Privacy Policy

This policy explains what personal data PreflightAI (“the Service”) processes, why, on what legal basis, who we share it with, where it goes, how long we keep it, and what rights you have. It is provided in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Italian data-protection law.

Last updated: 30 August 2026 (base notice); Training update: 6 September 2026

1.Who we are (Data controller)

The data controller for the PreflightAI service (website at preflight.bot and Telegram bot @PreflightAI_bot) is:

Francesco Lazzarotto

An individual, based in Italy.

Email: info@preflight.bot — for privacy matters and data subject requests.

We are not required to appoint a Data Protection Officer (Art. 37 GDPR does not apply), but the email above reaches the controller directly for all data-protection matters. We aim to respond to requests within one month (Art. 12(3) GDPR).

2.Overview of what we process

PreflightAI is a free, educational preflight-briefing tool. We deliberately collect very little personal data. What we process depends on how you use the Service:

  • As an anonymous website visitor — your briefing inputs are processed in memory and are not retained by PreflightAI after the response. A separate IP-address-based rate-limit counter is held in Upstash to enforce fair-use limits (see §4a). Anthropic provider retention also remains separate (see §6). Vercel Analytics and Speed Insights are disabled (see §7).
  • As a signed-in website user (Google sign-in) — we hold your basic Google profile and a rolling history of your recent briefings (see §3 and §4a).
  • As a Telegram bot user — we hold short-lived session data; if you use the roster feature, your flight schedule; and, if you choose to save one, a canonical aircraft type linked to your Telegram chat ID (see §4b).
  • If you contact us — we hold the message you send (see §5).

We do not sell or rent personal data, and we do not use it for advertising or cross-site tracking.

3.Accounts and Google sign-in

Signing in is optional. You can generate briefings on the website without an account (subject to lower rate limits). If you choose to sign in, we use Google OAuth (“Sign in with Google”).

DataSourcePurposeLegal basis
Your name, email address, and Google account identifierProvided by Google when you authorise sign-inCreate and maintain your account; store your saved briefing history; grant higher usage limits than anonymous usersArt. 6(1)(b) GDPR — performance of a contract (providing the account service you requested)

We store these in our user database as your account record (id, email, name, and account-creation date). We request only the basic Google scopes (openid, email, profile); we do not access your Gmail, Drive, contacts, or any other Google data. Google acts as an independent identity provider and processes your sign-in under Google’s own privacy policy.

4.Briefings and bot data

4a. Website briefings (preflight.bot)

When you request a briefing you provide IATA or ICAO airport codes, an aircraft type and, optionally, a UTC flight date, STD and STA, dispatch text or an uploaded file (e.g. a flight plan or NOTAM text). These are sent to our AI provider (Anthropic — see §6) to generate the briefing. Two cases apply:

You are…What happens to your inputs & the briefingRetentionLegal basis
Not signed in (anonymous)Processed in memory to generate your briefing and returned to your browser. PreflightAI does not retain the inputs or briefing after the response. Anthropic provider retention is separate; see §6.PreflightAI storage: none after the response. Anthropic provider retention: see §6.Art. 6(1)(b) — contract
Signed inThe generated briefing (departure, arrival, aircraft type, headline, briefing summary, airport data, advisories, generation and NOTAM-mirror timestamps, and normalized timing basis) is saved to your account history in our Postgres database so you can view it later. The summary field holds model-written text only when nothing was flagged; otherwise it holds text PreflightAI composes deterministically from the classification.Kept under a 20-briefing-per-user rotation: when you create a 21st briefing the oldest is automatically deleted. In practice a briefing remains until it rotates out, or until you delete it, or until your account is closed.Art. 6(1)(b) — contract

Signed-in users can view and delete individual saved briefings at any time from the account area. For deletion of your whole history or account, see §9.

Note: the raw dispatch text or file you upload for a briefing is used only to generate that briefing and is not stored in the saved-briefing record; only the resulting structured briefing is stored (for signed-in users).

Rate-limit dataStoragePurposeRetentionLegal basis
Anonymous visitor: IP address. Signed-in user: account ID.Upstash RedisApply anti-abuse and fair-use limits so the free service remains availableDaily counter: up to 24 hours. Weekly counter: up to 7 days.Art. 6(1)(f) GDPR — legitimate interest in preventing abuse, enforcing fair use and keeping the Service available

4b. Telegram bot (@PreflightAI_bot)

DataPurposeRetentionLegal basis
Your Telegram chat ID (a pseudonymous numeric identifier)Rate limiting / abuse prevention (fair-use counters)Rate-limit counters are retained for up to 14 daysArt. 6(1)(f) — legitimate interest in preventing abuse and keeping the free service available
Pending Telegram package uploads (PDF/images/CSV file references, captions and pasted text)Collected to extract a dispatch or Training package; downloaded bytes are held in operation memory only and are not retained by PreflightAIPending references/text: ~1 hour (auto-expiry), then deletedArt. 6(1)(b) — contract
Active General, Flight, Training or explicitly selected Duty context linked to your Telegram chat ID. An Active Flight context can include the structured briefing and metadata, extracted dispatch text — for a text-readable package this is a verbatim selection of the passages the extraction judged relevant to a weather/NOTAM briefing, taken from your own document rather than rewritten — added notes, bounded Q&A history, source health and selected reference transcriptions. Training holds scenario text, route, activation reason (including a source-label excerpt or chosen source date where applicable), selected reference transcriptions and bounded Q&A history.Answer aviation questions from the active context and selected reference excerptsRedis retention: two hours from activation, renewed after each successfully committed Q&A turn or accepted reference; earlier when you send /newflight or replace the context. Reads, failures and rejected inputs do not renew it.Art. 6(1)(b) GDPR — necessary to provide the requested assistant service
One-shot Training selection linked to your Telegram chat IDTreat the next package attempt as an explicitly requested scenarioUpstash Redis: 10 minutes, consumed by the next package attempt; reset or context switch clears it. Reads do not renew it.Art. 6(1)(b) GDPR — necessary to provide the requested Training selection
Pending Training/Live choice: bounded extracted package content, creation time, conversation version and token hash linked to your Telegram chat ID; no raw file bytes or Telegram file IDsLet you choose how to use a date-anomaly package without extracting it againUpstash Redis: one hour from creation; reads do not renew it. Single-use; reset, context switch or a new package invalidates it.Art. 6(1)(b) GDPR — necessary to provide the requested package choice
Bound Duty selection record and structured snapshotLet the owner activate the exact duty from its latest pre-brief button or a direct reply to that bot message36 hours after issue. Reads do not renew the period; expired or replaced selectors are unavailable.Art. 6(1)(b) GDPR — necessary to provide the requested Duty selection
Flight schedule you upload via /roster (dates, IATA or ICAO routes, times) linked to your chat IDSend you the daily evening weather digest for upcoming flights (18:00 UTC)60 days (auto-expiry), or immediately when you send /clearrosterArt. 6(1)(b) — contract, at your explicit request
Optional canonical aircraft type linked to your Telegram chat IDUse the saved default in two limited ways: when a user-initiated uploaded briefing package has a missing or blank aircraft type, it is supplied to the existing Anthropic briefing pipeline and copied into the two-hour active-flight context for later Anthropic Q&A; and when a scheduled duty digest reads it without renewing retention, only for deterministic NOTAM assessment and Telegram formatting, outside the digest AI-copy input. An explicit package value remains authoritative.365 days after you explicitly save or replace it, or after a qualifying user-initiated uploaded-package briefing actually uses it as fallback; earlier if you send /clearaircraftArt. 6(1)(b) GDPR — necessary to provide the optional profile-based service you request
Daily-digest delivery metadata (chat ID, canonical 18:00 UTC window, pending/claim state, enrollment cursor and short owner leases — no message or roster content)Resume bounded digest batches after an interruption while preventing duplicate AI calls and Telegram delivery attemptsPending backlog/enrollment metadata: max 7 days from its digest window. Terminal duplicate-suppression claim: max 8 days from its digest window. Execution/continuation leases expire within minutes.Art. 6(1)(f) — legitimate interest in service reliability, cost control and preventing duplicate operational messages
Sanitized runtime event logs (fixed operation/error codes and basic request diagnostics; no roster, uploaded-file content, Redis command values or Telegram chat IDs intentionally logged)Security monitoring, fault diagnosis and service reliability1 hour on the Service's current Vercel Hobby plan; no external log drain is configuredArt. 6(1)(f) — legitimate interest in securing and maintaining the Service

Training is scenario-only, with no live weather or NOTAM mixing. Treating scenario values as fictional does not mean uploads contain no personal or confidential data. Choose New conversation (/newflight) to clear the active context, pending mode and choice; your roster and saved aircraft profile remain. Local expiry or reset does not delete messages already held by Telegram or end Anthropic provider retention (§6).

Use /aircraft to replace the profile, /clearaircraft to delete it, or the controller email in §1 for a formal request.

Redis keeps bounded reference transcriptions and context for two hours after the last successfully committed Q&A turn or accepted reference. Bot session, selector and digest state described above is held in Redis with automatic time-to-live expiry, so it is deleted at the end of its TTL even if you take no action. A legacy roster-subscriber index used by an earlier version is placed under a non-renewing seven-day deletion deadline when migration begins. Runtime event logs are held separately by the hosting provider for the short period stated in the table. This optional profile is ordinary personal data, not special-category data. It is stored in the same Upstash Redis recipient already listed in §6. These profile uses add no provider, and the saved type is not used to train AI models. For scheduled daily digests, a saved profile is read without renewing its retention period and is used only for deterministic NOTAM assessment and Telegram formatting; it is never included in the AI input used by generateDutyPrebriefCopy() to produce the duty-prebrief copy. The 365-day period is a product retention choice, not a legal retention requirement. /clearaircraft deletes the dedicated stored profile and any pending guided mode. It does not recall Telegram messages already delivered to your chat. If the type was already copied into an active-flight context, it may remain available to Q&A until you send /newflight or the normal two-hour expiry ends. The rate-limit counters contain only the numeric chat ID and a date — no message content. Daily-digest reliability metadata likewise contains no uploaded file, roster row, weather result or generated message. To avoid duplicate paid calls or ambiguous duplicate messages, a digest may be omitted after a hard server interruption once its durable claim has been acquired. Uploaded files may contain other people’s personal data (e.g. crew names on a roster). Please read §8 before uploading.

4c. “Flag a problem” feedback

Web feedback reporting is currently paused. The public web endpoint does not accept or store new web reports while paused. The website action is hidden, and the Telegram bot currently exposes no public feedback action either. If this feature is re-enabled, this notice will be updated before new reports are accepted.

Historical reports were deliberately submitted before the pause through the optional, user-initiated “Flag a problem” action. They may still contain the following data until reviewed or deleted on request:

DataPurposeRecipientRetentionLegal basis
Historical flagged briefing/roster input and AI output, account ID (if signed in) or Telegram chat ID (if flagged via the bot), and the short-lived anti-abuse rate-limit record used when the report was submittedReview the deliberately submitted report, investigate the reported quality/safety issue and use that feedback for product improvementA short excerpt (e.g. the briefing headline) is also sent to the controller's personal Telegram account as a notification — see the Telegram row in §6 for that transportKept until reviewed; you may request deletion of your flagged reports at any time (see §9)Art. 6(1)(f) — legitimate interest in identifying and fixing incorrect or unsafe AI output, given this is an optional action you take yourself

This historical, deliberately submitted feedback is separate from ordinary use of the Service. Ordinary briefing, chat, dispatch and reference content — including the bounded active context used for follow-up questions — is not automatically or contextually reused for product improvement; see §6.

5.Email contact

If you email us, we process only the details you choose to include in that correspondence. The website itself does not receive or store your message.

DataPurposeRecipientRetentionLegal basis
Your email address, any name shown by your email account, and the message content you choose to sendReceive and reply to your enquiryForwarded by ImprovMX to the controller's private Gmail inbox; the destination address is not publishedOnly while needed to handle the enquiry and reasonable follow-up; ordinarily no longer than 12 months unless an ongoing exchange or legal obligation requires longer retentionArt. 6(1)(f) — legitimate interest in handling and responding to enquiries

Please do not send unnecessary personal data, company-confidential material, or operational briefing packages by email.

6.Recipients, sub-processors and international transfers

To run the Service we use the following providers. Those marked as processors act on our documented instructions under Article 28 GDPR data-processing agreements. Several are located outside the EEA; the applicable transfer safeguard (Art. 44–49 GDPR) is shown.

ProviderRoleWhat they processCountryTransfer safeguard
Anthropic, Inc.Processor (Art. 28)AI generation of briefings, dispatch/roster and scenario extraction, reference transcription, and Q&A including Training Q&A — receives your inputs, relevant context and uploaded files. Where we can read an uploaded operational PDF ourselves, its extracted text is sent in place of the file; scans, images and reference files are still sent as files.USEU–US Data Privacy Framework (DPF) + Standard Contractual Clauses (SCCs)
Vercel, Inc.Processor (Art. 28)Website hosting and serverless functions. Optional Vercel Analytics and Speed Insights client components are disabled and not loaded.USEU–US Data Privacy Framework (DPF) + SCCs
Upstash, Inc.Processor (Art. 28)Redis storage for bot sessions, roster, optional aircraft profiles, and website and bot rate-limit countersUSStandard Contractual Clauses (SCCs)
Neon, Inc.Processor (Art. 28)Managed PostgreSQL database storing user accounts and saved briefingsUSStandard Contractual Clauses (SCCs) (incorporated in Neon's Data Processing Agreement)
Google LLCIndependent controller / identity providerGoogle sign-in (name, email, Google account ID)USEU–US Data Privacy Framework (DPF); Google processes under its own privacy policy
ImprovMX IncorporatedEmail forwarding provider — processor contract status for the free account remains a launch checkSender address, routing metadata and email content sent to info@preflight.botUS; the provider states that processing may also occur in EuropeImprovMX reports following the EU–US Data Privacy Framework Principles but states that it is not certified under the Framework. Article 28 terms and an applicable Chapter V transfer mechanism, including whether Standard Contractual Clauses are available for the free account, remain unconfirmed before broad public launch.
Google (Gmail)Email inbox serviceContact correspondence forwarded to the controller's private inboxIreland / global infrastructureFor EEA users Google states that consumer services are provided by Google Ireland Limited; Google publishes international transfer frameworks including the EU–US Data Privacy Framework.
Telegram MessengerIndependent third-party controllerMessage transport between you and the botUAE (no EU adequacy decision)No EU adequacy decision applies. If you choose to use the Telegram bot, your messages are transmitted through Telegram's platform under Telegram's own privacy policy, over which we have no control. Telegram is not our Art. 28 sub-processor; it is a separate controller for the transport of your messages.
aviationweather.gov (NOAA/FAA)Public data sourceMETAR/TAF weather dataUSNo personal data is transmitted
OurAirports (public dataset)Public data sourceAirport/runway/frequency reference data—No personal data is transmitted

Anthropic provider processing and retention are separate from PreflightAI’s operation-memory and Redis deletion. For the standard commercial API currently used, Anthropic says API inputs and outputs are normally deleted within 30 days. Different contractual or service settings, Usage Policy and safety enforcement needs, or law can change or extend that period. Local deletion therefore does not state that provider-held data is deleted at the same moment.

Anthropic says commercial API inputs and outputs are not used for model training by default unless there is an explicit opt-in, the customer submits feedback, or use is otherwise agreed. PreflightAI does not use ordinary service content, including Training scenarios, for model training, product improvement or persistent learning, and does not automatically reuse chat, dispatch or reference content for those purposes. Historical, deliberately submitted feedback through the optional “Flag a problem” action is separate and may be reviewed for product improvement as described in §4c. The only bounded contextual reuse of ordinary retained chat, dispatch and reference content is to answer requested follow-up questions during the active two-hour context described in §4b; that active-context reuse is not product-improvement reuse.

Official Anthropic explanations: commercial data retention and model training. Sources checked 30 August 2026.

We do not otherwise disclose your personal data to third parties, and we never sell or share it for advertising. A note on US transfers: the EU–US Data Privacy Framework is currently valid but is subject to legal challenge. Transfer safeguards are stated provider by provider in the table; we do not assert an SCC fallback for ImprovMX while its free-account terms and Chapter V mechanism remain unconfirmed. You may contact us for more information on the safeguards in place.

7.Analytics and performance — disabled

Vercel Analytics and Vercel Speed Insights are disabled for this beta. Their client components and collection scripts are not loaded, and PreflightAI does not collect product-usage or performance analytics through those tools.

This does not affect the separate hosting runtime logs or the limited anti-abuse and fair-use counters described in §§4a and 6. Those operational records are not product analytics and follow the purposes, legal bases and retention periods stated there. If optional analytics are introduced later, this notice and any required consent controls will be updated before collection begins.

8.Your responsibilities when uploading documents

Dispatch packages, flight plans and crew rosters can contain other people’s personal data (for example, the names of other crew members, or passenger details).

  • Please do not upload personal data about other people unless you have a lawful reason to do so.
  • Redact or remove crew names, passenger names and any other personal details from documents before uploading them.
  • Uploaded files are sent to our AI provider (Anthropic, US) purely to generate your briefing/roster extraction, are processed transiently, and are not retained in your saved history. Where we can read an operational PDF ourselves, we send its extracted text instead of the file; a scan or image, which we cannot read, is still sent as a file. Provider processing and retention remain separate as described in §6.

The uploader must be authorised to submit third-party personal data and must ensure that the relevant controller has a lawful basis for the processing. Which party has the controller role depends on the circumstances; it is not assigned to the uploader categorically by this policy.

9.Your rights

Under Articles 15–22 GDPR you have the right to:

  • Access (Art. 15) — obtain a copy of the personal data we hold about you;
  • Rectification (Art. 16) — correct inaccurate data;
  • Erasure (Art. 17) — have your data deleted;
  • Restriction (Art. 18) — restrict processing in certain cases;
  • Object (Art. 21) — object to processing based on legitimate interests (§4a and §4b anti-abuse rate limiting, §4b digest reliability and runtime logs, §4c deliberately submitted historical feedback, and §5 contact);
  • Portability (Art. 20) — receive data you provided in a structured, machine-readable format, where processing is by automated means and based on consent or contract.

How to exercise them:

  • Bot data: send /clearaircraft to delete your optional aircraft profile and pending guided entry, and send /clearroster to delete your roster immediately. These commands cannot recall messages already delivered; aircraft data already copied into an active-flight context remains until you send /newflight or its normal two-hour expiry. Other session/pending-file data self-deletes within ~1–2 hours.
  • Saved briefings (signed-in users): delete individual briefings yourself from the account area at any time.
  • Full account deletion / any other request: email info@preflight.bot. Account deletion is currently performed manually by the controller on request — deleting your user record also cascades to (removes) your saved briefings. We will action verified requests within one month (Art. 12(3)).

Right to complain. If you believe your data has been handled unlawfully, you may lodge a complaint with the Italian supervisory authority:

Garante per la protezione dei dati personali

Piazza Venezia 11, 00187 Roma, Italy

Web: www.garanteprivacy.it

You may also complain to the supervisory authority in your own EU/EEA country of residence.

10.Children

The Service is intended for pilots, student pilots and aviation professionals and is not directed at children. In Italy, the age at which a child can consent to information-society services on their own is 14 (art. 2-quinquies of the Codice Privacy, under the derogation permitted by Art. 8 GDPR). We do not knowingly collect personal data from anyone below that age; if you believe a child has provided us data, contact info@preflight.bot and we will delete it.

11.Security

We apply appropriate technical and organisational measures (Art. 32 GDPR), including:

  • TLS/HTTPS encryption of all data in transit;
  • Encryption at rest by our storage providers (Redis, Postgres);
  • Automatic expiry (TTL) of short-lived bot data;
  • Access restricted to the controller; secrets held as environment variables, not in code;
  • Least-data design — we collect the minimum needed for each purpose (Art. 5(1)(c)).

12.Changes to this policy

We may update this policy to reflect changes in our processing or the law. The “Last updated” date at the top always reflects the current version; material changes will be signalled on the website and/or via the bot.

13.Aviation disclaimer

This policy covers data protection only. For the educational-use disclaimer, pilot responsibilities, AI-content limitations and liability terms, see the separate Disclaimer.