Privacy Policy
This policy explains what personal data Ereno ("we", "us") collects, why, how we protect it, and the rights you have. We aim to collect as little as possible and to be clear about the rest.
Who is responsible for your data
Ereno is the data controller for the personal data described here. For any privacy question or request, contact [email protected].
What we collect
- Account data if you sign in: your email and authentication identifiers, handled by our authentication provider.
- Account deletion suppression record: after account deletion, we keep a deterministic one-way digest of your Clerk authentication identifier. We do not keep the original identifier in this record and never expose the digest. It exists only to stop a still-valid session from recreating the erased account.
- Billing data if you subscribe to a paid plan: your plan, subscription status, and payment method, handled by our billing providers. We never see or store your full card details.
- Your questions and conversations with Ereno, so we can answer them and show your history.
- Usage and device data: basic, privacy-respecting analytics about which pages and features are used, to improve the product. If you sign in, we compute a one-way pseudonym from your account identifier and a private salt to link your usage across visits, together with your plan tier; we never send your name, email, or message content to our analytics provider. You can turn this off at any time from your profile.
- Price watch data: the public offer URL you choose, route or property, travel dates, party and room counts, currency, exact offer identity, and observed prices. We use this only to check the same public offer for a material price change.
We do not knowingly collect data from children, and the service is intended for adults.
Why we use it, and our legal basis
- To provide the service (answer your questions, keep your history). Legal basis: performance of a contract.
- To bill paid plans (process subscriptions, invoices, and refunds). Legal basis: performance of a contract.
- To improve and secure the product through analytics and abuse prevention. Legal basis: our legitimate interests, balanced against your rights.
- To honour and enforce account deletion by preventing a deleted Clerk subject from recreating data with an older session. Legal basis: our legitimate interests in service security and respecting erasure requests, balanced against your rights.
- To monitor a price at your request by checking the exact public offer you selected and notifying you of a verified material change. Legal basis: performance of a contract.
Who we share it with
We do not sell your personal data. We share it only with processors that help us run the service:
- Authentication and billing (Clerk, with Stripe as the payment processor) to sign you in securely and manage paid subscriptions.
- Data storage (Convex) to store your account, plan usage, and conversations.
- Product analytics (PostHog) to understand usage. Signed-in usage is linked only by a one-way pseudonym, never your name or email; guest usage is fully anonymous. Analytics storage is only set after you accept on the cookie banner. Signed in, you can change this later from your profile.
- Answer-generation services (such as OpenRouter and the services it connects to) to generate answers from the questions you send.
- Public web retrieval (Firecrawl) to revisit the exact public flight or stay offer you ask us to monitor. Firecrawl receives the public offer URL and offer details listed above, but not your name, email address, Clerk identifier, or chat text. Every request enables Firecrawl zero data retention.
Some providers may process data outside your country. Where that happens, we rely on appropriate safeguards such as Standard Contractual Clauses.
How long we keep it
Account data and conversations are kept while your account is active, and billing records as long as tax and accounting law requires. Because a travel date does not include a timezone, a price watch and its alerts are automatically deleted during the first daily cleanup after that date has ended in every worldwide timezone, or earlier when you remove the watch or delete your account. We keep at most the 100 most recent price alerts per account. Firecrawl is instructed to retain none of the request or response. Earlier waitlist signups are kept only to honour founder pricing, or until you ask us to delete them. The account deletion suppression record is kept permanently for the lifetime of the service because removing it would let an older Clerk session recreate the erased account. Delete your account or email us and we will remove your data, except for this minimal suppression record and anything the law requires us to keep.
Your rights under the GDPR
If you are in the EU/EEA or the UK, you have the right to:
- Access the personal data we hold about you.
- Correct data that is wrong or incomplete.
- Erase your data ("right to be forgotten").
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting prior processing.
- Lodge a complaint with your local data protection authority.
The account deletion suppression record is not included in the self-service export because it is created only after deletion, when account access and export are disabled. Export your account data before deletion. You may still ask us about this record or exercise your other rights by emailing [email protected]. You can unsubscribe from our emails using the link in any message.
Cookies and analytics
We keep tracking light. We do not use advertising cookies. Non-essential analytics only starts after you accept on the cookie banner (or turn analytics on in your profile). Rejecting keeps analytics off. If you sign in, we link your usage to a one-way pseudonym derived from your account identifier and a private salt, together with your plan tier, so we can understand usage by plan without knowing who you are; guest usage is never linked to any identifier. Legal basis for analytics after you accept: consent. Signed in, you can change this later from your profile, and deleting your account also removes the analytics record tied to your pseudonym.
Security
We use reputable providers and sensible safeguards to protect your data. No method is perfectly secure, but we work to keep your information safe and to limit what we collect in the first place.
Changes
We may update this policy as the product grows. We will change the date above and, for material changes, let you know by email or in the app.
Questions? Email [email protected].