← Back to home

Privacy Policy

Effective: May 31, 2026

1. What we collect

We collect only what is necessary to operate FlyAlong:

  • Pilots: name, email address, phone number, typical departure airports, aircraft type, and any optional notice you add to your profile.
  • Flyers: name, email address, and the flight interest request details you submit (party size, weights, expense-sharing preference, and any optional note to the pilot).
  • Subscribers: name and email address, the pilot whose updates you requested to follow, and whether that request is pending or approved by the pilot.
  • Technical data: session cookies (for authentication), and standard server logs (IP address, request timestamps). We use Cloudflare Turnstile for bot protection — see Cloudflare's privacy policy.

2. How we use it

We use your information only to:

  • Run the service — help pilots coordinate flights with friends, family, and colleagues they already know.
  • Send transactional emails: magic-link sign-in, flight interest confirmations, pilot status updates, and subscriber notifications.
  • Generate optional, clearly-labeled route descriptions using AI (AWS Bedrock). These are produced from public airport data only — never from your personal information — and a pilot's own note always takes precedence.
  • Prevent abuse (Turnstile bot protection).

We do not sell your data. We do not use it for advertising. We do not share it with third parties except as described in Section 3.

3. Who can see your data

  • Pilot profile data (name, typical airports, aircraft, scheduled flights, destinations) is visible to anyone with the Pilot's personal link. Pilots control who receives that link. A Pilot's phone number is shared with a Flyer only after the Pilot confirms that Flyer's request.
  • Flyer request data (name, email, weights, notes) is visible only to the Pilot the request was sent to.
  • Infrastructure provider: we use AWS (Amazon Web Services) to store data, send email, and generate optional route descriptions (AWS Bedrock). AWS is bound by its own privacy policy.
  • Content enrichment: to add photos and place summaries to destination cards, we query Wikipedia and Pexels. These services receive only public airport and place names — never your personal data.
  • No third party receives your personal information for advertising or sale.

4. Data retention

Pilot and Flyer account data is retained until you request deletion. Flight entries and requests are retained to maintain accurate records for both Pilots and Flyers. A subscription is deleted as soon as you unsubscribe. Magic-link tokens expire automatically (15–60 minutes depending on type) and are deleted shortly after.

Your data is stored in the United States (AWS, us-east-1).

5. Data security

We use industry-standard safeguards to protect your information, including encryption in transit (HTTPS) and AWS-managed encryption at rest, passwordless magic-link sign-in (no passwords to leak), and HttpOnly session cookies. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.

6. Children

FlyAlong is intended for adults (18+) and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

7. Your rights

You may request access to, correction of, or deletion of your personal data at any time by emailing hello@flyalong.net. We will respond within 30 days.

8. Cookies

We use three types of cookies, all strictly functional:

  • Session cookie (fa_session): an HttpOnly, Secure cookie containing a signed JWT. Valid for 30 days. Used to keep you signed in.
  • CAPTCHA grace cookie (fa_turnstile): set after you pass the Cloudflare Turnstile challenge. Valid for 4 hours. Prevents you from having to solve the challenge on every form submission.
  • Follow-convenience cookie (fa_sub_identity): if you request to follow a pilot without an account, we store your name and email in this HttpOnly cookie for 30 days so you don't have to retype them when expressing interest in a flight on the same device. You can clear it anytime via your browser.

No tracking cookies, analytics cookies, or advertising cookies are used.

9. Changes to this policy

We may update this Privacy Policy from time to time. Continued use of FlyAlong after a change constitutes acceptance. We will update the effective date above when changes are made.

10. Contact

Questions or requests? hello@flyalong.net

Terms of Service