Privacy notice

Updated 3 September 2026

Preview draft. Operator details and the final policy review must be completed before public launch.

Who operates the service

Operator: To be confirmed before launch. A contact address will be published before launch.

Information used

Account data includes an email address, a username and authentication records. Public contributions include post and comment text, travel details you choose to include, timestamps and any resolution you publish. Reports, moderation notes and account restrictions are restricted to authorized staff.

Saved posts and grouped reply notifications are private to your account. Editing a contribution changes its public text and adds an edited timestamp. Notifications refer to replies on your own posts; this version sends no reply emails or push alerts.

Why data is processed

Account and contribution data supports your requested community service. Account security, publishing limits and moderation help prevent abuse and protect the service and its users. The final operator will confirm the applicable legal bases before launch. Your email is not displayed with public posts.

Providers and browser storage

Supabase supplies authentication and database storage for this version, and Cloudflare Workers is configured as the web host for the production build. SkyyTrust uses system fonts, so normal page rendering does not contact a third-party font service. When security verification is enabled, Cloudflare Turnstile processes verification requests. If Google sign-in is enabled, Google and Supabase process the OAuth sign-in request. Airline logos that are not bundled with the app may be loaded from the jsDelivr CDN. The browser stores the login session so you can remain signed in and a local client identifier used by older versions. This build adds no advertising cookies. Optional SkyyTrust analytics records only coarse event names and broad route categories; the client intentionally excludes usernames, email addresses, post text and search queries from those events.

Unpublished post and comment drafts are saved in this browser, not sent to the server. One post draft and up to five recent comment drafts expire after seven days and are cleaned up the next time drafts are accessed. Drafts clear when published or when you log out. Clearing browser storage also removes them. Draft recovery may be unavailable in private browsing or when storage is blocked. Avoid entering private booking or payment details, especially on a shared device.

The hosting provider and email delivery provider, together with any applicable international transfer arrangements, must be finalized before launch and included here. The application can record sanitized technical failure events in the hosting logs; these events contain the release, broad route category and failure type, not post text, email addresses, credentials, query strings, raw exception messages or stack traces.

Retention and deletion

Account data is retained while the account is in use. Public contributions remain available until removed. Moderation and security records are used to investigate abuse and appeals. Exact retention periods, backup expiry and the procedure for deleting or anonymizing contributions are pending the operator's final policy review.

Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to certain processing. Contact the operator using the address above. You may complain to your local data protection authority. Do not send passwords or identity documents in a public post.