Your location, handled with care
We use your location once to answer your question, then let it go - it is never stored, never sold, and never tied to who you are.
The short version
- No cold pop-ups - you always see our plain-language sheet before any location prompt.
- Coordinates are used for one answer, then discarded - never stored, never logged with your identity.
- Your location is never sold, rented, or traded, and is never used to build a profile.
- Nominatim and Gemini are reached through our server, so your exact coordinates never touch a third party directly.
- Abuse limits ride on a hashed IP only - never on your coordinates, never on your route.
What we collect
Almost nothing about you, and nothing by default. The page does not ask the browser for your location when it loads, and it does not run any tracking scripts to guess where you are.
When you choose to share your location, we receive a pair of map coordinates for that single request. We also process a one-way hashed version of your IP address - a scrambled fingerprint we cannot reverse into your real address - purely to keep the service from being abused. We do not ask for your name, your email, or an account, because you do not need one to use VacationAgents.
How your location is used
Your coordinates exist only for the answer in front of you. When you ask where the nearest train station is or how to get to the airport, we pass those coordinates to our own server, ground that one answer in your surroundings, and then discard the coordinates. They are request-scoped: used for that reply, then gone.
We never write your coordinates to a long-term database, never attach them to your identity, and never build a profile or a movement history from them. There is no map of where you have been, because we do not keep one. Two questions in a row are two separate, throwaway uses - not a trail.
What we never do
We never fire the browser's native location dialog without warning. Before any OS prompt appears, you see our own plain-language sheet explaining exactly what happens - so the cold system pop-up never catches you off guard.
We never store your exact coordinates, never log them next to anything that identifies you, and never sell, rent, or trade your location to advertisers, data brokers, or anyone else. There is no profiling of you and no profiling of the places around you. Safety tips, when we offer them, are about behavior - what to do, not who to fear.
The AI agent (Gemini) and Nominatim data flow
Two outside services help answer you, and we deliberately stand between you and both of them so your raw data stays protected.
To turn coordinates into a readable place name, we use OpenStreetMap's Nominatim service - but the request goes out from our server, not your browser, so your exact coordinates never touch a third-party client directly. To write the actual answer, we use Google's Gemini model (gemini-2.5-flash) through a server-side proxy, with our API key held outside the public web root. Gemini receives only the grounded context needed for your reply, not your identity. Neither service is given a way to tie a location back to you, and the coordinates are released as soon as your answer is built.
Rate limiting and security
To keep VacationAgents fast, free, and fair, we limit how many requests can come from one source in a short window and cap overall AI spend. These limits are keyed on a one-way hashed IP only - never on your coordinates and never on your route.
That separation is the whole point: the thing we use to stop abuse (a hashed IP) is kept completely apart from the thing we use to answer you (transient coordinates), so the two are never joined into a profile. Requests are sanitized before they reach the AI, and secrets live outside the web root with verified, encrypted connections to every upstream service.
Your controls
You are always in charge of the location switch. Sharing is opt-in - nothing happens until you tap to allow it on our pre-prompt sheet, and you can decline and still use the planning side of the site.
A "Stop using location" control clears your coordinates from the session instantly, the moment you tap it - and because we never stored them anywhere else, that one tap is the end of it. Your browser also lets you revoke the permission at any time through its site settings, and the next visit starts fresh, with no memory of the last.
What stays on your device
Two conveniences live entirely in your browser, on your phone. Your Pocket - answers you choose to save - is kept in your browser's local storage so it works offline; it is never sent to us. And so a refresh doesn't lose your briefing, your conversation and the resolved place name (never coordinates) sit in your browser's session storage until the tab closes.
Both are yours to wipe any time: "Clear conversation" in the app menu, "Clear all" in the Pocket, or simply clearing your browser data.
Questions about your data? Contact us.