, and operational emails
- Enforce visibility, access, moderation, and search-publication controls
- Measure product usage and improve workflows
- Debug errors and maintain AI and system audit records
- Protect users, investigate abuse, and secure the Service
- Prevent fraud, spam, unauthorized access, and excessive automated use
- Comply with law and valid legal requests
- Establish, exercise, or defend legal claims
- Perform de-identified or aggregated analysis
Platix does not use the Service to make decisions that produce legal or similarly significant effects concerning employment, credit, insurance, housing, health care, or eligibility for government benefits.
4. AI processing
When you use an AI feature, Platix may send your prompt and relevant travel context to OpenAI or another disclosed AI provider so it can generate a response.
We attempt to limit context to what is relevant to the requested travel-planning task. Some workflows store prompts, context, responses, and audit information in Platix systems as described above.
Platix currently uses OpenAI's API rather than a consumer ChatGPT account. Platix requests that Responses API output not be retained as stored response state where that control is supported. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in, and that default abuse-monitoring logs may be retained for up to 30 days unless different approved controls apply. OpenAI's practices and available retention controls may change. Review the current OpenAI API data controls and OpenAI business data privacy information.
Platix does not currently use your private trips, private collections, or private chats to train a Platix general-purpose foundation model. If we propose materially different training or model-improvement use of identifiable User Content, we will update this Policy and obtain consent where required.
AI-generated editorial blog drafts use a sanitized source packet from a selected public trip or collection. A human review is required before publication. A separately published editorial article should be created only with the source owner's opt-in or other clearly disclosed permission.
5. How we disclose information
We may disclose personal information as follows.
At your direction
We disclose information when you:
- Make a trip or collection public or link-accessible
- Invite a collaborator
- Post a public comment or reaction
- Fork or share eligible content
- Ask us to send information to a third party
Service providers
We use service providers to operate the Service. Depending on configuration and use, these may include:
| Provider or category | Purpose and data involved |
|---|---|
| Supabase | Authentication, database, account records, and application content |
| OpenAI | AI generation and related processing of prompts and relevant context |
| Google Maps Platform | Maps, Places, search, location, place details, and related logs |
| Google Analytics | Website audience and acquisition measurement, including page addresses, referrers, IP address, and device information |
| Cloudflare R2 | User-uploaded media storage and delivery |
| Railway or another host | Application hosting, network delivery, and operational logs |
| Vercel | Frontend hosting, content delivery, and operational logs |
| Resend | Transactional and support-related email delivery |
| GoDaddy | Domain registration and DNS |
Providers process information under their contracts and policies. We may replace or add providers as the Service changes.
Google Maps
The Service includes Google Maps features and content. Google may process requests, device or server IP address, API or project identifiers, place searches, map interactions, and related information under its terms and policies.
Use of Google Maps features is subject to the current Google Maps/Google Earth Additional Terms of Service and Google Privacy Policy. Google Maps Platform information may also be subject to Google's own collection and retention practices.
Legal, safety, and corporate events
We may disclose information when reasonably necessary to:
- Comply with law, court order, subpoena, or valid legal process
- Protect rights, safety, and security
- Investigate fraud, abuse, or a violation of our Terms
- Respond to an emergency where disclosure is permitted by law
- Complete a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable safeguards
Aggregated or de-identified information
We may disclose aggregated or de-identified information that cannot reasonably identify you. We will not attempt to re-identify it except to test de-identification or as permitted by law.
6. Public, link-accessible, and collaborative content
Your visibility choice determines who can access content.
Private content
Private content is limited to authorized users, service operations, providers acting for Platix, and disclosures described in this Policy.
Link-accessible content
Anyone who obtains a valid link may be able to view link-accessible content. A recipient can forward the link. Do not treat link-accessible content as private.
Public content
Public content can be viewed by anyone. Approved public pages may be added to sitemaps and indexed by search engines. Search engines, archives, recipients, and other users may retain copies after you change visibility or delete the original.
Collaborators
Viewers and editors can access shared content according to their role. Editors may change content. Platix records access, invitation, and change information to operate and protect collaboration.
7. Cookies and local storage
Platix uses HTTP-only authentication cookies for access and refresh sessions. In production, these cookies are intended to use secure transport and SameSite=Lax controls.
The browser may also use local or session storage for:
- Your analytics consent decision and a consent receipt identifier
- A first-party anonymous analytics identifier, created only after you consent to analytics
- Tutorial progress and dismissal state
- Temporary authentication redirect paths
- Temporary application state
Google Analytics sets its own cookies, including _ga and related identifiers, to distinguish visitors and sessions for audience and acquisition measurement. These are set only after you consent. Platix implements Google Consent Mode with all storage signals defaulting to denied, and does not load the Google Analytics script at all until consent is given.
Platix stores your consent decision in local storage under platix_consent, and a randomly generated consent receipt identifier under platix_consent_id. Clearing your browser storage clears the decision, and Platix will ask again.
Google Maps or other third-party features may use cookies or similar technologies under their policies.
Platix does not use cookies for third-party cross-context behavioral advertising. Google Signals and Google Ads linking are not enabled for the Platix Google Analytics property.
8. Retention
We retain information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, maintaining security and auditability, resolving disputes, and complying with law.
Retention depends on:
- Whether your account remains active
- Whether content is private, shared, or public
- Whether a record is needed to provide a requested feature
- Security, fraud, and abuse-prevention needs
- Backup and disaster-recovery cycles
- Legal, tax, accounting, contractual, and dispute requirements
- The need to preserve a minimal deletion or operational audit record
Examples:
- Trips, collections, chats, preferences, and media are generally retained while your account or the content remains active.
- Public content and comments may remain until removed, moderated, or deleted.
- Contact messages may be retained to respond, track resolution, and maintain support records.
- AI audit records may be retained for quality, debugging, security, and cost accountability.
- Legal acceptance records are retained with your account so Platix can demonstrate which document versions you accepted. The current account-deletion process deletes those user-linked records.
- Infrastructure logs may be retained for a limited operational period.
- Backups may persist temporarily after active-system deletion until overwritten through normal cycles.
Platix is documenting specific retention periods for contact messages, analytics events, AI audit records, security logs, deleted-account audit events, and backups, and will publish them in this Policy. Until then, Platix retains this information only for as long as needed for the purposes described above and deletes or de-identifies it when that need ends.
9. Account deletion
You may request account deletion through available account controls or by contacting us.
The implemented account-deletion process is designed to:
- Delete owned trips, collections, saved places, chats, memories, preferences, reactions, bookmarks, tutorial state, and owned media
- Remove access grants and pending invitations associated with the account or email
- Delete social and collection comments associated with the account
- Anonymize blog comments and contact messages associated with the account
- Remove actor identity from change and share records where implemented
- Remove or anonymize user attribution from selected audit and recommendation records
- Delete the Supabase authentication user
- Delete user-linked legal acceptance records
- Preserve a restricted account-deletion event containing a user identifier, optional email hash, status, counts, metadata, and error information for operational accountability
Some information may remain where required for security, legal compliance, dispute resolution, fraud prevention, backups, or the rights of other users. Content others copied outside Platix cannot be deleted by Platix.
If account deletion cannot complete, contact support@platix.io.
10. Security
We use administrative, technical, and organizational measures intended to protect personal information. Current controls include server-side service credentials, HTTP-only session cookies, access checks, row-level database security, rate limits on selected endpoints, restricted media access, and account-deletion tooling.
No security measure is perfect. We cannot guarantee that information will never be lost, accessed, disclosed, altered, or destroyed without authorization.
You are responsible for protecting your account credentials and for avoiding unnecessary sensitive information in public or AI-assisted content.
11. Your choices and controls
Depending on the feature, you may:
- Edit your profile and display name
- Change trip or collection visibility
- Manage collaborators and invitations
- Edit or delete eligible comments
- Delete saved memory facts
- Update travel preferences
- Clear selected chat histories
- Delete trips, collections, saved places, and media through available features
- Delete your account
- Avoid posting public or link-accessible content
- Decline to provide optional author-input information for editorial content
You may contact us for additional privacy requests.
12. Privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to:
- Know whether we process your personal information
- Access or receive a copy of personal information
- Correct inaccurate information
- Delete information
- Restrict or object to processing
- Receive portable information
- Withdraw consent where processing is based on consent
- Appeal a denied request where applicable
- Lodge a complaint with a regulator
To submit a request, email support@platix.io with the subject "Privacy Request." We may need to verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and identity verification.
We will not discriminate against you for exercising an applicable privacy right.
13. California privacy notice
California residents may have rights under the California Consumer Privacy Act, as amended ("CCPA"), if it applies to Platix.
The categories of personal information described in California law that Platix may collect include:
- Identifiers
- Customer-record information
- Internet or electronic-network activity
- Geolocation information
- Audio, electronic, visual, or similar information, including uploaded media
- Commercial or interaction information, if future paid features are introduced
- Inferences about travel preferences
- Sensitive personal information when a user voluntarily provides precise location, account credentials, dietary information, or accessibility needs
Sources, purposes, and recipients are described in Sections 2, 3, and 5.
Platix does not currently sell personal information for money. Platix does not currently share personal information for cross-context behavioral advertising as "share" is defined by the CCPA. If those practices change, we will update this Policy and provide legally required opt-out methods before the change applies.
Because Platix does not currently sell or share personal information for cross-context behavioral advertising, a Global Privacy Control signal does not change those practices. If Platix begins an activity subject to opt-out preference signals, it will implement legally required handling before beginning that activity.
The CCPA does not apply to every business. This section is intended to provide transparency and applicable rights; it is not an admission that Platix meets a statutory threshold.
14. European, UK, and Swiss users
Where the GDPR, UK GDPR, or similar law applies, NUDOOO LLC is the controller of personal information described in this Policy unless stated otherwise.
We rely on one or more of the following legal bases:
- Contract, to provide the Service you request
- Legitimate interests, such as security, debugging, product improvement, support, and abuse prevention, balanced against your rights
- Consent, where required for optional processing
- Legal obligation
- Establishment, exercise, or defense of legal claims
Information may be transferred to and processed in the United States and other countries where our providers operate. Those countries may have different data-protection laws from your country. The transfer safeguards applicable to a provider are described in that provider's contractual terms and data-processing documentation. Contact support@platix.io for information about safeguards relevant to your use of the Service.
You may contact your local data-protection authority. European Commission information about GDPR rights is available through its data-protection guidance.
15. Children
The Service is not directed to children under 13. Platix does not knowingly collect personal information from a child under 13 without legally required parental consent.
Users must be at least 18 to create an account under the Terms. If Platix later allows users aged 13-17, it will implement a consistent age and guardian policy and update this Policy before doing so.
If you believe a child has provided personal information, contact support@platix.io. We will investigate and delete information where required.
16. Do Not Track
Some browsers offer a "Do Not Track" setting. There is no universally accepted technical standard for responding to these signals, and Platix does not currently respond differently to browser Do Not Track signals.
This does not affect legally required handling of other recognized privacy signals, such as opt-out preference signals where applicable.
17. Future paid and affiliate features
Product-planning documents discuss possible premium trips, creator payouts, affiliate links, and payment processing. Those features are not part of the currently implemented privacy practices described here.
Before launching any paid or affiliate feature, Platix will update this Policy to address payment providers, transaction records, tax data, fraud checks, affiliate tracking, tracking cookies, purchase history, creator applications, payouts, and legally required choices or disclosures.
18. Changes to this Policy
We may update this Policy as the Service or law changes. We will post the updated Policy, revise the effective date, and provide additional notice when required.
Materially different uses of previously collected personal information will be handled as required by law.
19. Contact
Questions, requests, or complaints may be sent to:
NUDOOO LLC
Palo Alto, California, United States
Email: support@platix.io
Privacy contact: COO