Controller
Tsugukura (Switzerland). Contact: contact@tsugukura.jp.
The site is shared by link and is not indexed by search engines (a noindex header on every response).
Cookies
- Session cookie — set only after the notebook password is entered, to keep you signed in (60 rolling days). HttpOnly, secure, used for nothing else.
- Demo cookie — set only when you start the demo, to tie your two phones to your sandbox (90 minutes at most).
No other cookie, no tracker. Refusing these cookies amounts to not signing in or not starting the demo: the rest of the site stays readable.
The notebook and the demo also keep settings and ticked boxes in the browser’s local storage, on your device. The demo uses separate keys, replaced with every new demo.
Demo
Starting the demo creates a temporary sandbox on the server, filled with a fictional trip. No personal data is asked for; what you write there (notes, spending, messages to the demonstration assistant) stays in that sandbox.
The sandbox is wiped after 20 minutes without activity, and 90 minutes after it was created at the latest. To limit abuse, the server counts, for one hour, the demos started from each IP address. The demo assistant is scripted: nothing is sent to an AI provider.
Do not write personal data into the demo: it is made to be tried, not to be kept.
Server logs
Like any website, the proxy and the server record technical logs: IP address, date, requested address, response code. They serve security (limiting password attempts and demo creations) and fault diagnosis, never profiling or advertising.
Services your browser contacts
Some functions of the notebook query third-party services straight from your browser. As with any web request, those services receive your IP address.
- Open-Meteo — the weather for a day of the trip within the next 16 days.
- 国土地理院 (Geospatial Information Authority of Japan) — map tiles for the cards to show, in the demo.
- Wikimedia — Wikipedia summaries and images for places without a photo.
- frankfurter.dev — exchange rates, only when you ask for an update.
The Google Maps, Apple Maps, Uber, Airbnb and Booking buttons are plain links: those services are only contacted if you press them, and their own rules apply from that point on.
Private notebook
For signed-in travellers, the plan, the shared state, “My details”, the conversations and the documents on file are stored on the server in Switzerland and backed up every night, encrypted. Documents and API keys are encrypted with AES-256-GCM.
When the travellers use the assistant, the server passes on to the AI provider they chose, with their own key:
- their messages;
- the parts of the plan and of the shared state that the assistant reads: ticked steps, notes, spending, chosen lodging;
- the metadata of every document on file (name, note, traveller, day, who filed it), including those marked not readable by the assistant;
- the text of documents marked readable.
“My details” is never passed to the assistant.
Your rights
You may ask which data concerns you (right of access, art. 25 of the Swiss Federal Act on Data Protection), have it corrected or erased, by writing to contact@tsugukura.jp.