Privacy notice
Clear about the account data MichiWise keeps.
This notice describes the current MichiWise Japan prototype. It describes the product as it operates today, not a promise about services that are not connected.
Google account and trip data
What MichiWise stores.
Google sign-in
When you choose to sign in, MichiWise uses Google's OAuth sign-in flow. In dedicated MichiWise authentication tables, it stores your verified Google email, Google display name, Google account subject identifier, active session records, and encrypted OAuth token material returned for sign-in. MichiWise requests only the basic OpenID, email, and profile scopes. It does not request offline access.
Saved-trip ownership
Saved trips, shares, anonymous shortlist ballots, feedback, rewrite quotas, and expense ledgers do not store your email address. The server derives separate one-way owner and voter identifiers from your verified email and a server secret. This preserves access to existing records when the same Google email is used.
Because those identifiers differ per account, two Google accounts see two separate trip lists. The saved-trips page intentionally has no separate account-identity panel; the site header, mobile menu, and footer show it on every page once you are signed in, alongside a sign-out control. That global account control reads the verified email in your own browser from your own MichiWise session, and no other visitor's browser can request it. The email is only displayed: that path does not write it into any saved trip, share, ballot, feedback, ledger, or measurement record; log it; send it to another service; or use it for a permission decision. If MichiWise cannot confirm the email, the header, menu, and footer say the sign-in status could not be checked rather than naming an account or implying you are signed out.
MichiWise Pro payments
Paid MichiWise Pro subscriptions may not be open yet. If you choose to buy MichiWise Pro when subscriptions are available, MichiWise creates a Stripe Checkout session. When your account has no stored Stripe customer, it sends your verified account email to Stripe in that checkout-session request to prefill Stripe's checkout page. When MichiWise has a stored Stripe customer for the account, later checkout sessions use that customer instead. Payment details, including card numbers, are entered on Stripe's hosted pages and never touch MichiWise.
MichiWise stores no email in subscription records. It stores the subscription status and paid-through date from which it derives entitlement, keyed by the same one-way owner identifier described above, plus Stripe customer and subscription identifiers so Stripe's delivery notifications can be matched to that account. Cancellation, card changes, and invoice history are managed in Stripe's hosted billing portal. Stripe processes that data under Stripe's own privacy policy.
Trip content and browser storage
A generated itinerary first remains in the current browser tab. If you explicitly save it, MichiWise stores the validated itinerary and the collaboration data you choose to create in its D1 database. Private share links use a random secret; MichiWise stores only a hash of that secret.
Other services
Planner answers and optional notes are sent to a third-party AI planning service only when you request an AI-generated or rewritten trip. Cloudflare processes the human-verification check. When the owner has enabled the selected-day Google Maps Embed route, its displayed stop names and places are sent to Google to calculate that iframe route; the referrer-restricted Embed key is visible in that request by design. If you deliberately select an affiliate action, Travelpayouts and the named provider receive the values required for that selected link. The separate eSIM action uses only a neutral Japan eSIM query; it does not include your trip origin, gateways, dates, or traveller count. MichiWise does not send your Google email or display name to those services for planning or links.
Prototype measurement
To improve this prototype, MichiWise records limited product-measurement data in its own database. Existing, separately scoped records hold only category identifiers, short enumerated selections, counts, and timestamps. They never include your itinerary content, the free text you type (planner notes, feedback notes, or rewrite instructions), the prompts sent to the AI planning service, your IP address, or your email. MichiWise does not send this measurement data to the planning, map, or booking services described above.
MichiWise attempts to increment a separate anonymous affiliate-funnel D1 daily aggregate when a supported browser shows the booking-hub entrance or when you select a booking action. Because this measurement is best-effort, an attempted increment is not a guarantee that a count was written. A written aggregate stores only a Japan-calendar day, affiliate category, placement, event type, coarse failure category, and count. It does not store a person, account, trip, generation ID, request ID, provider identifier, URL, search query, place, origin, gateway, travel date, IP address, credential, or raw timestamp. A trip identifier is verified before an aggregate is accepted but is not kept in it. These anonymous daily counts are retained indefinitely; MichiWise does not send them to booking providers or use them to claim a purchase or revenue.
Specifically, for each trip you generate MichiWise records whether validation passed, how many correction attempts were needed, which route-quality categories needed correction, the selected regional packs and their coverage tier, the planning mode, the model, and the trip length; that generation record is kept against the individual request only and is not linked to your account. When you refine a saved day, it records the day number and an optional reason you may pick from a short list. When you mark optional or flexible stops on a saved trip as skipped, it records those stop positions; refining a day or re-saving that itinerary clears them, because the recorded positions no longer describe the same stops. It keeps per-account counts of how many trips you save, share, and reopen; a save is counted once per new trip rather than on each re-save, and a reopen is counted only when you return on a later day. Trip feedback may include optional 1–5 ratings for pace, route coherence, and interest fit. The account-linked measures use the same one-way owner identifier described above, never your email.
Keep sensitive details out
Do not put passport, payment, medical, contact, or other sensitive details into planner fields, trip feedback, or rewrite instructions. MichiWise is a planning prototype and is not a booking, identity-verification, or emergency service.