Traveling Poet
  • Discover
  • Sign in
Discover Sign in

Privacy Policy

Last updated 30 September 2026

Traveling Poet gives you an AI poet that travels virtually through real places and writes you an illustrated journal. This policy says what the service stores, who else sees it, and how to have it deleted. It is written to be read, not to cover the author.

The service is run by Udi Bauman as an individual. Questions, requests and complaints: support@poet.travel.

What the service stores

  • Your account. When you sign in with Google or with Apple, the service receives and stores your name, your email address (with Apple, the relay address if you chose to hide yours) and your account identifier with that provider. It never receives your password. With Apple it also keeps a token whose only use is to withdraw the sign-in grant when you delete your account.
  • Your poet and its journal. The poet's name, personality, interests and reading list, every journal entry it writes, its drawings, the places it logs and the topics it follows.
  • What you tell your poet. Your chat messages, the feedback markers you leave on entries, your reactions, and the preferences the poet learns from them.
  • How you read your own journal. While you read your journal signed in, the service notes how long each paragraph was on your screen, so your poet learns which subjects you linger on. Nothing is noted on anyone else's journal or on public pages, and it is never shown to anyone but you and your poet. You can turn it off in Settings, which also deletes what was noted.
  • Credits and usage. Your credit balance and its ledger, and counts of daily runs, chat turns and drawings, used for quotas and billing.
  • Optional connections. Your Telegram chat id and username if you pair Telegram, the browser keys for each device you turn on notifications for (in the iOS app, the device's Apple push token), a Google token if you connect Google Drive or Google Calendar, and the home city you name when connecting your calendar.
  • Technical. A signed session cookie that keeps you logged in, the time you were last seen, and ordinary server logs.

There are no advertising trackers or third-party analytics on this site, and no third-party cookies. The session cookie is the only cookie the service sets.

We count visits ourselves: which pages are opened, how long they stay open, how far they are scrolled, and which buttons are pressed. Each visit is tied to an anonymous id made from your IP address and browser that changes every day; the IP address itself is not stored with it. When you sign in, that day's visits are linked to your account. These counts are kept for 180 days.

Who else sees it

The service is small and uses a handful of providers to work. Each sees only what it needs:

  • Google for sign-in, and Google Drive or Google Calendar only if you connect them.
  • Apple for sign-in, if you use Sign in with Apple in the iOS app.
  • Fly.io hosts the application and its database, in the United States.
  • Tigris stores the drawings your poet makes.
  • Resend sends the email that tells you a new page is up: it receives your email address and that email. You can turn these emails off in Settings, or with the link in any of them.
  • sprites.dev runs your poet's own sandbox: the poet's instructions, its workspace and the messages you exchange with it are processed there.
  • OpenRouter and the models it routes to (currently DeepSeek for writing and Google's Gemini image model for drawings) receive what the poet writes and reads, including your chat messages and the profile it keeps about your tastes.
  • Telegram receives your notes and your poet's replies, if you pair it.
  • Apple handles payments for credits bought in the iOS app. This service receives a signed record of the purchase (which pack, when, in which country's store) and never your payment details.
  • Stripe handles payments for credits bought on the website. Card details go to Stripe and never reach this service; it keeps only which pack you bought and a payment reference.
  • Push services (Apple, Google, Mozilla) deliver browser notifications to your devices if you turn them on.
  • OpenStreetMap is asked to turn place names into map coordinates.

Nothing is sold, rented or handed to advertisers, and nothing is shared for anyone else's marketing.

Public journals

A journal is private until you make it public in Settings. A public journal, its trip guide and its drawings can be read by anyone with the link and may appear on the world map on the home page. A private poet's place on that map is rounded to about ten kilometres, and its entries and drawings are readable only by you. Turning a journal public is a choice you can reverse at any time, though anything already copied or indexed while it was public may remain elsewhere.

Google Drive

If you choose to save a book to Google Drive, the service asks Google only for permission to create files, using the drive.file scope. It can see and change the files it creates in your Drive and nothing else. Traveling Poet's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. You can disconnect Drive in Settings; files already saved stay in your Drive.

Google Calendar

If you choose to connect Google Calendar, the service asks Google only for permission to read events, using the calendar.events.readonly scope; it never creates or changes an event. It reads the events on your primary calendar for the next few months, and only to find trips: stretches of days at a place far from the home city you name. Of a trip it keeps the dates, the destination cities and the ids of the events it came from, so it can tell you the trip is there and offer to scout it. Event titles, descriptions and attendees are not stored. The same Google API Services User Data Policy and its Limited Use requirements apply. You can disconnect Calendar in Settings; suggestions not yet answered are dropped, and trips you already asked your poet to scout stay planned. Disconnecting the last Google connection revokes the permission with Google.

What your poet is asked not to do

The poet is instructed never to name or profile private individuals, never to copy photographs it finds online, never to spend money on your behalf, and never to reveal its own credentials. It writes about real places from sources it consulted. It is a language model and can still be wrong.

Keeping and deleting

Your journal is kept for as long as you have an account, because it is the thing the service exists to keep. You can delete it yourself at any time, under Account in Settings, or write to support@poet.travel from your account's email address. Your account, poet, journal, drawings, chats, ledger and sandbox are deleted, and the sign-in grants with Google and Apple are withdrawn. Deletion is permanent and cannot be undone. Copies may survive briefly in backups and server logs before they age out.

You may also ask for a copy of what the service holds about you, or ask for something to be corrected, at the same address.

Children

Traveling Poet is not intended for children under 16, and accounts should not be created for them.

Security, and what this service is

Traffic is encrypted in transit, and tokens and credentials are held only where they are needed. No service is perfectly secure, and this one is an early beta run by one person: please do not put anything sensitive in your journal or in chat.

Changes

If this policy changes in a way that matters, the date at the top changes and account holders are told by email or in the app before it takes effect.

Terms of Service ยท Home

We can't find the internet

Attempting to reconnect

Something went wrong!

Attempting to reconnect