CoGo Back home

Privacy Policy

Last updated: July 9, 2026

Who we are

CoGo is operated by Brendan Born, a sole proprietor based in Washington State, USA, doing business as "CoGo." In this policy, "we" / "us" means CoGo and "you" means the person using the product.

The short version

We take privacy seriously. We only collect what we need to run CoGo, we don't sell your data, and you can delete your account at any time.

What we collect

  • Account info: your name, email address, and a password hash when you sign up.
  • Trip data: anything you add to a trip — blocks, notes, travelers, budgets, photos, forwarded booking emails — so we can save and sync it across your group.
  • Basic usage analytics: events like page views and feature usage via PostHog, used to improve the product.
  • Contact form submissions: the name, email, and message you send us via our contact page.
  • Billing info: if you subscribe, Stripe collects and stores your payment method on its own servers; we receive a customer ID and subscription status only.

What we don't collect

We don't collect payment card numbers directly — Stripe handles all card data. We don't track you across the web. We don't sell or rent your data to advertisers, and we don't use your trip content to train AI models.

How we use your data

We use the data above to run the product (sync your trips, send you account emails, parse forwarded booking confirmations using Anthropic's Claude API), to communicate with you about service-related changes, and to improve CoGo over time. We never read your trip content for any other purpose.

Third-party services we rely on

CoGo uses the following providers to operate. Each has its own privacy practices.

  • Supabase — authentication + database hosting
  • Vercel — web hosting + edge functions
  • Postmark — transactional email + inbound email parsing
  • Anthropic — Claude API, used to extract booking fields from forwarded emails
  • Google Gemini — AI extraction of place and booking details from links, videos, and pages you save to a trip feed (including saves made through the browser extension)
  • Stripe — payment processing for subscriptions and printed photo books; shipping address captured at checkout is shared with Stripe and our print partner
  • Prodigi — print + ship partner for photo books; receives the recipient name, shipping address, and the print-ready PDF for each order
  • PostHog — product analytics
  • Mapbox — geocoding + static map images for the Map block
  • Unsplash — stock imagery shown in the image picker

The "Save to CoGo" browser extension

Our optional Chrome extension lets you save the page you're looking at into a trip. It only acts when you click — there is no background collection, and it never collects your browsing history.

  • What it reads, and when:when you click Save, the extension reads the content of the page you're viewing — its title, URL, and page metadata, and on TikTok pages the location data embedded in the page. If you choose to save an open Gmail message, it reads that message's subject and body. It never reads anything without that explicit click.
  • Where it goes:the content you save is sent to CoGo's backend (Supabase) to create your saved card. Page and email text is processed by our AI extraction service (Google Gemini) solely to identify the place or booking details you're saving.
  • What it stores:your CoGo session token in the extension's local storage (so you stay signed in), and the resulting saved cards in your trip's feed. Sign-in itself happens on cogo.travel — the extension never sees your password.
  • Limited Use:data collected by the extension is used only to provide the save-to-trip feature. It is never sold, never used for advertising, and never shared with data brokers. No humans read your email content. Saved cards are deleted along with your trip or account on the schedule described in "How long we keep your data."
  • Opting out:remove the extension from Chrome at any time — this also deletes the session token it stored locally. You can also sign out from the extension, or delete your account from settings as described in "Your rights."

How long we keep your data

We keep your trip data for as long as your account is active. When you delete your account, we delete your trips, blocks, and profile from our production database within 30 days. Backup snapshots may persist for up to 60 days before being cycled out, after which the data is gone for good. We keep server logs for up to 90 days for security and debugging, and minimal billing records for as long as US tax law requires.

Security

All traffic to CoGo is encrypted with HTTPS. Passwords are hashed by Supabase Auth using industry-standard algorithms — we never see your password. We do our best to keep your data safe, but no internet service can guarantee perfect security.

Children

CoGo isn't designed for children under 13. We don't knowingly collect personal information from anyone under 13. If you believe a child has signed up, email us and we'll delete the account.

Your rights

You can export your trip data, edit your profile, or delete your account at any time from settings. You can also email us to request a copy of the data we hold about you, or to ask us to correct or delete it. We'll respond within 30 days.

Changes

If we make meaningful changes to this policy, we'll notify active users by email before the changes take effect.

Contact

Questions about privacy? Reach us through cogo.travel/contact. We respond to every message.