Privacy
What Andiamo knows about you
Andiamo works out journeys from public data. It does not need to know who you are to do that, and it only asks if you want watches, alerts or a profile that follows you from one search to the next. Here is the exact list.
In one sentence
Without an account, no personal data is collected and no tracking cookie is set. With an account, Andiamo keeps your email, your travel profile and the history of your tool calls, hosted in the European Union. Nothing is sold or handed to an advertiser.
Without an account: nothing that identifies you
The public MCP server (/api/mcp) and the showcase site work without signing up. Site traffic is measured without cookies and without any persistent identifier (the next point explains how): no advertising tracker, no third-party pixel, nothing that follows you from one visit to the next.
Every tool call is recorded on the server for technical monitoring: the tool name, its arguments (the stations, dates and places requested), the status, the duration. On the public URL, this line is tied to no account and no browser identifier. These are search parameters, not an identity, but you should know all the same.
Audience and usage measurement
The site may load two measurement tools, and only when they are configured in the deployment environment: without that configuration, no script is loaded and nothing is sent. Plausible counts page views and where they come from, without cookies and without any persistent identifier: two visits by the same person remain two anonymous visits. PostHog receives a handful of usage events sent explicitly by the site (a search launched, a guide viewed, a click through to a retailer), and it is configured with no cookie and no storage in the browser: the page's memory, nothing that outlives the tab.
These measurements carry neither your identity nor the content of your searches: no place, no date, no typed text. Plausible and PostHog (on an instance hosted in the European Union) are technical subprocessors, on the same footing as the hosting providers below: they handle these measurements to run the service, not on their own account. No cookie is set, and if that were ever to change, this page would change along with the code.
With an account: email, profile, history
Creating a free account serves three purposes: a personal MCP URL, seat watches and a profile of travel constraints. What is then kept:
- your email address, for authentication and to send you your alerts;
- your travel profile: TGV Max pass, discount cards, usual departure city, favourite stations, preference, connections you tolerate;
- your watches and the alerts they produce (journey, period, availability detected);
- the log of the calls made through your personal MCP URL: tool, arguments, status, date. It is visible in your dashboard, under History: you see exactly what is stored.
Andiamo asks for no name, no phone number, no postal address, no payment method. It has no use for them.
Where this data is hosted
The database and authentication are run by Supabase, on an instance hosted in the European Union (Paris region). The site and the MCP server run on Vercel. Alert emails, when you turn them on, go out through Resend.
These three providers are technical subprocessors: they handle the data to run the service, not on their own account.
What the external sources receive
A search queries outside services: SNCF Open Data for trains, transport.data.gouv.fr for bus and urban timetables, the French national address base to geocode a place, SerpAPI for flights. Andiamo passes them the question (a station, a city, a date, an airport code) and nothing more: not your email, not your account identifier, not your MCP token, not the content of your conversation with the assistant.
These sources therefore see requests that come from the Andiamo server, not from you.
The booking links
Andiamo sells no ticket: it sends you on to the retailer. Some of these links may be partner links, flagged as such, and what travels with them is an opaque surface identifier, never personal data. The detail is on the partner links page. Once you are with the retailer, its own cookie policy applies.
What Andiamo does not do
- No sale, rental or transfer of data to a third party.
- No advertising profiling, no reselling of audiences.
- No model training on your searches or your conversations.
- No tracking cookie, on any page of the site.
How long, and how to erase
Your profile, your watches and your alerts live for as long as your account exists. You can delete a watch at any time from the dashboard or with the delete_tgvmax_watch tool, and revoke a personal MCP URL from the Connector page.
Deleting the account erases the profile, the tokens, the watches and the alerts. The technical log lines are detached from the account: they no longer carry any link back to you.
You have a right of access, rectification, erasure, objection and portability over this data. To exercise it, or to request account deletion, go through the support channel below.
Support and contact
The public channel is the contact form on the site: contact us. It emails us, it opens no public thread: what you write there is read by us only. For a request that touches your account, just say what you want done, and verification will go through the account email address.
Andiamo is an independent project, not affiliated with SNCF or any operator. The code is not open: what is described here cannot be checked in the repository, only against what the service does, and against what we answer if you ask us.
If this page changes
It describes the real behaviour of the service at the moment you read it. Any change to storage or providers is written here at the same time as the code change, not afterwards.