FlightCal · Privacy
Privacy notice
FlightCal is operated by Sibyl Capital LLC. For privacy questions or account requests, email flightcal@sibylsignal.com.
Effective date: October 3, 2026.
This notice explains what FlightCal receives, how it is used, when it is shared, and how to request deletion or other privacy help.
Information we collect and receive
Account and authentication. Depending on the sign-in path and features you use, FlightCal receives a mobile phone number used for verification, an account email when one is present, Supabase Auth account and session identifiers, and account confirmation or status information. Phone sign-in uses one-time SMS verification. FlightCal also processes a per-installation identifier and Apple App Attest and DeviceCheck signals to protect sign-in and prevent fraud and abuse.
Flight monitoring. FlightCal receives the flight searches and watch settings you choose, including origin and destination airports, departure dates, trip-length ranges, cabin, stops, passenger count, currency, market, budget, alert thresholds, titles, and notification choices. It stores fare results, alerts, alert history, and related monitoring evidence so that it can monitor selected flights and show results in the app.
Account activity and notifications. FlightCal receives your account time zone and activity timestamps to apply daily limits, engagement reminders, and monitoring lifecycle rules. If you enable notifications, FlightCal stores an installation identifier, APNs device token, APNs environment and topic, notification permission state, delivery status, and inbox or alert read state. You can withdraw notification permission in iOS Settings; doing so stops push delivery but does not by itself delete your account.
Subscriptions and support. If you purchase, restore, or use a subscription feature, FlightCal processes the Apple transaction and entitlement evidence needed to bind and reconcile access. Apple processes App Store payments and manages renewal, cancellation, and refunds. If you send feedback or contact support, FlightCal receives the message and the account email associated with the authenticated session when available.
Operations and security. FlightCal processes request and job identifiers, status, bounded counts and durations, queue state, provider request identifiers, network and device-integrity signals, and abuse-prevention records. These records help operate the service, investigate failures, enforce usage limits, prevent fraud, and protect accounts.
How we use information
We use information to authenticate users; create and maintain accounts, watches, alerts, devices, and subscriptions; search for and monitor flight information; send in-app and push notifications; enforce usage and abuse controls; provide support; improve reliability and security; comply with legal obligations; and respond to privacy requests.
FlightCal does not sell personal information and does not use the information described here for advertising or cross-app tracking.
When we share information
FlightCal shares only the information needed for the service involved. We require service providers that receive personal information to provide the same or equal protection of that information as described in this notice and to use it only for the authorized service purposes.
FlightCal uses the following services for these purposes:
- Supabase provides authentication, account sessions, and the database-backed FlightCal service. It receives account identity, session, watch, alert, device, subscription, usage, and security records needed for those functions. See Supabase’s privacy notice and data-processing addendum.
- Twilio Verify and Lookup, when enabled, send SMS verification codes and check phone line information such as mobile-line type and, when the feature is enabled, reassignment status. They receive the phone number and the verification or lookup request data required for those operations. See Twilio’s privacy notice, Verify documentation, and Lookup documentation.
- SearchAPI.io, when flight acquisition is enabled, receives the route, dates, passenger count, currency, market, cabin, stop, and other search filters needed to return flight results. See SearchAPI’s privacy policy and Google Flights API documentation.
- Cloudflare provides the Worker and queue infrastructure used to serve the API and run background work. Cloudflare may process request, network, security, and platform-log metadata. Cloudflare Turnstile, when enabled, receives the challenge response and the network information needed to assess an authentication request. See Cloudflare’s privacy policy.
- Resend, when feedback or security-email delivery is enabled, receives the account email and feedback message or aggregate security notice needed to deliver that email. See Resend’s privacy policy.
- Apple provides App Store subscriptions, APNs notifications, and App Attest and DeviceCheck services. Apple receives the transaction, notification, or device-integrity data needed for those Apple services. See Apple’s privacy policy.
When you follow a FlightCal search or booking handoff, the destination, such as Google Flights, receives the route, dates, and other search parameters included in that handoff. The destination’s privacy notice governs its handling of that activity. FlightCal does not receive your payment details from the destination and does not buy tickets or make bookings.
We may disclose information when required by law, to protect users or the service, to investigate fraud or abuse, or as part of a business transfer. We do not authorize service providers to use FlightCal information for their own advertising.
Retention and deletion
We keep each category of information for as long as reasonably necessary to provide FlightCal, maintain account history, protect the service, enforce usage and abuse controls, reconcile subscriptions, and meet legal obligations. Retention can also be affected by the provider or hosting terms for the service used.
Account-bound watches, alerts, preferences, activity, device registrations, and other application records are removed when the account is deleted. A deletion request also revokes sessions and disables monitoring and device delivery. Identity cleanup may be accepted and completed by a retryable server-side process; while that cleanup is pending, access remains revoked and the account cannot be used.
We may retain limited usage, billing, security, abuse-prevention, support, and deletion records when reasonably necessary to enforce service allowances, investigate misuse, reconcile Apple transactions, resolve disputes, or meet legal obligations. Phone abuse-prevention records can include a protected phone identifier and a 30-day recreation hold. A deletion tombstone or other limited record may remain after the hold when needed to prevent repeated abuse. We do not include phone numbers or verification codes in general application logs by design, but provider and platform logs may have their own retention rules.
Deleting a FlightCal account does not cancel an Apple subscription. Manage or cancel that subscription through your Apple account.
Your choices and privacy requests
You can manage notification permission in iOS Settings and request account deletion in the app. For access, correction, deletion, or other privacy requests, email flightcal@sibylsignal.com. We may need to verify your identity before completing a request. Some information may remain when retention is required for security, abuse prevention, billing, dispute resolution, or law.
Contact
For privacy questions or requests, email flightcal@sibylsignal.com.