← strongtechnicalconsulting.com

Privacy Policy

Erik's Apps · Effective September 25, 2026

This covers every app at strongtechnicalconsulting.com. It is written in plain language and it describes what the code actually does. If something here is unclear, email me and I'll explain it.

Who runs this

Erik's Apps are built and run by Erik Strong (Strong Technical Consulting) in Atlanta, Georgia, USA. They include Trip Planner, the college football app, Hopscotch, Spellbook, DataViz, Friction, the Challenge Lab and its trial apps (challenge.strongtechnicalconsulting.com), the shared account site, this website, and one private, invitation-only family trip app. "I" and "me" below means Erik.

What is collected

Your account

What you put into the apps

The trips, itineraries, notes, packing lists, budgets, trip photos, chat questions and answers, prompts, uploaded data and other things you create. They are stored so the app can show them back to you. Other users can't see them unless you share them yourself: a trip you share with someone by email, which they can then see and change, or a share link.

Payments

Payments are handled by Stripe. I store your Stripe customer ID and your membership status. I never see or store your card number.

Your own API key

If you choose to bring your own Anthropic API key, it is stored encrypted (AES-256-GCM) and used only for your own requests.

Newsletter

If you subscribe to the blog, I store your email address and whether you confirmed or unsubscribed. Every email has an unsubscribe link.

Usage counts

Anonymous view counts: which app and page were opened, the site that linked to it (host name only), and a random ID in a cookie. IP addresses, device details and anything tied to your account are not stored. See also Cookies and analytics.

Receipts, card statements and photos

The trip apps can add spending from a photo of a receipt or from a card statement, and keep a trip's photos as Memories.

Receipt photos

When you scan a receipt, the photo is sent to Anthropic to read the total, the merchant and the date, and shown to you as a suggestion. The photo is not stored. It's read once and dropped. Only the spending line you choose to add is kept.

Card statements

There is no connection to your bank or card, and the apps never see a bank login. You download your statement as a CSV file from your card's website and upload it. The file is read once to list the charges that fall within the trip, and then discarded. Only the charges you tick are saved. Statements are not sent to any AI.

Photos

The Challenge Lab

The lab is where new apps are tried out, one a day. The same account, rules and protections apply, plus these:

Gmail and Google data

Trip Planner, and the private trip app, can read your travel booking confirmations from Gmail and offer to turn them into trips or bookings. This is off unless you connect Gmail yourself, and you can disconnect at any time.

What is accessed

Google's only permission for reading email is gmail.readonly, so Google's screen will say the app can "read your email." What the apps actually do is narrower, and the code enforces it:

How it is used

The text of those messages is used only to pull out booking details, such as flights, hotels, rental cars, reservations and confirmation numbers, and show them to you as a suggestion. Nothing is saved until you tap to add it. What you add becomes part of your trip, like anything else you type in.

What is stored

Who else sees it

To extract booking details, the message text is sent to Anthropic, which provides the AI model. It is sent only for that purpose, and Anthropic processes it under its commercial API terms, which do not allow it to train its models on that data. It is not shared with anyone else, not sold, and not used for advertising. I don't read your email. The only exceptions: if you ask me to help with a problem, if it's needed for security, or if the law requires it.

Google user data is never used to develop, improve or train AI or machine-learning models.

Disconnecting

Tap Disconnect Gmail in the app. This revokes access at Google first, then deletes the stored token. You can also remove access at any time from your Google Account at myaccount.google.com/permissions.

Erik's Apps' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Who else sees it

I don't sell your data and there is no advertising. These companies process data only to run the apps:

I would also disclose data if the law required it, or to protect the apps or their users from fraud or abuse.

Cookies and analytics

How long it's kept

Your account and what you create are kept until you delete them or ask me to. Payment records are kept as long as tax and accounting law requires. A Gmail token is kept until you disconnect or Google ends the connection. Email contents, receipt photos, lab app photos and statement files are never kept.

Deleting your data

Security

All traffic is encrypted with HTTPS. Passwords are hashed. API keys and Gmail tokens are encrypted. Each app runs under its own restricted service account that can reach only the data that app needs. No system is perfectly secure. If I learn of a breach that affects your data, I'll tell you.

Children

The apps are not meant for children under 13, and I don't knowingly collect data from them. If you believe a child has created an account, email me and I'll delete it.

Changes

If this policy changes, the date at the top changes too. If a change affects how your data is used, especially Gmail data, I'll say so in the app before it takes effect, and I won't use data you already gave for a new purpose without asking.

Contact

Erik Strong · erik.strong@strongtechnicalconsulting.com · Atlanta, Georgia, USA

Terms of Service · Home