Privacy Notice
Effective: 2 September 2026
Last updated: 30 September 2026
1. Introduction and scope
This notice explains how FarSerene handles personal information when you visit farserene.com, create or save a trip, use account features, submit feedback, or contact us. It does not govern travel suppliers, booking partners, or other third-party sites you visit from our service.
2. Who we are
FarSerene is an AI-assisted travel-planning and comparison service operated through farserene.com. For privacy questions, contact privacy@farserene.com.
3. Personal information we collect
Information you provide
- Trip information: prompts, destinations, dates, budget, currency, party size, transport preferences, interests, constraints, and generated itineraries.
- Account information: email address and account identifier when you use passwordless sign-in.
- Feedback and support: ratings, comments, optional contact email, and correspondence.
Information collected automatically
- a random session identifier and session creation time;
- security and rate-limit information, including IP address where needed to prevent abuse and verify requests;
- events such as generating, viewing, saving, comparing, or selecting an affiliate link;
- device, browser, page-view, and interaction information through an analytics service only if you consent.
We do not ask for payment-card or government-identification details. Do not include passport numbers, health information, or other sensitive personal information in a trip prompt.
4. How and why we use personal information
| Purpose | Legal basis where GDPR or UK GDPR applies |
|---|---|
| Generate, display, save, and compare itineraries; manage accounts and sign-in | Performance of our contract with you |
| Secure the service, prevent abuse, enforce limits, and diagnose failures | Legitimate interests in a safe, reliable service |
| Record product interactions and improve ranking and itinerary quality | Legitimate interests in improving the service, subject to your right to object |
| Measure site use with an analytics service | Consent |
| Respond to support, privacy, and legal requests | Contract, legitimate interests, or legal obligation, depending on the request |
5. AI-assisted processing
Most trip requests are read by FarSerene's own parser, and itinerary summaries are produced by FarSerene's own rules, without an AI service. When a free-text request cannot be read that way, we may send it to an AI processing service to interpret it. Information sent for this purpose can include your prompt and structured trip preferences. FarSerene records limited model-usage metadata—model, route, time, and token counts—but not the prompt in that usage log. Generated plans, whether or not AI was involved, may be incomplete or wrong. Confirm prices, availability, hours, schedules, entry rules, health and safety requirements, and other important details with the provider or official authority.
6. Cookies and similar technologies
We use a necessary session cookie and store your consent and display-currency choices in your browser. Google Analytics is loaded only after you accept analytics, so nothing is sent to Google before you choose, and advertising is not active. Fonts are served from farserene.com, not from a third party. Change your choice at any time through Privacy and cookie settings in the footer. See our Cookie Policy.
7. How we share personal information
We share information only as needed to operate the service, comply with law, or protect users and the service. Recipients may include hosting and security services, email delivery services, consent-based analytics services, AI processing services, and travel or booking providers you choose to visit. Each service is governed by its own applicable terms and privacy notice.
We do not collect or share payment details. We do not sell personal information.
8. International transfers
Service providers may process personal information outside your country. Where required, we use an applicable lawful transfer mechanism and appropriate safeguards.
9. Retention
- Anonymous trip records and associated product events are deleted after 30 days.
- The session cookie expires after 30 days; magic-link tokens after 15 minutes.
- Account information and saved trips remain until account deletion, subject to necessary legal, security, or dispute retention.
- Operational ingestion records are deleted after 90 days.
- Feedback, security logs, consent records, provider records, backups, and inactive accounts are retained only for as long as necessary for their stated purpose or a legal obligation.
10. Security
We use HTTPS, secure HTTP-only cookies, signed anonymous sessions, short-lived single-use sign-in links, access controls, request validation, rate limits, and infrastructure security controls. No online service is risk-free; we cannot guarantee absolute security.
11. Your privacy rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your information, and to withdraw consent. Withdraw optional consent through Privacy and cookie settings. Signed-in users can use account deletion. For other requests, email privacy@farserene.com. We may verify identity and may limit a request where law permits.
You may complain to the data-protection authority where you live or work. We do not use solely automated processing to make decisions producing legal or similarly significant effects about you.
12. Children
FarSerene is intended for people aged 18 or older. If we learn that we collected a child's information contrary to this rule, we will take reasonable steps to delete it. Applicable age thresholds and local exceptions may vary by jurisdiction.
13. Changes and contact
We may update this notice as the service, providers, or requirements change. We will update the date above and provide additional notice where a change materially affects your rights or our use of personal information. Contact privacy@farserene.com.