Kyvari legal
Privacy Policy
Last updated: 17 July 2026
This policy explains how Kyvari AI handles information for travel agents and people viewing or collaborating on their proposals.
Information we collect
We collect account information such as an agent’s email, name, agency profile, subscription and branding settings. We store itinerary content, uploaded briefs, destinations, dates, supplier selections, client details an agent chooses to provide, saved travel assets, enquiries, collaboration email addresses and client feedback.
How we use information
We use information to authenticate users, generate and edit itinerary drafts, enrich travel content, operate share links, deliver collaboration links, process subscriptions, provide support, prevent abuse and improve reliability. We do not sell personal information.
Shared itinerary telemetry
Public proposal links record cookieless engagement events such as a page open, active time, device category, approximate country, day-level dwell, item-detail opens and shares. A random browser-session identifier groups events into a visit. If a viewer submits an enquiry or uses a collaboration magic link, their email and feedback are associated with that itinerary and visible to its owning travel agent.
AI and travel-data providers
Kyvari uses Supabase for database, authentication, storage and Edge Functions; OpenRouter to route itinerary-generation requests to language models; Serper to enrich travel places with search information; and Resend to deliver private collaboration links when configured. Mapping, image and billing providers may also process the minimum data needed for their function. We do not place provider secret keys in the browser.
Public links and collaboration access
Anyone holding an active public proposal link can view the information the agent chose to publish. Client collaboration links are sent to the submitted email address, expire automatically and can be revoked. Collaboration tokens are stored as one-way hashes. Do not forward either type of link to people who should not access the proposal.
Retention and security
Tenant data is protected by Supabase row-level security. We retain account, itinerary, telemetry, enquiry and feedback information while needed to provide the service, meet legal obligations and resolve disputes. No internet service can promise absolute security, so agents should avoid entering unnecessary passport, payment-card or other highly sensitive data.
Your choices
Agents can edit or delete itinerary content and disable share links. Viewers may decline to submit an email. To request access, correction or deletion, contact the travel agent who shared the itinerary or the Kyvari support contact supplied with the service.
Questions about this policy should be sent through the support contact provided in your Kyvari account or to the travel agent who shared the proposal.