Supfabric

EN · TR

Privacy Policy

Effective date: July 7, 2026 · Version 1.0

This policy explains what data is processed when you use the Fly to Flight mobile app and the flytoflight.supfabric.com website (together, the "Service"), for which purposes and on which legal bases, who it is shared with, how long it is kept, and what your rights are.

Up front: we never ask for your name, email or phone number to create an account; we do not sell your data; we do not profile you for advertising. Privacy is an architectural decision in this product, not a marketing line.

1. Who we are and how to reach us

The Service is operated by Yalçın Savaş, an individual developer established in Türkiye ("we"). For all privacy questions and requests: [email protected].

2. Data we collect and why

The table below follows the same framework as App Store privacy labels:

DataExamplePurposeLinked to your identity?
Anonymous account identifierRandomly generated user ID and access tokenTying your account to your deviceNo — it cannot be matched to your real identity
Flight informationFlight number, date, route, fare classFlight tracking, alerts, timeline, rights calculationsLinked to the anonymous account
Document summaries (optional)Passport/visa/insurance summaries and attachmentsDocument wallet, expiry warningsLinked to the anonymous account; stored encrypted
Notification registrationDevice push token (FCM), platform, app languageDelivering real-time alertsLinked to the anonymous account
Location (optional)Momentary location, only while using the appMaps, travel time, leave-home reminderNo identified location history is written to our servers
Camera (optional)Boarding-pass barcode scanAdding a flight quicklyFrames are processed on device, never stored
DiagnosticsCrash/error reports, performance metricsFinding bugs, keeping the Service stableNot linked to identity
Security signalsSampled, salted-hash IP markers; audit logs with IPs masked to /24 (IPv4) or /48 (IPv6)Abuse and fraud detectionRaw IPs are not used for profiling

What we do not collect: name, email, phone number, contacts, photo library, advertising identifiers (IDFA), third-party analytics or marketing SDKs.

3. Legal bases

  • Performance of a contract: the core of the Service — flight tracking, alerts, timelines, rights calculations.
  • Legitimate interest: service security, abuse detection, error diagnostics.
  • Consent: location and camera access — granted through device permissions, revocable any time in system settings.
  • Legal obligation: where the law explicitly requires it.

4. Who we share data with

Your data is never sold and never shared for marketing. To operate the Service, the following sub-processors receive only the minimum data their function requires:

Sub-processorFunctionData sent
AeroDataBoxFlight status and schedule dataFlight number, date
Google (Routes, Places)Travel time, airport placesRoute endpoints, airport identifier
Google Firebase (FCM)Push deliveryDevice push token
OpenSky NetworkLive aircraft positionFlight/aircraft identifier
SentryCrash/error reportingDe-identified technical context
Open-Meteo, FrankfurterWeather, FX ratesAirport location, currency (no personal data)

Some of these providers are established abroad; transfers are limited to the minimum scope above and covered by contractual safeguards. Beyond legally binding requests from competent authorities, no data is disclosed to any public or private body.

5. Retention

DataRetention
Account, flights, documentsWhile your account is active; erased immediately and permanently when you delete it
Notification and operational logsPurged periodically by scheduled data-hygiene jobs
Security signals (hashed IP markers)Short-lived; deleted once the detection purpose is met
Crash reports (Sentry)Auto-deleted at the provider's standard retention window

6. Your controls

Both live inside the app — instant, no forms, no waiting:

  • Export: Settings → My data — a machine-readable copy of everything (portability).
  • Delete: Settings → Delete account — your account and all data (including attachments) are permanently destroyed. Details: Account & Data Deletion.

For other GDPR/KVKK requests (access, rectification, objection), email [email protected]; we respond free of charge within 30 days.

7. Security

  • All traffic is TLS-encrypted; our servers enforce HSTS.
  • Document-wallet content is additionally field-level encrypted in the database; attachments are protected in object storage behind signed, expiring links.
  • Your access token lives only on your device; the server stores only an irreversible digest of it.
  • Even our operations panel cannot display raw personal content (push tokens, document contents); every operator action is written to an audit trail.

8. Children

The Service is not directed at children under 13 and we do not knowingly collect their data. If you believe a child's data has been processed, contact us and we will erase it promptly.

9. Third-party links

The app may link to third-party pages such as airline claim forms or official authority sites. Their privacy practices are their own responsibility.

10. Changes

When we update this policy we publish the new version here and change the effective date. Material changes are additionally announced in the app.

11. Contact

[email protected] · Support