Last updated 29 July 2026
RefundTrip helps you find refunds and compensation US airlines owe you, and track the credit card travel benefits that cover what federal law does not. Doing that requires reading your travel confirmations. This page explains exactly what we access, why, how long we keep it, and how to make us delete it.
The short version. We read only the travel confirmation emails needed to build your trip history. We never sell your data, never use it for advertising, and never use it to train AI models. You can disconnect and delete everything at any time, and we delete it permanently.
RefundTrip is operated from the United States. For any privacy question, contact privacy@refundtrip.com. We respond to all requests within 30 days.
If you connect a Google account, RefundTrip requests read-only access to your Gmail messages. We request this scope because there is no narrower Gmail scope that permits searching for and reading travel confirmations.
| Scope | Why we need it |
|---|---|
gmail.readonly |
To locate airline, hotel, and travel agency confirmation emails and extract flight details: carrier, flight number, route, dates, confirmation number, fare paid, and the last four digits of the payment card. The last four digits are required because credit card travel protections only apply to the card that paid for the trip. |
userinfo.email |
To identify your account and send you claim notifications. |
Confirmation emails come in hundreds of different layouts, so we use an automated language model to pull the flight details out of them. In plain terms: after we have narrowed your mail to messages from known travel senders, the text of those messages is sent to our AI processing provider, Anthropic, which returns the carrier, flight number, route, dates, confirmation code and card last four. We store those fields and discard the message text.
Three things about that, stated plainly:
RefundTrip's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we affirm that Google user data is:
We do not sell your personal information. We share it only in these circumstances:
We keep your extracted trip data while your account is open. Card claim windows are short, from 20 to 100 days, but a statutory fare refund has no deadline and a travel credit can sit unused for a year, so an older trip is still worth holding.
Delete my account. Cancels any active membership, revokes Gmail access, and permanently removes your trips, claims, and history. This cannot be undone.
Type DELETE to confirm.
Data is encrypted in transit using TLS and at rest. OAuth tokens are stored encrypted and are never exposed to the browser. Access to production systems is restricted to personnel who require it, and is logged.
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to certain processing. California residents have specific rights under the CCPA, including the right to know what personal information we collect and the right to delete it. We do not sell personal information as defined by the CCPA. Exercise any of these rights by emailing privacy@refundtrip.com. We will not discriminate against you for doing so.
RefundTrip is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
If we make material changes to how we handle your data, we will notify you by email before those changes take effect, and update the date at the top of this page.