Privacy policy
[DRAFT — pending founder legal review] This is a working draft. Our lawyer is finalising the wording before we open to new users.
This policy explains what Flight Hero reads, what we keep, what we throw away, and the rights you have over your data. We’ve written it to match exactly how the product actually works.
Extract & discard
Who we are
[DRAFT — pending founder legal review] Flight Hero helps you find and claim the flight compensation you may be owed under UK261 and EU261, using your own booking and disruption emails. For any question about your data, contact us at oewh87@gmail.com. The data controller is the operator of Flight Hero; the full legal entity and address will be confirmed here before launch.
What we read, and how the scan works
[DRAFT — pending founder legal review] With your permission, we connect to your Gmail and look for flight-related mail: booking confirmations, e-tickets, and delay or cancellation notices. We do not read your whole inbox for its own sake — the scan is a funnel built to touch as little as possible:
- Most messages are ruled out from their headers alone (sender, subject) and are never opened or sent anywhere.
- Only messages that look like flight mail go through the next stages, where we identify the flight and extract its structured facts.
- The raw content of a message exists only for the moment it takes to pull out those facts, and is then discarded. We never keep the text of your emails.
Boarding passes and typed flights
[DRAFT — pending founder legal review] You can check a flight without connecting an inbox. We read the barcode on your device, and only the flight details (flight number, date, airports and booking reference) leave it; the image and the barcode itself never do. If the barcode cannot be read and you choose to send the photo, an AI model reads it once, in memory; we keep the flight details and discard the photo and your name. If you type a flight number and date, that is all we receive.
What we keep — and what we throw away
[DRAFT — pending founder legal review] We keep structured flight facts only: flight numbers, airports, dates and times, booking references, passenger names, and the disruption details relevant to a claim (for example, how long a flight was delayed). To trace a claim back to its source, we keep the identifiers of the source messages (message IDs) — never the subjects, bodies, or attachments themselves.
We discard the email bodies, attachments, and every message that isn’t about a flight. This “extract-and-discard” approach is a hard rule in how the system is built: raw email content is never stored beyond the moment of processing.
Other people named in your bookings
[DRAFT — pending founder legal review] A booking may name other passengers travelling with you (for example, a family member). Where that happens we hold their name as part of the flight record so the claim is accurate. We only ever use this to assess and pursue the claim connected to your booking; we do not use it for anything else, and it is deleted along with the rest of your data when you delete your account.
Why we’re allowed to do this (lawful bases)
[DRAFT — pending founder legal review] Under UK and EU data protection law we rely on:
- Your consent (UK GDPR Article 6(1)(a)) to connect your inbox and scan it for flights. You can withdraw this at any time by disconnecting — see “Your rights” below.
- Performance of our contract with you (Article 6(1)(b)) to prepare, file and pursue the compensation claims you ask us to handle.
Our fee
[DRAFT — pending founder legal review] If the airline pays compensation for your claim, our fee is 3% of that compensation. Nothing if we recover nothing. We only ever describe amounts as potential or estimated until an airline has actually paid.
Where your data is stored
[DRAFT — pending founder legal review] Your personal data is stored in the EU (our database is hosted in an EU region) and served through EU/UK infrastructure. To assess flights, some structured details are processed by a third-party AI provider (see below); that step involves a transfer outside the UK/EU, which our lawyer is confirming is covered by appropriate safeguards before launch.
Who we share data with (processors)
[DRAFT — pending founder legal review] We use a small number of service providers who process data on our behalf, under contract and only on our instructions:
- Our hosting and database provider (EU region), which stores your structured flight data.
- An AI provider that helps classify and read flight details from the structured content of relevant messages. This provider does not use the data we send to train its models, and processing takes place on its infrastructure (currently in the United States). A data-processing agreement and transfer safeguards govern this relationship.
- Airlines and, where needed, dispute-resolution bodies or courts, to pursue your claim.
We never sell your data, and we never use it for advertising.
We don’t train models on your data
[DRAFT — pending founder legal review] We do not use your email data to train our own models, and the AI provider we use does not train its models on the data we send it. Your data is used to find and pursue your flight compensation — nothing else.
How long we keep it
[DRAFT — pending founder legal review] We keep your structured flight data for as long as your account is open. When you delete your account, we delete the data we extracted. Where we have filed a claim on your behalf, we keep a limited audit record of that claim for as long as we are required to, and no longer.
[DRAFT — pending founder legal review] When your one-off scan finishes we revoke our access to your Gmail at Google and delete the tokens we held; connecting again asks for a fresh consent.
How we protect it (security)
[DRAFT — pending founder legal review] Our security baseline includes:
- Encryption in transit and at rest.
- Your inbox access tokens are stored encrypted (AES-256-GCM), with the encryption key held only in our runtime environment — never in the database.
- Strict access controls: each user’s data is isolated so it can only be read by them or by our least-privilege server processes.
- An append-only audit log of actions taken on a claim.
Your rights
[DRAFT — pending founder legal review] You have the right to:
- Withdraw consent and disconnect at any time — this stops future scanning immediately.
- Delete your data. Use the delete option on your account page, which disconnects your inbox and erases the flight data we extracted along with your access tokens.
- Access, correct, or ask for a copy of the personal data we hold about you.
- Object to or restrict certain processing, and complain to your data protection regulator (in the UK, the Information Commissioner’s Office).
To exercise any of these, use your account page or contact us at oewh87@gmail.com.
Changes to this policy
[DRAFT — pending founder legal review] We’ll update this policy as the product develops and as our lawyer finalises the wording, and we’ll note material changes here.