Privacy policy

Last updated

This is a careful draft, written from what PlanWild's code actually does. Nobody who worked on it is a lawyer, and it's waiting on a lawyer's review. If anything here doesn't match what you see, say so: privacy@planwild.net.

The short version

PlanWild keeps your gear, your lists and your trips so you and your crew can plan a trip together. It's free, and one person runs it.

There's no advertising here, no analytics, and nothing that tracks you. Nothing about you is sold, and nothing is handed to anyone beyond the companies named below and whatever mail provider carries Mark's email. PlanWild never sees your password and never takes a payment.

The one thing that becomes readable outside the app is a trip brief, and only when an organizer publishes one. Anyone holding that link can read it without an account.

Other people on a trip see your display name and what you're bringing. They don't see what you paid, the links you saved, or your notes.

Want to see what PlanWild holds about you, correct it, get a copy of it or have it gone? Write to privacy@planwild.net.

What PlanWild is and isn't — a planner, not a safety service — is in the terms of service.

Who runs PlanWild

PlanWild is run by Mark Onofrio LLC, a one-person company in the United States. There are no staff and no support desk, and the one person is Mark. That's worth saying plainly, because it sets what you can expect from the response times further down.

PlanWild is built for and offered to people in the United States. It's hosted in the US and everything it holds is stored there. There's no separate set of rules by country: whoever you are and wherever you live, you get the same rights, listed under what you can ask for.

Anything about this page goes to privacy@planwild.net.

What you give PlanWild

Grouped by what you did, rather than by where it ends up.

  • Your account. Your email address, your display name and your profile photo. Your account really lives at Clerk (below); PlanWild keeps a copy of those three things so a trip can say who's on it.
  • Your gear. For each thing: a name, a category, what kind of shared item it is, what it weighs, what you paid, a link to it, and a note of up to 2,000 characters. Plus whether you'll lend it, and to whom.
  • Your lists and kits. Their names and descriptions, the headings you use, and how many of each thing is on them.
  • Your trips. A name, a description, a place, the dates, and whether it's a backpacking trip or a casual one.
  • A route, if someone uploads a GPX file. PlanWild measures the file and keeps the distance, the climb, the high point, the shape of the climb, a start coordinate, the box the route sits inside, the file's name, and the track itself simplified to at most 1,000 points. The file isn't kept, and the per-point timestamps most GPX files carry are dropped when it's read.
  • Bringing lists, on a casual trip. What's on the list, any note beside it, and who said they'd bring it.
  • Lending. Who asked whom for what, and the message of up to 500 characters attached to the ask.
  • Friends. Who you've asked and who's asked you. Both ends have to agree, and turning one down deletes it rather than filing it.
  • Packing ticks. What you've ticked off for one trip.
  • Feedback. What you wrote, and the page you were on when you wrote it — the path only, never the whole address, so a brief or invite link can't ride along in a query string.

What PlanWild records without you typing it

  • Sign-in cookies, set by Clerk. See cookies.
  • Preferences kept in your own browser and never sent anywhere: light or dark, which headings you folded on a list, whether the weight breakdown was open.
  • Error reports, when something breaks on the server. Each one carries the route it happened on, the error, up to fifteen frames of the stack, and PlanWild's internal id for your account. Before any of it is written down or emailed, anything shaped like a link token and anything shaped like an email address is replaced — and if the finished text still looks like it holds one, the whole body is thrown away and only a headline goes out.
  • Request logs from Fly.io, which hosts PlanWild. They include your IP address, the way every web host's logs do. PlanWild's own code never reads or stores an IP address or a browser user agent. Clerk does, for each sign-in session — see the companies.

What isn't here is worth saying out loud, because most products can't say it. There's no analytics of any kind. No advertising. No tracking pixels or beacons. No profiling, and nothing that follows you to another site. Even the fonts come from PlanWild's own server rather than a font service. The only things a browser fetches from somewhere else are Clerk's sign-in script, on every page, and the map tiles on a signed-in trip page — both named under the companies that help run PlanWild.

Who can see what

This is the part worth reading twice.

  • Only you. What you paid for something, the link you saved and your notes, on every item in your gear library. Your kits, and your lists until you put one on a trip. Which items you've ticked off packing.
  • Everyone on a trip you're on. Your display name and photo. Once you attach a list to the trip: each thing on it by name, what it weighs, how many, what kind of shared item it is, and what your share of the crew's weight comes to. Not what you paid, not the link you saved, not your notes — those stay on your side. Anything you marked as lendable is listed for someone to ask to borrow — its name, category and weight — even when it's on no list, and who sees it is the choice you made on the item: everyone on the trip, or only friends who are on it. How far through packing you are: your name, a bar and a count like 3/12, never which items. They also see who's lending what to whom, though the message attached to a lending request only reaches the two people in it. On a casual trip: what's on the bringing list and who said they'd bring it.
  • Anyone holding a brief link. See the brief.
  • You and the administrator. What you sent as feedback. Nobody else sees it, and a private note an admin writes on it isn't shown back to you.
  • An administrator. Today that's Mark. The admin section lists every account's display name, email address and join date, counts of its lists, gear, trips and feedback, and every piece of feedback with its author's name and email beside it. It shows no gear, no lists, no trips and no briefs. And the honest half: he runs the database, so there's nothing in it he couldn't reach if he went looking. Nothing in the app puts your gear or your trips in front of him.
  • Nobody else. Other people never see your email address: every screen that names someone is given an id, a display name and a photo, and nothing else. The one place an address comes back is an invite you sent, where you see the address you typed.

The brief, and what publishing one means

A trip brief is the one thing PlanWild makes readable outside the app. An organizer publishes it, it lives at a long random link, and anyone holding that link can read it with no account. That's the point of it: it's for the people at home.

What's on it: the trip's name and description, the dates, when to expect the crew back, the place, and the display name of everyone on the trip. If there's a route, the name written inside the GPX file, its distance, climb, high point and the shape of the climb. If the organizer turns it on, who's carrying which communal item and what it weighs.

What's never on it: coordinates, the route line, anyone's email address, any internal id, the invite list, and anyone's pack weight. The brief is assembled one field at a time on the server, and there are tests that fail if an email address, an id or a token reaches it. An account with no name on it appears as “Crew member” rather than by its email address.

Now the honest part. A brief link works for whoever holds it, and the page can be saved, printed or forwarded. Turning the brief off, or replacing the link, stops anyone opening it from then on — it can't take back a page somebody has already read or saved. And a published brief says that a named crew is somewhere else and when they'll be home. That's worth a thought before the link goes any further than it needs to.

Search engines are asked twice to keep briefs out of their results, by a header and by a tag on the page. That's a request, not a wall.

Invites

If you invite someone. You type their email address. PlanWild stores it on the trip and sends one message to it through Resend, and caps how many invites one account can send in an hour. The link in that message only works for an account signed in with that address.

If someone invited you and you have no account. Somebody who knows your address typed it into PlanWild. It's stored on that trip so the invite can be matched if you sign up. You can ignore the message — the invite stops working after fourteen days either way. What PlanWild doesn't do is clear the address when that happens: there is no timer, so it stays on the trip until the trip is deleted, or until the person who invited you deletes their account. If you'd rather it were gone now, write to privacy@planwild.net and it will be.

An organizer's own join link is a different thing, and it does work for whoever holds it: anyone with an account who opens it joins the trip. The organizer can turn it off or replace it at any time.

The companies that help run PlanWild

Five of them run PlanWild, and here's what each one gets.

  • Clerk — sign-in and accounts. Your email address, name and photo, and the sessions that keep you signed in. Clerk records your IP address and which browser you're on with each session, so it can spot a session that isn't you. Your account really lives there and PlanWild holds a copy. If you sign in with Google, Google tells Clerk your email address, name and picture, and Google learns you signed in to PlanWild. United States.
  • Resend — email. For an invite: the address it's going to, the trip name, who invited them, and the join link. Also the error alerts that go to Mark. United States, and Resend keeps message content and delivery logs for thirty days.
  • Fly.io — hosting and the database, in Chicago. Everything above sits on machines Fly runs, and Fly's own logs record requests your browser makes, including your IP address.
  • The US National Weather Service — the forecast on a trip page. It's sent the route's start coordinate rounded to four decimal places and nothing else: no name, no address, nothing about whose trip it is. PlanWild's server asks, not your browser.
  • The US Geological Survey — the topo map on a trip page. Besides Clerk, this is the only third party your own browser talks to: fetching map tiles tells USGS your IP address and roughly where the route runs. It happens on the signed-in trip page only. A brief never draws a map, so someone reading a brief contacts nobody but PlanWild and Clerk.

And one that doesn't run anything: whatever mail provider carries Mark's email. An error alert lands there, and so does anything you write to the addresses on this page — the same as any email you send anyone.

None of them is an advertiser, and none of them is given anything about you to use for their own purposes. PlanWild doesn't sell personal information, doesn't share it for anyone's advertising, and has nothing to gain by doing either.

The exception every service has: if a law or a court order required something to be handed over, it would be, and you'd be told unless telling you was forbidden.

Where your information is kept

In the United States. The app and its database run in Chicago, and every company above is a US one. If you're somewhere else and use PlanWild anyway, what you put in is stored and handled in the US.

How long things are kept

A list rather than a paragraph, because PlanWild doesn't run a tidy expiry schedule and it would be easy to write this as though it did.

  • Your account and everything on it: until the account is deleted. Nothing expires on its own.
  • Feedback you sent: kept after your account goes, with your name taken off it. The text you wrote stays as you wrote it.
  • Things you added to someone else's bringing list: they stay on that trip, with no name on them.
  • An email address someone was invited at: until the trip is deleted, or the person who sent the invite deletes their account. Write to privacy@planwild.net to have one removed sooner.
  • Error reports: seven days in Fly's log search, which is Fly's own retention. The alert email sits in Mark's mailbox until he deletes it.
  • Resend's copy of an invite: thirty days.
  • Database backups: Fly takes a snapshot of the database's disk once a day and keeps five days of them, and on 18 September 2026 one of those snapshots was restored and read to check it works. Two things follow. A copy of something deleted can sit in a snapshot for up to five days after it's gone from the app. And because the snapshots are daily, a bad enough failure could lose up to a day of everyone's changes.

Deleting your account

Open your account from the menu in PlanWild and choose to delete it. That goes through Clerk, the same place your name and email address live. If anything gets in the way, write to privacy@planwild.net and Mark will do it by hand.

What it's meant to do: remove your account, your gear, your lists, your kits, your packing ticks, your friendships, and your place on every trip you're on. A trip you organized isn't deleted out from under everyone else — it passes to whoever has been on it longest, and its join link and brief are turned off on the way, because the new organizer never handed those out. A trip with nobody else on it is deleted.

What stays behind, by design:

  • Feedback you sent, with your name removed and the text intact.
  • Things you added to a bringing list on somebody else's trip, with no name on them — an open need is still a need.
  • A trip you organized, with its description, its dates and its route, now under someone else.
  • A copy in a database snapshot, for up to five days.

And the part a policy usually wouldn't admit. Deletion runs on a message Clerk sends PlanWild when an account goes. On 18 September 2026 one of those messages was watched arriving on the live site and answered, so the path is connected — but no real account has been deleted through it yet. So treat deletion as something to confirm rather than assume: delete the account, then write to privacy@planwild.net and Mark will check it actually happened. The same message carries a change of name or email address, so the same caveat applies there.

You won't find the words “permanently deleted” anywhere on this page. A snapshot holds a copy for a few days, and the honest version of that sentence is the one above.

Getting a copy of your data

There's no download button yet. Write to privacy@planwild.net and Mark will put together what PlanWild holds about you and send it within thirty days. It will leave out other people's personal information — the addresses on invites you sent, the other people on a trip — because that part is theirs.

One thing you can export yourself today: a single pack list, as a CSV, from that list's own page. That's a list, not a copy of your account.

Changing your name or email address

Both live at Clerk. Change them from the account menu and the change follows through to your trips, your lists and any brief, because PlanWild keeps your name in one place and every screen reads it from there — there's no stale copy sitting on a trip or a list to go and fix. The caveat under deleting your account applies here too: the change reaches PlanWild by the same message.

One thing that fails quietly: an invite already sent to your old address won't match your new one. Ask whoever invited you to send another.

What you can ask for

Wherever you live, you can ask to see what PlanWild holds about you, correct it, get a copy of it, delete it, or object to something PlanWild is doing with it. No thresholds, no forms, and nobody gets a worse service for asking.

Write to privacy@planwild.net. You'll get an answer within thirty days. One person answers them, so the answer may be short.

If you were invited and never signed up, you can ask for your address to be removed at the same place. You don't need an account to ask.

Cookies, and what's kept in your browser

PlanWild's own code sets no cookies in production. The one cookie it can write is a development switch used for testing, gated twice so it can't exist on planwild.net.

Clerk sets the sign-in cookies, and they're what keeps you signed in. Signed out, they're two small flags saying nobody is. Signed in, a session cookie, a refresh cookie and a client cookie, plus two short-lived ones while a session refreshes. Clerk's script also stores a copy of its own configuration in your browser, and Clerk's own cookie list names one more, set by Cloudflare, which sits in front of Clerk. These are Clerk's to set and Clerk's to change.

Three things live in your browser's own storage and never leave it: whether you chose light or dark, which headings you folded on a list, and whether the weight breakdown was open.

Why there's no cookie banner: none of this is advertising, analytics or tracking. Nothing here profiles anyone or follows you anywhere, and a cookie that signs you in isn't something to ask permission for.

One thing to be straight about, though. Clerk's script loads on every page of the site, including a published brief. A family member who opens a brief link, has no account and never signs in still gets that script and those two signed-out flags. Nothing about them is tracked and nothing profiles them — but it would be truer to say nothing is put on your device unless you sign in, and moving Clerk off the brief page is on the list.

Do Not Track and Global Privacy Control

No third party collects information about what you do across other websites on any PlanWild page. PlanWild doesn't sell or share personal information and doesn't use it for targeted advertising. So a Do Not Track or Global Privacy Control signal asks for something PlanWild already does, for everyone, all the time. PlanWild doesn't read the signal, because there's no behavior for it to change.

Children

PlanWild isn't meant for children and isn't aimed at them. Don't make an account if you're under 13. There's no age gate and PlanWild holds nobody's date of birth, so this is a rule rather than a check — it isn't verified and this page won't pretend it is. If Mark learns an account belongs to someone under 13, he deletes it.

The practical version for a family trip: a child should be a name on the bringing list, added by an adult, rather than an account of their own.

Security, and what PlanWild doesn't promise

What's true, and checkable:

  • Everything runs over HTTPS.
  • PlanWild never sees or stores your password. Clerk holds it.
  • PlanWild takes no payments and holds no card numbers, no government ids and no social security numbers. No field anywhere asks about health — but a note or a bringing-list item is a free text box, so don't type anything medical into one.
  • Brief and join links are 256-bit random tokens, and an organizer can turn either off or replace it.
  • An emailed invite expires after fourteen days, works once, and works only for an account signed in with the address it was sent to.
  • The brief is built one field at a time, with tests that fail if an email address, an id or a token reaches it.
  • Error reports are stripped of anything shaped like a link token or an email address before they're written or sent, and a report that still looks like it holds one is thrown away rather than sent.

And what isn't promised. No system is perfectly secure, and PlanWild doesn't promise that what you put in can't be lost or reached by someone who shouldn't. Fly takes a daily snapshot of the database and keeps five days of them, and a restore from one of those snapshots has never been tested — so nothing here should be read as a promise that your lists will still be there. Keep anything you'd hate to lose somewhere else too.

Found something wrong with PlanWild's security? Write to security@planwild.net. The same address is in /.well-known/security.txt.

If something goes wrong

If Mark finds that someone reached information they shouldn't have, he'll work out what happened, email the people affected, and tell whichever authority the law requires. That's one person sending emails. There's no automated notification system behind that sentence, and saying otherwise would be exactly the kind of promise this page is trying not to make.

Changes to this policy

The current version always lives at planwild.net/privacy, with the date it last changed at the top. If something material changes — a new company handling your information, a new kind of information collected, something newly visible to someone else — that gets said rather than quietly edited in. A typo fix doesn't get an announcement.

Getting in touch

privacy@planwild.net for anything on this page: a question, a correction, a copy, a deletion, or an address you were invited at and want gone.

support@planwild.net for everything else, and security@planwild.net for a security problem.

Mark Onofrio LLC, United States. PlanWild has no office to visit and no phone number to call. Email is the way in.