Last updated: 29 July 2026
Privacy policy
What FlightPeek stores, why, for how long — and what we deliberately do not collect.
Controller
KCraft Studio LTDNeofytou Nikolaidi & Theod. KolokotroniONISIFOROU CENTER (2nd floor)Agios Theodoros, 8011 PaphosCypruscontact@kcraft.ioWhat we do not collect
The app requests no location access, no contacts, no camera and no microphone. There are no ad networks, no cross-provider tracking and no sale of data. The optional calendar import reads your events exclusively on the device: a flight number is detected locally — only that number is sent to our server, never the event content. The same applies to text shared via the share sheet.
What data we process
- Account
- Email address, an optional display name, and your password as a bcrypt hash — it is never stored in clear text. An anonymous account without an email address is possible. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- Tracked flights
- Flight number and date of the flights you add, along with the status data retrieved for them. This reveals when and where you travel, so we treat it like account data and do not pass it on. Legal basis: performance of a contract.
- Push token
- A device identifier issued by the operating system, used to deliver notifications, plus the platform (Android or iOS). Without it we cannot send anything. If the service reports a token as invalid, we delete it.
- Subscription
- Whether your subscription is active and until when. Payment itself is handled by Apple and Google — we see no card details and no billing address.
- Server logs
- Accessing our API produces technical logs (timestamp, requested path, error states). Legal basis: legitimate interest in secure operation, Art. 6(1)(f) GDPR.
Recipients and third parties
To track your flight we send the flight number and date to a flight data provider. Your email address or account identifier is not transmitted — the provider does not learn who is flying, only which flight is queried.
- FlightAware AeroAPI / AeroDataBox
- Flight data. Flight number and date are transmitted.
- Google Firebase Cloud Messaging / Apple Push Notification service
- Delivery of push notifications and lock-screen Live Activities. Push token and message content (flight number, status, times) are transmitted.
- adsb.lol
- Live aircraft position from an open community network (ODbL licence). Only the aircraft identifier is queried — no personal data.
- AirLabs
- Supplementary airport data such as gate and baggage belt. Flight number and airport code are transmitted.
- Open-Meteo
- Weather at the arrival airport. The airport's coordinates are queried — not yours.
- Mapbox
- Map rendering in the app. Loading map tiles transmits your IP address to Mapbox.
- RevenueCat
- Subscription management.
- Email delivery service
- Sending the password reset code.
Server location
Our servers are operated by Hetzner Online GmbH in Germany. Account and flight data is stored and processed exclusively there — within the EU and thus directly under the GDPR.
How long we store data
- Account data
- Until the account is deleted.
- Raw responses from flight data providers
- 90 days, then deleted automatically.
- Refresh tokens
- 7 days, then invalid.
- Password reset codes
- 15 minutes.
Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can delete your account directly in the app, which also removes tracked flights and push tokens. For anything else, an email to contact@kcraft.io is enough.
You also have the right to lodge a complaint with a supervisory authority. Ours is the Commissioner for Personal Data Protection of the Republic of Cyprus; you may also contact the authority in your country of residence.
This website
This site sets no cookies and loads no external fonts. That is also why there is no consent banner — nothing is stored on your device that you could consent to.
We do, however, count page views — ourselves: no third-party service is involved, and nothing leaves our own servers. What we store is the page you opened, the language, the referring website (its name only, not your search query), the country and whether you are on a phone, tablet or computer.
Your IP address is not stored. It is used to determine the country and then discarded. To tell visitors apart from page views we derive a checksum from IP address, browser identifier and a secret value, which also includes the current date — it cannot be reversed and is different the next day. Anyone returning tomorrow counts as a new visitor. Recognising someone across several days is therefore technically impossible.
