What Intentative keeps about you, why, who else sees it, and how to take it with you or have it deleted.
Who we are
Intentative is run by ANDREAS BERG DOTDEV, a sole proprietorship in Norway (organisation number 937 794 355), Jotunveien 3C, 1185 Oslo. We decide what happens to your data here: in the GDPR's words, we're the controller.
Write to support@intentative.app about anything on this page.
What we keep
Only what your trips need. No ads, no tracking, and we never sell data.
- Your account: the name you give, your language, your home airport if you set one, and when you joined. Your passkey stays on your devices; we keep only its public half and the device's name.
- Your travel profile, if you fill it in: what you love, pace, budget, where you like to stay, and what's good to know, which can include health or mobility needs. It's optional, only you see it, and "Forget my profile" on your account clears it.
- Your trips: what you and the others on them put in. Where and when, who's coming (children's ages too), stays and addresses, booking references, plans, tasks, notes, hearts and conversations with Atlas.
- Photos and videos you add, with when and where they were taken if the file says so. The place shows on the trip's map, to its members only, and never in the keepsake.
- Confirmations and receipts you attach, and mail to the trip's own address: who sent it, the message and its files. Mail sent from the trip is kept the same way.
- Your voice, when you talk to Atlas: it's written down and the recording is thrown away. Only the words you send are kept.
- Where you are, only when you ask what's nearby and your phone allows it. It's used for that search and not kept.
- Hotel bookings: the name, email and phone of whoever books, the dates and who's staying. Card details go straight into the payment form; we never see them.
- Running the service: Cloudflare sees your IP address to deliver pages and keep attacks out. We count new accounts per address per hour, and each person's use per day, to keep costs and abuse down. When Atlas's guard stops a message that tries to steer it, we note its first words.
Most of this is needed to give you the service you asked for (GDPR article 6(1)(b)). Your travel profile, and any health needs in it, is there because you chose to give it (articles 6(1)(a) and 9(2)(a)); you can take that back at any time. Counting use, logs and the guard's notes are our legitimate interest in keeping Intentative safe and affordable (article 6(1)(f)).
Atlas is AI
To plan and research a trip, answer a question, read a mail or an attachment, or write down what you said, the text Atlas needs is sent to AI models: Luna (made by OpenAI) and Jev (made by Typesafe), reached through Cloudflare's Workers AI and AI Gateway, and speech and document reading run by Cloudflare. That can include your messages, the trip's details, who's coming and your travel profile.
The AI Gateway keeps a log of these requests so we can find faults and follow costs. It's deleted after 30 days.
We don't train AI on your data. Atlas suggests; it decides nothing about you on its own.
Who else sees it
The others on a trip see everything in it, and your name. An invite link you make lets the person it names join.
Services that run Intentative for us, under agreements that let them use your data only for that:
- Cloudflare (USA): hosting, the database, files, AI, mail to and from trips, and logs.
- OpenAI (USA) and Typesafe: the AI models above, through Cloudflare.
Services you choose to use, which are responsible for your data under their own privacy policies:
- LiteAPI (Nuitée), when you book a room: they make the booking with the hotel and take the payment, through Stripe.
- Stripe, when you buy the mail add-on.
- Flight sites (Google Flights, Skyscanner, Kayak, Momondo), when you open a search: the link carries airports, dates and how many are flying, never your name.
- Whoever you send mail to from a trip.
Places are looked up in open data: your browser loads the map from OpenStreetMap, which sees your IP address, and our server asks OpenStreetMap, Wikipedia, Wikidata and Wikivoyage about places and addresses, never about you.
We share data with authorities only when Norwegian law requires it.
Outside Europe
Cloudflare, OpenAI and Stripe are American. What goes to them is covered by the EU–US Data Privacy Framework and the EU's standard contractual clauses.
How long we keep it
- Your account and profile: until you delete them.
- A trip: while anyone is on it. When the last person on it deletes their account, it goes, with its photos, files and mail.
- Plans you haven't built: until you let them go, or delete your account.
- Signing in: a browser stays signed in for 180 days, the app for 30 days after you last used it.
- Counts of use: two days. The guard's notes: 90 days. Cloudflare's logs of requests and errors: about a week. The AI Gateway's log: 30 days.
- Backups: the database can be rolled back for up to 30 days, so what's deleted is gone for good 30 days later.
- Payments: Stripe and Nuitée keep their records, and we keep their statements for five years, as Norwegian accounting law requires.
Your rights
You can see, correct, take with you and delete what we keep about you:
- Download your data: everything about you, and each trip you're on, as a file.
- Change your name, profile and language on your account, and anything on a trip where it is.
- Delete your account: you, your profile and the trips no one else is on go at once. Trips you share stay with the others; if you owned one, whoever joined it first owns it now. What you wrote on them stays, no longer linked to you.
You can also object to how we use your data, ask us to limit it, or withdraw your consent, by writing to support@intentative.app. We answer within a month.
If you think we've got it wrong, you can complain to Datatilsynet, the Norwegian Data Protection Authority (datatilsynet.no).
Children
Accounts are for people 13 and over. Parents can tell Atlas about children coming along (a name and an age, to plan for them); only the people on the trip see it.
Keeping it safe
Passkeys instead of passwords, sign-in tokens stored only as fingerprints, everything over HTTPS, trips and their files only for their members, and uploaded files never run as code.
Changes
If this page changes in a way that matters, we'll say so in Intentative before it applies. The date at the top is the last change.