Privacy policy · draft — entity TBD
Privacy Policy — DRAFT
STATUS: DRAFT. NOT LEGAL ADVICE. This is written to satisfy Google's specific
requirements for restricted-scope OAuth verification and to be accurate about what the
code in this repository actually does. Have a lawyer review before publishing.
Google requires this page to be: publicly accessible (no login), hosted on the same
verified domain as the homepage, and linked from both the homepage and the OAuth consent
screen.
Replace
[DRAFT — entity TBD],[DRAFT — entity TBD],[DRAFT — entity TBD], and[DRAFT — entity TBD]before publishing.
Last updated: [DRAFT — entity TBD]
Who we are
[DRAFT — entity TBD] ("Recoup", "we", "us") operates the Recoup application at [DRAFT — entity TBD]. Recoup finds
money travelers have already lost or are owed on trips they have booked — fare drops,
expiring credits, statutory delay compensation, and unclaimed booking benefits.
What this policy covers
This policy explains what information we collect, why we collect it, how long we keep it,
and what we will never do with it.
Information we collect
1. Information you give us directly
- Account details: your name and email address.
- Travel preferences: alert thresholds, notification channels, home currency, home airport.
- Payment information, if you book through us. Payments are processed by our payment provider. We do not store your full card number.
2. Email content, if you connect your mailbox
If you connect a Google account, we read your mail to find travel bookings. Specifically
we extract:
- Airline, hotel, and rental-car confirmations: confirmation codes, ticket numbers, passenger names, flight numbers, dates, times, cabin and fare class, seat assignments, room and rate details, and the amount paid.
- Notices about travel credits, vouchers, and their expiry dates.
- Change and cancellation notices for bookings we already track.
We do not read, extract, store, or analyze email that is not a travel booking. Messages
our system determines are unrelated to travel are discarded and not retained.
3. Information we generate
- Price observations for flights and hotels you have booked, recorded over time.
- Our assessment of what you may be owed, and the evidence supporting it.
- A ledger of money recovered, with the underlying proof for each entry.
How we use your information
We use it only to provide the service you asked for:
- Building a record of your trips.
- Monitoring the price of bookings you already hold and telling you when they drop.
- Identifying compensation, refunds, or rights you may be entitled to.
- Filing claims on your behalf, when you ask us to.
- Booking travel for you, when you ask us to.
- Sending you alerts about your own trips.
Google user data — Limited Use
Recoup's use of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.
Concretely, and without exception:
- We do not sell your data. Not to anyone, in any form, ever.
- We do not use your Google data for advertising. We do not serve ads, and we do not transfer Google user data to any advertising platform, data broker, or information reseller.
- We do not use your Google data to determine creditworthiness or for lending purposes.
- Humans do not read your email. Processing is automated. A person on our team will only view specific message content when (a) you explicitly ask us to and grant permission, (b) it is necessary for security purposes such as investigating abuse, or (c) we are required to by law.
- **We use your Google data only to provide and improve the features described in this policy** — building your trip record, monitoring your bookings, and finding money you are owed.
How we make money — stated plainly
We earn commission when you book travel through us, and we may take an agreed percentage
of money we recover for you. We never make money from your data itself. Our revenue
never depends on selling, sharing, or advertising against your information.
What we never do
- Sell or rent your personal information.
- Use your email content for advertising or share it with advertisers.
- Read email unrelated to your travel.
- Transfer your Google data to third parties except the limited cases below.
- Make automated changes to your bookings without your authorization.
Who we share information with
We share only what is necessary, only with providers who need it to deliver the service:
| Who | What they get | Why |
| Airlines, hotels, and booking providers | Booking details necessary to rebook, claim, or reserve | To act on your behalf |
| Payment processor | Payment details | To take payment |
| Email delivery provider | Your address and message content we send | To send you alerts |
| Cloud hosting and database providers | Data at rest, encrypted | To run the service |
| Error monitoring and analytics providers | Technical diagnostics | To keep the service working |
We may also disclose information where required by law, or to protect our users' safety.
**We do not transfer Google user data to third parties for any purpose other than
providing or improving the features above, and never for advertising.**
How long we keep it
- Non-travel email: discarded immediately, never stored.
- Travel bookings and your savings ledger: kept while your account is open, so we can show you your own history and prove where each recovered dollar came from.
- Raw email content: retained only as long as needed to extract booking details and to support any claim we file on your behalf.
- After you delete your account: we delete your personal data within 30 days, except records we must keep for legal, tax, or accounting reasons.
Your choices and rights
- Disconnect your mailbox at any time, in the app or at myaccount.google.com/permissions. We stop reading new mail immediately.
- Export your data at any time.
- Delete your account and data at any time, from within the app.
- Turn off any alert without losing the rest of the service.
If you are in California, the EU, or the UK, you have additional rights over your personal
data, including access, correction, deletion, and portability. Contact us at
[DRAFT — entity TBD] and we will respond within the time your law requires.
Security
Data is encrypted in transit and at rest. Access to production systems is restricted and
logged. Credentials and access tokens are stored encrypted and are never written to logs.
Children
Recoup is not intended for anyone under 18 and we do not knowingly collect their information.
Changes to this policy
If we change this policy in a way that materially affects how we handle your data, we will
tell you by email before the change takes effect.
Contact
[DRAFT — entity TBD]
[DRAFT — entity TBD], [DRAFT — entity TBD]