Version 0.1-draft · prepared 2026-07-05 · effective date pending attorney sign-off · sha256 f8a3671ca905
Remy Marlo — Privacy Policy
DRAFT — attorney review required before publication. Prepared 2026-07-05. Not legal advice; not reviewed by licensed counsel. Bracketed items
[...]are open decisions for Mike/attorney.
Covers: remymarlo.com (the site), portal.remymarlo.com (the portal), and Remy the concierge (the WhatsApp-resident service and participant emails). One coherent policy for all three surfaces.
Effective date: [TBD — publication]. Version: 0.1-draft.
Plain-language summary (the layer travelers actually read)
Hi — Remy here. The legal text below is the real contract; this is the honest version:
- I read the group chat of trips I'm added to. That's how I work. I use what I read to answer questions, send reminders, and keep up with plan changes. I don't read anything before I'm added or after I'm removed.
- Your organizer gave me the trip. Bookings, the roster (including who's a kid), dietary needs and preferences — an organizer or travel advisor entered these so I can help without asking you twenty questions.
- Your trip's data stays with your trip. I don't use one group's trip to help another group unless your organizer explicitly turns that on (it's off by default).
- I never sell your data. No ads. Ever.
- You can tell me to ignore you — say
@remymarlo ignore mein the group and I'll stop processing what you say beyond what's technically unavoidable to deliver the group's messages. - You can get your data or have it deleted. Ask your organizer, or email us directly — details below.
- I'm an AI, and I say so when I join every group.
Full text follows. Questions: [privacy@remymarlo.com — mailbox TBD].
1. Who we are
The service is operated by [Remy Marlo / OPERATING ENTITY TBD — currently an individual owner; entity formation pending] ("Remy Marlo," "we"). We are the data controller for the processing described here, except where we act as a service provider/processor to a travel advisor (see §12).
Primary market: United States. Hosting: United States (see §9).
2. Roles and whose data we process
- Organizers — the person (or travel advisor) who sets up a trip, creates a portal account, and adds Remy to a group. Organizers have a direct account relationship with us.
- Travelers / group members — people in a bound WhatsApp group, including people who never signed up for anything. If you are in a group Remy has joined, we process the messages you send in that group as described here. Remy always announces himself and how to opt out when he joins (§6).
- Children — travelers under 18 appear on rosters (with an adult/child flag) entered by the organizer. We do not knowingly collect information directly from children (§10).
3. What we collect
From organizers (portal + intake): - Account data: name, email, home timezone, notification preferences, quiet-hours and personality settings. - Trip materials: itineraries, forwarded confirmation emails, PDFs, screenshots/photos of tickets and confirmations, links, and free-text notes. These routinely contain booking references, traveler names, flight details, and vendor information. - Roster data: traveler names, family grouping, adult/child flag, phone number or WhatsApp handle, home timezone, and private notes including dietary needs, allergies, accessibility needs, and preferences. See §4 (sensitive data). - Inbound email: mail forwarded to the trip's dedicated forwarding address. Inbound mail is treated as untrusted and is held as pending material until the organizer confirms it in the portal; unconfirmed mail is not attached to any trip. - Billing data (when billing launches): handled by Stripe; we do not store full card numbers. Pilot trips are free.
From the group chat (once Remy is added and has introduced himself): - Messages sent in the bound group, including plan changes stated in chat, questions, and @mentions of Remy. - Photos and images shared in the group, when our channel plumbing delivers them, used only to answer the question asked (request-scoped; see §4). - Location pins and voice notes, if sent: current product behavior is a graceful decline; the raw payload may still transit our systems. - Preferences volunteered in conversation (e.g., "Maya's allergic to shellfish") — persisted for the rest of the trip to tailor answers. Remy never interrogates the group to collect preferences.
From third-party data sources (about the world, not about you): flight status, weather, webcams, event/closure data, and public web pages about your booked venues. Our outbound queries to these sources are sanitized and never include traveler personal data.
From the website/portal automatically: standard logs (IP, browser, pages), authentication cookies, and minimal analytics. See the Cookie Notice.
What we do NOT collect: payment credentials for your bookings, loyalty-program logins, precise device location tracking, biometric identifiers, or anything from groups Remy isn't in. Remy cannot log into anything of yours — the product cannot book, cancel, pay, call, or transact (see Terms §3).
4. Sensitive data — dietary, allergy, accessibility, health-adjacent
Dietary restrictions, allergies, and accessibility needs can reveal health information. We treat all roster private notes and volunteered preference data as sensitive:
- Used only to tailor trip help (restaurant fit, activity suitability, reminders).
- Never announced in the group. Remy answers in "group fit" terms ("safest pick tonight covers everyone") without naming an individual's constraint in public.
- Never used in outbound web searches or enrichment queries.
- Never sold, shared for advertising, or used for cross-trip purposes without the explicit opt-in in §8.
- Entered by the organizer, who confirms they have each traveler's permission (and a parent's, for children) — see the Organizer Attestation in the consent kit.
[ATTORNEY: whether Art. 9 GDPR explicit-consent capture per traveler is required for EU-resident travelers, vs. reliance on organizer attestation — see findings memo Q6.]
5. Why we process (purposes and lawful bases)
| Purpose | Data | Lawful basis (GDPR, where it applies) |
|---|---|---|
| Answer questions and send reminders in the group | chat messages, trip knowledge, roster | Performance of contract (organizer); legitimate interests (group members), balanced by in-chat disclosure, opt-out, per-trip isolation, and no-advertising commitments |
| Build the trip knowledge base before the trip | trip materials, inbound email | Contract (organizer); legitimate interests |
| Tailor answers to dietary/accessibility needs | sensitive roster/preference data | Explicit consent, captured via organizer attestation + traveler notice [attorney to confirm mechanism] |
| Participant emails (recaps, summaries) | roster contact data | Contract / legitimate interests; see §7 |
| Post-trip keepsake album | group photos, chat highlights | Opt-in consent at album time (consent kit §3) |
| Cross-trip improvement | trip data/metadata | Opt-in consent only, default OFF (§8) |
| Service security, abuse prevention, audit logs | logs, delivery records | Legitimate interests / legal obligation |
| Billing (future) | payment data via Stripe | Contract |
Your trip information is processed by third-party AI model providers to generate responses, subject to their data-handling terms (see §9).
6. Group members who never signed up — disclosure and opt-out
This is the honest heart of the product: Remy lives in a group chat, and some people in that chat never clicked "I agree."
What we commit to:
1. Disclosure at joining. Remy's first message in every group says he is an AI, what he does, links to this policy, and explains the opt-out. He never joins silently.
2. Organizer responsibility. The organizer attests they have authority to add Remy and have told the group (including parents of minor travelers) before binding.
3. Per-person opt-out. Any group member can say @remymarlo ignore me. From then on we exclude that person's messages from concierge processing beyond technical necessity (message transit/delivery and the minimal record that the opt-out itself exists). @remymarlo include me reverses it. [REQUIREMENTS INPUT — this behavior must exist before this policy publishes.]
4. Leaving the group ends processing of your future messages entirely.
5. Scope confinement. Remy processes the group to help with the trip. He does not profile group members for any other purpose, does not adjudicate disputes, and does not volunteer descriptions of people (including children) in photos.
7. Emails we send
Remy emails trip participants only — recaps, detailed summaries, follow-up notes, and (with consent) the keepsake album. These relate to your active trip. Every email identifies the sender and includes a working opt-out; opting out of email never affects in-group help. We never email vendors or third parties on your behalf, and we do not send marketing email to travelers. [ATTORNEY: CAN-SPAM classification — we draft these as transactional/relationship messages; confirm footer requirements.]
8. Per-trip isolation and the cross-trip learning toggle
Architecture commitment: each trip's knowledge is isolated. Trip A's chat, roster, preferences, and materials are never used to answer Trip B.
One exception exists, and only if the organizer turns it on: "Help future trips" — an opt-in, default OFF, revocable toggle allowing us to use the trip's data and metadata (e.g., which questions travelers asked, which venue facts mattered) to improve the service for other trips. Full toggle copy and mechanics: data-rights-flows.md §4. Revoking stops future use; it cannot recall improvements already made.
9. Who touches the data (subprocessors and recipients)
| Provider | What | Where |
|---|---|---|
| Supabase | portal auth, database, file storage (trip materials) | US |
| Vercel | portal/site hosting | US |
Large-language-model provider(s) [current: OpenAI GPT-5.5 via subscription runtime — attorney to review provider DPA/training terms] |
generating Remy's answers; receives trip context and chat excerpts needed per request | US |
| WhatsApp / Meta | the chat channel itself (Meta's own terms/privacy apply to WhatsApp independently) | global |
| WhatsApp bridge tooling | message transport between WhatsApp and our runtime | [document exact tooling] |
| Google (Gmail) | inbound forwarded-confirmation mailbox (interim pilot scheme) | US |
| FlightAware (+ ADS-B fallbacks) | flight status; queries contain flight numbers, not traveler identity | US |
| Weather/webcam/event providers (e.g., Open-Meteo, NWS, webcam networks) | destination conditions; no personal data sent | various |
| Stripe (when billing launches) | payments | US |
Email delivery provider [TBD] |
participant emails | [TBD] |
We sign data-protection terms with subprocessors where available [REQUIREMENTS INPUT: collect DPAs]. We never sell personal data and never share it for cross-context behavioral advertising.
Disclosures required by law: we may disclose data to comply with legal process, enforce our terms, or protect safety. No government backdoor exists; we would challenge overbroad requests where feasible.
10. Children
Trips include kids; that's the product's reality, handled as follows:
- We collect children's information from organizers/parents, not from children. Roster kid entries (name, age flag, dietary/allergy notes) are entered by an adult who attests to parental consent.
- The portal and account surfaces are for adults 18+.
- Remy does not direct content to children, does not ask children for information, never uses kids as joke targets, and applies request-scoped vision behavior (no volunteered descriptions of anyone, especially children, in photos).
- Children's chat messages in the group are processed the same way as other group messages, under the organizer/parental attestation. Parents may exercise all rights in §11 for their children, including ignore and deletion.
- [ATTORNEY: COPPA posture — we believe the service is not "directed to children" (mixed-audience general service; no child accounts; no direct collection), but group-message processing where we have actual knowledge a sender is under 13 needs analysis — findings memo Q5.]
11. Your rights
Anyone — organizer or traveler, signed up or not — can:
- Access/export their data (organizers: full trip export; travelers: their messages, roster entry, preferences).
- Correct roster or preference data (travelers may also just tell Remy in chat).
- Delete — travelers: "delete my data" removes their messages, roster entry, and preferences from the trip; organizers: "delete my trip" removes the whole trip. Mechanics and timelines: data-rights-flows.md.
- Opt out of processing (@remymarlo ignore me), of email, of the keepsake, and of cross-trip learning (organizer toggle).
- Not be discriminated against for exercising rights.
How: in-chat (ignore me), via the organizer, via the portal, or by email to [privacy@remymarlo.com — TBD]. We verify requests reasonably (for non-account travelers: control of the WhatsApp number in the group). We respond within 30 days [45 under CCPA — attorney align]. Applicable state laws (California CCPA/CPRA and other state privacy laws, where their thresholds apply to us — most don't at pilot scale, but we honor the rights regardless) and, where applicable, GDPR/UK GDPR rights (access, rectification, erasure, restriction, portability, objection, complaint to a supervisory authority) are honored through the same channels.
12. Travel advisors (B2B)
When a travel advisor deploys Remy for their client's trip, the advisor is the organizer. As between us and the advisor, [recommended: we act as the advisor's service provider/processor for their client data; the advisor is responsible for client-facing notice] — see advisor-terms-skeleton.md. Client-intelligence reports for advisors are generated only with the disclosure/consent described in the consent kit and never expose an individual's sensitive preferences without that traveler's consent.
13. Retention
Defaults (organizer can delete earlier at any time; full schedule in data-rights-flows.md §3):
- Active trip data: retained for the trip.
- Post-trip: trip auto-archives [90] days after trip end (keepsake window), then chat transcripts and photos are deleted; a minimal trip record (dates, destination, billing, audit log) is kept [12] months, then deleted.
- Opted-out members' data: excluded from retention beyond technical necessity from opt-out forward.
- Inbound email never confirmed by the organizer: deleted after [30] days.
- Backups: purge within [35] days of deletion.
- Logs/audit records: [12] months.
14. Security
Row-level security on all portal tables (own-rows), private storage buckets, transport encryption, least-privilege access (currently: the owner-operator), sanitization of personal data before anything enters evidence/test corpora, and no traveler personal data in outbound third-party queries. We are a pilot-stage service and say so honestly: our security program is proportionate to our size and will formalize as we grow [ATTORNEY: written infosec program requirements under state law; breach-notification duty map — findings memo Q10].
Breach notice: if a breach affects your data we will notify affected organizers without undue delay and as required by law, with what happened, what data, and what we're doing.
15. International
We are US-based and store data in the US. Travelers may use trips from anywhere; using the service sends your data to the US. For EU/UK-resident data subjects, [ATTORNEY: confirm Art. 3(2) applicability posture and, if applicable, transfer mechanism — SCCs/DPF with subprocessors — findings memo Q6].
16. Changes
We'll post changes here and note the date. Material changes get organizer notice (email/portal) before taking effect; continued use after notice is acceptance. We will never retroactively weaken the per-trip isolation or no-sale commitments for data already collected without fresh consent.
17. Contact
[privacy@remymarlo.com — mailbox TBD] · [postal address — entity formation pending]