How Traveler uses Google user data

Last updated: July 21, 2026

What we access

Traveler is a travel-companion app. When you choose Import from Google Calendar, we ask Google for read-only access to your Google Calendar events so you can review upcoming events and choose which ones look like trips to import as draft itinerary entries.

The specific Google scopes we request are:

  • https://www.googleapis.com/auth/calendar.calendars.readonly — to list your calendars.
  • https://www.googleapis.com/auth/calendar.events.readonly — to read event titles, dates, locations, and descriptions.
  • https://www.googleapis.com/auth/userinfo.email and https://www.googleapis.com/auth/userinfo.profile — to associate the connection with your Traveler account.
  • openid — standard OpenID Connect sign-in.

We never request write, delete, or share permissions on your calendar. Traveler cannot create, edit, or remove any event in your Google Calendar.

Why we access it

The sole purpose is to let you turn calendar events that look like trips (flights, hotel stays, train journeys, etc.) into draft entries on your Traveler itinerary. Every event we surface is reviewed and confirmed by you before anything appears on your itinerary. We do not use this data for advertising, resale, model training, or any purpose other than helping you build your travel itinerary.

What we store

  • An encrypted per-user connection key issued by our OAuth gateway, so we can refresh the read-only connection on your behalf.
  • The parsed fields of events you explicitly import (title, location, start/end, description) — stored as a trip draft on your Traveler account.

We do not store your full calendar, events you did not import, contacts, attendees, or any other Google data. We do not use Google user data for advertising, resale, or model training.

Who we share it with

We do not share Google user data with any third party. Data is transmitted between Google, our OAuth gateway, and Traveler's own backend over TLS. It is not sold, rented, or transferred to advertisers, data brokers, or AI training providers.

How to revoke access

You can disconnect at any time from your Traveler itinerary page ("Disconnect" on the Google Calendar connection). You can also revoke Traveler from your Google Account permissions page. When you disconnect, we delete the stored connection key immediately. Trip drafts you already imported remain on your Traveler account and can be deleted from within the app.

Limited Use disclosure

Traveler's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Contact

Questions about how we handle Google data? Email hello@jointraveler.com.