Vaeli
Privacy policy
How Vaeli handles your data: what it collects, why, who it goes to and how to stop it. Last updated: 26.08.2026.
1. What this document is
Vaeli is a city-trip planner. This document sets out what data the service collects about you, why, who it goes to, and what you can do about it.
For anything about your data, write to:
- Service
- Vaeli
- Website
- https://vaeli.app
- Email for inquiries
- info@vaeli.app
The service is aimed at users in Europe, so it is written to the General Data Protection Regulation (GDPR, EU Regulation 2016/679), and with the Law of Georgia on Personal Data Protection No. 3144-XIმს in mind.
2. What data is processed
Data you enter yourself:
- the name shown in the interface;
- your email address, which is also your login;
- your password — stored only as a hash, which the password cannot be recovered from;
- trips: cities, dates, pace, chosen places, the order of the route;
- trip parameters: interests, budget level, travel party and, if you give them, children's ages;
- the text of your prompt, if you ask for a route in your own words;
- trip ratings and reviews, if you leave them.
Data that appears on its own:
- IP address, browser and device type, time of access;
- events inside the service — creating a trip, generating a route, errors — so we can see what breaks and what gets used;
- cookies and browser local storage, see section 8.
The service does not collect special category data — health, faith, political views, origin, sex life. Do not put it in text prompts either: free text goes to the language-model provider.
The service takes no payments yet, so no payment data exists.
3. Why, and on what legal basis
The GDPR requires a basis for every processing operation. There are four here.
Performance of a contract (Art. 6(1)(b)) — what the service is: registration and sign-in, storing and showing your trips, building routes, generating a route, the public link to a trip, answering what you write to us.
Legitimate interests (Art. 6(1)(f)) — security and keeping the thing running: protection against password guessing and automated abuse, rate limiting, error diagnosis, anonymous usage statistics. The interest is that the service stays up and unbreached, and the effect on your rights is minimal.
Consent (Art. 6(1)(a)) — only for the optional part: third-party partner scripts about flights and stays. You can withdraw it at any time; the "Cookie settings" link is in the footer of every page.
Legal obligation (Art. 6(1)(c)) — if data has to be kept or handed over under a binding requirement.
4. Who the data goes to
The service does not sell your data and does not pass it on for somebody else's advertising. For individual features to work, outside services get the minimum they need:
- OpenStreetMap mapping and geocoding services (Nominatim, Overpass) and MapTiler — place names and city coordinates;
- the OSRM routing service — coordinates of the points on a route;
- the Open-Meteo weather service — city coordinates and trip dates;
- the OpenRouter language-model provider (USA) — city, dates, pace, interests, budget and travel party; for generation from a text prompt, the prompt itself;
- Wikidata and Wikipedia — place identifiers and names, to show a photo and a summary;
- the Have I Been Pwned password check — the first five characters of the password's SHA-1 hash; neither the password nor its full hash is sent;
- partner travel and booking services — only when you follow a link; the service does not learn what you bought there.
Accounts, trips and everything else the service holds are stored on servers in Frankfurt, Germany (European Union). Some of the providers listed above operate outside the European Economic Area; they receive only what the specific feature needs — the language-model provider, for instance, is sent the city, dates, pace and chosen interests, but not your name, email address or account identifier.
5. How long data is kept
The account and its contents: as long as the account exists. You delete it yourself, in settings, and trips, places, routes, reviews, reactions and every active session go with it.
Sessions: the access token lives about 30 minutes, the refresh token 30 days. Both are revoked on logout and on a password change.
Events inside the service are not deleted when an account is, but they are detached from you: the reference to the user is cleared, leaving an anonymous line to the effect of "a route through Rome was generated on this day".
Server logs are short-lived and are overwritten as new ones arrive.
6. Your rights
Under the GDPR you can:
- find out what data about you exists and get a copy (Art. 15);
- correct anything inaccurate — name and email are editable in settings (Art. 16);
- have data erased (Art. 17): the "Delete account and all data" button in settings works immediately, with no correspondence;
- restrict processing (Art. 18);
- receive your data in a machine-readable form (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent for the optional part — "Cookie settings" in the footer (Art. 7(3)); this does not affect processing that already happened.
Anything without a button is done by writing to info@vaeli.app. We answer within a month, as Art. 12(3) requires.
If our answer does not satisfy you, you may complain to a supervisory authority (Art. 77) — in your country of residence in the EU or EEA, or to the Personal Data Protection Service of Georgia.
7. Children
The service is not meant for children under 16 and accounts are not created for them. Children's ages in the trip parameters are information about your travel party, given by you as an adult user, and are used only to pick suitable places.
8. Cookies and local storage
Necessary cookies are set without asking: sign-in and request protection do not work without them. Optional third-party scripts are not loaded until you agree to them.
- access_token
- Keeps you signed in between requests. Not readable by JavaScript. About 30 minutes.
- refresh_token
- Extends the session so you are not signed out every half hour. Not readable by JavaScript. 30 days.
- csrf_token
- Request-forgery protection: the page reads the value and echoes it back in a header. 30 days.
- vaeli_consent
- Your answer to the cookie question, so you are not asked again. 180 days.
- Local storage
- Your trip list is cached in the browser so the page opens without waiting. It never leaves the device.
You can change your cookie answer at any time through the "Cookie settings" link in the footer. Necessary cookies can be blocked in your browser, but then signing in stops working.
9. How the data is protected
The connection is encrypted (HTTPS). Passwords are stored as salted hashes. Session tokens are not readable by JavaScript, state-changing requests are protected against forgery, and sign-in attempts are rate-limited. The database is closed to the outside network.
That lowers the risk without removing it. Do not reuse your Vaeli password on other sites.
10. Changes
This document will change as the service does. The current version is always at https://vaeli.app/privacy. Material changes do not apply retroactively: what already happened is judged by the version in force at the time.
Last updated: 26.08.2026