Privacy

What we collect, why, and how we use it.

Plain English, no dark patterns. Written by a human.

Last updated · October 2026
TL;DR — WondrOut doesn't track you across the web, sell your data, or use profiling ads. If you browse without an account, almost everything stays in your browser. If you create an account, your saved spots, trips and purchases sync to our database so they follow you between devices. Payments go through Stripe — we never see your card number. We use Google Analytics and Microsoft Clarity (only if you accept the cookie banner) to understand how the site is used. Social videos in the Watch feed are embedded from Instagram and TikTok, so those platforms see your IP when the videos load. Some spot descriptions are drafted with AI; see "How we use AI" below.

Who we are

WondrOut is operated by WondrOut Pty Ltd (ABN 83 701 734 723), based in Perth, Western Australia. You can reach us at hello@wondrout.com for any privacy question, data access request, or complaint. If you need a postal address for a formal notice, email us and we will provide one.

If you're not happy with how we've handled a privacy matter, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. If you're in the EU or UK, you can complain to your local data protection authority.

What we collect

In your browser (localStorage)

If you're browsing without an account, this data stays in your browser unless you explicitly submit something (a tip, a shared trip, or a subscription).

If you create an account

You can browse WondrOut without an account. You need one to sync across devices, buy a paid list or guide, or publish as a creator. When you have an account, we store:

Accounts and this data are stored in Supabase (see "Third parties we use"). Sign-in emails are sent by Resend. Once you sign in, your saved data is no longer browser-only — it lives on our servers until you delete your account.

When you buy something

Paid trips, lists and guides are sold by independent creators and paid for through Stripe. Stripe processes the payment and, for creators, the payout.

When you submit a tip or review

Tips are stored in our database and moderated before being shown publicly.

When you use the help chat

Your messages are sent to Anthropic's Claude to write each reply. Under Anthropic's API terms they are not used to train its models. We keep chat transcripts for 90 days so we can see which questions the assistant could not answer and improve it, then delete them. Please don't put card numbers or passwords in the chat; the assistant never needs them and will never ask.

When you share a trip

When you subscribe to our newsletter

When you join a creator's email list

We use this so that creator can contact you about their new lists, trips, codes or recommendations. We don't sell these emails.

When you upload a photo or video

Photos you upload are stored on Cloudflare Images and served from there. We strip nothing from the file automatically, so if your photo carries EXIF location data it may be uploaded with it — don't upload photos of places you don't want located. Videos you link stay on Instagram, TikTok or YouTube; we only store the link.

Location

If you grant location permission, we use your coordinates only to:

Your location is used on your device and isn't stored in your profile or sold. If you deny permission, the app still works — we just fall back to the city you're browsing.

How we use AI

Some content on WondrOut is drafted using AI. We use AI tools (currently Anthropic's Claude and Google's Gemini) to draft spot descriptions, summaries, category tags and travel notes, which our team reviews before publishing. Content written by a named creator is theirs, not AI-drafted, unless it says otherwise.

AI-drafted text can be wrong. Treat descriptions, travel times and access notes as indicative and confirm with the venue — see section 7 of our Terms.

We don't feed your personal data to AI models. The inputs are public place information — name, address, coordinates, category. Your saved spots, tips, location and purchase history are not used to train anyone's model, and we don't sell data to AI companies. The one place your own words reach an AI model is the help chat, where what you type is sent to Claude to write the reply (see "When you use the help chat" above).

Analytics

We use Google Analytics 4 (GA4) to understand which pages people visit and which features they use, in aggregate. GA4 receives standard page-view data (URL, referrer, screen size, anonymised IP) and sets a first-party analytics cookie (_ga) to tell repeat visits apart. We don't use Facebook Pixel, ad-network trackers, or anything that follows you across other websites.

If you accept the cookie banner we also use Microsoft Clarity to see how people use the site — for example where they click, how far they scroll and where they get stuck — so we can fix confusing pages. Clarity records clicks, scrolling and mouse movement on our pages and masks text you type into forms. It sets first-party cookies (_clck, _clsk). If you decline, Clarity never loads. Microsoft's privacy statement: privacy.microsoft.com.

Watch feed (Instagram & TikTok embeds)

The Watch tab plays short videos by embedding them directly from Instagram and TikTok. When a video loads, your browser connects directly to those platforms — they can see your IP address, browser type, and (if you're logged into them) your account. WondrOut doesn't see or store any of that.

We don't host the videos. We don't claim ownership of them. The "Follow" button links to the original creator's profile.

If you're a creator and want a video featuring your content removed from the Watch feed, email hello@wondrout.com with the video URL or your handle. We'll remove it within 7 days. (See also our copyright / takedown section below.)

Connecting your Instagram account (creators)

Creators can choose to connect a professional Instagram account so their new Reels turn into places on their WondrOut map. This is optional and only happens when you tap Connect and approve it on Instagram's own screen.

What we read: your Instagram username and account ID, and for each post its caption, link, cover image, media type and the time it was posted. If you also allow insights, we read view, reach and engagement numbers for your posts and account so we can show them in your creator analytics. We do not read your messages, followers' details or anything you have not posted.

What we do with it: we send a Reel's caption and cover image to our AI provider to work out which place it shows, and the place name to Google Places to find its location. If we are confident, the Reel is added to that place on your map; if not, it waits for you to confirm. The cover image is copied to our own image storage to use as the place's photo. We never post to your Instagram, and we never sell or share this data.

Comment replies (optional): if a creator switches on "Comment for the link", we receive the comments posted on their Instagram posts so we can spot their chosen keyword. When a comment has it, we send that person one private message on Instagram with a link to the place on the creator's WondrOut map, and, if the creator chooses, a short public reply under the comment. We keep the comment's ID, the commenter's Instagram username and ID, and whether the message was sent, so nobody gets the same link twice. We don't store the text of comments, and we never message anyone who didn't comment the keyword.

What we keep: your Instagram access token, encrypted, so we can check for new posts; and an import history of the posts we looked at and what we decided. Places you approve stay on your map until you remove them.

Disconnecting and deletion: you can disconnect from your creator settings at any time, or remove WondrOut in Instagram under Settings, Apps and websites. Either one deletes your token straight away. To delete everything we hold from your Instagram account, including the import history, your Instagram stats and the comment-reply record, use Meta's data deletion request or email hello@wondrout.com. You can check a deletion request's status at the link Meta gives you.

Third parties we use

Some of these are outside Australia — mainly the United States and the EU. By using WondrOut you accept that your data may be handled overseas by the providers above.

Cookies

We don't use advertising or cross-site tracking cookies. What's set:

How long we keep things

Your rights

You can:

We don't sell your personal information, and we don't share it for cross-context behavioural advertising, as those terms are used in California law.

Copyright / takedown

If you believe content shown on WondrOut (an embedded video, a photo, a description, etc.) infringes your copyright or trademark — or if a video features you and you want it removed from the Watch feed — email copyright@wondrout.com with:

We aim to action takedown requests within 7 days. Full notice requirements, our United States designated agent, and our repeat-infringer policy are set out in section 12 of our Terms. Embedded social videos can also be removed instantly by deleting or privatising the original post on Instagram / TikTok — our embeds disappear automatically when the source is gone.

Security

Data is held with the providers listed above, in transit over HTTPS. Card details never touch our servers. No system is perfectly secure, but if a breach affects your personal information we'll notify you and the OAIC as required under the Notifiable Data Breaches scheme.

Kids

WondrOut isn't directed at children under 16. You must be at least 16 to create an account. If you're under 16, please don't submit tips or sign up for the newsletter without a parent's consent. If we learn we're holding data from someone under 16, we'll delete it.

Changes to this policy

If we change this policy materially, we'll update the "Last updated" date above and tell account holders and newsletter subscribers by email.

Contact

Questions, concerns, or complaints: hello@wondrout.com