Privacy Policy
Travis is an AI agent that operates across the vendor systems you use for work. To do that, we hold a working record of your activity behind your sign-in, sync it across the devices you use Travis on, and — only when you connect them — talk to the third-party systems you've chosen to integrate. This page describes exactly what we collect, how we use it, and the rights you have over it.
Who we are
Travis is operated by Travis (a three-cofounder team led by Michael Ezeoda, Taylor Turntime, and David Nnabuike). You can reach us at hello@usetravis.com. If you live in the EU, we are your data controller for the purposes of GDPR. If you live in the UK or California, the equivalent roles under UK GDPR and the CCPA apply.
How sign-in works
Travis requires a Google sign-in. We use it as your identity and as the key that ties your work to your account. We never receive your Google password — Google's standard OAuth flow lets you grant Travis a session without sharing it.
When you sign in on the desktop, your session token is stored in a permissions-restricted file inside the app's data directory on your device. On macOS, Windows, and Linux this means a file readable only by your operating-system user account. On the web, the session is a short-lived HTTP-only cookie scoped to usetravis.com.
What we store about you
On a Travis account, we hold the following:
- Account record: email, name, sign-in method, plan, when you joined.
- Connected sign-ins: basic Google profile + an encrypted refresh token to let you sign back in. No password.
- Connected integrations: if you connect a third-party system (Calendar, Gmail, LMS, CRM, etc.), we hold an encrypted OAuth token so Travis can act on your behalf in that system. We do NOT store a wholesale copy of the data inside that system — we read it on demand to do the work you asked for, and we cache only what's needed for performance.
- Your work: notes, conversations, captures, documents, memory entries, entity graph — everything you ask Travis to remember.
- Settings + preferences: voice preference, notification frequency, enabled packs, the like. Synced across your devices.
- Subscription state: your current plan and billing status.
- Usage records: the number of times Travis acted on your behalf and the rough cost — used to enforce your plan's daily cap, never to charge you more than your plan allows.
- Workflow runs: if you've set up scheduled work, we keep a record of each run for the "while you were away" feed.
- Sessions: the active devices signed in to your account, with last-used timestamps. You can revoke any individual session from your settings.
- Audit log: sign-ins, plan changes, support actions — kept for security and compliance.
What we never collect
- Wellbeing observations Travis might form about you — those stay on your device and are never sent to our servers.
- Your Google password.
- Bring-your-own-key (BYOK) API keys you store in your OS keychain — those never reach our servers, by design.
- Your contacts (unless you've connected an address book yourself).
- The contents of integrated third-party systems in bulk — only what's needed for the specific task you've asked Travis to do.
- Children's data (Travis is not directed to children under 13).
How integrations + packs work for privacy
Travis is a pluggable platform. Skills (atomic capabilities) and Packs (curated bundles) can use Integrations (OAuth wrappers around third-party systems) on your behalf, only with the scopes you grant.
- You see every integration you connect on the Connections page and can disconnect any one of them at any time.
- When you install a pack, you see what permissions and integrations it will use before you confirm.
- First-party packs (built by us) are reviewed before they ship. Partner-built packs (when we open that channel) will be signed and reviewed before being listed.
- Skills declare what data classes they touch (e.g., PII, FERPA, IEP, calendar). Access is logged in your audit trail.
How your data is used
To provide the service:
- Sync your work across your devices so it's there when you sign in.
- Talk to integrated third-party systems on your behalf, only as you've authorized.
- Run scheduled workflows you've set up.
- Enforce your plan's daily cap so we never charge you more than your plan allows.
- Bill you accurately.
- Support you when something goes wrong.
To improve the service:
- We look at how Travis is performing in real usage to find where it's getting things wrong, where features are confusing, and where we should focus our next investment. That includes reviewing aggregate patterns across the platform, and on a focused basis looking into specific user experiences when we're debugging or investigating a quality problem.
- What this never means: we do not share your work with third parties, we do not sell your data, we do not use your work to train any AI model — ours or anyone else's. Insights we derive stay inside Travis to make the product better for you.
- Access is logged. Reviews happen under named accounts; we record who looked at what and why. Privileged access is restricted to operators with explicit need.
- Where practical we work with aggregate counts and de-identified samples rather than individual records.
- Org accounts can opt out of platform-improvement use of their data as part of their contract. Personal accounts on Free, Pro, and Max tiers participate by default; an in-product opt-out toggle is on the roadmap.
Beyond providing and improving the service, we do not look at your work except when we must investigate an explicit support request, security incident, or legal compulsion — and even then access is logged.
Cookies and tracking
Our marketing site sets no cookies by default. We do not run third-party tracking pixels, profiling analytics, or advertising trackers. See the full Cookie Policy for the small handful of technical exceptions.
We send transactional email: welcome messages on first sign-up, new-device sign-in security notifications, plan-change confirmations, billing receipts, account-deletion confirmation, and other operational notices. We don't send marketing email without a separate opt-in. Transactional emails are required to operate the service and can't be opted out of without closing your account.
Who else processes your data
We work with a small number of vendors to deliver the service:
- Cloudflare — hosting, storage, edge compute, and at-rest disk encryption for stored data.
- Anthropic — provides the underlying intelligence for hosted plans (Claude models). Long-term, we plan to ship our own models alongside Anthropic's.
- Stripe — payment processing. We never see your full card number.
- Resend — sends transactional email.
- Google — sign-in, and (only if you connect them) Calendar / Gmail / Workspace integrations.
- WorkOS — planned for Enterprise SSO (SAML/OIDC) and SCIM provisioning. Not active yet for personal/Pro accounts.
We do not sell personal data. We do not share data with advertisers. We do not use your data to train any model.
Security
All data in transit is encrypted with TLS. Data at rest is encrypted at the storage layer by our hosting provider (Cloudflare's at-rest encryption). Sign-in sessions are short-lived and can be revoked instantly from your settings.
On the roadmap (not yet shipped): per-user application-level encryption of stored content using a master key issued at sign-up, so that even disk-level access to our hosting provider's storage cannot read your work without your active session. We'll update this policy with the precise threat model when that ships.
OAuth tokens for third-party integrations are encrypted with a server-side wrapping key before being stored, so they can't be read even if our database were compromised at the row level.
Only essential staff have production access today, and every administrative action is recorded in the audit log.
If you discover a security issue, please email security@usetravis.com. We respond within 72 hours and credit responsible disclosure with your permission.
Research access (opt-in)
Some users choose to help us improve Travis by opting in to "research access" — Travis observing how they actually work so we can build features that fit real workflows instead of guessed ones. This is strictly opt-in, per-layer, and can be paused, revoked, or wiped at any time from your account settings.
The layers you can turn on independently:
- Apps you're using — the app name and window title currently in focus, and how long. No content, no screenshots.
- Web pages you visit — URLs and page titles from browser tabs. Requires installing our browser extension separately.
- Screenshots — periodic captures of your screen, encrypted at rest and stored only for the retention window you choose.
- Document + email content — the actual text of what Travis sees. The deepest signal, and only recommended if you have a specific reason to want us reading what you write.
What we do with it:
- Analyze aggregate patterns to prioritize which packs, integrations, and workflows to build next.
- Review individual sessions (with your knowledge) when you're helping us debug a workflow.
- Never sell, share with advertisers, or use for anything besides improving Travis for you and future users.
What we don't do:
- Combine it with any dataset outside Travis.
- Use it to train third-party AI models.
- Continue capturing after you pause or revoke — the pause is immediate; revoke is immediate.
- Keep captured data past your chosen retention window (default 90 days, configurable per layer).
You can see a complete log of every consent change you've made (grants, revocations, pauses, deletes) alongside the raw captured data itself — both are surfaced in your account settings. Requesting deletion at any time removes every captured record for your account immediately; the consent history log stays so we have a record that you exercised your rights.
How long we keep things
- Account records: while your account is active; deleted within 30 days of closure.
- Your work: while your account is active; deleted within 30 days of closure.
- OAuth tokens: deleted immediately when you disconnect the integration or close your account.
- Usage records: 18 months for billing-dispute resolution, then deleted.
- Audit log: 24 months for security investigation, then deleted (Enterprise tiers may have longer retention by contract).
- Workflow runs: 90 days for the feed, then deleted.
- Sessions: revoked sessions are removed from the active list immediately; the row stays in the audit log for the audit-log retention window.
Your rights
Regardless of where you live, you can:
- Access a copy of the data we hold about you — request from settings.
- Correct any inaccurate data — most fields are editable in the app.
- Delete your account and all associated data — one click in settings.
- Export your data in a portable format — also one click.
- Withdraw consent at any time.
- Object to processing for any legitimate-interest purpose.
- Lodge a complaint with your local supervisory authority.
For EU residents, the legal bases for processing are: contract (running the service you signed up for), legitimate interest (security and abuse prevention), and consent (optional features). For California residents, we treat your personal information consistent with the CCPA — we do not sell or share it for cross-context behavioral advertising.
Children
Travis is not directed to children under 13 today. When our Education tier launches, K-12 student accounts will be provisioned only through a district's institutional agreement, and we will comply with COPPA's verifiable-parental-consent requirements before any under-13 account is created. Until then, please do not sign up children.
If you believe a child has signed up, email hello@usetravis.com and we will delete the account.
International transfers
Travis runs on a global hosting network. Data may be processed in any region that network operates in. When data moves out of the EEA, we rely on Standard Contractual Clauses as the transfer mechanism. Enterprise and Government tiers may include data-residency constraints by contract.
Changes to this policy
We will post material changes to this policy at least 30 days before they take effect, both here and by email to existing accounts. The "Last updated" date at the top always reflects the most recent version.
Contact
Privacy questions, requests, or complaints: privacy@usetravis.com. General questions: hello@usetravis.com.