Privacy Policy
Last updated 2 August 2026
Michi is a trip planner. This page explains exactly what it stores about you, why, who else sees it, and how to get it back or get rid of it. It describes what the product actually does — not what it might do one day.
Who is responsible
Michi is operated by Ofek Merhav, a sole trader based in Israel, acting as the data controller. For anything in this policy, including requests about your data, contact ofekmerhav08@gmail.com.
What Michi collects
Account information
You sign in with Google. Michi receives and stores your name, email address, profile photo URL, and Google account identifier. Your name, email, and initials are also copied into the member record of each trip you belong to, so that the people you travel with can see who is on the trip.
Trip content
Everything you put into a trip: its name, destination, dates and timezone; each day; the places you save, including their names, addresses, coordinates, and any notes, links, reservation details, or prices you add; your activities and their times; your categories; and the travel legs between stops.
Place searches
When you search for a place, the text you type — and, if available, a rough map position used to bias results toward where you are looking — is sent to our mapping providers to fetch results. Michi does not keep a history of your searches.
Technical information
Our hosting provider records standard server logs, including IP address, timestamp, and browser user agent. Your browser also stores a small display preference locally, and caches part of the app so it works offline. Neither is sent to us.
If you connect ChatGPT
Connecting Michi to ChatGPT is optional and off unless you set it up. If you do, an identity provider issues a token that identifies you to Michi, and the assistant can read the trips you belong to and propose changes to them. Anything the assistant reads is processed by OpenAI under its own privacy policy. Michi never sends your data to OpenAI unless you have connected the two yourself.
Anonymous counts
Michi keeps a small set of counters so it can tell how the product is doing — how many trips get created in a month, how many invitations are accepted, and so on. These are plain numbers stored in Michi's own database, one total per month. They record no user identifier, no session, no device, and nothing that could be linked back to you or to a particular trip. They cannot be used to reconstruct what any individual did.
Why Michi uses it, and on what basis
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Signing you in and keeping your account | Account information | Performance of a contract |
| Storing and syncing your trips | Trip content | Performance of a contract |
| Sharing a trip with people you invite | Name, email, initials | Performance of a contract |
| Returning place and route results | Search text, coordinates | Performance of a contract |
| Keeping the service secure and available | Technical information | Legitimate interests |
| Taking payment, once paid plans exist | Account identifier, billing status | Performance of a contract |
Who else receives it
Michi uses a small number of providers to run. They process data on Michi's behalf and are not permitted to use it for their own purposes, except where they act as their own controller as noted.
| Provider | What it receives | Why |
|---|---|---|
| Google (Firebase, Cloud Run, Cloud Functions, Hosting) | Account information, trip content, technical logs | Authentication, database, and hosting |
| Geoapify | Search text and coordinates | Place search and route calculation |
| Komoot Photon / OpenStreetMap | Search text and coordinates | Fallback place search |
| Auth0 (Okta) | Email address and sign-in events | Identity for the optional ChatGPT connection |
| OpenAI | Trip content you ask the assistant about | Only if you connect ChatGPT yourself; OpenAI acts as its own controller |
| Polar | Billing details you enter with them | Payments, once paid plans exist. Polar is the merchant of record and handles card details; Michi never sees your card number |
Where your data is held
Michi's database, server, and functions run in Google Cloud's us-central1 region in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, this means your data is transferred outside your region. Those transfers rely on the European Commission's Standard Contractual Clauses, which Google incorporates into its terms.
How long it is kept
- While your account is open — your account information and trip content are kept so the product works.
- If you close your account — your account is disabled and you can no longer sign in. Your trip content is kept, because trips are shared: deleting yours would remove itinerary data the people you travel with are still relying on. Your name and email remain on the trip's member record so co-travellers can see who made what, unless you ask for erasure.
- If you ask for erasure — your name, email, and initials are removed from every trip member record and replaced with an anonymous placeholder, and your account information is deleted. Trip content you created stays with the trip, no longer linked to you by name.
- If you delete a trip you own — the trip and everything inside it is permanently deleted straight away.
- Pending assistant proposals — deleted automatically 15 minutes after they are created.
- Server logs — kept according to Google Cloud's standard retention, generally around 30 days.
Your rights
Wherever you live, you can ask Michi to give you a copy of your data, correct it, delete it, or stop using it, and you can export your trips from inside the app at any time. Email ofekmerhav08@gmail.com and you will get an answer within 30 days.
If you are in the EEA, the UK, or Switzerland, you have the rights of access, rectification, erasure, restriction, portability, and objection under the GDPR, and you may complain to your local data protection authority.
If you are in California, you have the right to know what is collected, to delete it, to correct it, and not to be discriminated against for exercising those rights. Michi does not sell or share personal information as the CCPA defines those terms, so there is nothing to opt out of.
Security
Traffic is encrypted in transit. Access to trip data is enforced on the server by membership rules, so a person who is not a member of a trip cannot read it. Access to Michi's own infrastructure is limited to the operator. No service can promise perfect security, and this one does not.
Children
Michi is not intended for children under 13, and accounts may not be created by them. If you believe a child under 13 has an account, email ofekmerhav08@gmail.com and it will be removed.
Changes
If this policy changes in a way that materially affects you, the date at the top will change and you will be told in the app before the change takes effect.