Privacy

Privacy

What the current Asmaliana production service processes, does not store, and how retention is operated.

Itineraries

Planning and validation run as in-memory calculations. The application does not intentionally persist complete itineraries, exact starting coordinates, names, email addresses, phone numbers, or dietary preferences.

Technical events

Verified mode can record minimal events: request ID, pseudonymous tenant or short-lived anonymous key, route/tool, status, duration, cache indicator, data version, credits, error code, and time. Demo and internal-test events are excluded from market metrics.

Retention design

The engineering target is seven days for raw technical events and quota identity digests, and 90 days for non-sensitive aggregates. The purge command covers both telemetry and quota lease/counter tables. Production purge is an explicit operator-run operation until a recurring schedule is separately reviewed; data is not silently deleted by a hidden background task. IP-derived rate-limit keys are rotating digests and are not described as fully anonymous.

Review status

The production release records operator privacy and legal review references and publishes the contact path admin@asmaliana.com. This notice is an operational summary, not legal advice; send correction or deletion requests through that address.