Data discipline
Useful signals, not your flight data.
Flytebook uses PostHog for product analytics and session replay — to understand whether core workflows work and where people get stuck — and Sentry for crash and error reporting. Collection is deliberately limited to sanitized outcomes, coarse categories, anonymous website visits, and scrubbed technical error reports.
What we collect
Page and screen names, successful or failed feature outcomes, coarse count and distance buckets, app/build version, subscription tier/status, approximate location (city, region, country, and time zone derived from your IP address at ingestion — the address itself is discarded and never stored), and session replay. Replay records only the home, privacy, plans, and planner pages (/, /privacy, /billing/plans, /plan). The home, privacy, and plans pages are recorded as shown — everyone sees the same pages and prices, and checkout error messages stay hidden. The planner stays masked: text is obscured, images and maps are blocked, and only layout and interactions are visible. Anything you type is masked on every page. While we launch, sessions on those pages are recorded rather than sampled — we will sample this down as traffic grows — and recordings shorter than 15 seconds are discarded.
What stays out
Precise coordinates (GPS or otherwise — city-level IP-derived location above is the only location signal, and latitude/longitude fields are stripped at ingestion), routes, airport or waypoint identifiers, plan names, logbook details, tail numbers, callsigns, searches, images, charts, camera feeds, account fields, and payment identifiers. Analytics never receives raw errors or stack traces — technical error reports go only to the separate crash-reporting system below.
Crash reporting
When something breaks, Sentry receives the error type and stack trace, the page path with query strings and fragments stripped, browser and OS names, the app release, and the internal account UUID — never coordinates, routes, airport identifiers, cookies, form contents, or session recordings. Crash reporting is operational telemetry: it stays on so problems get fixed, and error events are retained for 90 days.
Identity
Signed-in activity uses the internal Flytebook account UUID so app and web outcomes can be understood together. Names, email addresses, usernames, and device models are not sent as analytics properties.
Retention
Product events are retained for up to 12 months and session replays for up to 30 days; both limits are enforced as PostHog project settings. Account-linked analytics can be located for an access or deletion request using the internal account UUID.
Cookies & device storage
Analytics state lives in this browser's localStorage and in a PostHog cookie (names prefixed ph_) set for flytebook.com and its subdomains, holding a random analytics identifier — never your name or email. Clearing site data for flytebook.com in your browser removes both, and the controls below stop collection without any clearing.
Controls
Privacy & analytics
These choices apply immediately in this browser. When you are signed in, they also sync to your Flytebook account and the mobile app.
Turning product analytics off also turns replay off. Turning analytics back on leaves replay off until you enable it separately.
Analytics and replay are enabled by default. We honour supported Global Privacy Control and Do Not Track browser signals locally for analytics and replay; crash reporting is operational and not governed by these signals or the controls above. These controls do not affect operational account, security, subscription, or flight data required to provide Flytebook.