← strongtechnicalconsulting.com
Privacy Policy
This covers every app at strongtechnicalconsulting.com. It is written in plain language and it describes what the code actually does. If something here is unclear, email me and I'll explain it.
Who runs this
Erik's Apps are built and run by Erik Strong (Strong Technical Consulting) in Atlanta, Georgia, USA. They include Trip Planner, the college football app, Hopscotch, Spellbook, DataViz, Friction, the Challenge Lab and its trial apps (challenge.strongtechnicalconsulting.com), the shared account site, this website, and one private, invitation-only family trip app. "I" and "me" below means Erik.
What is collected
Your account
- Email address, to identify your account and sign you in.
- Password, stored only as a one-way salted hash, never as the password itself.
- Passkeys (Face ID / Touch ID), stored as public keys. Your fingerprint or face never leaves your device.
- Usage balance: how much of your AI allowance or credit you have spent, and whether you have a membership.
What you put into the apps
The trips, itineraries, notes, packing lists, budgets, trip photos, chat questions and answers, prompts, uploaded data and other things you create. They are stored so the app can show them back to you. Other users can't see them unless you share them yourself: a trip you share with someone by email, which they can then see and change, or a share link.
Payments
Payments are handled by Stripe. I store your Stripe customer ID and your membership status. I never see or store your card number.
Your own API key
If you choose to bring your own Anthropic API key, it is stored encrypted (AES-256-GCM) and used only for your own requests.
Newsletter
If you subscribe to the blog, I store your email address and whether you confirmed or unsubscribed. Every email has an unsubscribe link.
Usage counts
Anonymous view counts: which app and page were opened, the site that linked to it (host name only), and a random ID in a cookie. IP addresses, device details and anything tied to your account are not stored. See also Cookies and analytics.
Receipts, card statements and photos
The trip apps can add spending from a photo of a receipt or from a card statement, and keep a trip's photos as Memories.
Receipt photos
When you scan a receipt, the photo is sent to Anthropic to read the total, the merchant and the date, and shown to you as a suggestion. The photo is not stored. It's read once and dropped. Only the spending line you choose to add is kept.
Card statements
There is no connection to your bank or card, and the apps never see a bank login. You download your statement as a CSV file from your card's website and upload it. The file is read once to list the charges that fall within the trip, and then discarded. Only the charges you tick are saved. Statements are not sent to any AI.
Photos
- Private. Photos are stored in private Google Cloud storage and are shown only to someone signed in to the account that owns the trip. They're never given a public link.
- No location. Your phone makes a smaller copy of each photo before uploading it, and that copy doesn't carry the photo's embedded location or camera details. The only thing kept is the date and time it was taken, so it's filed under the right day.
- Not sent to AI. Photos are not sent to Anthropic or any other AI service.
- Deleted with the trip. Deleting a photo, or the trip it belongs to, deletes the stored copies too.
The Challenge Lab
The lab is where new apps are tried out, one a day. The same account, rules and protections apply, plus these:
- Photos you snap in a lab app (a job site, an invoice, a review screenshot, a handbook page, a listing, a business card, a whiteboard) are sent to Anthropic to be read once, and are not stored. Only the details you choose to keep are saved.
- Voice notes are turned into text by your own browser's speech recognition. The app only receives the text.
- Other people's details. Some apps let you record details about other people, such as trade-show leads, team members or meeting attendees. Only add what you have a right to share. They are visible only to you and anyone you invite to that event or team, and are never shown publicly or used for anything else.
- Voting without an account. The lab's keep-or-kill votes, and votes in a meeting room, use a random ID in a cookie so each browser counts once. No IP address or device details are stored with them.
- Notes to Erik left in the lab go only to me. They are never displayed.
- Retired apps. Apps that are voted down are retired. Email me and I'll send you, or delete, whatever you stored in one.
Gmail and Google data
Trip Planner, and the private trip app, can read your travel booking confirmations from Gmail and offer to turn them into trips or bookings. This is off unless you connect Gmail yourself, and you can disconnect at any time.
What is accessed
Google's only permission for reading email is gmail.readonly, so Google's screen will say the app can "read your email." What the apps actually do is narrower, and the code enforces it:
- A fixed search. The apps search only for messages from a fixed list of about 100 travel companies, in nine groups: airlines, hotels and stays, car rentals, booking sites, trains and buses, cruises, tours and tickets, restaurants, and parking. The search covers the last 12 months only. The list is written into the code, and nothing you type or a request sends can widen it. It skips Gmail's Promotions and Social tabs.
- Forwarded bookings. It also finds emails from those same companies that were forwarded to you, such as a booking made from a work address. That means messages whose subject starts "Fwd" or "FW" and whose text names one of those companies' email domains. No other forwarded mail is searched.
- At most 40 messages per scan, and only when you tap to scan.
- Read-only. The apps can't send, delete, label or change anything in your mailbox.
How it is used
The text of those messages is used only to pull out booking details, such as flights, hotels, rental cars, reservations and confirmation numbers, and show them to you as a suggestion. Nothing is saved until you tap to add it. What you add becomes part of your trip, like anything else you type in.
What is stored
- Email contents are never stored. They are read once for the scan and then discarded. The only thing kept is the booking details you choose to save.
- A Google access token is stored, encrypted (AES-256-GCM) and tied to your account, so the app can scan again when you ask.
Who else sees it
To extract booking details, the message text is sent to Anthropic, which provides the AI model. It is sent only for that purpose, and Anthropic processes it under its commercial API terms, which do not allow it to train its models on that data. It is not shared with anyone else, not sold, and not used for advertising. I don't read your email. The only exceptions: if you ask me to help with a problem, if it's needed for security, or if the law requires it.
Google user data is never used to develop, improve or train AI or machine-learning models.
Disconnecting
Tap Disconnect Gmail in the app. This revokes access at Google first, then deletes the stored token. You can also remove access at any time from your Google Account at myaccount.google.com/permissions.
Erik's Apps' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Who else sees it
I don't sell your data and there is no advertising. These companies process data only to run the apps:
- Google Cloud: hosting and the databases everything above is stored in (United States).
- Anthropic: the AI model. It receives what you ask the AI features and the context needed to answer, such as a trip's details, the Gmail messages described above, a receipt photo you scan, or a photo you snap in a lab app.
- Stripe: payments.
- Google Analytics: usage statistics on the public apps (see below).
- Resend: sends newsletter and password-reset email.
- MET Norway and OpenStreetMap Nominatim: Trip Planner's weather. They receive only a trip's destination name or map coordinates, never who you are.
- Frankfurter (European Central Bank reference rates): Trip Planner's exchange rates for trips abroad. It receives only a currency code such as "USD", never the trip, the place or who you are.
- Open Brewery DB: Trip Planner's brewery crawls. It receives the map coordinates of the place you search near, never who you are.
- OpenStreetMap: the map on a brewery crawl. Your browser loads the map images directly from OpenStreetMap, so it sees your internet address and the area on screen, as with any map on the web.
I would also disclose data if the law required it, or to protect the apps or their users from fraud or abuse.
Cookies and analytics
- Sign-in cookies keep you signed in. They're required for the apps to work.
- A random visitor ID for the anonymous view counts above.
- A random voter ID in the Challenge Lab, so each browser's keep-or-kill vote counts once.
- Google Analytics runs on the public apps and sets its own cookies, to show which pages are used. It doesn't run on the admin pages or on the private trip app. You can block it with any content blocker, or with Google's opt-out add-on. The apps work the same either way.
How long it's kept
Your account and what you create are kept until you delete them or ask me to. Payment records are kept as long as tax and accounting law requires. A Gmail token is kept until you disconnect or Google ends the connection. Email contents, receipt photos, lab app photos and statement files are never kept.
Deleting your data
- Delete a trip, list, photo or other item from inside the app. Deleting a trip deletes its photos too.
- Delete your account from the account page. That removes the sign-in, but not what you made inside each app, so delete those items first or ask me to.
- To have everything removed from every app, or to get a copy of your data, email me from the address on your account. I'll do it within 30 days and confirm when it's done.
Security
All traffic is encrypted with HTTPS. Passwords are hashed. API keys and Gmail tokens are encrypted. Each app runs under its own restricted service account that can reach only the data that app needs. No system is perfectly secure. If I learn of a breach that affects your data, I'll tell you.
Children
The apps are not meant for children under 13, and I don't knowingly collect data from them. If you believe a child has created an account, email me and I'll delete it.
Changes
If this policy changes, the date at the top changes too. If a change affects how your data is used, especially Gmail data, I'll say so in the app before it takes effect, and I won't use data you already gave for a new purpose without asking.
Contact
Erik Strong · erik.strong@strongtechnicalconsulting.com · Atlanta, Georgia, USA