← FarSerene

Privacy Policy

Last updated 21 August 2026.

Draft · pending legal review before public launch

Who this applies to

FarSerene is available globally from launch. This policy is written to meet the requirements of the EU/UK General Data Protection Regulation (GDPR/UK GDPR) and the California Consumer Privacy Act (CCPA/CPRA), regardless of where you're located, and it will be reviewed against local law for any market where we see meaningful traffic.

What we collect

  • Trip requests you submit — free-text descriptions of where you want to go, when, with whom, and what you care about, plus the itinerary we generate in response.
  • Account details, if you create one — your email address, used for magic-link sign-in and saved trips. We don't collect a password.
  • Anonymous session identity — a session cookie that lets us recognize you across requests before you sign in (see ourCookie Policy).
  • Usage events — that a trip was generated, viewed, saved, or that you clicked through to a booking partner, so we can measure whether the product is useful and enforce free-tier limits.

We do not collect payment card details, government ID numbers, or health data. We do not currently run third-party advertising trackers.

How we use an AI model

When you describe a trip, we send that text to Anthropic's Claude models to parse your intent (destination, dates, party size, preferences) and to write itinerary copy. This is disclosed to you directly in the product, as required by Article 50 of the EU AI Act, before you start chatting. Anthropic processes this text under its own API terms; we do not send it anywhere else for AI processing.

Booking partners and affiliate links

Itineraries include links to third-party booking sites (hotels, flights, attractions). When you click through and book, that transaction happens entirely on the partner's site — FarSerene never sees or stores your payment details, and the booking itself never touches our systems. We may receive an affiliate commission from the partner for qualifying bookings; this does not change the price you pay.

Legal basis and retention

We process trip requests and account data to provide the service you asked for (contract necessity) and to keep the product secure and within free-tier limits (legitimate interest). We keep generated trips and account data for as long as your account is active, and anonymous session data for a limited window needed to enforce free-tier limits, after which it is deleted or anonymized.

Your rights

Under GDPR/UK GDPR and CCPA/CPRA you can request access to, correction of, export of, or deletion of your personal data, and can object to or restrict certain processing. We don't yet have a self-service export/delete button — until we do, emailprivacy@farserene.com from the address on your account and we'll action the request, generally within 30 days.

Security

Data is encrypted in transit (TLS) and at rest in our database provider (Cloudflare D1). Access to production data is limited to the people operating the service.

Age restriction

FarSerene is intended for users 18 and older. We do not knowingly collect data from anyone under 18.

Contact

Questions about this policy or your data: privacy@farserene.com.