Skip to content

Your information, and what Mytemized does with it

Mytemized reads travel confirmations you send it and builds a timeline from them. This page says what that means for the information involved.

In force since 1 October 2026.

Who is responsible for your information

Mytemized is operated by Richard Pinsenschaum, a sole trader in Ireland, at Feakle, Co Clare, Ireland, on 00353 85 742 8624.

Mytemized is the name of the service rather than a company: the person named above is who decides what happens to your information, and who answers for it.

You can write about anything on this page to:

support@mytemized.com

What Mytemized collects

Your account holds:

  • Your email address, and a display name taken from it when you register.
  • Your password, stored only as a scrypt hash with a salt unique to it. The password itself is never stored and cannot be recovered from what is.
  • A private forwarding address, so confirmations can be emailed straight in.

Your trips hold what you put in them, and what was read out of it:

  • The documents you send — uploaded, pasted, shared from another app, or forwarded by email — kept exactly as they arrived.
  • The text of each document, and the structured booking information read from it: dates, times, places, suppliers, booking references, costs.
  • The trip’s own name, destination and dates.

If you pay for a trip, Mytemized records that a payment happened: the amount, the currency, the payment provider’s reference for it, and whether it was later refunded. Card details never reach Mytemized — they are entered on Stripe’s own payment page.

Mytemized also keeps a short activity record: which action happened, when, and to which item. It holds counts, durations and codes only. Filenames, trip names, booking references, places and document text are never written to it, and that rule is enforced by the software rather than remembered.

Travel documents contain more than travel details

A booking confirmation often carries a passport number, a date of birth, a home address, a phone number, or the names of the people you are travelling with. Mytemized does not ask for any of that, and does not need it — but whatever is in a document you send is in the copy Mytemized keeps and in the text read from it.

Please do not send in more than the trip needs. If a document carries something Mytemized has no use for — a medical note, an insurance form, a passport scan sent for some other reason — it is better not to send it at all. Mytemized does not ask for information about anyone’s health, accessibility or dietary requirements, does not look for it, and does not build anything on it. But it cannot tell what is inside a file before it reads it, so the only reliable way to keep something out is not to send it.

The other people on a booking have not agreed to any of this. A confirmation naming your travelling companions brings their details in with yours. They have no account here and no dealings with Mytemized, and there is no way for Mytemized to contact them — so this page is where that is said, and it is worth telling the people you travel with that their confirmations are kept here. Their information is treated exactly like yours: never sold, never used for advertising, and removed when you remove the document it came in.

You can remove any document at any time, which is described further down.

If you are one of those people, and you have found this page: you can write in. Their information is held for one reason — to read the booking and put it on the timeline for the trip it belongs to — on the same footing as the customer’s own, and for as long as the customer keeps the document it arrived in. It is never sold and never used for advertising. The rights at the end of this page are theirs as much as anybody’s: you can ask what is held about you, ask for it to be corrected, ask for it to be deleted, and complain to the Data Protection Commission without writing here first.

Mytemized has no way to find you first — there is no account, no address, and nothing that says how to reach somebody named in somebody else’s confirmation, which is why this page is where it is said rather than in a message to you. Writing to the address at the end reaches a person rather than a form:

support@mytemized.com

Where it is kept

Everything is stored on a single rented server in Helsinki, Finland: the database, and your original documents alongside it. Your documents are not sent to a third-party file-storage service.

Connections between your browser and Mytemized use HTTPS, and the site is served over HTTPS only.

Passwords are stored as scrypt hashes, and the tokens behind your sign-in session are stored only as hashes, so the contents of the database cannot be used to sign in as you.

The database and your documents are held on an encrypted disk. Since 15 September 2026 they sit inside a LUKS2 encrypted volume, which has to be unlocked by hand after the server restarts. Somebody who took the disk without that key could not read what is on it.

That protects what is there now. It does not undo what came before. Until that date the same information was held unencrypted on the server’s original disk, and moving it did not erase the copy it left behind: the old files are gone, but the space they occupied is not overwritten, and on a rented virtual machine there is no way to prove from inside it that it ever will be. So no claim is made that the earlier copy has been destroyed — only that it is no longer how Mytemized stores anything.

Saying both halves is more useful than a reassuring sentence that is hard to check. What also protects your information is that the server is not shared, is not reachable except over HTTPS, and that the backups leaving it are encrypted.

Backups are made regularly. They are encrypted with AES-256 before they leave the server, and each one is read back and decrypted to check it worked.

Who else receives it

Five services are involved in running Mytemized. Nothing is sold, and nothing is shared for advertising.

  • The AI provider that reads your documents. A document’s contents — its text, or the file itself for a PDF or a photograph — are sent to be read. No account name, email address, trip name or identifier is sent with it, so what arrives is the document and nothing that says whose it is. The provider is not permitted to use it to train its models. It deletes it within 30 days, except for anything its automated safety checks flag, which it keeps for longer.
  • Stripe handles payment. Mytemized sends the amount, the currency, a fixed description of what is being bought — never the name of your trip — and identifiers for your account and that trip. You give Stripe your card details and a billing address directly. Mytemized never sees the card number, its expiry or its security code. Of the address, it receives and keeps only the country; it also receives and keeps the country where your card was issued. Those two are kept because tax rules on a sale like this have to be supported by two separate indications of where you are, and one of them on its own is not enough. Nothing else about the card reaches Mytemized.
  • Mailgun receives confirmations you forward by email, and delivers operational notifications to the operator. Those notifications contain an email address and a count — never the name of a trip or anything from a document.
  • The hosting provider runs the server everything is stored on.
  • The backup provider holds the encrypted backups described above, and cannot read them.

Each of these acts on Mytemized’s instructions rather than on its own account, and none of them is permitted to use your information for its own purposes. Mytemized’s agreements for reading your documents and for taking payment are both with Irish companies — Anthropic Ireland, Limited and Stripe Payments Europe, Limited. Both belong to groups based in the United States, and your information may be processed there by the rest of the group. Those transfers are made under the standard contractual clauses the European Commission publishes for the purpose, or under the EU–US Data Privacy Framework; write to the address at the end of this page if you want the detail. The server your documents sit on, and the backups taken from it, are both inside the EU.

The two typefaces the site uses are built into it, so displaying this page sends nothing to a font service.

Cookies, and what is kept in your browser

Mytemized sets one cookie, mytemized_session, which keeps you signed in for thirty days. It cannot be read by scripts, is sent only to Mytemized, and is required for the product to work at all.

Your choice of light or dark appearance is remembered in your own browser and is never sent anywhere.

There are no other cookies. Nothing here tracks you, and nothing follows you to another site.

What is not collected

Mytemized runs no analytics. There is no tracking service, no tag manager, no session recording, no heatmap and no advertising pixel anywhere in it.

The application does not record your IP address, and its server keeps no access log.

How long it is kept

Until you delete it. Nothing expires on its own. Your trips, your bookings, the documents you sent and the originals behind them stay until you remove them or ask for your account to be deleted.

There is no dormancy rule, no inactivity timer and no age limit on a trip. This is deliberate. Mytemized is somewhere your travel is kept, and a trip from three years ago is the point rather than clutter — quietly deleting one because you had not opened it lately would break the only promise the product makes.

Records of payments are the exception, and they are kept for longer than the account that made them: six years from the date of the payment. That is the period Mytemized works to, because a business has to be able to answer tax, accounting and dispute questions about a payment long after it was made. Where the law requires a particular record to be kept for longer, it is kept for longer.

Removing things

You can delete any document you have sent. Doing so removes the stored original itself, not only its entry — along with the bookings that came from it. You can also delete individual bookings.

Trips can be archived. They cannot currently be deleted on their own.

You can ask for your whole account to be deleted by writing to the support address below. There is no button for it in the product — it is done for you, by a person, on request.

What that removes is everything of yours: your trips, your bookings, the documents you sent and the stored originals behind them, your sign-in details and the record of what you did here.

Backups are the one thing deletion does not reach, and it is worth being exact about it. Mytemized is backed up every night, and those backups are kept in rotation — roughly fourteen days of them on the server and thirty days off-site, each replaced as newer ones are made. A deletion removes you from the product straight away; copies made before it can still hold your information until they age out of that rotation. Nothing reaches into an old backup to edit it, and nothing should: rebuilding a sealed archive to remove one person from it risks the very thing backups exist to protect.

One thing is deliberately kept: the record that a payment happened. The amount, the currency, the date and the payment provider’s reference for it stay, and the link between that record and you is removed, so what remains says a payment was made and no longer says by whom. A payment has to be accountable for longer than an account does — for a refund, a dispute, or a tax question that arrives after you have gone.

The basis for all this, and your rights

Data-protection law asks a business to say why it is allowed to handle your information, purpose by purpose. Mytemized’s reasons:

  • Running your account, storing what you send, reading it and building your timeline — because that is the service you asked for. Handling your information is how Mytemized does the thing you came here for; without it there is no product. This covers your account, your documents, the bookings read from them, your trips, and the emails that tell you what happened to a payment.
  • Keeping records of payments — because the law requires it. Tax and accounting rules oblige a business to keep the records behind its returns, which is why a payment record outlives the account that made it.
  • Keeping the service secure and catching misuse — because it is a legitimate interest. Narrowly: sign-in security, preventing fraudulent or abusive use, and keeping the thing running. This is the only place Mytemized relies on its own interests rather than on your contract or the law, and it is deliberately the smallest of the three.

The details of other people inside a document rest on the first and last of those reasons, and on your own undertaking in the terms that you are entitled to send what you send: reading a confirmation is how the service you asked for works, and it cannot be done to half of a document. Nothing is done with those details beyond building the timeline for the trip they appeared in.

Mytemized does not ask you to consent to any of this, because consent is the wrong basis for the ordinary running of a service you have asked for — a box you cannot meaningfully refuse is not a choice. If Mytemized ever wants to do something outside the list above, it will ask separately and you will be able to say no.

Mytemized is operated from Ireland, so the UK GDPR does not apply and the EU General Data Protection Regulation does. You can ask for a copy of what is held about you, ask for it to be corrected, and ask for it to be deleted — the section above says what deletion removes and what it deliberately does not.

If you think your information has been mishandled, you can complain to Ireland’s Data Protection Commission, and you can do that without writing here first.

You can write at any time to:

support@mytemized.com

Changes to this page

When this page changes in a way that affects what happens to your information, the date it took effect changes with it.