Legal
Privacy Policy
Last updated 24 September 2026
LetsFlight tracks your flights and shares them with the people you choose. This policy explains what we collect to do that, who helps us run the service, and how you can export or delete your data at any time. We do not sell your data, show ads or track you across other apps and websites.
1. Who we are
LetsFlight (the iOS app and letsflight.app) is operated by Pavel Soukup, who is the controller of the personal data described here. You can reach us at hello@letsflight.app.
2. Data we collect
Account
- Your email address, name and optional profile photo, and a password (stored only as a hash by our sign-in provider) or your Sign in with Apple identifier. If you use Hide My Email, we receive Apple's relay address.
Flights and trips you add
- Flight numbers, dates, airports, times and status for the flights you add, search for or import from a CSV file.
- Details you choose to record: seat, cabin class, travel reason, booking reference and notes.
- Stays: when you forward an Airbnb confirmation email to your personal LetsFlight address, we receive that email and keep the sender, the subject and the reservation details we extract (listing, dates, address, host name and phone, guests and price).
Friends
- The email addresses you enter to invite friends, your friend connections, groups, and which of your flights and stays you share with them. Friends see your name, photo and the flights you share.
Devices and notifications
- A random installation identifier, push notification tokens, Live Activity tokens, the device platform and your notification settings, so alerts reach the right device.
What we do not collect
- We do not access your device location, contacts, camera or microphone. The photo library is used only when you pick a profile photo.
- The app contains no advertising, analytics or tracking SDKs.
3. Google data
Connecting a Google account is optional and only happens when you start it and grant access on Google's consent screen. Depending on what you choose, LetsFlight requests:
- Gmail (read-only) to find flight booking confirmations and add those past flights to your log. Messages are read and parsed on our servers; we keep only the flight details we extract and a one-way hash of the booking reference. Message content is not stored.
- Google Calendar (read-only) to find flights in your calendar events, under the same rules as Gmail.
- Google Calendar events to add your LetsFlight flights to your calendar when you turn on calendar sync.
Google access tokens are encrypted on our servers. You can disconnect at any time in your Google Account permissions; deleting your LetsFlight account also revokes our access.
LetsFlight's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the import and calendar features you requested. It is never used for advertising, never sold, never used to train AI models, and people cannot read it except with your consent, for security or where the law requires it.
4. How we use data and our legal bases
- To provide LetsFlight (performance of our contract with you): keeping your flight log, live status, alerts, stays, sharing with friends, exports and imports.
- With your consent: Google access, push notifications and your profile photo. You can withdraw consent at any time in the app, iOS Settings or your Google Account.
- Legitimate interests: keeping the service secure, preventing abuse, fixing faults and answering your messages.
- Legal obligations, where a law requires us to keep or disclose information.
We do not use your data for automated decisions that have legal or similarly significant effects on you.
5. Who we share data with
We share data only with the people you choose (your friends) and with service providers who process it for us under contract:
| Provider | Purpose | Data |
|---|---|---|
| Convex (hosting in the EU) | Database and servers | All app data described above |
| Clerk | Sign-in and account management | Email, name, photo, sign-in identifiers |
| Apple | Sign in with Apple, push notifications, Live Activities, maps | Sign-in identifier, device tokens, notification content |
| Expo | Push notification delivery on Android | Device tokens, notification content |
| Flight data providers (AeroDataBox, FlightAware, AirLabs, Flightradar24, aviationweather.gov) | Schedules, live status, aircraft and weather | Flight numbers, dates, airport codes and aircraft registrations, never your name or email |
| Resend | Receiving forwarded booking emails | The emails you forward to your LetsFlight address |
| Airbnb listing data provider (via RapidAPI) | Photos and details of the stays you add | Airbnb listing identifiers only |
| Gmail and Calendar features, only if you connect | Access tokens and the requests described in section 3 | |
| Cloudflare | Hosting this website | Standard request logs such as IP address |
We may disclose data if the law requires it or to protect the rights and safety of our users. If LetsFlight is ever transferred to another operator, we will tell you before your data becomes subject to a different privacy policy.
6. International transfers
Our database is hosted in the European Union. Some providers, such as Clerk, Apple, Expo and Google, process data in the United States or other countries. Where the GDPR applies, these transfers rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
7. Retention and account deletion
We keep your data while your account exists. You can remove single flights and stays at any time. To delete everything, open Settings › Delete account in the app. Deletion starts immediately and, within a few minutes, removes your sign-in, flights, stays, friends and shared items, imports, notification settings and devices, and revokes any Google access.
- Your friends keep their own records, including any of your flights they copied into their own log.
- Events LetsFlight already added to your Google Calendar stay in your calendar until you remove them.
- We keep a minimal record that an account was deleted (a random account identifier and the date), and service providers may keep operational logs for a short period under their own retention policies.
If you cannot use the app, email us from the address on your account and we will delete it for you.
8. Your rights and choices
Depending on where you live, including under the GDPR, you have the right to access, correct, delete or export your data, to restrict or object to its processing, and to withdraw consent at any time.
- Export: Settings › Export flight history creates a CSV file of your flights.
- Correct: edit your profile and flight details in the app.
- Notifications: switch them off in the app or in iOS Settings.
- Anything else: email hello@letsflight.app. We reply within 30 days.
You can also complain to your local data protection authority.
9. Security
Data is encrypted in transit, Google tokens are additionally encrypted at rest, and access to production systems is limited to the operator. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as the law requires.
10. Children
LetsFlight is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this policy
We will update this page when our practices change and revise the date at the top. For significant changes we will also tell you in the app before they take effect.
12. Contact
Questions about privacy or a request about your data? Write to Pavel Soukup, the operator of LetsFlight.
hello@letsflight.app