Privacy policy

Last updated: 6 August 2026

In short

BeenBeen stores the travel data you enter yourself: marked places, notes, ratings, photos, flights and ground trips. We do not sell your data and we do not use it for advertising.

What we collect

Account data: your email address and, if you sign in with Google, the name and avatar Google returns.

Travel data: places you mark and their statuses, notes, ratings, photos you upload, trips, flights and ground legs.

Optional location data: only if you turn on auto-marking. Coordinates are used to suggest a place to mark and are stored only as a mark you confirm.

Optional photo metadata: if you use the photo import, EXIF coordinates are read on your device to suggest places.

Technical data: crash and error reports (Sentry) with no travel content attached.

Where it is stored

Data lives in Supabase (PostgreSQL and object storage) with row-level security: a row is readable only by the account that owns it. Photos are served through signed, time-limited URLs.

Third parties

Supabase — database, authentication and file storage.

MapTiler — map tiles; requests carry your approximate viewport, not your account.

Anthropic (or the AI provider configured at the time) — processes the text you send to AI features and the files you submit for AI import.

Google — only if you choose Google sign-in.

RevenueCat and Stripe — subscription payments. We never see your card details.

Sentry — anonymous crash diagnostics.

Your rights

You can edit or delete any mark at any time, and you can ask us to delete your account and everything attached to it by writing to the support address below. Deletion is permanent.

Children

The service is not directed at children under 13.

Contact

Questions about this policy: [email protected]