01
Who we are
Flight API (“we”, “us”) operates flight-api.dev — the website, the dashboard and the historical flight status API behind them.
We are the controller of account, billing and usage data for this product. Every privacy request goes to one mailbox: support@flight-api.dev.
02
What this covers
This policy covers the website, dashboard and API at flight-api.dev. It does not cover sites we link to, or data you already hold about passengers and then combine with a lookup.
Using the service is also governed by the Terms of service.
03
What we collect
Only what the product needs to run an account and meter the API.
- Account. Email address. Display name if Google sends one. Google account identifier if you continue with Google. Email-verified flag.
- Session. An httpOnly session cookie after Google or a magic link. No passwords are stored — there is no password sign-in.
- API keys. A name you choose, a prefix, a SHA-256 hash of the secret, created-at. The plaintext is shown once, at creation, and is not kept.
- Usage. Endpoint, flight number, UTC date, response status, latency, key id, credit remaining. Enough to bill and debug. Not a payload dump.
- Company profile (optional). Legal name, trading name, website, registration and VAT numbers, country, address, contact name / email / phone, stated use case and expected volume. Used on invoices and review.
- Billing. Stripe customer and subscription ids, plan, cycle, status. Card numbers never touch our database.
- Support mail. Whatever you put in a message to us.
04
Flight records
A lookup is a flight number and a UTC date, optionally narrowed by origin and destination. The stored record is operational: scheduled, estimated and actual times, delay, aircraft, carrier. It is keyed on number and date.
That is not a passenger record. We do not collect names, tickets, PNRs, seats or contact details of people who flew. If you join our record to data you already hold, that joining happens on your side and is your processing.
05
Why we process it
- Contract. Create the account, issue keys, run lookups, meter credits, take payment, send the magic-link mail.
- Legitimate interests. Abuse detection, debugging, product improvement on aggregated usage, keeping the archive coherent.
- Legal obligation. Tax and accounting retention on invoices.
- Consent only where a browser storage choice is not strictly necessary — today that is the theme preference in localStorage.
EEA and UK users: we rely on GDPR Art. 6(1)(b), (c) and (f) as above.
06
Who processes it
We do not sell account data. These processors run the product:
- Vercel — hosting, edge and logs.
- Neon — Postgres for accounts, keys, usage and frozen records.
- Stripe — checkout, subscriptions, invoices, cards.
- Resend — magic-link and transactional mail.
- Google — OAuth, only if you press Continue with Google.
How a lookup is produced stays ours. Upstream aviation sources are not named to you and are not given your account.
08
Retention
- Account and company profile — while the account exists, then deleted or anonymised within 30 days of a verified deletion request, except where invoices must be kept.
- API key hashes — until you revoke the key, then dropped.
- Usage logs — typically 24 months, enough to reconstruct a billing dispute.
- Stripe objects — whatever Stripe is required to keep; we keep the ids that point at them.
- Frozen flight records — operational archive, not tied to your account. Survives an account close. Not personal data of a passenger.
- Magic-link mail — delivery logs on Resend per their retention; the token is spent once or expires in 15 minutes.
10
Your rights
You can access, correct, export or delete the account data we hold, object to legitimate-interest processing, and restrict processing while a dispute runs. EEA and UK users also have the right to complain to a supervisory authority.
Mail support@flight-api.dev from the address on the account. We will need to confirm it is you. Deleting the account revokes every key. Usage already billed is not unwound.
We do not run automated decisions that produce legal effects about you. Metering a request is not a decision about a person.
11
Security
TLS in transit. Keys hashed at rest, compared in constant time. Session cookies httpOnly. Dashboard closed until the mailbox is proven — Google’s verified email, or the magic-link click.
No method is perfect. If we learn of a breach that risks your rights we will notify you and the competent authority where the law requires it.
12
Children
The service is for organisations and working-age developers. It is not directed at anyone under 16. If we learn an account belongs to a child we close it.
13
Changes
Material changes land on this page with a new effective date. If the change affects how we use account data we will also mail the address on the account. Continued use after the date is acceptance. The Terms say the same for the contract.
14
Contact
Flight API
support@flight-api.dev
Put “privacy” in the subject and mail from the address on the account — that is the fastest way to get a request actioned rather than verified twice.
Effective 28 August 2026.