Privacy policy

Scope

Flaut.Travel is operated by Andrii Bryhynets, who is the data controller for the processing described in this Privacy Policy. You can contact the controller at admin@flaut.travel. This policy covers our website, APIs, apps, plugins and AI or agent integrations (the Services). Privacy enquiries: legal@flaut.travel; general support: hello@flaut.travel.

Flaut.Travel compares flights and provides travel information. Searching does not require a customer account, passenger names, passport details or payment details. Purchases take place with external booking providers, whose processing is governed by their own policies.

Search, network and contact data

We receive the places you enter, routes, travel dates, passenger numbers and age categories, cabin class, currency, language, market and filters. Destination discovery can also use your preferred region, trip duration, budget category, climate and interests. We receive results and search, offer and referral identifiers from travel partners to display prices and open booking links.

Requests expose an IP address, User-Agent (browser or client information), requested address, headers and timing information. We use IP-based approximate location to suggest a departure city and regional settings, and network information to operate and protect the Services. Travelpayouts receives your IP address for location lookup and live search. Our server API client uses a Flaut.Travel User-Agent; direct browser requests to partners also expose your browser’s IP address and User-Agent.

If you email us, we receive your address, message and any name or attachments you provide. Please avoid sending passport, payment or sensitive personal information. Separate editorial accounts store administrators’ email and authentication data; published author names and photos accompany articles. These are not flight-search customer accounts.

AI systems and AI agents

You can use the Services through AI systems and AI agents, including ChatGPT, Claude, and other AI systems and agents, as well as MCP-compatible clients and other API integrations. We receive the parameters and content the client sends, plus technical request metadata. Current tools accept city queries, routes, dates or months, language, currency, market, filters and destination preferences. Display tools can receive previously returned result data again.

We return city matches, destination suggestions, route and airport information, prices, travel links and display data to the calling platform. The integration does not give us automatic access to your entire AI conversation. Any conversation content the client includes in a request can nevertheless reach us. Network metadata may describe the AI platform rather than you. The AI provider independently controls its processing of conversations, tool requests and results under its own privacy terms.

Analytics

We use Plausible at analytics.flaut.travel to measure page visits and actions such as searches, filter use and booking-link clicks. Events include language and device type. Page addresses and referral information reach the analytics endpoint, so travel parameters in addresses can also be received.

Plausible’s standard processing derives browser, operating system, device and approximate geography, and uses IP address and User-Agent to calculate a daily visitor identifier. It does not use analytics cookies or a visitor identifier that persists across days; raw IP addresses and full User-Agent strings are not retained in its analytics records. Most query parameters are excluded from statistics, with exceptions for campaign attribution. This does not exclude addresses or parameters from separate operational or diagnostic logs.

Logs, error monitoring and session replay

We process error messages, stack traces, URLs and query parameters, request and response metadata, browser and operating-system information, application versions, timing measurements and diagnostic breadcrumbs to investigate failures and reliability. Diagnostic records can include search identifiers, headers, IP addresses and request or response content. Sharing-link errors can include the link, ticket identifier and backend response.

Operational logs may be temporarily retained on servers operated by our hosting provider. Our backend also sends logs and technical measurements to our monitoring service. These disclosures support operations, security and troubleshooting.

Browser diagnostics include sampled session replays and replays associated with errors: reconstructions of page interactions, navigation and technical events. The replay configuration uses default text and input masking and media blocking. These protections do not remove all information from URLs, console messages or other diagnostic records. Replays use a session identifier stored in the browser’s session storage.

Cookies and browser storage

A language preference cookie lasts up to one year after selection; routing may also set a session language cookie. Local storage remembers currency, regional and display preferences and up to five recent destinations until replaced or cleared. Session storage remembers search filters, dismissed language suggestions and replay session information.

You can clear or block cookies and site storage in your browser; this can reset preferences or affect features. Embedded services and booking partners may use their own cookies or storage under their policies. Clearing site storage does not delete records already received by us or third parties.

Recipients and external services

Hosting, network delivery, database and media-storage providers process data to serve the Services. Analytics and monitoring services process the information described above; email providers process correspondence. Travelpayouts and associated travel-data and affiliate partners receive search parameters, IP addresses where required, search and offer identifiers, and referral information to provide results and booking redirects.

Opening a booking link can load an affiliate pixel with click and provider identifiers, alongside browser network metadata, to attribute a referral and commission. External booking providers then process your visit and any purchase information themselves.

Maps, schedules, images and other embedded resources can connect directly to providers such as CARTO, Flightera, Avionio, FlagCDN and content delivery networks. They receive your IP address, User-Agent and requested resource, and may receive referrer information. Their services have separate privacy terms. Data may also be disclosed to authorities when required by applicable law.

Purposes and legal grounds

We process data to fulfil requested searches and information requests, localize results, enable sharing and referrals, answer correspondence, measure usage, diagnose failures and prevent abuse. Search parameters are needed to return relevant results; optional preferences refine them.

Where the GDPR or similar rules requiring a legal basis apply, processing necessary for a requested service is based on providing that service or taking requested pre-contractual steps. Security, reliability, proportionate diagnostics and usage analysis serve our legitimate interests in operating and improving the Services, subject to applicable balancing requirements. Processing required by law rests on that obligation. Where consent is legally required, it must be obtained separately; visiting the site or reading this policy is not consent.

International processing

Our providers and travel or AI partners may process personal data outside your country, where data-protection laws may differ. Where the GDPR, UK GDPR or other applicable law restricts international transfers, transfers for which we are responsible must meet those requirements, including the use of legally required safeguards. You can request information about relevant recipients, processing countries and transfer arrangements, including any applicable safeguards and how to obtain a copy, at legal@flaut.travel.

Retention

IP-based location cache entries, including the IP address in the cache key, expire after 10 days. Search initialization records last about 24 hours. Live results are cached for 15 minutes; related result metadata for 14 minutes 50 seconds, from the cache write. These are cache lifetimes, not deletion deadlines for separate logs or partner records.

Website share links store a destination URL, code and timestamps for 365 days; expired records are scheduled for daily deletion. API-created links can have a shorter expiry or no automatic expiry. Anyone with a working link can access its destination and the travel details it contains.

General route and price data are cached separately according to their freshness, relevant travel dates or the end of a day or month. They are not a customer account history. Browser storage lasts as described above. AI requests do not create a separate conversation-history database in our integration, but request information can appear in logs and diagnostics.

Operational/server logs are retained only for as long as needed to operate and secure the Services, investigate failures and address abuse. Monitoring and diagnostic records, including session replays, are retained only for as long as needed to investigate and resolve errors or security incidents. Relevant criteria include whether an incident remains open and whether the records are still needed to verify a fix or investigate recurrence.

Plausible analytics records are retained for measurement of usage and comparison of trends over time, only while they remain necessary for those purposes. These criteria do not imply an automatic deletion schedule for logs, monitoring or analytics.

Support and privacy correspondence is retained until the enquiry is resolved and any necessary follow-up is complete. After that, we retain only records necessary to meet applicable legal obligations or establish, exercise or defend legal claims, for the applicable legal period or duration of the claim, and delete them when that need ends. This is a purpose-based retention rule, not an automatic mailbox deletion period.

Editorial account records and author materials remain until managed or deleted by the operator. Third parties apply their own retention rules to processing they control.

Your rights and choices

Your rights depend on the law applicable where you reside or access the Services, not on the language selected. Where applicable, you may request access, correction, deletion, restriction or portability, object to processing based on legitimate interests, withdraw consent without affecting earlier lawful processing, and complain to a competent data-protection authority. Regional laws may also provide rights to opt out of sale, sharing or targeted advertising, limit certain uses, or appeal a decision, without unlawful discrimination.

Send requests to legal@flaut.travel. Include enough context, such as approximate dates or a relevant link, to help locate records; we may need proportionate identity verification. We respond within the applicable legal deadline and charge only where legally permitted. We may be unable to associate aggregate statistics or expired records with you and do not collect extra identifying data solely for that purpose. Contact a booking or AI provider directly for data it independently controls.

Ranking, advertising and children

Search ranking and destination matching use your criteria and travel data. They do not make decisions producing legal or similarly significant effects about you. We do not build personal profiles for targeted advertising or offer personal data for sale. Affiliate referral measurement described above is part of how the service earns revenue; partners control their subsequent processing.

The Services are intended for general travel research, not directed at children. Adults can search for trips including children using passenger counts and age categories, without entering children’s names. A parent or guardian concerned about a child’s personal data can contact us for review and deletion where appropriate under applicable law.

Security, changes and contact

Technical protections include encrypted website connections and authentication for editorial administration. No transmission or storage system provides an absolute security guarantee.

We publish changes on this page with a revised update date. Where applicable law requires additional notice or consent, those requirements apply. For this policy or your data-protection rights, contact legal@flaut.travel. General support is available at hello@flaut.travel.