Privacy Policy

Last updated: August 29, 2026

1. Introduction

Adventure Getter is operated by Mason Stanton Bartlett, a sole proprietor located in Austin, Texas. References to "Adventure Getter," "we," "our," or "us" mean the same person. We operate a web application for planning trips around your available time.

This Privacy Policy describes what data we collect, why we collect it, how we store it, who we share it with, and what rights you have. By using Adventure Getter, you agree to this policy.

2. Data We Collect

  • Name and email address — provided at signup, used to identify your account and to send password-reset emails
  • Password — stored only as a one-way bcrypt hash. We never store, and cannot recover, your actual password
  • Session records — for each signed-in session we record the IP address and browser user agent, so you can recognise unfamiliar activity and so we can investigate abuse
  • Trip content you create — adventures, itinerary items, cost figures, research and free-text notes, availability windows (labels and dates), your annual plan, and the candidates you shortlist against it
  • AI generation requests — the trip idea, home base, party size, and notes you submit for generation, along with the generated result, any error, and metering figures (input and output token counts, number of searches)
  • Share tokens — random public identifiers created when you publish an adventure or create a plan share link

We do not collect payment card or bank details, phone numbers, precise device geolocation, or contacts. We do not run third-party analytics, advertising, or tracking scripts.

Note that "home base" and any location you type into an adventure are free text you supply. Treat them as data you are choosing to store, and avoid entering a precise home address if you plan to share that content.

3. Why We Collect It

We use this data to operate the Service: to authenticate you, to store and display the trips and plans you create, to run AI generation you request, to match adventures to your availability windows, to enforce usage quotas and rate limits, to send password-reset email, and to diagnose failures and improve reliability.

4. How Data Is Stored

Data is stored in a PostgreSQL database hosted by our cloud infrastructure provider on servers located in the United States. Traffic to the Service is served over HTTPS. Passwords are hashed with bcrypt. Your session cookie is signed, HTTP-only, and same-site restricted. Application secrets and API keys are held in environment configuration, not in the database.

No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

5. Third-Party Data Sharing

We share data only as needed to operate the Service:

  • Anthropic (Claude) — when you request an AI generation, the trip idea, home base, party size, and notes you entered are sent to Anthropic's API, and the generated record is returned to us. Your name, email address, and password are not sent. Anthropic's commercial API terms prohibit using this data to train models. Anthropic may retain inputs and outputs for a limited period for trust and safety purposes. See Anthropic's privacy policy.
  • Web search during generation — generation uses a server-side web search tool operated by Anthropic. Search queries derived from your trip description, and requests to the websites returned, are made by that provider on our behalf. Those queries may reflect the destination and details you entered.
  • Hosting and database provider — stores and serves all application data, and processes request logs including IP addresses.
  • Email delivery provider — receives your email address in order to deliver password-reset messages.
  • Google Fonts — our pages load a web font from Google's font servers. Your browser makes that request directly, and Google receives your IP address and user agent as a result. We send Google no account data.

We do not sell, rent, or share your personal information with third parties for marketing or advertising purposes. The only parties that receive data are the service providers listed above, and only to the extent necessary to operate the Service. Each provider has its own privacy policy governing its use of data.

6. Public Sharing and Visibility

Adventure Getter includes deliberate sharing features, and content you share stops being private:

  • Publishing an adventure, or creating a plan share link, produces a URL containing a random unguessable token
  • Anyone who has that URL can view the shared content without signing in, and may copy it into their own account
  • Shared content includes the notes and cost figures attached to it. It is not filtered for anything sensitive
  • Copies other users have already made remain in their accounts after you revoke a link or unpublish an adventure

Do not put private, sensitive, or third-party information into content you publish or share.

7. AI-Generated Content

Adventure Getter uses artificial intelligence to research and draft adventure records. AI-generated content may contain errors, outdated information, or fabricated details — including permit rules, fees, prices, drive times, and seasonality. Confidence indicators shown in the app are the model's own self-assessment, not verification. The Service is not a substitute for professional advice, and generated trip information should be confirmed with the relevant agency or operator before you rely on it. See our Terms of Service for the full disclaimer.

8. Data Retention

  • Account data (name, email, password hash) — retained for the life of your account, and deleted within 30 days of a deletion request
  • Trip content (adventures, itineraries, plans, availability windows) — retained until you delete it or your account is deleted
  • AI generation records (your prompt, the generated payload, errors, token and search counts) — retained while your account is active so you can revisit a generation, and deleted with your account
  • Session records (IP address, user agent) — retained until the session is signed out or your account is deleted
  • Server and application logs — retained for a short period by our hosting provider for operational and security purposes
  • Aggregated, anonymised usage figures — may be retained indefinitely for product improvement

Copies of content you published or shared that other users have saved into their own accounts are their data, and are not removed when you delete yours.

9. Your Rights

You may request a copy of your data, correction of inaccurate data, or deletion of your account and its associated data. To make a request, contact support@one-less.io. We may need to verify your identity — typically by confirming control of the account's email address — before acting on a request.

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to know — the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties we share it with
  • Right to delete — subject to exceptions such as legal obligations
  • Right to correct — inaccurate personal information
  • Right to opt out of sale or sharing — we do not sell or share personal information as defined by the CCPA. If that ever changes, we will provide an opt-out mechanism
  • Right to non-discrimination — we will not discriminate against you for exercising these rights

To exercise any of these rights, contact support@one-less.io. We will respond within 45 calendar days.

11. Data Breach Notification

In the event of a data breach affecting your personal information, we will notify you promptly and in accordance with applicable state law, by email to the address on your account. Our notice will describe the nature of the breach, the data affected, and the steps you can take to protect yourself.

12. Cookies and Local Storage

We set one cookie: a signed session cookie that keeps you logged in. We also store your light or dark theme preference in your browser's local storage; that value never leaves your device. We do not use third-party tracking, analytics, or advertising cookies.

13. International Users

Adventure Getter is currently offered only to users in the United States, and all data is stored in the United States. We do not knowingly offer the Service to individuals located in the European Union, European Economic Area, or the United Kingdom. If you are located outside the United States, please do not use this Service.

14. Children (COPPA)

Adventure Getter is not intended for users under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at support@one-less.io and we will delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. Material changes will be communicated by email or in-app notice where appropriate.

16. Contact

For privacy inquiries, data requests, or questions about this policy, contact support@one-less.io.