Last updated: 3 October 2026
The short version: if you create a free account, FlyWell keeps your email address, an irreversible hash of your password and the date the account was created. Nothing else is attached to your account. There are no analytics, no advertising and no tracking, and the site loads nothing from other domains. You can delete your account yourself at any time.
FlyWell is offered to the public as a free beta. Its owner is established outside the European Union. The personal data it handles is handled to the standard of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), and anyone may exercise the rights in section 7 wherever they live.
No data protection officer has been appointed. Privacy questions are answered at the contact address above.
When you visit. Your IP address and the technical details a browser sends with every request, such as its type and the time of the request. The hosting platform needs them to deliver the page and may keep them for a time in its own technical logs. The application itself does not write IP addresses to its database or its logs, and does not write email addresses to its logs.
When you create an account. Your email address, your password and the moment the account is created. The password is stored only as an irreversible argon2id hash; the password itself is neither stored nor logged. Email addresses are not verified, and FlyWell never sends email to them — it has no system for sending email. The address is simply the name you sign in with.
When you sign in, create an account or delete one. These attempts are limited per IP address (five sign-ins every fifteen minutes, five sign-ups every hour) to stop password guessing and automated sign-ups. To count them, the address is held in the server's memory. It is never written to disk and it is gone when the server next restarts. The sign-up form also contains a hidden field that people do not see and automated programs tend to fill in; a sign-up that fills it in is not created.
While you are signed in. A session cookie that holds a signed timestamp, whether the session is a free account or the operator's, and, for an account, its internal identifier (see the Cookies policy). On each request the server checks that the account still exists. The application keeps no record of which pages or deals you look at.
When you play the airport game. Nothing leaves your browser. Your best score is saved in your browser's own storage so the game can show it next time.
When you write to us. Your email address and whatever you choose to tell us, used only to answer you.
There are no analytics, advertising or tracking tools on this site. It loads nothing from third-party domains. We do not buy data, we do not build profiles and we do not send marketing.
| Purpose | Legal basis |
|---|---|
| Creating your free account, signing you in, keeping you signed in and showing you the deals | Performance of the contract you enter into by accepting the Terms of use (GDPR art. 6(1)(b)) |
| Delivering the pages you ask for and keeping the site secure, including the limits on sign-in and sign-up attempts and the check against automated sign-ups | Legitimate interest in running and protecting the site (GDPR art. 6(1)(f)) |
| Answering your messages | Legitimate interest in replying to people who write to us (GDPR art. 6(1)(f)) |
| Handling a request to exercise your data-protection rights | Legal obligation (GDPR art. 6(1)(c)) |
No decision that has legal or similarly significant effects on you is taken by automated means (GDPR art. 22): the scores FlyWell computes are about fares, not about people. You do not have to provide any data to visit the site or to play the game; an email address and a password are needed only to create an account.
We do not sell or share personal data. The site and its database run on the hosting platform Zeabur, on a server located in Frankfurt (Germany). As the host, it necessarily stores and processes the data described above. No other company receives it: there is no email provider, no analytics provider and no payment provider.
The tool's own work never involves your data. The fare lookups it makes on its schedule carry only a route, dates and a cabin, never anything about an account, and no account can start one. The alerts it sends to its operator carry only flights and prices.
Data may also be disclosed to public authorities and courts where the law requires it.
The server is in the European Union. The owner is established in the United States and administers the site remotely, so the data described above may be accessed from outside the European Economic Area when that is needed to maintain the site or to answer a request. You can ask us for more information at the contact address.
You may ask at any time for access to your personal data, for its rectification or erasure, for the restriction of its processing or for its portability, and you may object to processing based on legitimate interest. You can erase your account yourself, at any time, from the Account page. For anything else, write to hola@biglobster.top saying which right you wish to exercise.
Because email addresses are not verified, we may need to check that a request about an account comes from the person who holds it before acting on it. For data that is not tied to an account, such as an IP address, we may need something from you to find it, such as the approximate time of your visit.
If you are in Thailand, you also have the rights the Personal Data Protection Act B.E. 2562 (2019) gives you, including access, correction, deletion, portability, objection and the withdrawal of any consent you gave, and you may complain to the Office of the Personal Data Protection Committee.
We answer within one month. If you believe your request was not handled properly, you can complain to the data-protection authority of the country where you live; in Spain, the Agencia Española de Protección de Datos (www.aepd.es).
Measures are proportionate to the risk: connections are encrypted; passwords are stored only as irreversible argon2id hashes; sign-in and sign-up attempts are limited; the session cookie cannot be read by scripts or sent from another site; and every response carries security headers that stop the browser from loading anything from elsewhere. If a breach posed a risk to your rights, we would notify the competent authority and, where required, you, within the legal deadlines. Because we hold no verified contact address for you, we would do so by a notice on this site.
Accounts are for people aged 18 or over, and the sign-up form asks you to confirm it. The site is not directed at children and knowingly collects no data about them. If you believe a child has created an account, write to us and we will delete it. The game asks for no information from anyone.
If this policy changes, the new version is published on this page with its date at the top.