Iodine Studio · California
Privacy Policy
Effective September 27, 2026. Contact support@iodine.studio.
1. What this policy covers
Outset Travel is a trip-planning service. This policy explains the information we collect, why we use it, who can receive it and the choices available to you. It covers our service; external sites, map providers and integrations you choose to use have their own privacy practices.
2. Information we collect
Account and security information. We collect your username, password in hashed form, optional email address, account role, the time and policy version of your signup agreement, and account/security activity needed to manage access. Recovery codes are stored as protected hashes, not as readable codes. Security records can include sign-in attempts, timestamps, session state, tokens and hashed identifiers used to limit abuse. Infrastructure providers may process IP addresses and request information when delivering the service.
Trip information you enter. This can include trip names, destinations and dates; lodging and booking details, confirmation references, notes, activities, saved places and map coordinates; packing/checklist items; and budget information. Free-text fields may contain personal information you choose to enter. Please avoid unnecessary sensitive information about yourself or other travelers.
Sharing and publication information. We store sharing permissions, invitation email addresses, invitation status and public-sharing settings. We receive information about you when another user invites you or includes information in a trip they share with you.
Support and authorized integrations. We receive messages you send to support. If you authorize an integration, we process credentials, authorized trip requests/changes and relevant audit information to provide and secure that access. An integration can receive the trip information you authorize it to access; review its separate privacy practices.
Optional analytics. If you choose “Allow analytics,” we collect limited usage and performance information through AWS CloudWatch RUM: random browser/session identifiers, timestamps, general page categories, active-time and page-performance measurements, and technical browser/device information. AWS processes the connection and may derive coarse geographic information. Our custom events exclude private trip identifiers, account names, emails, trip content, booking details, form contents and full page URLs. We do not enable session replay or screen recording in this analytics implementation.
Public discovery, attributed display names and anonymous stars are planned features. Before enabling them, we will explain any additional data collected, its use, storage lifetime and available controls.
3. How we use information
We use information to provide accounts and recovery, store and display trip plans, enable the collaboration/publication choices you make, provide authorized copies and exports, respond to support requests, detect and address abuse, and maintain the service. With your analytics choice, we use limited measurements to understand usage and improve reliability and performance.
We may also use information where necessary to handle a documented dispute, comply with applicable requirements or protect people and the service. We limit access to what is appropriate for those purposes.
4. Who can see or receive information
Your collaborators. People you give access to can see or edit the trip information their permission allows. Removing access does not erase information they already retained outside the service.
The public, when you choose public sharing. The public preview identifies the information included. Current public links expose selected trip and activity information, including travel dates, but exclude private notes, booking-linked events, lodging events, exact addresses/coordinates, private budget rows, collaboration records and account identity. Text you choose to make public can still contain identifying details. Public links are live: later edits to included fields and eligible activities can appear automatically.
People can make independent private planning copies of a public itinerary. Disabling the original link does not delete those copies, screenshots, or information cached by outside parties.
Planned discovery controls. Public discovery and public-display-name attribution are not yet available. When introduced, discovery enrollment will require a separate opt-in from a shareable link. Attribution will be a separate choice for each itinerary and will not expose your login username or email.
Service providers. We use AWS Lightsail to host the application and database in US East (Northern Virginia), and AWS CloudWatch RUM for optional analytics. Providers may receive information necessary to deliver their services. We also use an email provider to receive and manage support correspondence. External integrations and providers may process information in locations beyond our application hosting region.
Google Maps. When configured map features load, Google can receive connection/device information and information associated with the map interaction. Opening a Google Maps link sends the requested location information to Google. Maps are separate from optional Outset analytics; declining analytics does not by itself disable maps or all third-party requests. See the Google Privacy Policy and Google Maps terms.
Integrations you authorize. External clients can receive the authorized trip context and submit changes on your behalf. Authorization does not make the provider part of Outset, and its use of received information is subject to its own terms.
Other necessary disclosures. We may disclose information when reasonably necessary to comply with applicable requirements, respond to valid process, protect rights or security, or address abuse. If Outset Travel is sold or reorganized, Iodine Studio may transfer information necessary for the transaction and continued operation of the service, subject to continued privacy protections. We will notify you of material changes and request any new consent required. This does not authorize a standalone sale of user data.
5. Browser storage, analytics and acquisition advertising
Some storage is used for sign-in, security and saving functional choices such as your trip view. Optional analytics starts only after affirmative consent. You can choose “No thanks” or later use “Analytics preferences” to stop collection and clear the analytics identifiers/session information stored in your browser. Choosing “No thanks” does not prevent you from using the planner.
The analytics preference lasts 180 days. The anonymous analytics browser cookie lasts up to 30 days after renewal, and an analytics session is treated as expired after 30 minutes of inactivity. This inactivity limit does not by itself delete the saved session state from local storage. Temporary AWS credentials used for measurement are held in page memory. Withdrawal stops future collection; events already received by AWS remain subject to their retention period.
We plan to advertise Outset on Reddit to attract visitors. We will measure this initial campaign using Reddit's campaign reports and our existing optional, consent-based analytics. The approved launch scope excludes a Reddit tracking pixel, conversion API and customer-list uploads.
In-product advertising is deferred. Outset does not currently use Reddit pixels, conversion APIs or customer-list uploads. Our optional analytics follows the choice you make in Analytics preferences; the application does not separately change that choice in response to Do Not Track or Global Privacy Control signals. Google Maps and sites you visit through external links have their own practices and may collect information about your use of their services over time and across sites. Contact us about privacy rights or opt-out requests that apply to you.
6. Retention and deletion
We retain account and trip information while providing the service and for approved operational needs. You can request account deletion in account settings. The request immediately deactivates access and makes the account eligible for permanent deletion after 30 days. Permanent purges are manually reviewed rather than run automatically each day, so eligibility does not mean all records are erased exactly on day 30. The current release does not provide self-service cancellation of deletion; contacting support does not automatically stop or extend it.
Raw analytics events in AWS RUM and its configured log export are retained for 30 days. Ordinary resolved support messages follow a 180-day retention period. Other application records and aggregate summaries currently have no fully implemented, verified time-based cleanup schedule. Contact us to request review or deletion of your information.
Approved retention plan. We are implementing weekly manual review of eligible account deletions, 30-day ordinary deleted-trip trash retention, deletion of inactive invitations and expired/revoked integration tokens after 30 days, 90-day minimal security/integration logs, 90 days after resolution for security/privacy/moderation cases, and 13-month aggregate analytics retention. These are planned limits, not a claim that all cleanup procedures are already operating. Until implementation is verified, records can remain beyond these planned periods. Missed reviews or overdue candidates will be flagged for review rather than triggering automatic destructive runs. Narrow incident, dispute or legal holds must have a documented reason and review date.
The managed database currently has a seven-day automatic point-in-time recovery window. Other snapshots, dumps or exports may have different retention; the seven-day window is not an expiry promise for every copy. Information in isolated backups may remain until the applicable backup cycle expires. Removing a source publication does not remove independent copies owned by other users or copies retained outside Outset. Account deletion and unpublishing are distinct from withdrawing already delivered optional analytics events.
7. Your choices and requests
You can manage optional email, rotate recovery codes, export your account information, request account deletion, manage trip collaborators and disable public links using the available controls. Email is currently unverified and is not an account-recovery method.
Contact the privacy address for questions or requests concerning your information. We may need to verify your authority before acting, without asking you to email passwords or recovery codes. Depending on applicable law, you may have additional rights; we will assess requests under the requirements that apply.
Use support@iodine.studio for privacy requests. We verify authority before disclosing or deleting account information; an email address alone does not prove ownership. We assess applicable rights and response deadlines for each request. Ordinary support availability does not change deadlines that apply by law.
8. Children
Outset Travel is intended for adults 18 and older. We do not knowingly invite children to create accounts or submit personal information. If you believe a child has provided information, contact us so we can assess and take appropriate action.
When we learn that a child has submitted information, we will restrict access as appropriate, review the information and take steps to remove it, subject to applicable requirements.
9. Security and changes
We use access controls and other safeguards intended to protect information. No online service can promise absolute security. Keep your account and recovery material secure and contact support if you suspect unauthorized access.
We will update this policy as practices change, show the effective date and provide a conspicuous notice of material changes through the service. When a change requires a new choice or consent, we will request it.
For questions, contact support@iodine.studio.