Privacy Policy
Last updated July 30, 2026
This describes what Flagger (“we”, “us”) collects when you use the app, why, and how to see, limit, or remove it. Flagger is a small, actively-developed product, so this policy will keep being updated as the product changes, and we'll update the date above when it does.
What we collect
- Account details. Name, email address, and password (stored hashed, never in plain text).
- Forwarded email content. The subject, sender, date, and body of any email you forward to your Flagger address, plus the attachments it arrives with.
- Itinerary data. Trips, stays, transport, and dates, either extracted from forwarded email or entered by you directly.
- Basic usage data. Aggregate, anonymised page-view analytics (via Vercel Analytics), no cookies, no cross-site tracking, no ad identifiers.
What we don't collect
We don't run advertising, we don't use third-party ad or tracking pixels, and we don't sell or share your data with data brokers. There is no ad network on this site.
How forwarded email is used
When you forward a booking confirmation, its content is sent to an AI model (currently Anthropic's Claude) to decide whether it's a real booking and, if so, pull out the details, dates, place, price, confirmation code. That happens automatically by default; you can turn it off entirely in Preferences, in which case forwarded email is only read when you choose to process it. You can also restrict which sender addresses are allowed to reach your account. Mail from anyone else is held, not silently dropped, until you approve it.
Raw email content is kept only as long as it's useful: if a forwarded email didn't produce anything added to your itinerary, its stored body is deleted after 60 days. If it did, we keep the original alongside the itinerary entry it created, so you can always see what produced it.
Who else sees it
A few infrastructure providers process data on our behalf, under their own security and confidentiality terms, to run the app:
- Xano. Our database and backend API.
- Anthropic. Processes forwarded email content to extract bookings, as described above.
- Cloudflare. Routes forwarded email to our systems.
- Netlify. Hosts the web app.
- Vercel Analytics. Anonymous, aggregate usage analytics.
None of them are permitted to use your data for their own purposes.
Your controls
- Turn off automatic processing. Preferences → Email. Forwarded mail then waits for you to review it.
- Restrict senders. Preferences → Email. Only addresses you've approved are processed automatically.
- Delete an email or booking. Remove any forwarded email or itinerary entry from within the app at any time.
- Delete your account. Email hello@flagger.world and we’ll remove your account and associated data.
Children
Flagger isn't directed at children, and we don't knowingly collect data from anyone under 16.
Changes
If this policy changes in a way that matters, we'll update the date at the top of this page.
Contact
Questions, data requests, or anything else: hello@flagger.world.