← Back to WhatWeShouldSee

Privacy Policy

Effective date: June 29, 2026  |  Last updated: June 29, 2026  |  Version 2026-06-29

WhatWeShouldSee (“we,” “us,” or “our”) operates the WhatWeShouldSee website (www.whatweshouldsee.com) and the WhatWeShouldSee mobile application (collectively, the “Service”). This Privacy Policy explains what information we collect, why we collect it, how it is stored and protected, when it may be shared, and your rights regarding your personal data.

By using the Service you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service. Please also review our Terms of Service, which govern your use of the Service.

1. Information We Collect

1.1 Information You Provide Directly

CategoryExamplesPurpose
Account & Profile Name, email address, password, birthday, gender, phone number, profile photo, biography, Instagram handle Create and manage your account, personalize your experience, enable social features
Travel Preferences Interest tags, travel style, pace, party composition, diet requirements, must-do / avoid preferences, home city, nearest airport Generate personalized itineraries and recommendations tailored to your travel style
Trip & Itinerary Data Trip names, dates, destinations, budgets, traveler counts, day-by-day activities, notes, reviews Build, store, and share your travel itineraries
User-Generated Content Photos, videos, comments, messages, recommendation requests, blog posts, community posts Enable content creation, sharing, and social interaction within the Service
Community & Social Community membership, follow/block lists, messages, comments, invitations Power social features such as communities, messaging, and friend discovery
Payment Information Payment account identifier (for creators receiving payouts) Process creator payouts; actual payment card details are handled entirely by our payment processor and never touch our servers

1.2 Information Collected Automatically

CategoryExamplesPurpose
Device & Browser Data Device type, operating system, browser type, screen resolution, language preference Optimize the Service for your device and diagnose technical issues
Usage Data Pages visited, features used, clicks, time spent, navigation paths Understand how the Service is used so we can improve it
Anonymized IP Address Your IP address is anonymized before storage — your full IP is never retained Security, fraud prevention, and aggregate geographic analytics
Cookies & Similar Technologies Session cookies, analytics cookies (see Section 5) Keep you logged in, remember preferences, and gather usage analytics

1.3 Information from Third-Party Sign-In

If you sign in via Google or Apple, we receive limited identity information from your account (typically name and email) so we can create or recognize your WhatWeShouldSee account. We do not receive or store your Google or Apple password.

If you use Apple’s “Hide my email” feature when signing in with Apple, you will share a private relay email address instead of your real email. We accept this and use the relay address for account-related communication. You can update to a non-relay email at any time in Settings → Account.

1.4 Contact Sync (Optional)

The Service offers an optional “Find Friends” feature. If you grant permission, the app reads contacts from your device locally, generates one-way cryptographic hashes of phone numbers and email addresses, and sends only the hashes to our server. Your raw contact data (names, numbers, emails) never leaves your device. Uploaded hashes are used for matching only, are never stored on our servers, and are discarded immediately after the lookup completes.

2. How We Use Your Information

We use the information we collect to:

We do not sell your personal data. We do not use your data for targeted advertising. We do not engage in cross-app or cross-website tracking — the analytics we run measure how you use WhatWeShouldSee itself, not your behavior on other apps or sites. For this reason, our iOS app does not present the “Allow tracking” (App Tracking Transparency) prompt.

3. AI & Automated Processing

We use third-party artificial intelligence services to power features such as itinerary generation, travel personality analysis, place descriptions, and trip reviews. When these features are used:

4. How We Store & Protect Your Data

4.1 Storage

Your data is stored on secure, commercially hosted cloud infrastructure located in the United States. Different types of data (account information, session data, uploaded media) are stored using industry-standard database and file-storage services, each with encryption at rest and in transit.

4.2 Security Measures

4.3 Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, legal obligations). Anonymized, aggregated data that cannot identify you may be retained indefinitely for analytics purposes.

5. Cookies & Tracking Technologies

Cookie / TechnologyTypePurposeDuration
Session cookie Essential Keep you logged in and manage your session securely Up to 30 days
Remember-me cookie Functional Persist your login across browser sessions Up to 30 days
Analytics cookies Analytics Understand usage patterns, feature adoption, and user experience Session-based
Error monitoring cookies Performance Detect and diagnose errors and performance issues Session-based

You can disable non-essential cookies through your browser settings. Disabling essential cookies may prevent the Service from functioning correctly.

6. Third-Party Services & Data Sharing

We share data with third parties only as described below. We do not sell or rent your personal data.

Service ProviderPurposeData Shared
AI service providers AI-powered itinerary and content generation Travel preferences and trip queries (no directly identifying personal data)
Google Maps Platform Maps, place search, directions, geocoding Search queries, coordinates; subject to Google’s Privacy Policy
Payment processor Payment processing for creator payouts Payment account ID; card/bank details handled entirely by our payment processor and never touch our servers
Google OAuth Social sign-in Email and name from your Google account
Error monitoring provider Error monitoring and performance tracking Error traces, anonymized request data (PII is stripped)
Analytics provider Product analytics Anonymized usage events, pageviews, feature interactions
Cloud infrastructure provider Hosting and storage All Service data is hosted on secure, commercially operated cloud infrastructure
Avatar service provider Default profile avatars A one-way hash of your email address (used to look up your public avatar)
Accommodation search provider Accommodation search and booking lookup Place names and coordinates (no user personal data)

We may also disclose your information if required by law (e.g., court order, subpoena) or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

All third-party service providers are contractually obligated to handle your data in accordance with applicable data protection laws and are prohibited from using your data for their own independent purposes.

7. Your Rights & Choices

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, please contact us at the address below. We will respond within 30 days (or sooner if required by applicable law).

Account Deletion

You can delete your account directly from within the app at Settings → Account → Delete Account. Deletion is subject to a 14 day grace period, during which you may cancel by signing back in. After the grace period, your personal data is deleted or anonymized within 30 days, subject to any legal retention requirements.

You may also email privacy@whatweshouldsee.com to request deletion if you cannot access the app.

8. Children’s Privacy

The Service is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

9. International Data Transfers

Your data may be transferred to and processed in countries other than your own, including the United States, where our cloud infrastructure is hosted. We ensure that appropriate safeguards are in place to protect your data in accordance with applicable data protection laws.

10. California Residents (CCPA)

If you are a California resident, you have the right to: (a) know what personal information we collect and how it is used; (b) request deletion of your personal information; (c) opt out of the sale of personal information — we do not sell personal information; (d) non-discrimination for exercising your rights. To make a request, contact us below.

11. European Residents (GDPR)

If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, the legal bases for processing your data are: (a) contractual necessity — to provide the Service you requested; (b) legitimate interests — analytics, security, and service improvement; (c) consent — where you have opted in (e.g., optional analytics, contact sync). You may contact your local data protection authority if you have concerns about our data practices.

12. Data Breach Notification

In the event of a data breach that compromises your personal data, we will notify affected users and relevant regulatory authorities as required by applicable law. Where required, we will provide notification within 72 hours of becoming aware of the breach, including a description of the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

13. Do Not Track Signals

Some browsers transmit “Do Not Track” (DNT) signals. There is currently no uniform standard for how online services should respond to DNT signals. At this time, the Service does not respond to DNT signals. You can control your cookie preferences through your browser settings as described in Section 5 above.

For terms relating to acceptable use, disclaimers of warranties, limitation of liability, indemnification, account suspension and termination, and dispute resolution, please refer to our Terms of Service.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page and, for material changes, notify you via the Service or by email. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

WhatWeShouldSee
Email: privacy@whatweshouldsee.com

We aim to respond to all privacy-related inquiries within 30 days.