Privacy & Cookie Policy
Plain-language explanation of what we collect, why, and how we protect it.
Last updated: February 24, 2026
Introduction
FlightDesk ("we", "us", "our") operates the flightdesk.dev website and the FlightDesk platform. This policy describes how we collect, use, store, and protect your personal information when you use our services.
By creating an account or using FlightDesk, you agree to the practices described in this policy. If you don't agree, please don't use the service.
What we collect
Account information
- Name and email address (when you sign up)
- Password (hashed — we never store your password in plain text)
- Organization and team membership details
- GitHub profile information (if you connect your GitHub account)
Usage and product data
- Task metadata (titles, descriptions, status, timeline events)
- Project configuration and settings
- Context notes, test plans, and session summaries you save
- Check results and review feedback aggregation data
Payment information
- Payments are processed by Stripe. We do not store your credit card number or bank details on our servers
- We store your Stripe customer ID, subscription status, and billing plan to manage your account
Analytics data
- We use Google Tag Manager (GTM) to manage analytics and marketing tags on our website
- Through GTM, services like Google Analytics may collect anonymized usage data such as pages visited, time on site, referral source, browser type, and device information
- IP addresses may be collected by these analytics services but are anonymized where possible
What we don't collect
- Your source code (preview environments run it but we don't store it)
- Your environment variables (passed to containers at runtime, not persisted)
- Git history or diffs
- Claude Code session contents or prompts
- Credit card numbers (handled entirely by Stripe)
How we use your information
- Provide the service — authenticate you, manage your projects and tasks, run preview environments, and process payments
- Communicate with you — send transactional emails (account verification, password resets, billing receipts) and product updates
- Improve the product — analyze aggregated, anonymized usage patterns to understand which features are used and where the product falls short
- Ensure security — detect abuse, prevent fraud, and monitor for unauthorized access
We do not sell your personal information. We do not use your data for advertising.
Third-party services
We share data with the following third parties only as necessary to operate the service:
Stripe
Payment processing
Handles all payment processing. Receives your name, email, and payment method details. Subject to Stripe's Privacy Policy.
Google Tag Manager & Google Analytics
Website analytics
Collects anonymized usage data about how visitors interact with our marketing site. Subject to Google's Privacy Policy.
Stack
Authentication & CRM
We use Stack for user authentication and customer relationship management. Your name and email address are shared with Stack to manage your account and enable login functionality.
GitHub
Source control integration
When you connect your GitHub account, we receive repository metadata and pull request information via the GitHub API. We use short-lived GitHub App installation tokens — not personal access tokens. Subject to GitHub's Privacy Statement.
Data storage & security
- All data is stored in our own database infrastructure
- All traffic is encrypted in transit via TLS (HTTPS everywhere, no HTTP fallback)
- Integration credentials (e.g., SonarQube tokens) are encrypted at rest using AES-256
- Passwords are hashed using industry-standard algorithms — never stored in plain text
- Preview environments run in isolated Docker containers that are destroyed when no longer needed
For more details on our security practices, see our Security page.
Data retention
- Active accounts — we retain your data for as long as your account is active
- Account deletion — when you delete your account, we remove your personal data from our systems. Some anonymized, aggregated data may be retained for analytics
- Backups — data may persist in encrypted backups for up to 90 days after deletion
Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Correction — request that we correct inaccurate data
- Deletion — request that we delete your personal data
- Portability — request your data in a machine-readable format
- Opt out — unsubscribe from marketing communications at any time
To exercise any of these rights, email us at privacy@flightdesk.dev.
Children's privacy
FlightDesk is not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. If we make material changes, we'll notify you by email or by posting a notice on the site before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Questions about your privacy?
If you have questions about this policy or how we handle your data, we're happy to help.