Privacy Policy
Last updated: September 2026
Tseril is a road-trip planner. You can browse trips, the map and the public gallery without an account — nothing of yours reaches us. When you sign in, your trips are stored on our servers so any device can restore them. That means they are readable by the service (unlike a share link, which is end-to-end encrypted), and this page says exactly what that means.
1. What we store, and why
- Account — your email address, an internal user id and timestamps, created the first time you sign in with an emailed one-time code. There is no password to store; if you sign in with Google we keep the linked Google account id and email.
- Trips, saved places and folders — readable (plaintext) JSON in our Cloudflare D1 database, so that signing in on another device restores them. This is what "cloud sync" means here: unlike a share link, this content is not end-to-end encrypted. A deleted trip leaves a small deletion marker (~100 bytes) so an offline device cannot bring it back.
- Sessions — a session cookie and a session record (browser label, IP address, expiry). This is how you stay signed in, and it is the only cookie Tseril sets.
- Published gallery trips (opt-in) — the trip's name, description, day/stop counts and its encrypted share link. Publishing makes the trip public: anyone opening the gallery entry can view it. You can unpublish at any time.
- Share links — a share link carries the trip inside the URL, encrypted end-to-end (AES-256-GCM) with the key in the link fragment. A trip too large for a link is stored on our server as ciphertext only: we cannot read it, and it expires.
- Usage events — anonymous product events (app opened, trip created, share created, …) with no personal data attached, kept for 90 days. No analytics cookies, no third-party analytics script, no cross-site identifier.
- Abuse protection — short-lived counters keyed by IP address and email, used only to rate-limit login-code requests and API calls. They expire within hours.
- Content reports — when someone reports a gallery trip, the report is kept for 30 days.
- Subscription records (only if you subscribe) — your Waffo Pancake customer and subscription ids, plan, status and billing period. Card details are handled by Waffo Pancake and never reach us.
- Error reports — when the app hits a bug we store a diagnostic record (error message, a stack excerpt, the page path) in our own log for 30 days, with any share-link fragment removed so the decryption key never leaves your browser. It is readable only in our admin console, carries no account identifier and is never sent to an advertising or analytics network. If a third-party error service is ever enabled, this page will say so first.
2. Cookies and local storage
One cookie: the session cookie that keeps you signed in (it expires after about a week of inactivity). The app also keeps your trips and preferences in your browser's local storage as an offline cache. Waffo Pancake may set its own cookies while you complete a checkout. No advertising cookies, no tracking pixels.
If you arrive from a campaign link — for example a post we published
containing ?ref=… — the site stores that short label locally
(things like advrider or newsletter) so we
can tell which channel brought you. It holds no identifier of you, it
is never shared with anyone, and clearing your browser's site data
removes it.
3. Who processes data for us
- Cloudflare — hosting, database, key-value storage, map-tile proxy
- Waffo Pancake — payments, invoices and tax, as Merchant of Record
- Google — only if you choose "Continue with Google"
- Gmail SMTP — delivery of your login code
- Sentry — error reports, if enabled
- Geoapify / TomTom — place search, geocoding and driving times when you search or plan a route
- OpenFreeMap / USGS — map imagery and tiles
These providers run on a global network, so your data may be processed outside your country. We do not sell your data or share it with advertisers.
4. Keeping it, and deleting it
Your account and cloud data stay until you delete them — which you can do yourself, immediately, from the account menu (Delete account): that removes your account, your sessions, your cloud-synced trips and your published gallery entries. Trips that exist only in this browser are kept until you clear your browser storage. Usage events expire after 90 days; rate-limit counters within hours.
5. Your rights
You can ask for a copy of your data, correct it, delete it, or object to how we use it. Most of that you can do directly: export any trip as GPX, or delete your account in the app. For anything else, email us — we answer within 30 days. If you are in the EU, the UK or China you also have the right to complain to your local data-protection authority.
6. Children
Tseril is not directed at children under 16, and we do not knowingly hold their data. If you believe a child has created an account, email us and we will remove it.
7. Changes to this policy
If we change how we handle data we will update this page and, for anything significant, say so in the app before it takes effect.
8. Contact
Tseril is run by an independent developer (a sole operator, not a company). Data questions, requests and complaints go to the address below and are handled by that person. leeppk082@gmail.com