Back to Kyvari AI

Kyvari legal

Privacy Policy

Last updated: 17 July 2026

This policy explains how Kyvari AI handles information for travel agents and people viewing or collaborating on their proposals.

Information we collect

We collect account information such as an agent’s email, name, agency profile, subscription and branding settings. We store itinerary content, uploaded briefs, destinations, dates, supplier selections, client details an agent chooses to provide, saved travel assets, enquiries, collaboration email addresses and client feedback.

How we use information

We use information to authenticate users, generate and edit itinerary drafts, enrich travel content, operate share links, deliver collaboration links, process subscriptions, provide support, prevent abuse and improve reliability. We do not sell personal information.

Shared itinerary telemetry

Public proposal links record cookieless engagement events such as a page open, active time, device category, approximate country, day-level dwell, item-detail opens and shares. A random browser-session identifier groups events into a visit. If a viewer submits an enquiry or uses a collaboration magic link, their email and feedback are associated with that itinerary and visible to its owning travel agent.

AI and travel-data providers

Kyvari uses Supabase for database, authentication, storage and Edge Functions; OpenRouter to route itinerary-generation requests to language models; Serper to enrich travel places with search information; and Resend to deliver private collaboration links when configured. Mapping, image and billing providers may also process the minimum data needed for their function. We do not place provider secret keys in the browser.

Public links and collaboration access

Anyone holding an active public proposal link can view the information the agent chose to publish. Client collaboration links are sent to the submitted email address, expire automatically and can be revoked. Collaboration tokens are stored as one-way hashes. Do not forward either type of link to people who should not access the proposal.

Retention and security

Tenant data is protected by Supabase row-level security. We retain account, itinerary, telemetry, enquiry and feedback information while needed to provide the service, meet legal obligations and resolve disputes. No internet service can promise absolute security, so agents should avoid entering unnecessary passport, payment-card or other highly sensitive data.

Your choices

Agents can edit or delete itinerary content and disable share links. Viewers may decline to submit an email. To request access, correction or deletion, contact the travel agent who shared the itinerary or the Kyvari support contact supplied with the service.

Questions about this policy should be sent through the support contact provided in your Kyvari account or to the travel agent who shared the proposal.