flypoints Privacy Policy
flypoints (“flypoints”, “we”, “us”) is an AI travel
concierge. You describe a trip in chat; we search cash and award (points/miles) flight
availability and reply with options and booking links. This policy explains what personal
information the flypoints Android app (ca.flypoints) and the flypoints website
(app.flypoints.ca) collect, why, who it goes to, how long we keep it, and the
rights you have over it.
flypoints is offered only in Canada and the United States.
Data controller: FlyAI Inc., 37 Richard Way SW, Suite 200, Calgary, AB T3E 7M8, Canada
Contact: info@flypoints.ca
1. Information we collect
1.1 Account information (from Sign in with Google)
flypoints has no password of its own. You sign in with Google. Google’s Credential Manager returns a signed ID token to the app; we verify it and read the following claims:
- Email address
- Display name
- Profile picture URL
- Google account identifier (the OpenID
subclaim — a stable, opaque id)
We store all four in our database, together with the date your account was created and the timestamp of your most recent sign-in.
We do not receive or store your Google password, and we request no Google API scopes beyond
basic sign-in identity (openid, email, profile).
1.2 Conversation content
flypoints is a chat product, so the conversation is the service.
- Your messages — everything you type into the chat.
- The concierge’s replies, including the flight results it shows you.
- System messages the app generates on your behalf — for example, the greeting that opens a conversation, and a note recorded when you open the detail card for a particular flight.
- The concierge’s internal steps for your request — the flight searches it runs (origin, destination, date range, cabin class, passenger count) and any web searches it performs to answer travel questions.
- A running summary of your conversation. When a conversation grows long, the AI model condenses the earlier part into a summary so it can keep answering with context. That summary is stored on your account.
All of the above is stored on our servers and associated with your account, so your history is there when you come back.
1.3 Usage and safety records
- Message timestamps, kept to enforce a daily message limit.
- Abuse counters — a per-account counter incremented when a message trips our prompt-abuse guardrails.
- Content reports you file about a concierge reply, including the reason you select and the reply you reported.
- IP address — used transiently to rate-limit sign-in attempts. We do not store IP addresses in your account record. An IP address appears in our server logs when a sign-in is rate-limited.
1.4 Information stored on your device
- Your session token, in encrypted app storage (Android Keystore-backed
EncryptedSharedPreferences). - A random identifier generated on first launch. It is generated locally and is used only by a development-only sign-in path that is disabled on our production servers. It is not transmitted in normal use of the released app.
1.5 What we do not collect
The flypoints Android app requests only the INTERNET permission. It contains no
advertising SDK, no analytics SDK, and no crash-reporting SDK. We do not collect location,
contacts, photos, files, the microphone, the camera, calendar, health data, SMS, call logs,
installed-app lists, or the Android Advertising ID. We do not build advertising profiles, and
we do not sell or share personal information as those terms are defined under California
law.
2. Why we use your information
| Purpose | Information used |
|---|---|
| Create and authenticate your account | Email, name, profile picture, Google account id |
| Keep you signed in between visits | Session token |
| Run the concierge and answer your requests | Conversation content, flight/web search terms |
| Show you your conversation history | Conversation content |
| Personalise the concierge to the trip you’re planning | Conversation content, conversation summary |
| Enforce fair-use limits and prevent abuse | Message timestamps, abuse counters, IP address (sign-in only) |
| Review reports of inappropriate AI replies | Content reports, the reported reply |
| Diagnose faults and keep the service running | Server logs |
We do not use your personal information for advertising or for profiling that produces legal or similarly significant effects.
3. Legal basis and consent
flypoints is offered in Canada and the United States.
Under Canadian privacy law (PIPEDA, and Quebec’s Law 25 where applicable), your use of flypoints after being presented with this policy constitutes meaningful consent to the collection, use, and disclosure described here. You may withdraw consent at any time by deleting your account (section 7).
We collect only what is needed to provide the service you asked for — account creation, authentication, running the concierge, and storing your history — and to keep the service safe and reliable through abuse prevention, rate limiting, and security logging.
Because the concierge is an AI system, please do not type payment card numbers, passport or government ID numbers, health information, or other sensitive personal information into the chat. flypoints does not need it and does not ask for it.
4. Who we share information with
We do not sell personal information and we do not share it with advertisers. We do disclose information to the following service providers (“subprocessors”), strictly to operate flypoints:
4.1 AI model provider
The conversation — your messages, the concierge’s replies, the conversation summary, and the concierge’s internal tool calls — is transmitted to OpenAI, which generates the concierge’s responses using the GPT-4o model. Your name, email address, and Google account id are not included in what we send.
Under OpenAI’s API terms, data submitted through the API is not used to train their models, and is retained for up to 30 days for abuse monitoring before deletion. OpenAI acts as our service provider and may not use your conversation for its own purposes.
4.2 Flight and travel data providers
To answer a search we send the route, dates, cabin class, and passenger count — and nothing that identifies you — to:
- Skyscanner (accessed via RapidAPI) — cash fares and booking deep links
- Seats.aero — award (points/miles) availability
- PointsYeah — award availability and points-purchase links
4.3 Web search provider
When you ask a general travel question (visa rules, baggage policy, transit requirements), the concierge issues a search query to Brave Search. That query is derived from your question and may therefore contain text you wrote. It is sent without your name, email, or account id.
4.4 Identity provider
Google operates Sign in with Google. Google’s own handling of your sign-in is governed by the Google Privacy Policy.
4.5 Hosting
flypoints runs on Amazon Web Services in the AWS us-west-2 region
(Oregon, United States). Our database, application servers, and logs are hosted there.
4.6 Booking links
Selecting a flight opens a booking link in your device’s browser, on a website operated by an airline or online travel agency. Those sites are outside our control and have their own privacy policies. flypoints does not transmit your account information to them.
4.7 Legal disclosure
We may disclose information where required by law, court order, or lawful request by a public authority, and to establish or defend legal claims.
5. Cross-border transfers
Your information is stored and processed in the United States (AWS
us-west-2, Oregon), and our subprocessors may process it in other countries.
If you are in Canada, this means your information is transferred outside Canada and, while it is there, may be accessible to United States courts and law-enforcement authorities under the laws of that country. By using flypoints you consent to that transfer. We remain accountable for your information when it is handled by a subprocessor on our behalf, and we require each of them by contract to protect it to a comparable standard.
6. How long we keep information
| Data | Retention |
|---|---|
| Account record (email, name, picture URL, Google account id) | Kept for as long as your account exists |
| Conversation history and conversation summary | Kept for as long as your account exists |
| Message timestamps used for the daily limit | Kept for as long as your account exists |
| Content reports | Kept for as long as your account exists |
| Conversation data held by OpenAI | Up to 30 days, for abuse monitoring, then deleted |
| Flight search results | Held temporarily in memory/cache and discarded within one hour |
| Session token | Expires 30 days after sign-in |
| Server logs | 14 days, after which they are deleted automatically |
Deleting your account removes your account record, your conversation history, your usage timestamps, and your content reports (section 7).
7. Your rights and choices
Subject to applicable law, you may:
- Access the personal information we hold about you;
- Correct inaccurate information (your name, email, and profile picture are refreshed from Google each time you sign in);
- Delete your account and your conversation history;
- Withdraw consent, by deleting your account;
- Complain to your data-protection authority (in Canada, the Office of the Privacy Commissioner of Canada, or the Commission d’accès à l’information du Québec for Quebec residents).
If you are a California resident, you may also request disclosure of the categories of personal information we have collected about you, request its deletion, and not be discriminated against for exercising those rights. We do not sell or share personal information, so there is nothing to opt out of.
Signing out clears the session token from your device. It does not delete your data.
Account deletion
You can delete your account in two ways:
- In the app — open the account screen and choose Delete account.
- On the web — visit https://app.flypoints.ca/delete-account.html and follow the instructions there.
Deletion is immediate and irreversible. There is no recovery window and no delayed second phase: by the time your request returns, we have
- invalidated every session token ever issued to your account, so you are signed out everywhere;
- ended any live conversation session and closed its connection;
- purged your cached conversation state and flight working set; and
- erased your rows from our database — your account record, chat history, conversation summary, saved flights, usage timestamps, content reports, abuse counters, and guardrail records.
Nothing about your account is retained afterwards except entries in our server logs, which are deleted automatically within 14 days.
To exercise any other right, contact us at the address in section 12. We respond within 30 days.
8. Security
- All traffic between the app and our servers uses HTTPS. The Android release build refuses to start against a non-HTTPS endpoint and permits no cleartext traffic.
- The app is excluded from Android cloud backup and device-to-device transfer, so your session token never leaves your device.
- Your session token is held in encrypted storage on your device, protected by the Android Keystore.
- Session tokens are cryptographically signed and expire after 30 days.
- Sign-in attempts are rate-limited per IP address.
- Access to production data is restricted to authorised flypoints personnel. Our internal support console can display a user’s conversation history when investigating a support case.
No system is perfectly secure. We cannot guarantee absolute security of information transmitted to or stored by us.
9. Children
flypoints is not directed to children. It is intended for users aged 18 and older. We do not knowingly collect personal information from children. If we learn that we have, we will delete it. A parent or guardian who believes we hold a child’s information should contact us at the address in section 12.
10. Automated decision-making and AI-generated content
The concierge is an AI system: its replies, its flight recommendations, and its ranking of results are generated automatically. These outputs are informational. flypoints does not make automated decisions that produce legal effects or similarly significant effects concerning you.
AI-generated replies can be wrong. Availability, fares, and award pricing come from third-party sources and may be inaccurate or out of date; confirm details with the airline or booking site before purchasing.
If a reply is offensive, misleading, or otherwise inappropriate, you can report it from inside the app by pressing and holding the message and choosing Report this reply. We review every report.
11. Changes to this policy
We will post any change on this page and update the effective date. Material changes will be communicated in the app before they take effect.
12. Contact
info@flypoints.ca
FlyAI Inc.
37 Richard Way SW, Suite 200
Calgary, AB T3E 7M8
Canada