Privacy Policy
Last updated
Past the Hedge operates this service. This policy describes what Past the Hedge collects about you, why, and where it goes. It's written to be accurate about what the code actually does, not a generic template.
On this page9 sections
What we collect
Your email address and password (stored as a salted one-way hash — we never see or keep the plain password after you set it). If you turn on two-factor authentication, the shared secret and hashed backup codes. If you link a Google account, its account ID and email, so you can sign in that way instead. A private forwarding address unique to your account. Whichever passport countries and travel-companion names you choose to enter. And the travel bookings you forward or add — confirmation numbers, dates, addresses, prices, and the like.
How booking emails are processed
When you forward a confirmation email, it's received by Cloudflare's email service, parsed by a script running on Cloudflare's infrastructure, and sent to Past the Hedge's server. From there the email text (and any PDF attachment) is sent to an AI model to pull out the flight, hotel, or other booking details. Data sent to the AI model is used solely for real-time parsing and is not used to train AI models. The raw email is also kept as-is on our own server, so that if the parser gets something wrong, nothing is lost and it can be fixed. We log how much this costs and how often it runs, per account, to enforce a daily budget — that usage log does not contain the email content itself.
Other third parties data passes through
Checking a flight's status sends its flight number and date (not your name or any other personal detail) to third-party flight status APIs. If you use Google sign-in, Google is involved in that exchange in the usual OAuth way. Looking up a place by name may call Google's Places API. Cloudflare also handles the network path into the server and stores encrypted nightly backups. None of these third parties receive more than what's needed for the specific thing they're doing.
How we secure it
Passwords are salted and hashed. Session cookies, password-reset links, and backup codes are stored as hashes, not the values themselves — a copy of the database alone can't be used to sign in as you. We use essential session cookies solely for authentication and security. There is no analytics or tracking script on this site, and the application itself does not log your IP address. Cloudflare, which handles the network path into the server and receives forwarded mail, keeps its own connection and delivery records as any such provider does.
Backups and retention
The database is backed up nightly, encrypted on our own server (before it ever leaves) with industry-standard strong encryption, then stored off-site. Backups older than 90 days are deleted automatically.
Your choices
You can remove passport countries, edit or delete bookings, and disconnect a linked Google account yourself, at any time, from your account settings. To request a copy of your data or full deletion of your account, email legal@pastthehedge.com.
Children
Past the Hedge isn't directed at children, and accounts aren't knowingly created for anyone under 16.
Changes to this policy
If what's collected or how it's used changes meaningfully, this page changes with it. Last updated 20 August 2026.
One more thing
This page is about data about you. The separate question of which public map and rail datasets Past the Hedge is built on, and under what licence, is answered on the colophon page.

