Legal
Privacy Policy
Last updated August 15, 2026
We collect as little as the product needs to work: search criteria, enough signal to stop abuse, and an account if you sign in. You can run one free search without creating an account. We do not sell your data and we do not run advertising trackers.
What we collect
- Account data. Your email address and login identifiers, created when you sign in. If you use a social login, we receive the basic profile your provider shares.
- Search data. The criteria you submit (airports, continent, trip type, date window, stay length, price bounds, theme) plus the report we generate and its status, so you can revisit it in your history. Signed-in searches are stored in our database. Guest searches are sent to the model to run and are not saved to your history.
- Billing data. Your subscription status, plan interval, renewal date, and provider customer and subscription identifiers. Card numbers go directly to Stripe; we never see or store them.
- Abuse-prevention data. Your IP address and a random guest identifier stored in a cookie, used as counters to enforce free and monthly search limits. This is collected whether or not you have an account.
- Analytics data. Page views, the referring site, and coarse device and browser information, collected by Vercel Analytics so we can see which pages are used.
- Technical data. Standard request logs kept by our hosting and infrastructure providers, such as IP address, user agent, and timestamps.
Cookies we set
- Session cookies from our authentication provider, required to keep you signed in.
fcf_guest: a random identifier, valid for 90 days, that tracks whether your free search has been used. It is not a name or email, but it is a persistent ID and can be combined with your IP address for quota enforcement.theme: remembers light or dark mode so the first paint matches your choice. It lasts one year. The same preference is also stored in your browser's local storage.
These are functional cookies, not advertising cookies. Clerk, Stripe, Cloudflare (bot checks), and Vercel Analytics may also set their own functional cookies or similar identifiers. We do not use third-party ad networks or cross-site tracking pixels.
How we use it
- to run your searches and show you the results;
- to keep your search history available to you;
- to create your account and keep it secure;
- to process subscriptions and honor plan limits;
- to detect and prevent abuse, fraud, and cost attacks through rate limiting;
- to fix bugs, monitor reliability, and see which pages are used;
- to send transactional messages about your account or billing.
We do not sell your personal information, and we do not share it for behavioral advertising. We do not send marketing or fare-alert email unless we update this policy first.
Who processes your data
We use a small number of providers, each handling only what its job requires:
- Clerk: accounts, sign-in, and session management.
- Convex: the database that stores your user record, search criteria, and reports.
- Upstash Redis: short-lived counters keyed to your guest identifier or IP address for rate limiting.
- Stripe: checkout, card processing, and subscription management.
- OpenRouter and the underlying model provider: they receive your trip criteria in order to run the search. We do not use your prompts to train a model of our own. We cannot control whether those providers log requests or use them under their own terms. Do not put sensitive personal details into free-text fields.
- Vercel: hosting, edge routing, request logs, and Vercel Analytics page-view data.
These providers may process data outside your country, including in the United States.
How long we keep it
Account records and signed-in search history stay until you ask us to delete them. They do not expire on their own. Rate-limit counters expire automatically: daily free-search counters within about 36 hours, monthly Pro counters within about 40 days, and guest counters within 90 days. After a deletion request we remove your Clerk login, Convex user record, and search history. Stripe and other providers may keep billing or log records as long as their own rules and tax law require. Provider logs follow each provider's retention schedule.
Your choices and rights
You can update your account details from the account menu. To delete your account and personal data, email support@findcheapflights.ai from the address on the account. We will verify the request, then delete your Clerk login, Convex user record, and search history, and ask Stripe to close the customer record where that is allowed. Copies held by providers for tax, fraud, or legal reasons may remain.
Depending on where you live, you may also have the right to access, correct, export, or delete your personal data, or to object to certain processing. Email the same address and we will handle the request. You can also block cookies in your browser, though sign-in and quota tracking will stop working.
Security
Traffic is served over HTTPS, the guest cookie is HTTP-only, and access to production data is limited. No system is perfectly secure, so we cannot guarantee absolute protection. Please use a strong, unique login.
Children
You must be at least 18 to use the service or subscribe. The service is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has given us information, email us and we will delete it.
Changes and contact
We will update this page when our practices change and revise the “last updated” date above. Questions, deletion requests, or privacy concerns: support@findcheapflights.ai. See also our Terms of Service.