Privacy policy.
FlyCheap (the "Service", available at flycheap.live) is operated by Myron Mekhael (sole proprietor, New York, USA) and is a fare-monitoring tool that tracks flight prices on the routes you choose and notifies you when they drop. This page explains what data we collect, why, and where it goes.
What we collect
- Tracked routes you create: origin, destination, target price, date windows, and adult/infant counts. We need these to poll fares for the routes you care about.
- Account info (if you sign in): your email address. Sign-in is passwordless — we email you a one-time link or code; we never ask for or store a password.
- Alert contact details (only if you turn that channel on): a phone number for SMS alerts, a Telegram chat ID for Telegram alerts, and a push token for the mobile app. Each is stored only while that channel is enabled.
- Early-access sign-up: if you join the waitlist we keep the name, email, optional phone number and home airport you enter, a referral code, and the IP address the request came from.
- Click logs:when you click a "Book" button we record a click token, the route, your account (if you're signed in), your IP address, and browser. Only the token — never your email or account — is passed on to the affiliate partner.
- Usage analytics:as you use the site we log page views, clicks, form interactions, and roughly how you move the pointer, tied to a session ID kept in your browser, your IP address and browser, and — if you're signed in — your account. This helps us find broken flows and slow pages. We never log what you type into a password or email field.
- The AI flight-chat assistant: if you use it (web or app), your message and our reply are sent to whichever of our configured AI providers is available at that moment — currently Anthropic, Groq, Google Gemini and OpenRouter (which relays to the model provider it selects) — to generate the answer, and we keep a copy of the exchange tied to your account.
- Support requests: if you contact us (in-app or by email), we keep the message thread so we can help you and follow up.
- Marketing attribution:if you follow a link that includes a tracking marker from one of our posts, we forward that marker to the affiliate partner when you click "Book", so we can attribute a resulting booking to that post.
- Standard server logs: request paths, response codes, and timing — used to diagnose outages and improve performance.
What we do NOT collect
- Your card number or bank details. Subscription payments run through Stripe's own checkout page — we only ever see a customer/subscription ID and status, never your card. Flight bookings happen entirely on the airline or travel site you choose.
- Passport or government-ID data.
- Precise (GPS) location. We do log IP addresses (see above), which can hint at your general location, but we don't run any location lookup on them ourselves.
How we use it
- To query the flight-data providers enabled at the time — currently Travelpayouts (Aviasales) — for the routes you track. Providers receive route parameters only.
- To send you fare alerts: by Email on the Free plan, and by Email, SMS and Telegram on paid plans if you enable those channels.
- To process your subscription payment, through Stripe and PayPal.
- To attribute affiliate revenue back to the right partner and campaign.
- To power the AI flight-chat assistant, if you use it.
- To keep the service running, debug problems, and prevent abuse.
Sharing
We don't sell your personal data. We share it only with the following, and only what each needs to do its job:
- Fare-data partners (Travelpayouts — the only provider enabled right now) — we forward route parameters only, never your email or account ID.
- Affiliate networks— when you click "Book" or “Compare on”, you're sent to the partner site with a click token and, if present, an attribution marker. This lets us match any later commission payment back to your click. Current affiliate partners (see also our About page):
- Travelpayouts — the affiliate network behind Aviasales (flights), Hotellook (hotels), WayAway (cashback flights), EKTA (travel insurance) and Kiwitaxi (airport transfers).
- Trip.com Partners — flight and hotel bookings.
You pay exactly the same price as if you visited the partner site directly — commission comes from the partner's margin, not your wallet.
- AI providers — Anthropic, Groq, Google Gemini and OpenRouter (which relays to the model provider it selects) — see messages you send the flight-chat assistant. The same providers also draft some of the copy in our own marketing posts, which contains no customer data.
- Slack (internal) — when you sign up or delete your account, a short notice including your email and IP address posts to our own private team channel, so we can watch for abuse; subscription events (started, payment received or failed, cancelled) post your email and the amount. Only our team can see it.
- Infrastructure providers (Resend (email), Twilio (SMS), Telegram (bot messages), Stripe and PayPal for billing and our hosting provider) — they only see what they need to deliver that specific service.
Cookies and browser storage
fareintel_session— keeps you signed in (httpOnly, 30 days).fareintel_device— remembers your device so you can skip the sign-in code next time (httpOnly, 90 days).fc-theme— remembers your light/dark preference (1 year; also mirrored in local storage). Not personal data.fc_lang— remembers the language you picked (1 year). Not personal data.- A telemetry session ID is kept in your browser's local storage (not a cookie) so we can group your usage events together — see "Usage analytics" above.
Your rights
- Access / delete:sign in to delete individual tracked searches any time, or permanently delete your account from Settings → Danger zone. This removes your account, tracked routes, and fare history immediately, along with your sessions, settings, chat history, click logs and usage events. A few records that include your email or IP address can remain afterward — expired sign-in links and codes, support tickets you opened, an early-access waitlist entry, and server logs — email us if you'd like those erased too.
- Opt out of alert emails: every alert email has a one-click unsubscribe link.
- Contact: for any privacy question or request, email support@flycheap.live.
Children
The Service is not directed at children under 13. We don't knowingly collect data from them. If you believe a child has provided us with data, contact us and we'll delete it.
Changes
If we make material changes, we'll update the "Last updated" date at the top of this page.
Operated by Myron Mekhael, sole proprietor. Questions: support@flycheap.live.