That One Time (“ThatOneTime,” “we,” “us,” or “our”) is a real-time shared trip and event guide operated by Gosugi, based in California, USA. This Privacy Policy explains what information we collect when you use our website (thatonetime.app), our app (app.thatonetime.app), and our iOS app (together, the “Service”), how we use it, and the choices you have.
By using the Service, you agree to the collection and use of information as described here. If you don’t agree, please don’t use the Service.
1. Information we collect
Information you give us
- Account details. When you create an account, we collect your email address and your name. We sign you in with a magic link or a one-time code sent to your email; if you choose to set a password, we store it in a securely hashed form. You may optionally add a profile photo (avatar).
- Trip & event content. The content you create in the Service — trips and events, itineraries, days and activities, places, notes, reservations, travel legs, and the people you invite.
- Text you paste into AI-assisted features. Some features read text for you rather than making you retype it — for example, pasting a booking email to pre-fill a lodging or travel record. The text you paste is sent to our AI provider (Google) to be read back as form fields, and a booking email typically contains names, an address, dates, and a confirmation code. We do not store or log the text you paste — only the details you review and save become part of your trip. For what our AI provider does with it, see Service providers.
- Place searches. When you search for a place, or enter an address we need to put on a map, we send that text to a place-search and address-look-up provider (see below) to find a match.
- Photos and videos. Media you upload to a shared album, along with any captions you add. Photos and videos can contain metadata (EXIF), which may include the date, time, and GPS location where the media was captured. We use this to group and place your memories; you can remove media at any time.
- Payment information. If you buy a paid trip or event tier, our payment processor (Stripe) collects and processes your payment details. We do not receive or store your full card number — we receive only a confirmation of payment and limited billing details needed to manage your purchase.
- Communications. If you contact us for support, we keep your messages and contact details so we can help you.
Information collected automatically
- Usage & device data. Basic technical information such as your IP address, browser and device type, and how you interact with the Service, so we can operate, secure, and improve it.
- Session data. A session identifier stored in a cookie (or in secure app storage on iOS) that keeps you signed in.
- Analytics. Privacy-friendly, cookieless web analytics (Cloudflare Web Analytics) that give us aggregate traffic trends without tracking you across other sites.
2. How we use information
We use the information we collect to:
- Provide the Service and keep everyone’s plan and photos in sync in real time;
- Create and secure your account, and sign you in via magic link, code, or password;
- Send you service messages — magic links, trip invitations, and (if you enable them) push notifications;
- Look up the places and addresses you search for, and read text you paste into AI-assisted features, using the providers listed below;
- Process payments, manage your tier, and provide receipts and support;
- Maintain, troubleshoot, secure, and improve the Service and prevent abuse; and
- Comply with our legal obligations.
We do not sell your personal information, and we do not use it to serve third-party advertising.
3. How we share information
ThatOneTime is built for sharing within your group. We share your information only as described below:
- With your group. The content of a trip or event — including itineraries, notes, and photos — is visible to the members you invite and to anyone you give an access link to (for example, a read-only guest link or a recap link). You control who is invited and can revoke links at any time.
- With service providers. We share information with the vendors that power the Service, listed in the next section. They may process your data only to provide services to us.
- For legal reasons. We may disclose information if required by law, or to protect the rights, safety, and security of our users, the public, or ThatOneTime.
- In a business transfer. If ThatOneTime is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to this policy.
4. Service providers
We rely on a small set of trusted providers to run the Service:
- Railway — application hosting and database.
- Cloudflare — content delivery, security, cookieless analytics, and media storage/streaming (Cloudflare R2 for photos and Cloudflare Stream for video).
- Resend — delivery of transactional email such as magic links and invitations.
- Stripe — payment processing.
- Apple — push notification delivery and in-app purchases for the iOS app.
- Google — place search and address look-up (Google Places API), and the AI that reads text you paste into AI-assisted features (Gemini API). Map and directions buttons open Google Maps in a new tab; once you tap one, Google receives that request directly from your device under its own privacy policy. We use Google's paid API tier, under which Google does not use the prompts or responses sent through it to improve its own products or models. Google does log them for a limited period, solely to detect and prevent abuse of its service.
- OpenStreetMap (Nominatim) — address look-up, used as a fallback when Google Places has no match or is unavailable.
Each provider is bound by its own privacy and security commitments and processes data on our behalf.
5. Cookies & analytics
We use a single essential cookie (or equivalent secure storage in the iOS app) to keep you signed in — the Service won’t work without it. We use privacy-friendly, cookieless analytics to understand aggregate traffic. We do not use advertising cookies or cross-site tracking.
6. Data retention
We keep your information for as long as your account is active or as needed to provide the Service. Some specifics:
- Trip & event lifecycle. Content is retained according to the plan (tier) of the trip or event. On the free tier, a trip becomes read-only a period of time after it ends; you can upgrade to keep it editable and stored longer. ThatOneTime is not a backup service — please keep your own copies of important photos, which you can download at any time.
- Deleted photos. When you delete a photo it is moved to a recoverable trash for a limited period (around 30 days) before it is permanently removed.
- Account deletion. When you delete your account, we delete or de-identify your personal information, except where we must retain it to meet legal, tax, or security obligations.
7. Your choices & rights
- Access & update. You can view and update your name, email, avatar, and password from your account profile.
- Export. You can download the photos and videos from a trip or event at any time.
- Delete. You can delete individual content, leave a trip, or delete your account entirely from within the Service.
- Notifications. You can turn push and other optional notifications on or off.
- Regional rights. Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to certain processing — including under the California Consumer Privacy Act (CCPA) and the EU/UK GDPR. We do not sell personal information. To exercise any of these rights, contact us at the address below; we will not discriminate against you for doing so.
8. Children’s privacy
The Service is intended for people 13 years of age or older, and account holders must meet that minimum age. We do not knowingly collect personal information from children under 13. Children may appear in photos or plans that adults choose to add — the adult who uploads that content is responsible for it and for having permission to share it. If you believe a child under 13 has created an account or that we hold a child’s information without appropriate consent, contact us and we will delete it.
9. Security
We protect your information with industry-standard measures: encrypted connections (HTTPS/TLS) in transit, hashed passwords, revocable sessions, signed time-limited links for media, and access controls that keep each trip private to its group. No method of transmission or storage is perfectly secure, but we work to protect your information and to promptly address issues if they arise.
10. International users
ThatOneTime is operated from the United States, and our providers may process and store data in the United States and other countries. If you use the Service from outside the U.S., you understand your information may be transferred to and processed in the U.S., where data-protection laws may differ from those in your country.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, notify you. Your continued use of the Service after an update means you accept the revised policy.
12. Contact us
Questions about this policy or your information? Reach us at [email protected].
See also our Terms of Service, which govern your use of ThatOneTime.