Andeor privacy
Privacy Policy
Last updated 30 August 2026. This policy explains how Andeor handles personal data across its marketplace and services, including Andeor Vault and the Andeor app in ChatGPT. It covers what we collect, why we use it, who receives it, how long we keep it and the choices available to you.
1. Who is responsible for your data
Andeor is responsible for the Andeor marketplace and the Andeor app in ChatGPT. Questions and privacy requests can be sent to info@andeor.travel.
2. Andeor Vault
Andeor Vault is a private password manager for authorised Andeor team members. Its sole purpose is to let a team member save, synchronise and fill login credentials that they choose to place in their personal encrypted vault.
Credential data
A saved entry can contain a title, website address, username, password, notes, favourites and update information. Vault encrypts this content in the user's browser before it is synchronised.
Login-form detection
The browser extension checks secure webpages for login fields so it can offer saving and filling. A detected credential remains in protected browser-session storage for no more than ten minutes unless the user reviews it sooner. Vault does not submit login forms and does not send an unsaved candidate to Andeor's servers.
Account and device data
Andeor processes the signed-in team member's account identifier, extension identifier, device identifier, device name, authorisation dates and limited security metadata to connect, synchronise and revoke approved browsers. A single-use code sent to the authorised Andeor email verifies each new browser. Supabase verifies the code, and the extension receives only a revocable Vault device token.
Technical data
Hosting and security systems may process an IP address, request time, endpoint, response status and limited diagnostic data needed to operate and protect Vault. Passwords, master passwords and decrypted vault contents are not intentionally written to application logs.
Encryption and access
Vault uses authenticated encryption for the saved vault and derives its encryption key from the team member's master password in their browser. Andeor stores and synchronises the encrypted vault but does not receive the master password or the decrypted credential entries. Authorised infrastructure providers process the encrypted vault and limited account, device and request data needed to deliver the service.
A trusted browser keeps an encrypted offline copy and limited connection information. Unlocking places the derived key and decrypted working data in protected browser-session storage for the active Vault session. The user can lock Vault at any time. The session also locks automatically after inactivity.
Retention and controls
Encrypted entries are retained until the team member deletes them or deletes the vault. Device access records are retained while that browser remains approved and can be revoked from the Vault security centre. Disconnecting the extension removes its local connection, encrypted cache and session material. Limited security logs are ordinarily retained for no more than thirty days unless a longer period is needed to investigate abuse, a security incident or a legal claim.
Team members can review, add, change and delete entries, export an encrypted backup, revoke one or all browsers and delete their vault. Support requests must never include a password, master password, recovery secret, device token or decrypted backup.
Andeor Vault's use of information received from Google APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Vault does not sell credential, browsing or account data, use it for advertising or allow people to read decrypted credentials.
3. The Andeor app in ChatGPT
The public Andeor app helps people discover current Mauritius experiences and check published departure information. It is a read-only discovery service. It does not create an Andeor account, make a booking, take payment or send a message to an experience partner.
Search tool inputs
ChatGPT may send Andeor a search phrase, activity category, Mauritius location, family-friendly preference, maximum price, currency, bundle preference and requested result limit.
Experience tool inputs
ChatGPT may send the exact public listing slug selected from a search result so Andeor can return current details for that experience.
Departure tool inputs
ChatGPT may send a public listing slug, an optional requested date and a guest count from one to twenty so Andeor can check the published calendar.
Technical request data
Our hosting and security infrastructure may process an IP address, browser or client information, request time, requested endpoint, response status and limited diagnostic information needed to deliver and protect the service. Andeor also records aggregate tool telemetry containing the tool name, success or error outcome, response time, result count, controlled result status and, when relevant, the selected public listing slug.
Andeor does not receive your complete ChatGPT conversation. We receive only the tool arguments that ChatGPT sends to the Andeor service. The tool schema does not ask for a name, email address, phone number, account credentials, payment information, passport details, precise home address or health information. If you place personal information inside a free-text search, that text may still be included in the search phrase sent to Andeor. Please do not include sensitive information in a search.
Information returned to ChatGPT
Search results can include the number of matches and public listing facts such as listing identifiers, titles, partner display names, categories, locations, duration, difficulty, starting prices, ratings, family suitability, availability model, summaries and public images. An experience detail result can also include highlights, inclusions, exclusions, gallery images, group-size information and family policies. A departure result can include the requested date and guest count, calendar status, published dates and times, labels, places remaining, alternatives and a plain-language status message.
The visual card can keep the selected listing, preferred date and guest count in ChatGPT's widget state so the card remains usable in the conversation. Andeor receives the date and guest count only when a departure check is sent to our tool. ChatGPT and OpenAI handle conversation history and widget state under their own terms, privacy policy, plan settings and retention controls.
4. Why we use data
We use the data described above to provide the exact function requested by the user.
- We match search preferences against current public Andeor marketplace listings.
- We return public facts for the selected experience.
- We check a published departure calendar for the requested date and guest count.
- We format the results as readable text and visual cards inside ChatGPT.
- We operate, secure, troubleshoot and prevent misuse of the service.
- We measure aggregate tool reliability, public listing interest and journeys that continue to Andeor.
- We comply with lawful obligations and respond to valid legal requests.
Andeor does not use ChatGPT app tool inputs or outputs to create advertising audiences, personal marketing profiles or automated decisions about a person. We do not sell this data.
5. Who receives data
Data is disclosed only as needed for the purposes described in this policy.
OpenAI and ChatGPT
OpenAI processes your conversation, decides which tool arguments to send and receives the tool results and widget state needed to show the Andeor response in ChatGPT.
Service providers
Hosting, content-delivery, security, database and infrastructure providers process limited data on Andeor's behalf to run the endpoint, retrieve public catalogue data and deliver public images.
Authorised Andeor personnel
A small number of authorised personnel may access limited diagnostic information when needed to investigate reliability, security or a support request.
Legal recipients
We may disclose information to a regulator, court, law-enforcement body or professional adviser when required by law or necessary to establish, exercise or defend legal rights.
The public ChatGPT app does not send a user's tool inputs to experience partners and does not expose private customer, booking, account, admin or travel-agency records.
6. How long we keep data
Tool inputs and outputs
Andeor processes tool arguments and results in working memory for the time needed to answer the request. The public app does not intentionally write those arguments or results to an Andeor customer or conversation database.
Technical logs
Limited hosting, security and error logs are ordinarily retained for no more than 30 days. A relevant record may be kept longer when reasonably needed to investigate abuse, a security incident or a legal claim.
Aggregate app telemetry
Aggregate tool events are retained for no more than 30 days. They exclude prompts, search phrases, requested dates, guest details, IP addresses and ChatGPT account identifiers. A public listing slug can be retained when a listing detail, departure or booking-link tool is used.
ChatGPT history and widget state
OpenAI controls retention of ChatGPT conversations and widget state. You can use the controls in your ChatGPT account to manage or delete that information.
Privacy and support requests
If you contact Andeor, we ordinarily keep the correspondence for up to 24 months after the request is resolved. We may retain a minimal record longer when required to demonstrate compliance or manage a claim.
7. Your choices and controls
- You can avoid including personal or sensitive information in an Andeor search.
- You can stop using or disconnect the Andeor app through the controls available in ChatGPT.
- You can manage or delete the relevant conversation through your ChatGPT account controls.
- You can contact info@andeor.travel to ask whether Andeor holds data about your request or to request access, correction or deletion. Depending on applicable law, you may also have rights to restrict or object to processing and to complain to a competent data-protection authority.
The public app does not receive a ChatGPT account identifier that lets Andeor find a request by account. Please include an approximate date, time and the tool action involved if you ask us to locate a technical log. Do not send passwords, payment data or other sensitive information with your request.
8. Cookies and analytics
The Andeor tool endpoint and embedded discovery card do not set Andeor advertising cookies and do not use advertising pixels. Requests for the endpoint and public images can still produce the limited technical logs and aggregate app telemetry described above. OpenAI may use its own storage to operate ChatGPT and the widget.
If you leave ChatGPT and visit the Andeor website separately, that website may use essential account, preference and booking storage, first-party performance and interaction analytics, Vercel Analytics and Google Analytics. Website analytics help us understand visits and improve performance. They are separate from the public ChatGPT app tool inputs and outputs.
9. Other Andeor services
When you separately create an Andeor account, save a plan, request a guide, join a newsletter, contact us, submit a review, apply as a partner or affiliate, place an order or make a booking, we process the details you provide to deliver that service, provide support, prevent fraud, maintain business records and comply with law. This can include contact details, account details, participant information, booking and order records, communications, consent choices, reviews, referral attribution and transaction status. Payment credentials are handled by the applicable payment provider and are not exposed through the public ChatGPT app.
We share those records only with the service providers and experience partners needed to fulfil the request, with authorised Andeor personnel and where legally required. Service and financial records are kept for the period required by applicable accounting, tax, fraud-prevention and legal obligations. Marketing contact data is kept until you unsubscribe or ask for deletion, subject to a minimal suppression record needed to respect that choice.
When a participant signs an Originals or Editions participation acknowledgement, Andeor records the participant's name, optional email address, drawn signature, tour and date, the exact version and language of the wording shown, the responsible guide and the server signing time. This creates an auditable record of what the participant acknowledged and supports safety follow-up and the establishment, exercise or defence of a claim. The form does not record health details. A participant can instead tell the guide privately about anything that could affect safe participation.
Signed participation records are available only to authorised Andeor personnel and necessary infrastructure providers. They are kept through the period in which the tour may reasonably give rise to a complaint, safety follow-up or legal claim, and longer only when a specific dispute, legal duty or preservation requirement applies. We erase or de-identify the record when those purposes have lapsed.
10. Security, international processing and changes
We use access controls, encrypted connections and service-provider safeguards intended to protect data. No internet service can guarantee absolute security. Providers may process information outside your country. Where required, we use appropriate contractual or legal safeguards for that processing.
We will update this policy when the Andeor app, its tool inputs or outputs, our recipients or our retention practices materially change. The date at the top identifies the current version.
11. Contact Andeor
Send questions, requests or complaints about this policy to info@andeor.travel. Please state that your request concerns the Andeor app in ChatGPT when applicable.