Privacy Policy

This policy explains what Zuzli stores, which services it relies on, and how your trip data is used. It describes the product as it is currently built.

Last updated: August 3, 2026

Who operates Zuzli

Zuzli is an independently developed travel-planning project operated by Nati Tal, an independent developer based in Israel. It is currently available to a limited group as part of a closed beta for testing, evaluation, and continued product development.

The service is currently free of charge. There are no subscriptions, purchases, payment obligations or financial commitments, and Zuzli does not process payments or store payment-card information. Beta access may be limited, manually approved, changed, suspended or discontinued, features may change during development, and there is no service-level commitment or guarantee of continued availability. If paid features are introduced in the future, users will be informed before any charge applies.

For any privacy question or request, contact support@zuzli.app or use the support page.

What Zuzli is

Zuzli connects trip planning done in ChatGPT with a visual travel app. An itinerary that you plan in a chat can be created and updated in Zuzli, where you can see it on a map, day by day and stop by stop, while you travel.

Accounts and authentication

You need an account to use the app. Sign-in is handled by our managed authentication service, using either Google sign-in or an email address and password. We store your user identifier, email address, and an optional display name and avatar image supplied by your sign-in provider. Passwords are handled by the authentication service and are never stored by the app itself.

Zuzli is currently in a closed beta. New accounts are created with a pending status and require manual approval before trips can be created. We store your account status, role, trip allowance, and the time you were last active, so access can be managed.

Trip data you provide

We store the trip content you or your AI assistant create, which can include:

  • Trip title, subtitle, city, country, dates, time zone and language
  • Days, stops, addresses, coordinates, descriptions, notes and travel legs
  • Cover images and links you add to a trip
  • Your progress: which stops are completed, skipped or currently active

Database and hosting

Application data is stored in a managed PostgreSQL database provided through Lovable Cloud (built on Supabase), and the app is served from Lovable's hosting infrastructure. Access to your rows is restricted at the database level so that, in normal use, only you, users you have shared a trip with, and the operator can read your trip data.

ChatGPT and the MCP connection

Zuzli exposes an MCP (Model Context Protocol) endpoint that ChatGPT and other compatible AI clients can connect to. The connection is authenticated: you must sign in and explicitly authorise the client before it can act on your behalf. ChatGPT accesses Zuzli data only after you have authenticated and requested an action.

When a user authorizes ChatGPT to perform a Zuzli action, the information required to complete that specific request may be exchanged between ChatGPT and Zuzli through the MCP integration. Information processed by OpenAI is governed by OpenAI's own terms and privacy policy. Zuzli does not receive your ChatGPT conversation history, and it does not automatically send your trips to OpenAI outside of the actions you request. You can revoke the connection from your AI client at any time.

We log AI tool activity — which tool was used, whether it succeeded, how long it took, any error message, and the trip involved — so that account limits can be enforced and problems diagnosed.

Maps and place information

Zuzli uses Google Maps Platform to display maps and to look up place details, addresses, coordinates, photos, ratings, opening hours and travel routes between stops. Map tiles and related assets are loaded directly from Google in your browser, which means Google receives your IP address and technical request information. Place and route lookups are performed by our server using the place names and coordinates in your itinerary. Resolved place details are cached in our database so trips load quickly.

Some trips display images and text sourced from Wikipedia when a cover image is generated from a destination name.

Device location

When you enable follow mode on the map, the app asks your browser for your device location and uses it only in your browser to centre the map and show your position. Zuzli does not send this location to our servers and does not store or track your location history.

Shared trips

You can share a trip with another Zuzli user by entering their email address. If an account with that email exists, that user is granted access to the trip and can view it and update shared progress. Sharing reveals the trip content to that user; it does not give them access to your other trips or to your account. Trip owners can see who a trip is shared with and can remove access.

Cookies and local storage

Zuzli does not use advertising or third-party tracking cookies. The app stores your sign-in session in your browser's local storage so you stay logged in, plus a locally generated session identifier used to track trip progress on your device. Third-party services such as Google Maps may set their own cookies when their content loads.

Logging and analytics

We do not run a third-party product analytics or advertising suite. Our hosting and database providers keep standard technical logs, such as request and error logs, which may include IP addresses. Within the app, administrative actions are recorded in an audit log, together with the AI tool activity described above.

Administrative access

Administrative access to user or trip data occurs only when reasonably necessary for support, security, abuse prevention, troubleshooting, service maintenance, or legal compliance. Because Zuzli is a closed beta operated by a single developer, account approval, support handling and deletion requests are performed manually.

Support messages

When you write to support@zuzli.app, we store the name, email address, subject and message you submit so we can read and reply to your request. Please do not include passwords, access tokens, or other sensitive credentials in a support message.

Data retention

  • Account and trip data is retained while the account remains active, until a trip is deleted, or until a verified deletion request is completed.
  • Shared-trip and progress data is retained while the relevant trip and permissions remain active.
  • Support submissions and operational logs may be retained for a reasonable period for support, security, troubleshooting, abuse prevention and service maintenance.
  • Limited information may be retained where legally or operationally necessary.

Deleting your account or data

Deleting a trip in the app removes the trip and its related progress and sharing records. To request access to your data or deletion of your account, contact support@zuzli.app or use the support page.

Account deletion is currently handled manually after verification of the request, and is completed within a reasonable period. It is not automatic or immediate.

Children

Zuzli is not intended for children. Accounts should be created and managed by adults, who may of course plan family trips that include children.

Changes to this policy

This policy may be updated as the product changes. The date at the top of this page always reflects the most recent update.

Contact

For any privacy question or request, write to support@zuzli.app or use the support page.