← Back to One Week In New York

What we hold, and why

Privacy

This is a trip planner. It needs an email address to sign you in, and the details of your trip to plan it. That is very close to everything it holds, and this page is the whole account of it — written against what the software actually does, not against a template.

1

Who this is

One Week In operates this service, and is the controller of the data described here. Where this page says we or us, that is who it means.

Who operates this service, and the address for correspondence

Privacy questions, and any request about your own data: privacy@oneweekinnewyork.com. Anything else: hello@oneweekinnewyork.com.

If we handle your data badly, you can complain to us first and to the Information Commissioner's Office — the UK data protection regulator — after that.

2

What we hold, and why

Six things, and nothing else. Each one is here because the product stops working without it.

Your email address
Signing you in — we send a link and never store a password — plus receipts and messages about your own trip. Basis: performing our contract with you.
Your trip
Dates, where you are staying each night, the display names, age bands, pace, tastes and notes you give the people you are traveling with, and the plan itself. This is the product: an itinerary cannot be drawn around your people without it. Basis: contract.
Your conversation with the guide
Kept so you can read your own history back, and so the guide remembers your trip between visits instead of asking you everything twice. Basis: contract.
Purchases
What was bought, when, the amount, and the payment processor's reference. Basis: contract, and the tax law that sets how long the record has to survive.
Server and network logs
Our server and the network in front of it record connection metadata, including IP address, to keep the service up and to stop the free preview being abused. Basis: our legitimate interest in a service that stays available and is not drained by bots.
Your account activity
While you are signed in we keep a short record of what your account did: which action, whether it worked, and our own error code when it did not. It exists so that if you write in for help, we can see what actually happened instead of asking you to reconstruct it. It holds no message text, no addresses and no search terms, and your email address is not copied into it. Deleted after 90 days. Basis: our legitimate interest in being able to answer you when something goes wrong.

For account activity, we may also keep one coarse label for which optional planning details you supplied — accommodation, ages or interests, or a combination — never those details themselves. Deleted after 90 days. Basis: our legitimate interest in improving the service and answering you when something goes wrong.

3

What we do not do

No advertising scripts, no third-party analytics, no trackers, no pixels, no session recording, no cross-site profiling, no data broker, and nothing sold or shared for marketing — ever. We do count visits ourselves, on our own server: your IP address and browser identification string are turned into a one-way key using a secret that is thrown away every midnight, neither raw value is stored, and so yesterday's visits cannot be matched to today's. Before the browser string is discarded, it is reduced to one coarse class: mobile, tablet, desktop, unknown, or an automated request. If a landing address carries standard UTM campaign labels, we accept only source, medium, campaign, term and content, normalize each to a short campaign token, and keep them on the anonymous event and daily totals. We do not collect click-identifier values or other query-parameter values. If an unknown key makes a plan link fail closed, one server diagnostic may retain up to three short lowercase token-shaped key names; unsafe names become only an unnamed count. No query values or full query string are logged. Campaign labels follow only the current server request and explicit next link: there is no first-touch profile and nothing is stored on your device. Nothing is sent anywhere else, and nothing in this counting identifies you. If that ever changes, it changes here first — and anything non-essential would ask your consent before it ran.

For the anonymous planner, we may also reduce the trip length, party size, party age composition, number of chosen sights and published route language to coarse bands on our server, then discard the choices themselves. These bands tell us which starting plans are useful; they are not a profile of you.

  • We never ask for anyone's real name. The people in your party are whatever you choose to call them; first names or nicknames are exactly enough.
  • We do not ask for your home address, your date of birth, your documents, or your card details.
  • We build no profile of you beyond the trip you are planning, and make no automated decision about you with a legal or similarly significant effect.
  • We send no marketing email. Every message we send is either your sign-in link or something about your own trip.
4

Cookies, and what stays in your browser

The sign-in cookie keeps you signed in after you follow a sign-in link. It is strictly necessary for the service you asked for. It lasts up to 90 days and renews while you keep using the service.

If you choose a language or dismiss a language suggestion, a second strictly necessary cookie remembers only the canonical locale or that dismissal for up to one year. We write it only after your explicit action, never from browser detection, and never use it for analytics, marketing, or tracking.

One other thing is stored on your device and never reaches us: whether you chose the light or dark theme, kept in your browser's local storage. Clearing your browser data removes it.

There are no other cookies. None for advertising, none belonging to anyone else, and none for our own counting. Both cookies above are strictly necessary, so there is no consent banner to dismiss.

5

Sharing an itinerary

The free, anonymous itinerary can be shared by copying its current web address. That address contains the trip dates, coarse party counts and the checked sights you chose — no names, email or accommodation — and anyone holding it can rebuild a read-only plan from those choices using the checked guide data then current. It stays in browser history and cannot be revoked, so share it only with people you mean to. A signed-in paid itinerary uses a different, revocable read-only link.

A shared link shows the plan, not where you sleep. The name of each place you are staying travels with it, because a day has to start and end somewhere, but the street address does not — on the page or on the map. The full address stays on your own signed-in copy.

A paid-trip share link can be stopped whenever you like from the trip itself, and it stops working immediately for everyone who has it. Making a new paid link also stops the old one. The anonymous preview address is ordinary browser history, not a revocable credential; changing the choices creates a different address but does not disable an address already shared.

We do not store an anonymous preview or its address: the server validates the choices in the address and rebuilds the plan from the pinned guide data. For a paid share, we store only a one-way fingerprint of the link — enough to recognize it, not reconstruct it — with its creation time and, at most once an hour, that it was opened. We do not record who opened either kind of link.

6

The guide is an AI system

The guide you talk to is an AI system, and it tells you so the first time you meet it in any conversation. It runs on a model operated by OpenAI, which processes your messages on our instructions under a data processing agreement.

What reaches the model is your messages and the trip details needed to answer them — dates, who is traveling, pace, tastes, the plan so far, and the label and timing of where you are staying. What does not reach it is your email address, or the street address or coordinates of your accommodation.

Venue facts come from our own verified database rather than the model's memory, and we do not permit providers to train on your data.

7

Travel times and routing

Walking and transit estimates are computed from data we already hold, so no third party sees where you are going. Every travel estimate tells you whether it was measured or assumed.

When you save an accommodation address, its address text — and no account, trip or traveler identifier — is sent once to NYC Planning GeoSearch to find its map point. Low-confidence and ambiguous answers are discarded. The address and accepted point remain private trip data and are never sent to the guide's model.

No live routing provider receives any trip data. One will be named here before live routing is ever switched on.

8

Payments

This section applies whenever one of our pages shows a price, whether or not you go on to buy paid itinerary planning.

Checkout is handled by Paddle as merchant of record: you buy from Paddle, your card details go to Paddle, and they never pass through us. Paddle's own privacy notice covers the payment itself.

To show a localized price on the home page, pricing page, checkout page, and initial itinerary page, our server sends your IP address to Paddle. Paddle uses it to work out your country, currency, and the right tax treatment. This can happen when one of those pages is rendered, before you buy anything and whether or not you ever make a purchase. We do not store the IP address for pricing; Paddle's privacy notice explains what Paddle does with it.

We hold the order record — what was bought, when, the amount, and Paddle's transaction reference — because we need it to give you what you bought, to handle refunds, and to keep the accounts tax law requires.

9

How long we keep it

Free preview conversations
Expire 30 days after they start and are deleted. The expiry is stamped on the conversation at the moment it is created.
Paid trip conversations
If you archive the trip, or it is automatically archived when paid access expires 12 months after purchase, that archival starts a 90-day period; then the conversation and the guide's trip memory are deleted. Your itinerary stays with your account until you delete it or the account.
Trips without paid planning
The trip is automatically archived 12 months after it was created. Its free preview conversation is still deleted on the 30-day schedule above.
Account and sign-in records
Kept while your account exists. A sign-in link expires 15 minutes after we send it; a signed-in session expires after at most 90 days.
Order records
Kept as long as tax law requires, then deleted.
Server and network logs
Kept no longer than 30 days, unless one of them is evidence in an abuse incident we are still dealing with.
Account activity
Deleted 90 days after it happened.
Anonymous counts
The individual events, including any accepted campaign labels, are deleted after 90 days. What remains is daily totals — how many, of what, the coarse device class or automated-request class, and anonymous campaign totals — with nothing in them that refers to a person.
Share links
Kept until you stop the link or the trip is deleted, and only ever as a one-way fingerprint. Stopping a link leaves that fingerprint marked as withdrawn rather than removing the row, so a withdrawn address can never quietly start working again.
10

Your rights

You can ask for a copy of what we hold about you, have it corrected, have it deleted, take it elsewhere in a portable form, object to the processing we do on legitimate interests, or withdraw a consent you gave. Your itinerary is exportable from inside the product.

Ask at privacy@oneweekinnewyork.com and we answer within one month. Deletion you can also do yourself, from your account page, without asking: it removes your trips, conversations and itineraries immediately and cannot be undone. Order records survive for the tax period, kept against a record that no longer names you.

11

Where it lives, and who else touches it

The service runs on one rented Hetzner server in Falkenstein, Germany (European Union), behind Cloudflare, which terminates encryption and filters abusive traffic. Data is encrypted in transit, and access on our side is limited to what running the service needs.

Hosting and network
Hetzner in Falkenstein, Germany (European Union), and Cloudflare, which sits in front of it.
Email delivery
Resend delivers sign-in links and service messages, from servers in the European Union.
The guide's model
OpenAI, as described above.
Payments
Paddle handles payments and works out the country, currency and tax treatment for localized price previews. At checkout it receives your payment details; when the home, pricing, checkout or initial itinerary page needs a localized price, our server sends it your IP address.
Live routing
No live routing provider processes trip data. One will be named here before live routing is enabled.
Accommodation map points
NYC Planning GeoSearch receives only the accommodation address text when you save it, so the itinerary can start and end at the right place.
Map background
OpenFreeMap, which serves the map background under the anonymous itinerary and signed-in day views, so this can happen before you have signed in or bought anything. Your browser fetches those tiles directly, so OpenFreeMap sees your device's IP address and roughly which itinerary neighborhoods you are looking at — and nothing else about your trip: the places, order and route lines on top are drawn by this site, and no private accommodation coordinate travels with a tile request. It sets no cookie and runs no script here.

Some of these operate outside the United Kingdom; those transfers rely on the standard contractual safeguards in our agreements with them.

12

Changes

If we change something that matters, it appears here and we email account holders before it takes effect. This version is dated 2 September 2026.