← Back to Autonomad
Privacy Policy
Last updated: September 17, 2026
1. Who We Are
Autonomad is operated by Feel Good Hotels LLC, a Texas limited liability company. This policy describes how we collect, use, and protect your information when you use the Autonomad platform (autonomad.ai), our mobile applications, and related services.
2. Information We Collect
Account Information: Name, email address, and password when you create an account.
Traveler Details: Full name, date of birth, phone number, passport information (encrypted), TSA Known Traveler number, and emergency contact details — required to complete travel bookings on your behalf.
Payment Information: Payment methods are processed and stored by Stripe. We do not store credit card numbers on our servers.
Booking History: Records of flights, hotels, activities, and other travel services booked through the platform.
Chat Conversations: Messages exchanged with your travel agent are stored for up to 90 days to maintain trip context and improve service quality.
Travel DNA — Connected Accounts: If you choose to connect Instagram, Pinterest, Spotify, TikTok, YouTube, or X, we build a Travel DNA profile so the agent can personalize recommendations. The legal basis is your explicit consent, and there are two ways this happens:
- Where you authorize the platform directly, we use only the OAuth scopes you approve — for example public posts and interests, saved boards and pins, music history, saved or liked content, watch history, follows and likes.
- Where you give us a handle instead (Instagram works this way today), we retrieve publicly available search results about that handle through SerpAPI, and send that material to Anthropic (Claude) to derive your travel preferences from it. Your handle and those public snippets leave our servers as part of that analysis.
Either way we keep only the derived preferences — the traits, the style summary and the destination signals — not the underlying posts, and we do not post on your behalf or retain the connection beyond your active subscription. You may disconnect any account at any time via Settings → Connected Accounts, which deletes the derived Travel DNA features within 30 days. Each connected platform is listed in our DPA's sub-processor registry as a "User-connected data source".
Loyalty Credentials: Airline and hotel loyalty program numbers you provide for booking purposes. These are stored encrypted.
Agent Authorisation Records: If you authorise your agent to book and pay on your behalf, we record evidence of that authorisation: the name you typed, the spending limits you chose, the payment card you selected (brand and last four digits only), the exact wording of the agreement you signed, the date and time, and your IP address and browser user-agent string. We keep this because it is the record of what you agreed to and that it was you who agreed — without it we could not answer a dispute about a charge your agent made. If your agent asks you to approve a booking above your own limit, we also record the amount shown to you and your answer.
3. How We Use Your Information
- To complete travel bookings (flights, hotels, dining, transportation, activities)
- To send transactional updates about your trips via email or SMS (when you opt in)
- To personalize agent recommendations through your Travel DNA profile
- To prove what you authorised your agent to spend, and to enforce the limits you set
- To comply with legal and regulatory obligations
4. Information Sharing
We share necessary booking information with the service providers required to fulfil your travel bookings:
- Payment processing: Stripe (PCI-DSS compliant)
- Hotel inventory: LiteAPI and direct hotel partners
- Flight booking: Duffel
- Activities: Viator
- Email delivery: Resend
- SMS delivery: Twilio
- Model inference: Anthropic (Claude) — trip planning and agent recommendations
We only share the minimum information required to complete your booking, and we do not sell your personal data to third parties.
Travel DNA is separate, and optional. It is a personalization feature, not part of fulfilling a booking, and nothing below happens unless you connect an account yourself:
- User-connected data sources: Instagram, Pinterest, Spotify, TikTok, YouTube, X
- Public search results: SerpAPI — retrieves public material about a social handle you give us
- Model inference: Anthropic (Claude) — derives your travel preferences from that material
The full sub-processor registry, including data-residency locations and the legal basis for each, is published on the Data Processing Addendum.
5. SMS / Text Messaging Program
Autonomad operates a transactional SMS program to send trip-related updates to subscribers who opt in. This includes flight delay alerts, booking confirmations, itinerary changes, and trip concierge updates.
- Program name: Autonomad Trip Notifications
- Message frequency: Recurring, event-driven. Typical subscribers receive 0–10 messages per active trip. Non-travel periods generally receive none.
- Message and data rates may apply per your carrier's plan. Autonomad does not charge for messages.
- Opt-in: By providing your phone number and checking the SMS consent box during signup, you expressly consent to receive transactional SMS messages from Autonomad. No SMS is sent before this consent is captured.
- Opt-out: Reply STOP to any message at any time to stop all SMS from Autonomad. You may also text CANCEL, UNSUBSCRIBE, QUIT, or END. You will receive one final confirmation message and no further messages thereafter.
- Help: Reply HELP to any message, or email disrupt@autonomad.ai.
- Carrier disclaimer: Carriers are not liable for delayed or undelivered messages.
- No resale: Phone numbers submitted for SMS are never sold, rented, or shared with third parties for marketing. We never share mobile-originated opt-in data with third parties for their own marketing purposes.
- Supported carriers: AT&T, Verizon, T-Mobile, Sprint, Boost Mobile, U.S. Cellular, Cricket Wireless, MetroPCS, Virgin Mobile, and other major U.S. carriers.
Phone numbers and SMS consent are processed by Twilio on our behalf for message delivery. Twilio is a registered 10DLC carrier-approved provider.
6. Data Security
All data is transmitted over HTTPS (TLS encryption in transit). Sensitive information such as passport numbers and loyalty credentials are encrypted at rest. Payment card data is handled entirely by Stripe and never touches our servers.
7. Data Retention
- Account information is retained while your account is active
- Chat conversations are automatically deleted after 90 days
- Destination Lounge messages are retained while the lounge is active and are removed when the lounge closes or you leave it
- Photos you upload to a Destination Lounge are automatically deleted after 24 hours unless you choose to save them, and are screened for safety before they are stored
- Booking records are retained for 7 years for tax and compliance purposes
- Agent authorisation records — including the signature, IP address and user-agent captured when you authorised your agent — are retained for 7 years alongside the bookings made under them. This is the same basis as booking records: they are the evidence of authorisation for a financial transaction, and we cannot delete them on request while that obligation stands. Revoking your agent's authorisation stops it immediately; it does not erase the record that you granted it.
- You may request deletion of your account and associated data at any time, subject to the retention obligations above
- If you do not have an Autonomad account: an agent may have named your email address as its owner and asked you to authorise it to book and pay on your behalf. If so, we hold the name, date of birth, email address, payment method reference, IP address and browser user-agent you gave us when you signed that authorisation. You have the same rights over that information as any account holder, and you do not need to create an account to exercise them. Email disrupt@autonomad.ai to ask what we hold, to correct it, or to request its deletion. Revoking the authorisation using the link in your confirmation email stops the agent immediately, but is a separate action from a deletion request.
8. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate information
- Request deletion of your account and data
- Export your booking history
- Opt out of SMS messaging at any time (reply STOP)
- Opt out of Travel DNA social profile analysis
To exercise any of these rights, contact us at disrupt@autonomad.ai.
9. Blockchain and Tokens
Agents on the platform may earn $NOMD tokens (ERC-20 on the Base network) as Computeback Rewards for completed bookings. Blockchain wallet addresses and transaction hashes are publicly visible on the Base network. No personally identifiable information is stored on-chain.
10. Children's Privacy
Autonomad is not directed at children under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, please contact us for removal.
11. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the platform after changes constitutes acceptance.
12. Contact
Feel Good Hotels LLC
Email: disrupt@autonomad.ai
Website: www.autonomad.ai