Draft
This is a placeholder, not the final legal text. A lawyer will review it before OneGulf launches.
Privacy policy (draft)
This page explains in plain words what the waitlist website and the OneGulf app do with your information.
What we collect
When you join the waitlist we store your email address, the language you used, the countries you ticked (if any), the time you joined and the version of this notice you agreed to. We do not store your IP address.
What we use it for
Only to email you about the OneGulf launch. We do not sell or share the list.
Cookies and analytics
The website does not use analytics. It may set one cookie that remembers your language.
The OneGulf app
The app keeps your answers (language, traveller type, nationality, travel style, and the country of residence if you give it), your trips and their plans, your saved places, and, when you save your trip to an account, the phone number or Apple account you sign in with. You can use the app as a guest; a guest’s answers and trip are kept under an anonymous account. Your answers about food needs and allergies, accessibility needs and prayer times are kept only after you agree on that screen. Your precise location never leaves your phone; the app keeps only the starting city you pick.
This data is stored with Supabase in its Mumbai region. Error reports go to Sentry, set up to leave out personal data. Usage counts go to PostHog in the European Union, and only with your consent, as the next paragraph says.
Two more services take part. To order the places in a plan, our server sends Anthropic’s Claude model the candidate places it chose for your trip, with their names, categories, interests and positions, together with the trip’s pace, the kind of party (such as a family), your interests, the city of each day, and whether a day falls in Ramadan or in a heat window. It never sends your name, phone number, account id, travel dates, or your answers about food, accessibility or prayer; the model only chooses an order, and our server checks every choice. When you first open the app, and when you sign in by phone, a Cloudflare Turnstile check runs in a hidden web view to tell people from bots. Cloudflare sees the device’s IP address and the browser signals that check needs; the app receives only a pass token.
Counting is off until you say yes on a card that appears on Home after your first plan. With your consent, the app counts steps such as an onboarding screen completed, a plan built or a trip saved, with the app’s language and version and whether the account is a guest’s or a member’s. It never sends an answer, a place, a city, a phone number or a search, and nothing about food, accessibility or prayer. These counts are kept by PostHog in the European Union, under your account’s id. You can stop the counting at any time in Profile → Your data; the app then asks PostHog to delete what it holds about you, and deleting your account does the same.
In the app, Profile → Your data lists each consent with a switch to withdraw it, and a button that deletes your account. Deleting removes everything at once: answers, consents, trips, plans, saved places and the sign-in, and asks PostHog to delete your usage counts. It does not reach the SMS provider’s own logs, or backups until they rotate.
Deleting your email
Write to [contact email] and we will remove your email from the list.
Changes
This text will be replaced by the reviewed policy before launch.