Legal
Privacy Policy
Last updated September 11, 2026
Wendily is where trip itineraries live. You talk to an AI agent you already use, and that agent writes the itinerary into Wendily over our API. This policy explains what information Wendily collects when you do that, how it is used, who else can see it, and the choices you have.
Wendily is operated by the Wendily team (“we”, “us”). If anything here is unclear, write to team@wendily.com.
What we collect
Account information
You sign in with your email address and a magic link. We store your email address and a profile record. We do not store passwords.
Trips and itineraries
Trips, days, and itinerary items are written to your account, usually by an AI agent acting on your instructions and sometimes by you. That content can include destinations, dates, places, addresses, notes, booking references, links, and image URLs. We store what your agent sends and show it back to you and to the people you share the trip with.
Booking references and private links are shown to you and to your trip’s collaborators only. They are never made public.
Agent connections
To connect an agent you create a connection in the app, which comes with a private key the agent uses to act for you. We store a cryptographic hash of that key and a short prefix so you can recognise it, plus the name you gave the connection, when it was created, when it was last used, and whether it has been disconnected. We do not store the key itself and cannot recover it for you.
Sharing and invitations
When you invite someone to a trip we store their email address, the role you gave them, and whether they have accepted. We send them an email with a link to the trip.
Travel progress
If you mark itinerary stops as visited, that record is private to you. Collaborators on the same trip see only their own progress.
Technical information
Our hosting providers keep standard server logs, such as IP address, browser type, and the time of each request, for security and reliability. We do not run advertising trackers or sell analytics data.
How we use it
- To provide the service: store your itineraries and show them to you and your collaborators.
- To let your agent write on your behalf, scoped to your account by your token.
- To send the emails the service needs: sign-in links and trip invitations.
- To keep the service secure, prevent abuse, and debug problems.
- To respond when you contact us.
We do not sell your information and we do not use your itineraries to train AI models.
Your AI agent is not us
The conversation you have with your agent happens in that agent’s product, under its own privacy policy. Wendily receives only what the agent sends to our API. We have no access to the rest of your conversation, and we cannot control what the agent’s provider keeps.
Who else sees your information
We rely on a small number of service providers for hosting, data storage, authentication, and email delivery. Each processes information only as needed to provide its service to us and is bound by confidentiality and data-protection obligations. Images on your itinerary are loaded directly from the URLs your agent supplied, so those sites will see a request from your browser when you view a trip.
People you share with see the trip you shared, including its days, items, booking references, and the email addresses of the trip’s owner and other active collaborators. Pending invitations are visible to the owner only.
We may disclose information if required by law, or to protect the rights, safety, or property of Wendily, our users, or others.
How long we keep it
Your trips stay in your account until you archive or delete them. Archived trips remain readable to you and your collaborators until restored. Revoked agent tokens are kept as a record but can no longer be used. If you ask us to delete your account we delete your trips, tokens, and profile; copies in backups expire within 30 days.
Your choices
- You can revoke any agent token at any time from the app; it stops working immediately.
- You can remove a collaborator or cancel an invitation from the trip’s sharing dialog.
- You can archive a trip so it can no longer be changed.
- You can ask us to export or delete your information by writing to team@wendily.com.
Depending on where you live you may have additional rights, such as access, correction, portability, and objection. We honour those requests for everyone regardless of location.
Security
Data is encrypted in transit. Connection keys are hashed at rest. Access to your trips is enforced both in our API and in the database itself, so a collaborator can only ever see the trips they were granted. No system is perfectly secure, so if you believe your token or account has been compromised, revoke the token and tell us.
Children
Wendily is not directed at children under 16 and we do not knowingly collect their information.
Changes
If we change this policy in a meaningful way we will update the date at the top and, for significant changes, tell you by email or in the app.
Contact
Questions and requests: team@wendily.com.