Privacy Policy.
Effective date: [EFFECTIVE DATE]
This policy explains how [Company LLC] ("Curatour", "we") processes information when you use the Curatour website, its public API, its MCP connector and its instruction skill (together, the "Service"). The short version: Curatour has no accounts, never receives your conversation, and gets only what it needs to find things to do in a place.
- Scope
- Information processed
- How information is used
- Disclosure to others
- Affiliate tracking and privacy signals
- Retention
- Your choices and rights
- Security
- Children
- International use
- Changes
- Contact
1. Scope.
This policy covers curatour.ai, travelskills.ai, traveltogether.ai and the Service's API and MCP endpoints. It does not cover the AI assistant you use (for example ChatGPT, Claude or Grok Bot) or the travel partners you book with (for example GetYourGuide, Viator or partners reached through Travelpayouts). Their own privacy policies apply to what you share with them.
2. Information processed.
At a glance
| What | When | Never included |
|---|---|---|
| Destination, travel dates (if given), currency, skill version | Each lookup | Your name, chat, itinerary, contact details |
| One-way keyed hash of the connection's IP address | Each request, for rate limits and anonymous counts | The raw IP address, stored with a lookup |
| Which activity a link was for, and the referring domain | When you open a Curatour link | Anything that identifies you |
| Activity ID and whether it was good | Only if you share feedback | Personal or booking details |
Lookups
When your AI assistant asks Curatour for recommendations, it sends the destination, optional travel dates, the currency and the version number of the instructions it follows. Curatour does not receive your conversation, your name, your location history or your booking details.
MCP server and AI assistants
Requests to the MCP connector carry the same fields as API lookups. Your assistant's provider may log its own requests under its own policy.
Aggregate service analytics
We keep aggregate counts (for example, lookups per day and per destination, and install-link clicks per source domain) to run and improve the Service. These counts contain no IP addresses, user agents or raw text you typed.
Website
The Curatour website uses no analytics, advertising pixels or tracking cookies. Our hosting provider, [Vercel Inc.], processes standard request logs (such as IP address and user agent) to deliver and secure the site.
Feedback and Community mode
Feedback is off by default (Private mode). If you choose to share whether a recommendation was good, or turn on Community mode, your assistant sends a random report ID, the activity ID and the result. Nothing about you, your trip or your booking.
Information you send us
If you email us, we receive your email address and what you write, and use it only to respond.
3. How information is used.
To return recommendations, prevent abuse and enforce rate limits, keep links working, measure overall usage, improve ranking quality using anonymous feedback, and respond to you. We do not sell personal information and do not build profiles.
4. Disclosure to others.
We share information only with service providers that help us run the Service (such as hosting and database providers) under contract, when required by law, or to protect the Service and its users. Travel partners receive information only when you choose to open one of their links, as described in section 5.
5. Affiliate tracking and privacy signals.
When you open a Curatour link, you pass through a Curatour redirect at curatour.ai/go/ to the partner's site. The partner or affiliate network may set cookies or similar technologies to attribute a booking to Curatour. Those are governed by the partner's own policy. Curatour receives only aggregate booking and commission reports, not your identity. [Describe handling of Global Privacy Control / Do Not Track signals.]
6. Retention.
Rate-limit hashes rotate and expire within [X days]. Aggregate counts may be kept indefinitely because they contain no personal information. Feedback reports are kept for [X months]. Emails are kept as long as needed to resolve your request. Hosting request logs follow the hosting provider's retention schedule.
7. Your choices and rights.
You can use Curatour without sharing feedback, turn off Community mode at any time, ask your assistant for plain partner links, or remove Curatour entirely (see Support). Depending on where you live, you may have rights to access, correct, delete or object to processing of personal information. Email privacy@curatour.ai. Because we avoid identifiers, we may be unable to link records to you.
8. Security.
We use HTTPS everywhere, keyed one-way hashing instead of storing IP addresses, least-privilege access and reputable infrastructure providers. No method of transmission or storage is perfectly secure.
9. Children.
The Service is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their personal information. Bookings are made with partners, who set their own age requirements.
10. International use.
Curatour is operated from [COUNTRY] and information may be processed there and wherever our providers operate. [Add GDPR/UK GDPR details: legal bases, EU/UK representative, transfer mechanisms, if serving European travelers.]
11. Changes.
We'll update this page and its effective date when this policy changes, and highlight material changes on the site.
12. Contact.
[Company LLC], [POSTAL ADDRESS]. Email: privacy@curatour.ai.
