Your data and choices
Privacy
Last updated August 17, 2026
The short version
You do not need an account. LayoverLab does not ask for your name, email, payment information, or traveler identity. Enter only the trip details needed for the score.
Uploaded itinerary files
When file import is enabled, up to four screenshots or unencrypted PDFs are sent over an encrypted connection to LayoverLab. Google Cloud Document AI and Gemini temporarily process each source to copy visible itinerary details and verify them against the file. Each PDF is limited to four pages, each file is limited to 8 MB, and the combined upload is limited to 30 MB.
LayoverLab does not save the uploaded file or extracted source text to object storage or a database. Request bytes are cleared after processing, and only editable itinerary fields are returned. Under Google's terms, request content flagged for abuse review may be retained by Google for up to 90 days; it is not used to train or fine-tune models without prior permission.
Do not upload payment information. Review every imported field before continuing.
Flight detail lookup
When flight lookup is enabled and you press Find flight details, LayoverLab uses only the local departure date, airline, flight number, departure airport, and optional final destination and departure-time hints to check current public Google Flights schedule pages. It does not send passenger names, booking references, confirmation codes, email addresses, uploaded files, OCR text, notes, or saved-trip links.
The check uses a credential-free server request. LayoverLab does not save the page request, source page, embedded schedule payload, or raw lookup response. Matched fields remain editable; only itinerary details you review and continue with enter the ordinary scoring flow.
Trip and score data
LayoverLab processes the flight details and trip priorities you confirm to calculate the result. Operational records retain versioned scoring facts and sanitized result evidence for reproducibility and abuse investigation, subject to configured expiration. Raw upload bytes and raw extracted text are not part of shared results or product analytics.
Product analytics
LayoverLab records a small allowlisted set of first-party events, such as stage completion, import outcome category, correction-count bucket, result-detail engagement, coarse viewport class, and duration bucket. Events must not contain names, booking references, uploaded text, exact itineraries, scores, verdicts, session identifiers, or free-form traveler input. They expire under the serving retention policy.
Advertising and consent
Ads are disabled unless LayoverLab has configured an approved AdSense account and Google-certified consent management platform. When enabled, one labeled ad may appear only after the complete result and its actions. Google and its advertising partners may use cookies, local storage, device information, and network data according to the choices presented by the consent message. LayoverLab does not use uploaded files or itinerary contents to target ads.
Sharing and security
Result links, if enabled later, will use opaque server-side tokens and a sanitized projection. Uploaded files and raw extracted text will never be included in the URL. LayoverLab applies bounded requests, same-origin mutation checks, rate limits, least-privilege service identities, and no-store response headers. No internet service can promise absolute security.
Your choices
You can enter flights manually instead of using lookup or uploading a file, decline advertising consent where offered, or stop before requesting a score. Browser controls can clear cookies and local storage.
Contact
For support or privacy questions, email layoverlabdev@gmail.com.