Sign in once, and the desk answers for your wallet

Your card list now follows you between devices, /me computes your position in eight sections, and the alerts checkbox finally mails you — only for cards you actually hold. Plus the parts we owe you: we logged everyone out on purpose, here is exactly what we store, and deleting an account now deletes it.

What you can do now. Sign in with Google and your card list stops dying with a cleared cache — it follows you to the second device. /me then opens as a desk that computes your position in eight sections: your cards, where you’re leaving points, what changed under you, your doors, your firepower, where your points fly, your worth, and this month’s move. Nothing on this site sits behind that sign-in. Skip it and every page works exactly as it did.

The alerts checkbox finally does something. Tick it and a major devaluation reaches you within a day of verification — but only if it hits a card you actually hold. One mail a day, maximum, and no model gets to phrase the number. Signed in, subscribing is one tap with no confirmation round-trip; the weekly digest now leads with ₹ per point instead of a headline; /programs is a new A–Z of all 107 currencies we mark; and the 271 lounges that lived only inside a fetched JSON file now render on /lounges.

Now the parts we owe you.

We signed everyone out. Once, on purpose. Session cookies changed shape three ways in one release: a server-side session id inside the signature, a verified-email claim, and the __Host- rename. A cookie missing any of them fails closed — which is the point, because signing out now revokes the session on our server, so a copied cookie dies with it. One logout beat three.

What we hold, in full. Your Google account’s email address, the name on that account, the opaque id Google gives us for it, and your card slugs — literally strings like axis-atlas. That is the entire record. Balances and spend profiles are computed in your open tab and never uploaded. Subscribing stays a separate fact from signing in, and we keep it that way.

Delete means delete. One batch: cards, profile, session rows — not a “revoked” flag, which would keep the id — the newsletter row address and all, the alert ledger, then the account itself. If you were subscribed we keep a one-way hash of the address so we can never mail you again; it cannot tell us who you were. The full list is on /privacy.

Why announce this at all. We run a watchdog over 175 issuer documents and publish when a bank retypes one cell without telling anyone. Doing that while changing our own terms quietly is a double standard with a schedule.

One thing this is not, deliberately: a tracker row. /tracker logs what issuers did to your points. Every row there needs an issuer, and a travelwith.cc row would mint a /tracker/travelwith.cc page and count itself among the sourced events we hold banks to. Our own changes belong here, in News.

Source ↗