Last Updated: October 5, 2026
Welcome to RopeDrop Planner ("we," "our," or "us"). We are committed to protecting your privacy and handling your data in an open and transparent manner. This Privacy Policy explains how we collect, use, and protect your personal information.
You sign in with Google, Apple or X (Twitter). We don't use passwords of our own. When you create an account, we store:
If you use the mobile app, we also issue sign-in tokens to your device so you stay signed in.
When you use our trip planning features, we store what you enter, including:
When you set up an alert, we store what you're watching for. For a dining alert, that's the restaurant, date or date range, party size, meal period, time window, and whether you want push, email or both. We also keep a history of the availability we found for it.
You never give us your Disney password for alerts. Availability checks run on accounts that we own and operate, not on your Disney account. Dining alerts only notify you; we do not book dining reservations for you.
The Concierge is an optional paid feature that watches for and books or changes Lightning Lane return times for your party. Because it works with your Disney plans, here is exactly what it involves.
How you connect it. You give us the email address and first and last name on your My Disney Experience account. We then connect one of our own Disney service accounts to your party through Disney's Friends & Family feature. You do this in one of two ways:
Nothing happens until you agree to the Concierge terms in the app.
What we can see and store. Once connected, our service account sees what Disney shows any Friends & Family connection. We store:
What we do on your behalf. Depending on the mode you choose, the Concierge can move Lightning Lanes you already hold to better times, or, in the beta auto-book mode that needs a separate consent, also book new Lightning Lane return times. You choose whether it acts automatically or asks you first; approval requests expire after a few minutes. The Concierge only uses Lightning Lane passes you already own. It never buys anything for you. We send you push notifications about proposals and bookings. Members of your trip who have their own RopeDrop account receive them too.
How to stop it. Use "Disconnect" in the Concierge settings. We stop acting on your party right away. To fully cut off our access, also remove our service account from your Friends & Family list in My Disney Experience. Only you can do that, and deleting your RopeDrop account does not do it for you. When you disconnect, we delete the Concierge data described above 30 days later: your My Disney Experience email and name, your party's names, your Lightning Lane holdings, itinerary copies and the reservations we imported. We keep only a record that a Concierge link existed and when, with no names or contact details, for billing and abuse checks. If you reconnect within those 30 days, nothing is lost. Deleting your RopeDrop account removes it all right away.
RopeDrop Planner is not affiliated with Disney. Disney can see the actions our service accounts take, and Disney's own terms and privacy policy govern your Disney account.
When you use the in-app AI chat, we save your messages and the replies with your account so you can see past conversations. Archiving a conversation hides it but does not delete it. Deleting your account deletes your chat history. To answer, we send Google Gemini your recent messages in that conversation and, when the question is about your trip, the relevant trip details (such as party member names and whether they are children). The route-insights feature also sends party names, ages and preferences to Gemini. Questions typed into the public "Ask" search box are stored without being linked to an account.
Web purchases are handled by Creem.io. Purchases in our iOS or Android app are handled by Apple or Google. Creem is the merchant of record for web purchases: it is the seller of record, collects any sales tax or VAT, and handles refunds and chargebacks. We never see or store your card number. We store your payment provider's customer and subscription IDs, the product you bought, your plan and its expiry date, and the purchase records the provider sends us. At checkout, we send Creem your email and account ID.
If you allow notifications, we store the token your browser or device gives us so we can reach it: a Web Push subscription (browsers), an Apple Push Notification device token (iOS) or a Firebase Cloud Messaging token (Android).
Travel planners who use Pro Planner can store information about their own clients: names, email addresses, phone numbers, notes, trip details and intake-form answers. Clients may also submit a planner's public intake form without an account. The planner decides what to collect and is responsible for having permission to share it with us. We store and process it on the planner's behalf. Clients with questions should contact their planner first; we will help where we can. Planners' public profiles (bio, website, social handles, photo) are visible to everyone.
The park map can show your location. That stays in your browser. When you ask for walking directions, your current coordinates are sent to our server to calculate the route and are not saved to your account.
We automatically collect:
If you sign up for our newsletter, a feature waitlist or a beta program, we store your email address and anything else you enter on that form, such as your name or trip dates. These records are kept separately from your account.
Our app for AI assistants (ChatGPT, Claude, Gemini and others that use the Model Context Protocol) calls our public server at ropedropplanner.com/mcp. It needs no sign-in and has no access to your RopeDrop account, trips or alerts. See ropedropplanner.com/ai for how it works.
utm_source=mcp tag so our analytics
can count visits that came from the assistant (section 3.4).Our Chrome extension shows a countdown to your trip and the shortest current ride waits at Walt Disney World. It has no account and collects no personal information.
We use your information to:
We do not sell your personal information.
We use the following third-party services:
For user authentication. Each provider's privacy policy applies, including Google's: https://policies.google.com/privacy
For parsing uploaded files, answering AI chat questions and generating route insights. We send the content described in sections 1.3 and 1.6 to Google's Gemini API. Google handles it under its Gemini API terms.
Park maps use OpenStreetMap and CARTO map tiles, displayed with the Leaflet library. Your browser requests map tiles directly from those providers, so they receive your IP address. We do not use Google Maps.
We use Google Analytics 4 (GA4) to understand how visitors use our site, including pages visited,
session duration, and general geographic region. We use Google's Consent Mode. Until you accept our cookie
banner, Google Analytics sets no cookies and sends Google only cookieless, anonymous measurement pings.
If you click "Accept," GA4 sets cookies (_ga, _ga_*) to distinguish unique
visitors. Accepting grants analytics only: we run no ads, and Google's advertising consent signals always stay off.
If you decline, no analytics cookies are set.
We also use Ahrefs Web Analytics on most pages. It measures page visits and sets no cookies.
We use PostHog (PostHog Inc., servers in the United States) for product analytics, only if you click
"Accept" on our cookie banner. Until you accept, PostHog's code is not loaded and nothing is
sent to PostHog. After you accept, PostHog stores an anonymous identifier in a cookie and in your browser's
local storage (names starting with ph_) and records the pages you view and the page elements you
click, together with your IP address and browser type. We do not use session recording or surveys, and we
do not send PostHog your name, email or account details. If you decline, PostHog is not loaded and
nothing is stored or sent. PostHog's privacy policy applies:
https://posthog.com/privacy.
Google's privacy policy applies: https://policies.google.com/privacy. You can also opt out via the Google Analytics Opt-out Browser Add-on.
Our infrastructure provider. Our app runs on Google Cloud Run in the United States, and our secrets are kept in Google Secret Manager.
We run an automated account, built on Reddit's Devvit platform, in the r/ropedropplanner subreddit. When someone submits a post there, or mentions u/ropedropplannerbot in a comment, the bot reads the post or comment and, if it can answer from our data, replies.
Don't want the bot to reply to you? Message the r/ropedropplanner moderators and we'll handle it.
We share personal data with these providers only so they can run parts of our service for us:
You have the right to:
To delete your account, use the "Delete Account" button in Settings. Deletion removes your account, trips, party members, reservations, uploads, chat history, alerts, Concierge data, device tokens, public content and planner client records. There are three exceptions:
For a copy of your data or any other request, contact us at [email protected].
We implement industry-standard security measures:
Our service is not directed to children under 13, and account holders must be at least 13. We do not knowingly collect personal information directly from children. Parents and guardians planning a family trip may enter details about children in their party (such as name, age and height) so we can plan around them. That information belongs to the adult's account, is used only for trip planning, and is deleted when the trip or the account is deleted. If you believe a child has created an account or given us personal information directly, please contact us and we will delete it.
Our service is hosted in the United States. If you access our service from outside the US, your data will be transferred to and processed in the US. By using our service, you consent to this transfer.
If you are in the European Union, you have additional rights under GDPR:
California residents have the right to:
We use the following cookies and browser storage:
session): Required for sign-in. It cannot be disabled and
expires after 14 days.rd_cookie_consent)_ga, _ga_*): Set by Google Analytics
only if you click "Accept" on the cookie banner. Used to distinguish unique visitors and understand
site usage. These expire after 2 years.ph_*): A cookie and a local-storage item holding an anonymous
identifier, set by PostHog only if you click "Accept" on the cookie banner (section 3.4). Not set
if you decline or make no choice.We do not show ads. You can change your analytics cookie preference at any time by clearing your browser's localStorage for this site.
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last Updated" date and, if appropriate, sending an email notification.
If you have questions about this Privacy Policy, please contact us: