Privacy Policy
Last updated: September 2026
1. Information We Collect
When you create an account, we collect your name, email address, and a securely hashed password (we never store your password in plain text — see Security below).
When you use the budget planner, we store your search inputs (origin, budget, traveller count, dates, destination type, travel style preferences) so we can generate and later show you your results.
When you save a trip or a destination, we store that association with your account.
2. Account Data
Your account data (name, email, role, status) is used to authenticate you, personalize your dashboard, and enforce access control (for example, only you can see your own saved trips and search history).
3. Trip and Search Data
Search results and generated itineraries are linked to a search record with a public, non-sequential identifier so a shared link cannot be used to guess or browse other users’ searches. If you are logged in when you search, that search is also linked to your account so it appears in your history.
4. Cookies and Local Storage
We use an essential, httpOnly session cookie to keep you logged in. This cookie is required for authentication and cannot be disabled while remaining logged in.
We use a small cookie and your browser’s local storage to remember your language preference (English/Bangla). This is not used for advertising or cross-site tracking.
We do not currently use third-party advertising or analytics cookies.
5. Third-Party AI and Data Providers
Trip content (destination research, places to visit, food and stay recommendations) is generated using DeepSeek, a third-party AI provider. Requests sent to DeepSeek include the travel context needed to generate that content (such as destination name, budget range, and trip duration) — never your name, email, or account credentials.
Destination images are sourced from Wikipedia’s public API, which does not require or receive any of your personal data.
We do not sell or share your personal data with third parties for their own marketing purposes.
6. Security
Passwords are hashed using bcrypt before storage. Sessions are tracked server-side so they can be revoked (for example, when you reset your password or an administrator suspends an account). All traffic to Tripazai AI is encrypted via HTTPS.
7. Data Retention
Account data is retained while your account is active. Saved trips, saved destinations, and search history are retained until you delete them or close your account. You may request deletion of your account and associated data by contacting us (see below).
8. Your Rights
You may access, update, or request deletion of your personal data at any time by contacting us. If you no longer wish to receive account-related communication, you may close your account.
9. Contact
For privacy questions or data requests, please contact us through the details provided on the Tripazai AI website or by your account administrator.
10. Changes to This Policy
We may update this policy as Tripazai AI’s features change. Material changes will be reflected by updating the “Last updated” date above.
