Privacy Policy
Waypad (“we”, “us”) helps you plan and use travel itineraries. This page explains what data we store when you use the Waypad website, API, MCP connectors, or ChatGPT Custom GPT Actions that call Waypad.
Who this covers
- People using the Waypad web app
- Agents and tools that call the Waypad API or MCP endpoint
- People using a Waypad ChatGPT GPT that accesses trip data through Actions
Information we store
- Trip content you provide: titles, dates, notes, places, itinerary cards, checklists, change-log entries, and related metadata.
- Account / auth data (when signed in): email for magic-link login, OAuth tokens for connectors, and invite metadata for shared trips.
- Technical logs: standard request logs needed to operate and debug the service (timestamps, paths, error codes). We do not sell this data.
Location
If you allow it, Waypad uses your device location for one purpose: to rank place search results near where you are standing. The coordinates are sent with that single search request and are not stored, not attached to your account, and not used for anything else. Declining is fine — search then ranks results near the places already in your trip.
How we use it
- To show and sync your itinerary across devices and share links
- To power agent tools (MCP / GPT Actions) that read or edit trips you authorize
- To improve reliability, security, and trip-planning features
Sharing
We do not sell personal data. Trip content may be visible to people or agents you share a trip with, or that you authorize through connectors. Third-party services used to operate Waypad (for example Cloudflare hosting, optional Google Maps lookups, and OpenAI when you chat through ChatGPT) process data under their own policies for those services.
ChatGPT conversations and tokens are billed and processed by OpenAI according to OpenAI’s terms. Waypad hosts trip data the GPT Actions call; OpenAI hosts the chat.
Retention
Trip and account data remain until you delete them or ask us to remove them, unless we must keep limited records for security or legal reasons.
Your choices
- Edit or delete trip content in the Waypad app
- Revoke connector / OAuth access and shared invite links
- Email us to request account or trip deletion
Contact
Questions or deletion requests: support@xeo.com
We may update this policy as Waypad changes; the “Last updated” date above will change when we do.