Privacy Policy
This policy explains what data is processed when you use the Fly to Flight mobile app and the flytoflight.supfabric.com website (together, the "Service"), for which purposes and on which legal bases, who it is shared with, how long it is kept, and what your rights are.
Up front: we never ask for your name, email or phone number to create an account; we do not sell your data; we do not profile you for advertising. Privacy is an architectural decision in this product, not a marketing line.
1. Who we are and how to reach us
The Service is operated by Yalçın Savaş, an individual developer established in Türkiye ("we"). For all privacy questions and requests: [email protected].
2. Data we collect and why
The table below follows the same framework as App Store privacy labels:
| Data | Example | Purpose | Linked to your identity? |
|---|---|---|---|
| Anonymous account identifier | Randomly generated user ID and access token | Tying your account to your device | No — it cannot be matched to your real identity |
| Flight information | Flight number, date, route, fare class | Flight tracking, alerts, timeline, rights calculations | Linked to the anonymous account |
| Document summaries (optional) | Passport/visa/insurance summaries and attachments | Document wallet, expiry warnings | Linked to the anonymous account; stored encrypted |
| Notification registration | Device push token (FCM), platform, app language | Delivering real-time alerts | Linked to the anonymous account |
| Location (optional) | Momentary location, only while using the app | Maps, travel time, leave-home reminder | No identified location history is written to our servers |
| Camera (optional) | Boarding-pass barcode scan | Adding a flight quickly | Frames are processed on device, never stored |
| Diagnostics | Crash/error reports, performance metrics | Finding bugs, keeping the Service stable | Not linked to identity |
| Security signals | Sampled, salted-hash IP markers; audit logs with IPs masked to /24 (IPv4) or /48 (IPv6) | Abuse and fraud detection | Raw IPs are not used for profiling |
What we do not collect: name, email, phone number, contacts, photo library, advertising identifiers (IDFA), third-party analytics or marketing SDKs.
3. Legal bases
- Performance of a contract: the core of the Service — flight tracking, alerts, timelines, rights calculations.
- Legitimate interest: service security, abuse detection, error diagnostics.
- Consent: location and camera access — granted through device permissions, revocable any time in system settings.
- Legal obligation: where the law explicitly requires it.
4. Who we share data with
Your data is never sold and never shared for marketing. To operate the Service, the following sub-processors receive only the minimum data their function requires:
| Sub-processor | Function | Data sent |
|---|---|---|
| AeroDataBox | Flight status and schedule data | Flight number, date |
| Google (Routes, Places) | Travel time, airport places | Route endpoints, airport identifier |
| Google Firebase (FCM) | Push delivery | Device push token |
| OpenSky Network | Live aircraft position | Flight/aircraft identifier |
| Sentry | Crash/error reporting | De-identified technical context |
| Open-Meteo, Frankfurter | Weather, FX rates | Airport location, currency (no personal data) |
Some of these providers are established abroad; transfers are limited to the minimum scope above and covered by contractual safeguards. Beyond legally binding requests from competent authorities, no data is disclosed to any public or private body.
5. Retention
| Data | Retention |
|---|---|
| Account, flights, documents | While your account is active; erased immediately and permanently when you delete it |
| Notification and operational logs | Purged periodically by scheduled data-hygiene jobs |
| Security signals (hashed IP markers) | Short-lived; deleted once the detection purpose is met |
| Crash reports (Sentry) | Auto-deleted at the provider's standard retention window |
6. Your controls
Both live inside the app — instant, no forms, no waiting:
- Export: Settings → My data — a machine-readable copy of everything (portability).
- Delete: Settings → Delete account — your account and all data (including attachments) are permanently destroyed. Details: Account & Data Deletion.
For other GDPR/KVKK requests (access, rectification, objection), email [email protected]; we respond free of charge within 30 days.
7. Security
- All traffic is TLS-encrypted; our servers enforce HSTS.
- Document-wallet content is additionally field-level encrypted in the database; attachments are protected in object storage behind signed, expiring links.
- Your access token lives only on your device; the server stores only an irreversible digest of it.
- Even our operations panel cannot display raw personal content (push tokens, document contents); every operator action is written to an audit trail.
8. Children
The Service is not directed at children under 13 and we do not knowingly collect their data. If you believe a child's data has been processed, contact us and we will erase it promptly.
9. Third-party links
The app may link to third-party pages such as airline claim forms or official authority sites. Their privacy practices are their own responsibility.
10. Changes
When we update this policy we publish the new version here and change the effective date. Material changes are additionally announced in the app.