VILDRA
Privacy policy
This policy describes the personal data VILDRA processes in the current product and why.
Controller
VILDRA
operated by Moritz Künzi
Murtenstrasse 131
3179 Kriechenwil
Switzerland
Email: hello@vildra.site
Accounts and host workspace
For registration, sign-in and account recovery, VILDRA processes the email address, password data protected by Supabase Auth and technical session data. For profiles, stays, host knowledge, recommendations and publishing, VILDRA processes information entered or confirmed by the host.
Protected host areas use Secure, HttpOnly and SameSite session cookies. Access and refresh tokens are not stored in Local Storage.
Subscriptions and payment
For paid subscriptions VILDRA processes technical customer, Checkout, price, subscription and payment-status metadata. Stripe provides Checkout and the Customer Portal and sends signed webhooks to VILDRA. VILDRA does not store card or bank details.
Guest guide and browser storage
The guest guide may locally store saved and visited places, interests, mobility, travel preferences, stay dates, language and feedback. Voluntary comments may contain personal data; do not enter sensitive information.
An anonymous stay-specific analytics ID exists only in Session Storage for the browser session. There is no persistent analytics ID in Local Storage and no marketing pixel or external web analytics.
Feedback, contributions and analytics
VILDRA processes technical guide events, ratings, comments and voluntary place suggestions to operate the product and provide host insights. Contributions are not published automatically.
Raw data in guest_events, recommendation_feedback and guest_experience_feedback, and unreferenced guest_sessions, are deleted automatically after 90 days.
OpenAI
The Guest Assistant sends free-text questions, limited conversation context and required published guide content to OpenAI. Published content may include host knowledge. Questions and answers are not stored as VILDRA analytics content.
Host generation may send the entered task and required stay, place or recommendation context to OpenAI. Every production Responses API request uses store: false. OpenAI may still process data under its own security, abuse-prevention and legal obligations.
Location, maps, weather and events
Geoapify processes a host-entered stay address for geocoding. VILDRA may store the normalized address, coordinates, country code, Geoapify provider ID and verification time.
Google Places is used server-side for place search. New Google content is generally transient; technical Place IDs and provenance may be stored. Google terms apply when a Google Maps link is opened.
An OpenStreetMap iframe loads only when the map is opened. The browser may send IP address, browser information and referrer directly to OpenStreetMap. Google places are not shown on the OSM map.
VILDRA sends rounded stay coordinates to MET Norway for weather. Ticketmaster may receive a broadly location-based event query, country and stay period.
Infrastructure and email
VILDRA uses Vercel for hosting and technical logs and Supabase for authentication and database services. Confirmation and password-reset emails are sent through the mail infrastructure configured for Supabase Auth. VILDRA does not name an unverified separate SMTP provider.
Providers may process data outside Switzerland depending on their infrastructure. VILDRA sends only data required for each function.
Retention and rights
Account, host, stay, publishing and subscription data are retained while required for the contract, guide, security or legal obligations. Local guest data can be reset in the browser. Provider logs and payment records may follow separate retention periods.
Requests for access, correction, export or deletion can be sent to hello@vildra.site. VILDRA verifies identity, ownership, legal retention duties and affected systems. Complete self-service deletion is not currently offered.
Last updated
27 August 2026