Privacy

ClassFlyer searches award flights for you and keeps watching after you leave. To do that it stores what you asked for and what it found. This page lists every kind of data, why it is kept, who else receives it, and how to get rid of it. Last updated 23 August 2026.

Without an account

You can use ClassFlyer without signing up. Your browser or phone then carries a random anonymous id, and everything you do (conversations with the agent, the flights it found, watches, preferences, a cart) is stored under that id. Nobody can claim it but the device that minted it. Clearing the browser, or the Reset anonymous data action in the app, forgets it; whatever it owned is then unreachable and is purged on our side.

With an account

An account is an e-mail address and a password (hashed, never stored in clear). Signing up or in moves the anonymous work above into the account. We also keep: your conversations and their results, standing goals and watches and the hits they produced, preferences (home airports, cabin, programs, currency, notification choices), what the agent remembers about you in its own words, your cart, and when you last opened the Alerts tab. Usage is metered per account (which searches ran, when, at what cost to us) so plan limits can be enforced; the metering keeps no content.

Referral links

Arriving through a partner's referral link (classflyer.com/l/ref/…) records, on our servers, that your anonymous id came through that partner's code. Nothing extra is stored in your browser. The note expires on its own after 30 days; if you create an account within that window, the account remembers which partner referred it so we can pay them their commission. The partner is told a sign-up happened and, later, that a subscription started; they are never told who you are.

The phone app

The app stores your sign-in token and anonymous id in the device keychain. If you turn on notifications it registers a push token for this device with us; we keep the token, the platform and the app version, and delete it when you sign out, turn notifications off, or delete the account. A notification carries a route, a price and a short line from the agent; it never carries where the data came from. If you allow it once, the app reads a coarse location to suggest a home airport; the position is not stored.

Who else receives data

  • Apple and Google deliver push notifications (the device token and the notification text).
  • Stripe processes subscriptions bought on the web; Apple and Google process those bought in the app, through RevenueCat, which sees your account id and the purchase. We never see card numbers.
  • Cloudflare runs the occasional human check on expensive actions (your IP address and browser signals).
  • Map tiles come from OpenFreeMap and destination photos from Wikimedia; loading them sends those services your IP address, as any image does.
  • Our servers and database are hosted in Europe.

We do not sell data or use tracking SDKs. There is no cross-app tracking, so the app never asks for tracking permission.

Deleting everything

Delete account, on the account page and in the app under You, removes the account and everything listed above, including device tokens, after confirming your password. A subscription bought through Apple or Google is cancelled in that store, not by deleting the account. Requests by e-mail are handled the same way.

Contact

Questions about your data: privacy@classflyer.com.