This policy explains what data FlightNerve collects when you use our flight data API, website and developer console, how we use and protect it, and the rights you have over it.
FlightNerve is a flight-operations data product. We collect the minimum needed to run your account, meter usage and keep the Service secure. We do not sell your personal data, and we do not hold passenger records, reservations or personal travel data — the flight data we return is operational information about aircraft and flights, not people.
| Category | Examples | Why |
|---|---|---|
| Account data | Email address, hashed password, company name (optional) | To create and secure your account |
| API credentials | Your API key(s) and their status | To authenticate and meter requests |
| Usage & request metadata | Endpoints called, timestamps, credit consumption, response codes, IP address | Billing, rate limiting, security, diagnostics |
| Communications | Messages you send us via the contact form or email | To answer and support you |
| Technical logs | Server logs, error traces | Reliability and abuse prevention |
We do not require, and ask you not to send, sensitive personal data through the API. Query parameters (such as a flight number or airport code) are operational identifiers, not personal data.
Where the GDPR or similar laws apply, we process personal data on these bases: performance of a contract (running your account and the Service), legitimate interests (securing and improving the Service, preventing abuse), legal obligation (tax and accounting records), and consent where specifically requested (for example, optional communications).
The developer console uses strictly necessary cookies or local storage to keep you signed in and to remember essential preferences. We do not use advertising cookies or sell data to advertisers. If we introduce analytics, we will use privacy-respecting, aggregated measurement and update this policy accordingly.
We use a small number of infrastructure providers to host and operate the Service (for example, server hosting, transactional email delivery, and upstream flight-data sources). These providers process data only on our instructions and under appropriate data-protection terms. A current list is available on request from api@flightnerve.com.
We keep account data for as long as your account is active and as needed to provide the Service. Usage and request metadata is retained for a limited period for billing, security and diagnostics, then aggregated or deleted. Records we must keep for legal or accounting reasons are retained for the required period. You can request deletion of your account as described below.
We protect data with encryption in transit (HTTPS), hashed credentials, access controls and monitoring. No system is perfectly secure, but we work to protect your data and will notify affected users and authorities of a material breach as required by law. Keep your API key confidential; treat it like a password.
Depending on your location, you may have the right to access, correct, delete, restrict or object to processing of your personal data, and to data portability. To exercise any of these, email api@flightnerve.com from your account address. You also have the right to lodge a complaint with your local data-protection authority.
We may process data in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards (such as standard contractual clauses) where required by applicable law.
The Service is intended for developers and businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16.
We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date and, where appropriate, notified to account holders. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Questions about privacy or a data request? Contact us at api@flightnerve.com or via the contact page. See also our Terms & Conditions.