Draft. This text has not yet been reviewed by a lawyer and may change before it takes effect.
Privacy Policy
What we collect, why we collect it, who helps us process it, how long we keep it, and what you can ask of us.
Draft of 5 October 2026. Not yet in effect.
Who is responsible
Farheimr B.V. i.o., the company described in our terms, is the controller of your personal data. Until the company has been incorporated and has ratified what was done in its name, its founder, Alexandre Moreau-Lemay, is personally responsible for it. Questions and requests about your data go to privacy@farheimr.com, or by post to the address in the terms.
We have not appointed a data protection officer, because our core activities do not require one under Article 37 of the GDPR; our founder answers privacy requests himself.
We never sell your data, we show no advertising, and we use no tracking or analytics cookies.
What we collect and why
Your account
Your name, email address, password (stored only as a one-way hash) and passkeys, so that you can sign in and we can send you the messages the service needs, such as password-reset links and Mailbox notices. A name and an email address are needed to create an account; without them we cannot provide the service. Everything else you add is up to you. Legal basis: performing our agreement with you.
Your trips
Everything you put into a trip: days, places, bookings, notes, polls, payments, documents, and who you share it with. We store it so that the service can show it to you and to the people you share it with. No person at Farheimr reads it, except when you ask us to help, when we must act on a report or a legal order, or when we have to fix a fault. Legal basis: performing our agreement with you.
When you invite someone to a trip, we store their email address to send the invitation. When someone votes in a poll through a share link, we store the vote and a cookie that remembers it.
When a trip is created, a description of its destination is sent to an image-generation model to make its cover picture. That description does not include your name or anything else about you.
Mail to your Mailbox
When mail arrives at a Mailbox address, we store the message and read it automatically to find the booking in it. We record what was read, which travel company sent it, and whether its signatures checked out. The text of the message and of its kept attachments, never its images, is read by two models: a classifier that sorts mail and spots messages that are not what they claim to be, and a language model that pulls out the booking details. That includes any login codes or password-reset links in the message. Legal basis: performing our agreement with you.
A PDF copy of each message, and the tickets and receipts in it, are saved into the trip as documents. Mail to a trip's own Mailbox can be read by the trip's owners and editors, and by the viewers the trip allows to.
We also keep, for each booking read, what you did with it (accepted, corrected or dismissed), with the reader's scores and the travel company, but without the email or anything else about you. That is how Farheimr learns which travel companies it can trust. Legal basis: our legitimate interest in reading mail accurately.
Helping improve mail reading (optional)
If you turn on "Keep scrubbed copies of my mail to improve reading" in your Mailbox, we keep a copy of mail sent to your own Mailbox (not a trip's) after it has been read: its subject, sender address and text, with names, addresses, booking codes and other personal details replaced by stand-ins, together with the bookings as you accepted them, scrubbed the same way. We use these copies to test and improve the reader. Only our founder can see them. A copy used in a test run is deleted from that run within 30 days. Legal basis: your consent.
The copies are kept until you turn the setting off or close your account. Turning it off deletes every copy at once, and you can do so at any time.
Mail to our team
When you write to one of the addresses on our contact page, we keep your message and our answers so that we can deal with your request and show that we did.
- Keeping and answering a report under the Digital Services Act or a privacy request is something the law requires of us. Legal basis: legal obligation.
- An automated classifier and a language model read the text to sort it and to prepare a draft answer; a person reads every message and writes or approves every answer. Images in such mail are checked only by a classifier running on our own servers and are never sent to an outside model. Legal basis: our legitimate interest in handling mail quickly and safely. You can object to it.
- Other mail is kept so that we can answer it. Legal basis: our legitimate interest in answering you.
A report can name the person it is about. We use that only to deal with the report.
Security and abuse prevention
Technical records of requests to our servers, such as IP addresses and times, and the IP address and browser of each signed-in session, to keep the service secure and to investigate abuse. Legal basis: our legitimate interest in keeping the service and its users safe.
Cookies
We set only the cookies the service needs to work:
- Sign-in cookies, which keep you signed in for up to seven days, including a short-lived one used while you sign in or register with a passkey.
- A ballot cookie, which remembers your vote when you vote in a poll through a trip's share link.
The app also keeps a few interface preferences in your browser's local storage, such as which map app to open and which hints you have dismissed. They never leave your device. None of these is used for tracking, and none needs your consent.
If you are named in mail or a trip someone else keeps
Farheimr holds data about people who have no account with us: fellow travellers named on a booking forwarded to a Mailbox, people invited to a trip, and people named in a report to our team. It reaches us from a Farheimr user, or from a travel company writing to that user's Mailbox address. It is typically a name, contact details, booking references, and seat or ticket details.
We use it only to put the booking into the user's trip, to send an invitation, or to deal with the report, and we keep it only as long as the table below says. Legal basis: the user's legitimate interest in organising their trip, and ours in providing the service. We cannot tell each such person individually, so this section is how we inform you. You have the same rights as anyone else, including the right to object, described under Your rights.
Automated decisions
The models that read mail can hold a message for you to look at, or set it aside as spam. Farheimr may add a new booking without asking when it comes from a travel company it has learned to trust and was read with high confidence; you are told, and can undo it. When a reading is uncertain, comes from a sender Farheimr cannot verify, or would change a booking you already have, Farheimr asks you first. None of this has a legal effect on you, and you can ask a person to look at any of it.
No model can suspend your account, remove your content or answer a report on its own; a person does that.
Who processes your data for us
We use the following processors.
| Processor | What it does for us | Where |
|---|---|---|
| Scaleway SAS | Hosting, database, file storage, backups, our mail servers, and the emails we send | France, with backups in another EU region |
| OpenRouter, Inc. | Passes the text of mail, and trip destinations for cover pictures, to the model providers below, which work for it as its sub-processors | United States |
| OpenAI | The language model that reads mail text and drafts answers to mail sent to our team, reached through OpenRouter | United States |
| TypeSafe | The classifier that sorts mail and checks it for deception, reached through OpenRouter | [TODO for the owner: location] |
| The image-generation model provider reached through OpenRouter | Makes trip cover pictures from a description of the destination | [TODO for the owner: provider and location] |
For each processor outside the European Economic Area, the transfer rests on [TODO for counsel: EU-U.S. Data Privacy Framework certification of the named entity, or standard contractual clauses]. You can ask for a copy of the safeguards at privacy@farheimr.com.
[TODO for counsel and the owner, before this page takes effect: confirm the contractual chain (that OpenRouter is our processor and the model providers its sub-processors), that a data processing agreement covers each, that none may use the data for its own purposes, and how long each provider keeps request content. State any retention here.]
Other services we use
These services are not our processors. They receive only what is needed to answer a lookup.
| Service | What it receives | Where |
|---|---|---|
| Photon, run by komoot | Place and address searches you type, from our servers and from your browser | Germany |
| The public OSRM routing server | The coordinates of places in a trip, to draw routes between them | [TODO for the owner: operator and location] |
| AeroDataBox, through RapidAPI | Flight numbers and dates, to look up flight times | [TODO for the owner: location] |
| adsbdb | Flight numbers, to look up a flight's route | [TODO for the owner: location] |
AI assistants you connect. If you connect an AI assistant to Farheimr, it receives what you let it read, including documents, under its own provider's privacy policy. You can disconnect it at any time.
Services your browser contacts directly
Some features load data straight into your browser from another service, which then sees your IP address: map tiles from OpenStreetMap, exchange rates from Frankfurter, airline logos from Kiwi.com, and the fonts of the app and this website from Google Fonts, in the United States. [TODO for the owner: self-host the fonts and the airline logos, and remove them from this list.]
When we access or disclose your data
Only our founder, who is at present the whole team, can access personal data at Farheimr, and only when needed: to help you when you ask, to fix a fault, to investigate abuse, or to act on a report or a legal order. We disclose personal data to authorities only when the law requires it: for example a valid order from a Dutch court, or when we must inform the police of a suspected criminal offence that threatens someone's life or safety (Article 18 of the Digital Services Act). Unless the law forbids it, we tell you when we have had to disclose your data.
How long we keep it
| What | How long |
|---|---|
| Your account and your trips | Until you close your account. Deleted within one month of your request. |
| Documents saved into a trip from mail, including the PDF copy of each email | With the trip, until you delete them or the trip. |
| Mail in a Mailbox | 30 days after the later of the end of its trip and its arrival, and never more than a year after it arrived; 30 days if it belongs to no trip. |
| Mail holding a booking not yet in a trip | Up to one year, so that it can join a trip you create later. |
| Anything else read from mail | Nothing from a message is kept beyond one year, except what was saved into a trip and the optional copies described above. |
| What you did with each reading, without the email or anything about you | [TODO for the owner: state the period, or the rule that ends it.] |
| Optional scrubbed copies of mail | Until you turn the setting off or close your account. |
| A Mailbox address that was switched off | The address alone, without any mail, for good, so that it is never given to anyone else. The list of travel companies that sent account mail to it is deleted with your account or its trip. |
| Invitations to a trip | [TODO for the owner: confirm the period after an invitation is accepted or expires.] |
| Poll votes through a share link | With the trip, until it or the poll is deleted. |
| Reports of illegal content or abuse, and privacy requests | Two years after we have closed them. |
| Other mail to our team | One year after we have closed it. |
| Spam to our team | 30 days. |
| Database backups | 14 days. Data you delete disappears from backups within that time. |
| Signed-in sessions, with their IP address and browser | Until the session ends, at most seven days after it was last used. [TODO for the owner: confirm expired sessions are deleted.] |
| Security records of requests to our servers | [TODO for the owner: confirm the period for each log source.] |
Where the law requires us to keep something longer, for example as evidence for the police, we keep that item for as long as required and no longer.
Your rights
You can ask us for a copy of your personal data, to correct it, to delete it, to restrict how we use it, or to receive it in a machine-readable form. Where we rely on your consent, you can withdraw it at any time. Write to privacy@farheimr.com.
You can object to any processing we base on our legitimate interests, including the automated reading of mail to our team, and we then stop unless we have compelling grounds to continue.
We answer within one month. If a request is complex, we may take up to two more months, and we tell you within the first month if we do. Before we share or delete anything, we confirm that the request comes from you: if you have an account, by a link sent to its email address; if you have none, or can no longer reach that address, we ask only for what we need to match the request to the data we hold.
If you are unhappy with how we handle your data, you can complain to the Autoriteit Persoonsgegevens, the Dutch Data Protection Authority, or to the authority in the EU country where you live. We would be glad to hear from you first.
How we protect it
Everything is encrypted in transit. Mail is stored in a private bucket that nothing serves to the internet, attachments are cleaned before they are kept, and mail is shown through a renderer that cannot load anything from outside. Every action by our team on a report or a privacy request is recorded.
Changes
When we change this policy, we tell you at least 30 days before the change takes effect, by email or in the app. A change that only works in your favour can take effect straight away.
This policy is adapted from the Basecamp open-source policies, licensed under CC BY 4.0. We have rewritten it for Farheimr, the GDPR and Dutch law; Basecamp does not endorse it.