מדיניות הפרטיות זמינה כרגע באנגלית; גרסה עברית בקרוב.
Privacy Policy — Takrita
Last updated: 18 August 2026. DRAFT — NEEDS LEGAL REVIEW.
Plain-language promise up front: we collect the minimum needed to plan your trips, we don't run ad trackers, we don't sell your data, and our analytics are cookieless.
1. Who we are
Takrita (takrita.com) is operated under the registered Raayona (רעיונא) trade name (Osek Patur, registered 18 August 2026), Israel. Contact: hello@takrita.com. We are the "controller" of the personal data described here, except where noted (payments — see §6).
2. What we collect
- Account data: email address, display name, and authentication identifiers, managed via Supabase Auth (including Google sign-in if you use it), plus a record of when you accepted our Terms.
- Trip inputs: the travel chips you tap and options you select — destination, dates, interests, pace. Deliberately structured, not free-text-heavy.
- Generated itineraries you create or save.
- Purchase records: which token pack you bought and your token balance. Payment details (card numbers, billing address) go to Paddle, not us — we never see your full card number.
- Usage analytics: anonymous, cookieless product analytics via PostHog (EU Cloud). See §7.
- Technical logs: standard server logs for security and debugging, kept only as long as needed for those purposes.
3. What we do NOT collect
No advertising trackers, no third-party ad cookies, no data brokers, no selling or renting personal data. We don't ask for passport numbers, precise geolocation, or payment credentials.
4. Why we process it (legal bases under GDPR / Israeli law)
- Running the service you asked for — generating itineraries, keeping your account and token balance: contract.
- Security, abuse prevention, debugging: legitimate interests.
- Analytics: cookieless and anonymous by design (§7); where consent is required, we ask for it.
- Anything else we'd ever want to do (e.g., a newsletter): opt-in consent, granular and revocable — per GDPR and Israel's Privacy Protection Law as amended by Amendment 13 (in force since 14 Aug 2025), which requires explicit, documented, granular consent and expanded notice (what is collected, why, the risks, and who it's shared with).
5. AI processing — where your trip data goes
When you generate an itinerary, your trip inputs are sent to AI providers to produce the plan:
- Google Gemini API (paid tier): Google states it does not use paid-tier prompts or responses to train or improve its models; it may retain data up to 55 days solely for abuse monitoring.
- Perplexity Sonar API: Perplexity states API requests follow a zero-data-retention policy — prompts and responses are not stored and are never used for model training.
We send trip context (destination, dates, preferences, and any notes you type into the planner), not your email or identity, to these providers.
6. Payments — Paddle as merchant of record
Token packs are sold by Paddle (paddle.com) as merchant of record: your purchase contract is with Paddle, and Paddle processes your payment and billing data as an independent data controller under its own Privacy Notice and Buyer Terms (updated 31 Mar 2026). Paddle shares with us only what we need (e.g., that a purchase succeeded) — see Paddle's privacy notice for their practices.
7. Analytics, cookies & browser storage
Our third-party analytics is PostHog, hosted on PostHog Cloud EU (Frankfurt), configured in cookieless mode: PostHog itself sets no cookies and stores no identifiers in your browser — visitors are counted via a privacy-preserving server-side hash with a salt that rotates daily, and IP capture is disabled.
Separately, Takrita itself does use cookies and browser storage: the strictly necessary Supabase Auth cookies that keep you signed in, your language preference, and first-party product storage — a random per-tab session id plus local usage and personalization caches that help us improve suggestions. These first-party records are ours (they are not shared with advertising or third-party analytics networks) and some anonymous usage signals sync to our own database to improve the product.
8. Who else touches the data (processors)
| Provider | Role | Where |
|---|---|---|
| Supabase | database, auth | Frankfurt, EU |
| Vercel | hosting/CDN | global edge network |
| Google (Gemini API) | itinerary generation | per Google DPA |
| Perplexity (Sonar API) | live travel search | zero retention (their stated policy) |
| PostHog EU | analytics | Frankfurt, EU |
| Paddle | payments (independent controller) | per Paddle |
Each is bound by a data-processing agreement or acts as an independent controller (Paddle).
9. International transfers
We're based in Israel, which holds an EU adequacy decision; some processors are in the US/EU. Transfers rely on adequacy decisions and standard contractual clauses in theprocessors' DPAs.
10. Retention
Account data: while your account exists, then deleted within a short period after account deletion. Itineraries: until you delete them or your account. Purchase records: as long as tax law requires. Logs: see §2. Analytics: anonymous/aggregate.
11. Your rights
Depending on where you live (GDPR for EEA/UK, Israel's Privacy Protection Law for Israel): access, correction, deletion, portability, objection, and withdrawal of consent. Email hello@takrita.com; we respond within 30 days. You can also complain to your local supervisory authority (in Israel: the Privacy Protection Authority).
12. Security
Encryption in transit, hashed identifiers for the learning layer, row-level security in the database, least-privilege access. No system is perfect; we'll notify you and the regulator of breaches as the law requires.
13. Children
Takrita is not directed at children under 16 and we don't knowingly collect their data.
14. Changes
We'll post changes here and bump the date; material changes get an in-app notice.
15. Contact
hello@takrita.com · Raayona (רעיונא), Israel.