Privacy Policy
Last updated: September 16, 2026
Drift helps you and your friends plan trips together, book stays and tours, and split the costs. This policy explains what we collect, why, and the choices you have. We keep it in plain language on purpose.
Who this applies to
This policy covers the Drift mobile app and drift.after-hours.app (together, "Drift", "we", "us"). By using Drift you agree to the practices described here.
Information we collect
Account information
When you create an account we collect your email address, a username, and any display name or profile details you add. Authentication is handled by our backend provider (Supabase); we don't store your password ourselves. You can sign in with a link sent to your email address, with Apple, or with Google — signing in with Apple or Google tells us only your name and email address, or the private relay address Apple gives us if you choose to hide yours.
Trip content
The itineraries, destinations, stops, notes, dates, and expenses you and your travel companions add to a trip. On shared trips, this content is visible to the other members of that trip.
Location
If you use trip recording, Drift collects your device's precise location, including in the background, to map your route and place your moments on the map. Background tracking only runs while you have recording turned on for a trip, and you can stop it at any time. You can also disable location access entirely in your device settings — Drift still works for planning without it.
Photos and videos
Media you capture or add to a trip. Photos and videos are uploaded to our media storage (Amazon S3) and served through a content delivery network (Amazon CloudFront). Location metadata embedded in a photo may be used to place it on your trip map.
Financial connections (expense import)
If you choose to connect a bank or card account to import travel expenses, we use Plaid to establish that connection. Plaid collects and processes your financial data under its own privacy policy; Drift receives transaction details (such as merchant, amount, and date) to help you track and split trip costs. We never receive or store your banking credentials — you enter those directly with Plaid. Connecting an account is entirely optional, and you can disconnect it at any time.
Google account (email and calendar booking import)
If you choose to connect your Google account, Drift uses Google Sign-In to request read-only access to your Gmail messages so it can find travel booking confirmations — flights, hotels, trains, cars, and tours — and extract the reservation details (such as dates, locations, confirmation numbers, and amounts) to build your itinerary automatically.
Separately, and only if you choose "Google Calendar" as an import source, Drift requests read-only access to your Google Calendar so it can find travel events you have already saved and import them into a trip.
Both are entirely optional and are requested independently — Drift works fully without either, connecting one does not connect the other, and each is requested only at the moment you start that import, never at sign-in. You can disconnect your Google account at any time in Settings or revoke access from your Google Account permissions. Exactly which scopes are requested, and how the data is used, stored, and protected, is described in Google user data and Limited Use below.
Social activity
If you follow other users, like, or comment, we store those interactions to operate the social features and send related notifications.
Device and usage data
Basic technical data needed to run the app and keep it reliable — device type, app version, and diagnostic information. If you enable push notifications, we store a device token to deliver them via Apple Push Notification service.
Account usage history
“Share usage to improve Drift” in Settings is on by default, and you can turn it off at any time. Each record says which feature you used, the action and whether it succeeded or failed, when it happened and how long it took, whether the app was in the foreground, and random session and action identifiers that let one action be joined to its outcome — plus platform and app version, linked to your account. A copy of each record is also sent to PostHog, our product-analytics provider, linked to the same account identifier. This usage log does not include chat or search text, names, emails, destinations, precise locations, URLs, advertising identifiers or session recordings. Operational chats you choose to save remain separate.
We use aggregate reports to improve Drift. Individual usage histories are restricted to authorized administrators. Usage events and last-seen summaries are kept until you delete your account; nothing deletes them on a schedule. Undelivered events are eligible for retry for seven days; expired records are cleared when Drift next runs. Native queues are excluded from cloud backup. Turning sharing off stops collection and new copies to PostHog and clears this device’s undelivered queue; usage history already collected is kept, and copies PostHog already holds follow its retention, not ours; other devices clear their queues when they next receive your account choice. Server ingestion rejects events while sharing is off. Account deletion also removes this usage data. Backups follow our hosting provider’s backup lifecycle.
How we use your information
- To provide and sync your trips, bookings, expenses, and media across your devices and trip members.
- To power features you invoke — mapping your route, comparing stays and tours, splitting costs, and generating AI trip summaries.
- To send notifications you've asked for (trip activity, reminders).
- To keep Drift secure, debug problems, and improve the product.
- To comply with legal obligations.
AI features
Some features use AI models — including Google's Gemini, Anthropic's Claude and OpenAI's models — to do things like answer a question about a destination, extract highlights from a video, or write a trip recap. When you use these features, the relevant content (for example, a video or your trip details) is processed by these providers to generate the result. We don't use your private trip content to train third-party models.
How we share information
We do not sell your personal information. We share it only in these cases:
- Service providers that run Drift on our behalf — Supabase (database, authentication), Amazon Web Services (media storage and delivery), Google (maps and place data, Gemini AI), Anthropic (Claude AI), OpenAI (the Ask Drift assistant), Plaid (financial connections), Apple (push notifications, payments, Sign in with Apple), Resend (transactional email, such as trip invitations and your deletion receipt), PostHog (product analytics), Sentry (crash diagnostics), Vercel (web hosting) and Cloudflare (bot protection on sign-in). They may only use your data to provide their service to us.
- Booking partners. When you tap a stay or tour, Drift opens a link to a booking partner (such as Booking.com, Expedia, Hotels.com, Vrbo, Viator, Klook, or Priceline, sometimes via the Stay22 or Travelpayouts networks). Your booking is made on the partner's site under their terms and privacy policy. Drift may earn a commission on qualifying bookings — see our Terms. We don't share your personal profile with these partners; they receive only the click needed to attribute the referral.
- Other users, for content you choose to share — members of a shared trip see that trip's content, and public profiles or trips are visible to others.
- Legal and safety — if required by law, or to protect the rights and safety of our users and the public.
- Business transfers — if Drift is involved in a merger, acquisition, or sale of assets, with notice to you.
Google user data and Limited Use
Drift requests exactly two Google scopes. Both are read-only, both are optional, and each is requested only at the moment you start that specific import — never at sign-in, and never together.
https://www.googleapis.com/auth/gmail.readonly
- What we access — read-only Gmail message content. Drift runs a bounded search of your mailbox scoped to known travel-provider senders and to your trip's date window, and reads only the messages that match.
- Why we need it — the reservation details Drift imports (confirmation numbers, times, addresses, amounts) exist only in the message body. Narrower Gmail scopes cannot read message bodies and cannot perform the targeted search that keeps our access minimal.
- What we store — the structured reservation details we extract, for example a flight's route, times, and confirmation code, saved as part of your trip. We also keep, for each message we scanned, the sender, the subject line, and a short excerpt of up to 800 characters of the text we parsed, so that a failed or wrong import can be diagnosed. We do not store the full body of your emails, and we never store your mailbox.
- Tokens — the access token is used for a single scan and discarded. Drift does not store a Gmail refresh token and cannot read your mail in the background.
https://www.googleapis.com/auth/calendar.readonly
- What we access — read-only calendar data. On iOS, Drift lists your readable calendars so you can see which ones are being searched, then reads events falling inside your trip's date range. On the web, Drift reads events from your primary calendar only. Drift never creates, edits, or deletes calendar events.
- Why we need it — to identify travel events you have already saved and offer them for import.
- What we store — the itinerary items you confirm, saved as part of your trip. We also keep, for each event we scanned, its title and a short excerpt of up to 800 characters of the text we parsed, so that a booking you have already imported is not offered to you a second time and a failed or wrong import can be diagnosed. We do not store the full text of your calendar events, and we never store your calendar.
How both are handled
- You review before anything is added — every extracted booking is shown to you for confirmation. Nothing is written to a trip without your approval.
- Use — Google user data is used only to provide the import feature you invoked. We do not use it for advertising, and we do not sell it or transfer it to others except as needed to provide that feature to you, or as required by law.
- Human access — our team does not read your Google user data, except where you give explicit consent (for example, to troubleshoot a specific import at your request), where necessary for security or to comply with applicable law, or in aggregated or anonymized form.
- AI processing — to read a booking out of an email, Drift sends the relevant message text to Anthropic's Claude API, which returns the structured reservation. This is inference only, performed solely to produce your import result. Anthropic does not train on data submitted through its API. We do not use or transfer Google user data to develop, improve, or train generalized or non-personalized AI and/or machine-learning models.
- Deleting it — you can delete any imported item from your trip, disconnect Google in Settings, or revoke Drift entirely at myaccount.google.com/permissions. Deleting your Drift account deletes the imported reservation details along with it. To have Google-derived data removed without deleting your account, email us and we will remove it.
Drift's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Data retention
Google user data has a hard limit. The full body of an email and the full text of a calendar event are never written to our database at any point. The sender, subject or event title, and the short parsed excerpt we keep for each scanned item are erased automatically by a scheduled job that runs every day and clears anything older than 30 days. After that, all that remains of a scan is the structured booking you chose to confirm, which stays on your trip until you remove it or delete your account.
We keep your other information for as long as your account is active or as needed to provide Drift. We retain data beyond that only where we must to comply with legal obligations, resolve disputes, or enforce our agreements.
When you delete your account
You can delete your account yourself: in the iOS app under Settings › Delete Account, or on the web under Settings › Danger zone. Before anything is deleted, we confirm it is you — a six-digit code sent to your account's email address, or Sign in with Apple if that is how you sign in. Nothing is removed until that step passes, so an unlocked phone alone cannot close your account. The screen shows you what will happen, with your own numbers, before you confirm, and offers you a copy of your data first.
The deletion itself is immediate and permanent. It removes your profile; the trips only you were on, with their itinerary, notes and packing lists; your photos, videos and files; your chats with Drift; your comments, likes and follows; the bookings imported from Gmail, Calendar and forwarded email, together with the Google-derived records described above; your saved places and guides; your travel preferences; the device tokens used to send you notifications; and your login itself, so the account can no longer be signed in to. It cannot be undone, and we cannot restore it for you afterwards.
Trips you organised with other people are handed over, not destroyed. If someone accepted an invitation to a trip you organise, that trip passes to the traveller who joined first, so their itinerary and everything they added to it survive. They are told the trip has a new organiser; they are not told why.
A few shared records are kept deliberately, with your identity removed. Expenses and settle-ups on trips you shared with other people stay, so their balances remain correct, and they appear as “Former traveller” rather than under your name. Your receipts, photos, messages and comments on those trips are removed.
We disconnect the services Drift connected on your behalf. Google access is revoked; Sign in with Apple tokens are revoked, so Drift stops appearing under your Apple ID; and any bank connection is removed at Plaid, so it stops sharing data with us. If a provider cannot be reached at that moment, we keep retrying automatically and tell you what you can do yourself in the meantime.
We email a receipt to your account address when it is done, listing what was removed and what was kept.
What can still exist for a short time afterwards. We would rather say this plainly than promise more than we can do. Encrypted daily database backups hold your data until they age out of a rolling seven-day window; if we ever restore one, we re-apply your deletion to it. Authentication security logs keep the record of sign-ins for up to 90 days. Media already delivered may sit in content-delivery caches for a short time after the files themselves are deleted. Our email provider keeps its own delivery logs for messages already sent to you. Our product-analytics provider holds usage events tied to a random identifier rather than your name or email address, and those events remain in its systems. We also keep a record that an account was deleted, when, and anything that could not be reached at the time — without your name or email address — because that record is how we prove the deletion happened and finish any outstanding step. And if you unsubscribed from any Drift emails, we keep a one-way hash of your address with that choice, so it is still honoured if the address ever reaches us again — the Email item under Your rights and choices explains that record.
Your rights and choices
- Access and correction — you can view and edit most of your information in the app.
- A copy of your data — under Settings › Download your data, in the app or on the web, Drift gives you everything it holds about you as one JSON file: your profile, trips and their stops, photos and files as links to the originals, expenses and settle-ups, saved places and guides, imported bookings, which accounts were connected, and your chats. The file explains itself, and it names the few things it leaves out and why — credentials such as bank access tokens and invite links, which are keys rather than records. Other travellers appear by display name, never by email address.
- Deletion — you can delete your account in the app or on the web, and we confirm it is you first. See When you delete your account for exactly what is removed, what is handed to the people you travelled with, and what is kept.
- Location and notifications — you control these in your device settings at any time.
- Email — you can turn off the emails Drift sends about trip invitations, bookings found in your inbox and settling up, changes to your trips, and news from Drift. Do it under Settings › Email on the web or Settings › Email preferences in the app, or from the Unsubscribe and Email preferences links at the bottom of each of those emails, which work without signing in. Every one of them also supports one-click unsubscribe, so the Unsubscribe button your email app shows next to our name stops that kind of email in a single step. Security and account emails — sign-in links and codes, the code that confirms an account deletion, and the receipt afterwards — can't be turned off, because they are how we keep your account safe and tell you what happened to it. When you unsubscribe, we keep a record of it so it is honoured from then on, including after you delete your account. That record does not contain your email address: it holds a one-way hash of it, which kind of email you turned off, when, and whether you used a link or the app.
- Financial connections — you can disconnect a linked account at any time.
- Google account — you can disconnect it in Settings, or revoke Drift's access anytime at myaccount.google.com/permissions.
- Depending on where you live (for example, the EEA/UK under GDPR, or California under the CCPA/CPRA), you may have additional rights to access, port, or restrict processing of your data. Contact us to exercise them.
Security
We use industry-standard measures — encryption in transit, access controls, and row-level security on our database — to protect your information. No method of transmission or storage is completely secure, but we work to protect your data and to notify you of material incidents where required.
Children
Drift is not intended for children under 13 (or the minimum age required in your country), and we don't knowingly collect their data. If you believe a child has provided us information, contact us and we'll remove it.
International users
Drift is operated from, and processes data in, the United States and other countries where our providers operate. By using Drift you consent to the transfer of your information to these locations, which may have different data-protection laws than your own.
Changes to this policy
We may update this policy as Drift evolves. We'll revise the "last updated" date above and, for material changes, provide additional notice in the app.
Contact us
Questions about privacy? Email privacy@after-hours.app.
← Back to Drift