Skip to main content

Privacy policy

WikiTraveler is open-source software for community-verified stay accessibility facts. The operator of the WikiTraveler node you connect to is the data controller for that node. The project hub is node-eu.wikitraveler.org (Access: access.wikitraveler.org). The canonical policy URL is https://www.wikitraveler.org/privacy; Node and Access serve the same article at /privacy.

Who this covers

This policy describes WikiTraveler Lens (Chrome extension), Access (traveler/auditor app), the Node dashboard and API, and the optional agency SDK widget — as shipped in this project.

What we store

  • Account. Username, password hash, and role on the node you register with. Lens and Access send the password only to that node’s login API; they do not keep the password after sign-in.
  • Session. A short-lived JWT. Node and Access keep it in an HTTP cookie (wt_token). Lens stores the token, username, home-node URL, and locale in chrome.storage.sync so they follow your Chrome profile across devices.
  • Preferences. Accessibility search preferences, theme, locale, and favorites. Access may sync those to your home-node account when you are signed in.
  • Audits. Structured accessibility facts, notes, and photos attached to wizard steps or room types — submitted by auditors to the node.
  • Lens on booking sites. To look up a listing, Lens reads the page URL and visible hotel name/address. It does not read payment forms, booking personal data, or your Google account. Host access is limited to Booking.com, Expedia, and Hotels.com unless you grant optional HTTPS access so the service worker can reach the node (and mesh peers) you configured.
  • Technical. Operators may log request metadata and apply IP-based rate limits (optional Upstash/Redis) to protect public APIs.

What we do not do

  • We do not sell personal data.
  • We do not show ads, and the shipped apps do not embed third-party analytics SDKs.
  • Lens does not scrape booking sites for inventory or prices — only enough to resolve a WikiTraveler property.

Optional services operators may enable

  • AI gap-fill / vision. If the operator sets an AI provider key, selected audit fields or photos may be sent to that provider to produce AI_GUESS facts.
  • Photo storage. Audit photos may live in the node database or in operator-configured object storage (for example R2 or Supabase).
  • Federation. Linked peer nodes may receive gossip copies of facts and photo references for properties in their region.
  • Agency SDK. Partner sites that embed the widget receive the accessibility facts the node is configured to share (including optional public reads).

Legal bases and retention

Where GDPR applies: we process account and session data to provide the service (contract), security and rate limiting as legitimate interest, and optional AI only when the operator has enabled it. Data is kept until you delete your account or the operator’s retention policy says otherwise. JWTs last until they expire or you sign out.

Your rights

You can sign out (clears the Lens/Access token on that device), ask the node operator to correct or delete your account, or open a project issue for the hub. Security reports go through private vulnerability reporting, not a public issue.

Children and transfers

WikiTraveler is not directed at children under 16. If an operator federates with peers in other countries, facts you submit may be stored there as well.

Changes

Material changes will be published on this page with an updated date. Chrome Web Store listings point at https://www.wikitraveler.org/privacy.

Last updated: 13 September 2026