Privacy policy
These tools are run by me, Mario, the person behind Kind of Lost (kindoflost.com). Contact: mario@kindoflost.com. Versión en español más abajo.
What you send
To plan routes the tool needs your stops: addresses and/or coordinates, quantities, time windows, service times and vehicle details. You send them by uploading a workbook, pasting a Google Sheet link or a list of addresses on the web page or in the embedded widget, or through an AI assistant connected to the MCP server. With an assistant, I never see your conversation, only what the assistant chooses to send to the tool.
Who else receives part of it
Computing real routes needs two public map services, and this is the part of your data that leaves my server:
- Address lookup (geocoding). Each address given without latitude/longitude is sent, on its own, to the US Census Bureau geocoder and, when that cannot match it or for non-US addresses, to OpenStreetMap Nominatim. Stops you give as coordinates are not sent to either.
- Driving times. The coordinates of the depot and the stops (not the addresses, names or quantities) are sent to the public OSRM routing server to get the drive time between every pair.
- Google Sheets. If you paste a Google Sheet link, the tool downloads that sheet from Google to read it.
Those services have their own privacy policies. If you do not want an address sent to a geocoder, give its latitude and longitude instead.
What I keep
- Address lookups. Every address that is found is kept on the server's disk together with its coordinates, so that it never has to be looked up again (for you or anyone else who sends the same address). This cache holds the address text and coordinates only — no names, quantities, times, or who sent it — and it has no expiry. Ask me and I will delete an address from it.
- Driving-time tables. The drive times between a set of points are kept on disk, filed under a one-way hash of the coordinates, so the same set of stops is not re-requested from OSRM.
- Everything else is not kept. Workbooks, stop lists and results are held in memory while the solve runs — and, for the MCP server, for at most 15 minutes after so the assistant can collect the result — and are then discarded. They are not written to a database, not used to train any model, not sold and not shared.
- Run log. For each run I record one anonymous row: date and time, country (from the network, not your address), device type, the page that linked to the tool, how the data was sent (file, sheet, pasted addresses, widget or AI assistant), the number of stops and routes, how long the solve took and whether it succeeded. No addresses, names, email or IP address.
- Email. If you choose to leave your email for tool updates, it is stored only to send those updates, and you can ask me to delete it at any time.
The web pages use Google Analytics to count visits. To stop any one caller from overloading the server, the calling IP address is held in memory for up to 10 minutes for rate limiting only.
MCP server for AI assistants (routing.kindoflost.com/mcp)
Everything above applies. What the assistant does with the routes it gets back is governed by that assistant's own privacy policy.
How your data is protected
- Encryption in transit. The web tool and the MCP server only accept HTTPS (TLS), and the calls to the geocoders and OSRM are made over HTTPS.
- Isolation. Each MCP solve runs in its own short-lived process, discarded when the solve ends.
- Restricted access. Only I, the developer, can access the server and its configuration.
- No AI/ML training. Data sent to the tool is not used to develop, improve or train AI or machine-learning models, by me or by anyone else.
- Hosting. The server runs on Render (render.com) in the United States. Render provides the infrastructure only.
Changes
If this policy changes, the new version will be posted on this page with a new date.
Política de privacidad (español)
Para armar las rutas la herramienta necesita sus paradas (direcciones o coordenadas, cantidades, ventanas horarias, tiempos de servicio y datos de los vehículos), que usted envía desde la página web, el widget o un asistente de IA conectado al servidor MCP. Con un asistente, no veo su conversación, solo lo que el asistente envía a la herramienta.
Quién más recibe una parte. Cada dirección sin latitud y longitud se envía al geocodificador del Censo de EE. UU. y, si no la encuentra o no es de EE. UU., a OpenStreetMap Nominatim. Las coordenadas del depósito y de las paradas (no las direcciones ni los nombres) se envían al servidor público de OSRM para obtener los tiempos de manejo. Si pega un enlace de Google Sheets, la hoja se descarga de Google. Si no quiere que una dirección se envíe a un geocodificador, indique sus coordenadas.
Qué guardo. Cada dirección encontrada queda guardada en el disco del servidor con sus coordenadas, sin vencimiento, para no volver a buscarla (solo la dirección y las coordenadas: sin nombres, cantidades ni quién la envió); si me lo pide, la borro. Los tiempos de manejo se guardan bajo un hash de las coordenadas. Todo lo demás (planillas, listas de paradas, resultados) se mantiene en memoria mientras se resuelve y, en el servidor MCP, como máximo 15 minutos después, y se descarta: no se guarda en una base de datos, no se usa para entrenar modelos, no se vende ni se comparte. Por cada corrida registro una fila anónima (fecha y hora, país, tipo de dispositivo, página de origen, forma de envío, cantidad de paradas y rutas, duración y resultado), sin direcciones, nombres, correo ni dirección IP. La dirección IP que llama se mantiene en memoria hasta 10 minutos solo para limitar el uso. Las páginas usan Google Analytics. Todo viaja cifrado por HTTPS; solo yo tengo acceso al servidor, alojado en Render (render.com) en Estados Unidos. Contacto: mario@kindoflost.com.
Kind of Lost