Privacy Policy
Last updated: June 28, 2026
This Policy describes what personal data RouteLab (the “Service”, “we”) collects, why we use it, whom we share it with and what rights you have regarding this data. By using the Service you confirm that you have read and understood this Policy.
1. Data controller
The data controller (in GDPR terms) is the RouteLab team. For any questions about personal data, contact us at privacy@routelab.app.
2. Data we collect
2.1. Sign-up and profile
- Email (used as your login and for account verification)
- Password (stored hashed by Supabase Auth; we never see it in plain text)
- Name, username, bio, avatar — whatever you enter in your profile
2.2. Content you create
- Routes, days, places, notes, budget, transfers — everything you add to your routes
- Saved routes and places (favorites)
- Place names you enter for AI route generation
2.3. Technical data
- IP address and browser info (Supabase logs, for security and abuse prevention)
- Technical cookies to maintain your session (see Cookie Policy)
3. Why we use this data
- Providing the Service (creating, storing and viewing routes)
- Authentication and account protection
- Sending transactional emails (email confirmation, password reset)
- Abuse prevention and security
- Improving the Service based on anonymized aggregate statistics
4. Legal basis for processing (GDPR Art. 6)
- Contract (Art. 6(1)(b)) — processing needed to provide the Service under our agreement with you
- Legitimate interest (Art. 6(1)(f)) — account security, abuse prevention, basic technical analytics
- Consent (Art. 6(1)(a)) — publishing routes publicly by your explicit choice
5. Who we share data with (Sub-processors)
We do not sell your data to third parties. To run the Service we use the following sub-processors, which may receive data to the extent needed to provide their services:
- Supabase (database hosting and auth) — all profile data and route content. Hosted on AWS. Privacy Policy →
- Resend (transactional email) — your email and message content. Privacy Policy →
- Anthropic (AI generation via Claude) — text prompts for generation. API data is not used to train models. Privacy Policy →
- Unsplash (place photo search) — place name only, no personal data. Privacy Policy →
- Mapbox (map previews and routing between points) — place coordinates, no personal data. Privacy Policy →
- YouTube Data API (Google) and Supadata (only when creating from a video link) — the public video link/ID. No personal data is shared. Google → Supadata →
- Nominatim / OpenStreetMap (geocoding) — place names and addresses only, no personal data. Privacy Policy →
- Wikimedia / Wikidata (fallback photos/geodata) — place names only, no personal data. Privacy Policy →
- Sentry (error tracking) — stack trace, page URL, your UUID (no email), browser/OS. Privacy Policy →
- Google Analytics (Google) — web analytics, cookies _ga/_ga_*; anonymized identifiers and event categories, not your email or name. See Cookie Policy. Privacy Policy →
- Yandex Metrica (Yandex) — web analytics and session replay (Webvisor, with input masking), cookies _ym_*; anonymized data, not your email or name. See Cookie Policy. Privacy Policy →
6. Public content
A route “published to the feed” is publicly visible to all users, including logged-out visitors. A route “via link” is accessible to anyone with the direct link. A “draft” is visible only to you. Your name, username, avatar and public routes appear on your public profile at /u/<username>.
7. Retention
We keep your data while your account exists. When you delete your account (available in profile settings), all your data is irreversibly removed from our database. Supabase backups may retain deleted data for up to 7 days.
8. Your rights
Under GDPR (Articles 15–22) you have the following rights:
- Right of access — learn what data we hold about you
- Right to rectification — correct inaccurate data (available in profile settings)
- Right to erasure (“right to be forgotten”) — delete your account and all data (in settings)
- Right to portability — get a copy of your data in a machine-readable format (JSON) by emailing privacy@routelab.app
- Right to restriction of processing and right to object
- Right to lodge a complaint with your supervisory authority (for the EU — the relevant Data Protection Authority)
Send rights requests to privacy@routelab.app. We respond within 30 days.
9. Data security
We use industry practices: encryption in transit (TLS), Row Level Security in the database (only you can access your data, and only via an authorized session), password hashing. However, no online service can guarantee 100% security — use unique passwords and never share your credentials.
10. Children
The Service is not intended for anyone under 16. If we learn we collected data of a child under 16 without a parent's or guardian's consent, we will delete it promptly.
11. International data transfers
Our sub-processors' servers may be located outside the European Economic Area (EEA). Transfers rely on Standard Contractual Clauses (SCC) approved by the European Commission, or other legal mechanisms ensuring an adequate level of protection.
12. Changes to this policy
We may update this Policy. We will notify you of material changes by email or through the Service. The last-updated date is shown at the top.
13. Contact
For any questions about your data, contact privacy@routelab.app.