Tomo
Your privacy

Privacy

Last updated 16 September 2026

The short version

Your itineraries live in your browser — unless you sign in to save them to your account. Analytics are cookieless. We don’t run ads and we don’t sell personal data. The trip you describe is sent to Anthropic’s Claude to generate your plan, and a trip becomes visible to others only when you share it.

Who we are

Tomo (tomo.voyage) is an AI travel-planning service operated by Altitudes B.V., Amsterdam, the Netherlands. For anything in this policy, contact hello@tomo.voyage.

Where your trip data lives

  • Itineraries stay on your device. Plans you build are stored in your browser’s localStorage. They are never sent to a server unless you choose to share a trip or save it to your account. Clearing your browser data deletes them.
  • Shared trips are stored server-side. When you share a trip, a copy of that itinerary is saved by our backend to an Amazon S3 bucket in the EU (eu-central-1) and becomes visible to anyone who has the link. Don’t put anything in a trip you wouldn’t want a link-holder to see. To have a shared trip removed, email hello@tomo.voyage.

Accounts and sign-in

You don’t need an account to plan with Tomo — your itineraries stay on your device, as above. If you choose to sign in, we create a lightweight account so the trips you save (and any Tomo credits) stay with you. Sign-in is passwordless: you enter your email and we send a one-time magic link — valid for 15 minutes and usable once — through our email provider (Amazon SES). For an account we store only your email address, your language preference, and the date you joined.

  • Staying signed in. Once you sign in we set a first-party session cookie (tomo_session) that lasts up to 90 days; it is HttpOnly, Secure, and SameSite=Lax. Behind it the app uses short-lived access tokens (15 minutes) that renew automatically, backed by a refresh token valid for 90 days. Logging out ends the session and clears the cookie right away.
  • Tomo credits. If you have an account, we keep a ledger of any Tomo credits linked to it. There is no credits economy yet — the ledger simply records a balance against your account.
  • Delete-by-default. Your account is built so that deleting it erases everything linked to it — your sign-in sessions and tokens, your credit ledger, and the trips you saved to the account. Ownerless and curated trips are left untouched. To delete your account or ask us to erase your data, email hello@tomo.voyage.

Hosting and where data lives

Tomo’s website is hosted on Netlify, which keeps standard server logs (such as IP addresses and requested URLs) for operations and security. Accounts, saved trips, and sign-in are handled by our own backend service on Amazon Web Services (AWS) in Frankfurt (eu-central-1), so that data stays in the EU; it keeps operational logs too.

Analytics — cookieless

We use Plausible, a privacy-friendly analytics service that sets no cookies and collects only aggregate usage statistics — no cross-site tracking, no personal profiles. It loads only when analytics is configured for the site. Because there are no analytics cookies, there is no cookie banner to click.

AI planning (Anthropic Claude)

Tomo’s planning is powered by Anthropic’s Claude. In live mode, the trip description you type — destination, dates, budget, preferences, and your chat messages — is sent to Anthropic to generate and revise your plan. Please don’t include sensitive personal details in a trip description that you don’t want processed for this purpose.

Destination photos and facts

Destination data and imagery come from Google Places and Google Maps, Wikipedia and Wikimedia, and Pexels. Your browser may load media directly from these services, which means they receive your IP address under their own privacy policies, as with any image on the web.

Booking links and affiliates

“Book” links redirect through our /api/click-out endpoint to travel partners — Viator, GetYourGuide, Stay22, and Travelpayouts — so Tomo may earn a commission on bookings. We count the click itself (an anonymous counter); we do not sell or pass personal data to partners. Once you land on a partner’s site, their privacy policy applies.

Your rights (EU/GDPR)

You have the rights to access, correct, delete, and object to the processing of your personal data. Most of your Tomo data is on your own device, where you control it directly. If you have an account, emailing us to delete it erases your account and everything linked to it (see “Accounts and sign-in” above). For shared trips, server logs, or any other request, email hello@tomo.voyage. You can also lodge a complaint with your data-protection authority — in the Netherlands, the Autoriteit Persoonsgegevens.

Changes

When this policy changes, we’ll update this page and the date at the top. Material changes will be called out on the site.

Your data and AI models

Your trip briefs and edits are sent to our AI model provider (Anthropic) solely to generate your plan. They are never used to train AI models — not by us, and per our provider agreement not by the provider. Privacy questions or requests: hello@tomo.voyage (privacy contact).