wendily

Legal

Privacy Policy

Last updated September 11, 2026

Wendily is where trip itineraries live. You talk to an AI agent you already use, and that agent writes the itinerary into Wendily over our API. This policy explains what information Wendily collects when you do that, how it is used, who else can see it, and the choices you have.

Wendily is operated by the Wendily team (“we”, “us”). If anything here is unclear, write to team@wendily.com.

What we collect

Account information

You sign in with your email address and a magic link. We store your email address and a profile record. We do not store passwords.

Trips and itineraries

Trips, days, and itinerary items are written to your account, usually by an AI agent acting on your instructions and sometimes by you. That content can include destinations, dates, places, addresses, notes, booking references, links, and image URLs. We store what your agent sends and show it back to you and to the people you share the trip with.

Booking references and private links are shown to you and to your trip’s collaborators only. They are never made public.

Agent connections

To connect an agent you create a connection in the app, which comes with a private key the agent uses to act for you. We store a cryptographic hash of that key and a short prefix so you can recognise it, plus the name you gave the connection, when it was created, when it was last used, and whether it has been disconnected. We do not store the key itself and cannot recover it for you.

Sharing and invitations

When you invite someone to a trip we store their email address, the role you gave them, and whether they have accepted. We send them an email with a link to the trip.

Travel progress

If you mark itinerary stops as visited, that record is private to you. Collaborators on the same trip see only their own progress.

Technical information

Our hosting providers keep standard server logs, such as IP address, browser type, and the time of each request, for security and reliability. We do not run advertising trackers or sell analytics data.

How we use it

We do not sell your information and we do not use your itineraries to train AI models.

Your AI agent is not us

The conversation you have with your agent happens in that agent’s product, under its own privacy policy. Wendily receives only what the agent sends to our API. We have no access to the rest of your conversation, and we cannot control what the agent’s provider keeps.

Who else sees your information

We rely on a small number of service providers for hosting, data storage, authentication, and email delivery. Each processes information only as needed to provide its service to us and is bound by confidentiality and data-protection obligations. Images on your itinerary are loaded directly from the URLs your agent supplied, so those sites will see a request from your browser when you view a trip.

People you share with see the trip you shared, including its days, items, booking references, and the email addresses of the trip’s owner and other active collaborators. Pending invitations are visible to the owner only.

We may disclose information if required by law, or to protect the rights, safety, or property of Wendily, our users, or others.

How long we keep it

Your trips stay in your account until you archive or delete them. Archived trips remain readable to you and your collaborators until restored. Revoked agent tokens are kept as a record but can no longer be used. If you ask us to delete your account we delete your trips, tokens, and profile; copies in backups expire within 30 days.

Your choices

Depending on where you live you may have additional rights, such as access, correction, portability, and objection. We honour those requests for everyone regardless of location.

Security

Data is encrypted in transit. Connection keys are hashed at rest. Access to your trips is enforced both in our API and in the database itself, so a collaborator can only ever see the trips they were granted. No system is perfectly secure, so if you believe your token or account has been compromised, revoke the token and tell us.

Children

Wendily is not directed at children under 16 and we do not knowingly collect their information.

Changes

If we change this policy in a meaningful way we will update the date at the top and, for significant changes, tell you by email or in the app.

Contact

Questions and requests: team@wendily.com.