Privacy Policy

In plain words

ManyToFly answers one question: given everybody's home city, where is it cheapest for the group to meet? To answer it we need the cities, the dates and the currency — and nothing about who you are.

There is no account, no email address, no password and no advertising. The app never asks for your location: "nearby airports" is worked out from the cities you type, not from your phone.

We do keep a record of the searches themselves, tied to a random identifier rather than to you, because it tells us which routes to keep priced. That is the honest headline, and §02 spells it out.

01Who to hold responsible, and where to write.

Who we are

[[LEGAL_NAME]], [[ADDRESS]] ("we", "us") is the data controller for the processing described here.

Write to [[EMAIL]] with any question or request about your data. A person reads that address.

This policy covers the ManyToFly mobile app. It does not cover how Apple, Google, or the travel sites we link out to handle data under their own policies for their own purposes.

02The app described honestly as a data flow. The section to read if you read one.

How ManyToFly works

There is no sign-up

The first time the app runs it signs in anonymously and is issued a random identifier — a string of digits and letters generated for that installation. It is not linked to your name, email address, Apple ID or Google account, and we cannot work out who you are from it. It is the only identifier in the app.

What a search sends

When you run a search, the app sends us the home cities you entered (as airport and city codes such as MAD or BER), the date range you chose, your trip-length preference, any filters you set — a maximum price per person, or a region — and the currency you are viewing in. We send back the ranked destinations.

What we keep afterwards, and why

That search is stored on our servers against your random identifier: the cities, the dates, the filters, the currency and the results we returned. It is stored because a search engine over cached fares only works if it knows what people are actually asking for. Concretely, it tells us which departure cities to keep priced, which combinations return nothing useful, and which cities to add next. Where a city you asked for had no cached prices, that miss is recorded too.

What the city picker sends

When you type into the city picker we record what you typed, up to 120 characters, together with how many matches it produced and which city you finally chose. This includes text you typed and then abandoned without choosing anything. It exists for one reason: to find the gaps in our city index, where somebody types Cologne and our list only answers to Köln. Please don't type anything into it that you would not want recorded — it is a city search box, and that is all it is for.

What you tell us on purpose

Every so often, after a set of results, the app asks whether we found you somewhere good. Answering is entirely optional and the question can be dismissed. If you answer no, you are offered a box to say what was wrong; what you write there is sent to us, along with the language and platform you are using, and stored against the search that prompted it so we can reproduce the problem. Write only what you want us to read, and please leave out anything that identifies you or anybody else. If you answer yes, nothing is sent but the thumbs-up, and your phone's own app store handles any rating you choose to leave — we never see it as coming from you.

What your taps send

We record which destinations a results list showed you and in what order, which one you opened and where it sat in the list, and the same again if you share one. That is how we know whether the ranking is any good — a list nobody taps is a list in the wrong order. No page-by-page trail of your movements through the app is kept.

03The full list, with a legal basis for each.

What is processed, and why

DataPurposeLegal basis
A random identifier created on first launch To run searches against our backend and to keep any future purchase restorable Performance of the contract, Art. 6(1)(b) GDPR
Your search: home cities, date range, trip length, filters, currency, and the results returned To produce the ranking you asked for, and afterwards to decide which routes and cities to keep priced Performance of the contract, Art. 6(1)(b), and our legitimate interest in a search index that covers the places people ask for, Art. 6(1)(f) GDPR
Text typed into the city picker, including searches you abandoned, with the number of matches and the city chosen To find and fix gaps in the city index Legitimate interest in a working search box, Art. 6(1)(f) GDPR
Feedback you choose to send: the thumbs up or down, anything you write in the box that follows a thumbs-down, the language and platform, and the search it referred to To find out where the ranking is wrong, and to fix it Your consent, Art. 6(1)(a) GDPR — the question is optional and dismissable, and nothing is sent unless you answer
Which results were shown, opened and shared, and their rank To measure whether the ranking is useful Legitimate interest in improving the service, Art. 6(1)(f) GDPR
A usage snapshot held at RevenueCat: app language, onboarding step reached and whether it was completed or skipped, number of searches, time of the last one, the origin codes and how many, the length of the date window, trip-length preference, currency, how many destinations were opened and the last one, and the build type To understand how the app is used and to prepare paid features Legitimate interest in developing the product, Art. 6(1)(f) GDPR

Where we rely on legitimate interest you may object at any time under Art. 21 GDPR — see §08.

What we never collect

  • No location. The app requests no location permission on either platform, and there is no code in it that could ask for one. Nearby airports are calculated from the coordinates of the cities you typed against a fixed airport list.
  • No account, name, email address or phone number. There is no sign-up and no newsletter.
  • No advertising identifier, no ad networks, no cross-app tracking and no marketing profile. There is no advertising in the app at all.
  • No contacts, photos, microphone or camera. None of these permissions are declared.
  • No payment details. The app takes no payments — see §05.
  • No special category data in the sense of Art. 9 GDPR. Nothing here reveals health, beliefs, politics or anything comparable.

04Everyone else who touches it, and what each one gets.

Who else is involved

  • Supabase, Inc. — hosts our database, the anonymous sign-in and the functions that answer searches, as our processor under a data processing agreement. Hosting region: [[SUPABASE_REGION]]. supabase.com/privacy
  • RevenueCat, Inc. — receives the random identifier and the usage snapshot listed in §03, as our processor. It receives no free text and no city-picker input. revenuecat.com/privacy
  • Travelpayouts — supplies the cached fares that the ranking is built from. We query it from our servers for routes and dates; your identifier is not sent with those queries, and it does not learn who asked. Separately, it is the partner behind the booking links described in §05.
  • Apple Inc. and Google LLC — app distribution and, if you switched it on at the operating-system level, crash and usage reporting. They act as independent controllers for their own purposes.

We do not sell personal data, do not share it for advertising, and do not disclose it to anyone else except where compelled by a valid order from a competent authority.

05What happens the moment you leave the app.

Booking links and commission

ManyToFly does not sell flights, take payments or make reservations. When you tap through to check live fares, we open your normal browser at our travel partner's site, and the link carries a code identifying ManyToFly as the referrer. If you go on to book, we may earn a commission. That commission is what keeps the search free, and it does not change the ranking: destinations are ordered by what the group pays, not by what we earn.

From the moment that link opens you are on someone else's site, under their privacy policy and their terms. We do not send them your search history or your identifier, and we do not receive your booking, your name or your payment details back — only, at most, the fact that a referred booking happened.

06Where in the world it goes.

Transfers outside the EEA

Supabase, RevenueCat, Apple and Google are established in the United States, so the data described here may be transferred there. Those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the provider's certification under the EU–US Data Privacy Framework. Ask us and we will send you the relevant safeguards.

07How long we keep it.

Retention

  • Searches and the records derived from them — the cities, dates, filters, results, city-picker text and result taps: kept for [[RETENTION]], then deleted.
  • Feedback you sent us — the verdict and anything you wrote: kept for [[RETENTION]], then deleted, unless it describes a bug we are still working on.
  • The usage snapshot at RevenueCat: kept while the app is in service. Each attribute holds only the latest value, so it is overwritten rather than accumulated.
  • Everything on your phone — your saved home cities, your last twenty searches, your settings: kept until you clear them or uninstall the app. See §09.

Aggregate figures that no longer identify any installation — how many people searched a given route in a month, for instance — may be kept indefinitely, because they are no longer personal data.

08Your rights, plus the honest catch about anonymous identifiers.

Your rights

Under the GDPR you may request access to your personal data, correction, erasure, restriction of processing, a portable copy, and you may object to processing based on legitimate interest.

There is a practical catch worth stating plainly. Because the app knows you only as a random string, we usually cannot tell which records are yours. To act on a request we need that identifier: find it at [[ID_PATH]] and include it in your email. Without it, Art. 11(2) GDPR applies and we may have to tell you that we are unable to identify you — which is a consequence of collecting so little, not an excuse for keeping anything from you.

If you think we have handled your data improperly you can complain to your national supervisory authority. In [[COUNTRY]] that is [[AUTHORITY]].

09What sits on your phone, and how to wipe it.

On your device

Some things never leave your phone at all:

  • Your saved home cities, your chosen currency and whether you have seen the introduction.
  • Your last twenty searches, and the last set of results, so the app opens on something useful and can show you a result again while offline.
  • Two counters — how many searches you have run and how many destinations you have opened — which feed the usage snapshot in §03.
  • A copy of the city list, refreshed about every two weeks, so the picker works instantly and without a round trip.

Clear your search history from the History screen at any time, or delete a single entry by swiping it. Uninstalling the app removes everything in this section from the device.

10What protects it.

Security

Traffic between the app and our backend is encrypted in transit with TLS, and every request carries the session token issued at anonymous sign-in. Data on your phone sits in the operating system's app-private storage, so other apps cannot read it.

No system is perfectly secure and we cannot guarantee absolute security. What limits the damage here is how little there is to take: no names, no addresses, no card numbers, and no way to turn a row in our database back into a person.

11Age.

Children

ManyToFly is a travel planning tool for a general audience. It is not directed at children, collects no information about them, and contains nothing age-restricted — no advertising, no chat, no user-generated content and no purchases.

12How you find out if this changes.

Changes to this policy

If something material changes — a new provider, a new category of data, or the day the app starts selling something — we will update the effective date above and surface it in the app rather than quietly editing this page. The current version always lives at this address.

Questions: [[EMAIL]].