ffly

Privacy Policy

Last updated: October 4, 2026

01Who We Are

ffly is an iPhone app that finds cheap multi-city trips. It is operated by Yauheni Malashchytski, trading as OverX AI ("we", "us"), the controller of the personal data described here. This policy covers the ffly app, the ffly API at api.overx.ai/ffly that the app talks to, the form service at api.overx.ai/forms that receives feedback from the app, and this website.

02What We Do Not Collect

  • No account. ffly has no sign-up or login, so we hold no name, phone number, password or profile. We receive an email address only if you add one to feedback you send (Section 8).
  • No location. You pick places by name. ffly does not use Location Services.
  • No advertising identifier and no tracking. ffly does not read the IDFA, does not show the App Tracking Transparency prompt because it does not track you, and contains no advertising SDKs.
  • No ads. ffly shows no advertising.
  • No payment details. Apple processes all payments. We never see your card or Apple ID credentials.
  • No sale of data. We do not sell your data or share it for advertising.

03Trip Searches Sent to Our Server

When you tap Find route, ffly sends the search to the ffly API over HTTPS:

  • the start place, the end places and the cities you want to visit (each marked "must" or "maybe"), plus the airports you chose for them;
  • the date window, the minimum and maximum nights per city, and the priority you picked;
  • a random request id, so that a retried request does not count as a new search;
  • the fact that the request comes from the iOS app.

We use this only to compute your routes. The search and its results are kept in the server's memory only, never in a database, and are deleted after at most 24 hours, or sooner when the server restarts. Each search carries your anonymous app user id (Section 4), so we treat your searches as data linked to you.

Our server checks fares on third-party airline and fare-search websites by itself. One of those sources is the Aviasales data API, provided through the Travelpayouts partner programme, which our server queries for cached fares. Your device does not contact those websites or that API while a search runs. Our server sends them only the airports and dates it is checking, never your app user id, IP address or anything else that identifies you.

04Anonymous App User ID

Each request from ffly to our server carries an anonymous app user id. It is the random, app-specific id that RevenueCat (our subscription provider, see Section 6) assigns to your installation, or a random install id if subscriptions are unavailable. It is not your Apple ID and contains no personal information.

We use it to:

  • check with RevenueCat whether you have ffly Pro, by subscription or Lifetime;
  • count the free searches you have used and apply the fair-use daily search limit for ffly Pro;
  • tell which feedback messages come from the same installation (Section 8).

The subscription status (cached for about 10 minutes) and the search counters are held in the server's memory only and are lost when the server restarts.

On its own the id does not identify you. If you add an email address to feedback, the two travel together, so we treat the app user id as data linked to you.

05IP Address

Like any internet service, our server receives the IP address your request comes from. The ffly API uses it only to apply a daily search limit to requests that arrive without an app user id. Those counters are held in memory and reset daily. We do not use your IP address to locate you or to build a profile of you. The infrastructure that hosts our servers may process it to route and protect traffic.

06Subscriptions and Purchases

ffly Pro is sold through the App Store as weekly and yearly in-app subscriptions and as a one-time Lifetime purchase. Apple processes the payment, under Apple's Privacy Policy.

We use RevenueCat, a third-party subscription platform, to verify purchases. RevenueCat receives your anonymous app user id and the App Store transaction details of your ffly Pro purchases (product, dates, status). It does not receive your name, email address or payment card. Our server asks RevenueCat only whether your app user id has active ffly Pro access. Apple and RevenueCat keep purchase records as needed for entitlement, accounting, refunds and fraud prevention. RevenueCat keeps them under your app user id, so we treat your purchase history as data linked to you. See the RevenueCat Privacy Policy.

07Anonymous Usage Analytics

ffly sends anonymous usage events to our own analytics service at analytics.overx.ai. The events are: search submitted, priority chosen, search finished, booking link tapped, paywall shown and purchase completed; onboarding started, page viewed, answered, completed or skipped; and feedback sent, and search rated or rating dismissed.

Each event carries:

  • the app version, iOS version and device model;
  • your device's language, region and time zone settings;
  • whether you are on Free or ffly Pro;
  • the identifier for vendor (IDFV, an Apple id that is unique to our apps on your device and is not the advertising identifier), a random install id and a random session id;
  • event details: the number of cities, maybe cities and end places in a search and the chosen priority; whether you changed the suggested priority; the outcome of a search and the number of routes found; the position of a route whose booking link you tapped, with its airline and fare source; the screen that opened the paywall; the purchased product; the onboarding page you viewed or finished on, and whether you set a home place (yes or no, never the place); the category of feedback you sent, whether you added an email address (yes or no, never the address), whether the message was sent or queued, and whether it was about the app or a search; and, for a search you rate (ffly Pro only), the number of stars, the search's priority, its number of routes and whether you went on to write feedback.

Analytics events never contain the names of the places you search, your travel dates, the text of your feedback, or any contact detail. They are not linked to your identity and are not used for tracking or advertising. We keep them only as long as needed to understand how the app is used, then aggregate or delete them.

08Feedback You Send

You can send us a message from Send feedback in Settings, from Tell us about this search on a search, or, with ffly Pro, after rating a search with three stars or fewer. Nothing is sent until you tap Send. A message contains:

  • the text you write and the category you pick (general, feature request or bug report), and the stars you gave if you came from rating a search;
  • the app version and build, iOS version, device model, the app's language and whether you are on Free or ffly Pro;
  • when you send it from a search: the search id, the codes of the places in the route, the date window, the priority, whether the search found routes, found none, failed or was still running, the number of routes, your plan and, if you were looking at a route, its position in the list;
  • your email address, only if you type one into the optional email field;
  • your anonymous app user id (Section 4) and a two-letter language code.

We use it only to read and answer your feedback and to fix what you report.

The message goes over HTTPS to our own form service at api.overx.ai/forms. It stores the message in its database together with the IP address and user agent of the request, and records it in its server logs. It also uses the IP address to limit how many messages can be sent per minute. It then forwards a copy to a Telegram chat that our team uses to read feedback: the text (long messages are shortened), your email address if you added one, and your app user id. Telegram processes that copy under the Telegram Privacy Policy.

Feedback is linked to you: it carries your app user id, and your email address if you added one. If you would rather not be contacted, leave the email field empty. We keep feedback as long as we need it to handle your message. You can ask us to delete it, and the email address you gave, at any time by writing to support@overx.ai.

If you are offline, the message waits on your device (up to 20 messages, for at most 7 days) and is sent the next time ffly starts and can reach our server.

09Data Stored Only on Your Device

  • Trips: up to 20 past searches, each with its request and the latest results, so you can reopen them. You can delete a trip by swiping it in the Trips list.
  • Free search counter: the number of free searches used, kept in the iOS Keychain. iOS may keep Keychain items after the app is deleted, so reinstalling does not reset it.
  • App settings: the random install id and app state such as whether onboarding is done and when the notification and rating prompts were shown, and which searches you rated or dismissed the rating for.

This data is not uploaded. Deleting the app removes it, except the Keychain counter described above.

10Notifications

ffly can notify you when a search finishes while the app is in the background. It asks for permission the first time you search. These notifications are created on your device; ffly does not register for push notifications and sends no device token to us. You can turn them off at any time in iOS Settings.

12App Store Privacy Details

  • Data used to track you: none.
  • Data linked to you: Search History (trip searches, which carry the app user id), Purchase History (ffly Pro transactions, kept by RevenueCat under the app user id), User ID (the anonymous app user id), Email Address (Contact Info), only if you add one to feedback, and Customer Support (User Content), the feedback you send.
  • Data not linked to you: Product Interaction (usage events) and Device ID (IDFV and the random install id).

14Who Receives Data

  • Apple processes App Store payments.
  • RevenueCat verifies subscriptions, as described in Section 6.
  • Our form service receives the feedback you send, and Telegram carries a copy of it to our team, as described in Section 8. See the Telegram Privacy Policy.
  • The infrastructure providers that host our servers and this website process data on our behalf.

We may also disclose information when the law requires it. We do not sell data and do not share it with advertisers or data brokers.

15Your Choices and Rights

Depending on where you live, you may have the right to access, correct, delete or port your personal data, and to object to or restrict its processing. ffly has no account and never asks your name, so unless you added your email address to feedback we usually cannot tell which records are yours. Search data on our server expires on its own within 24 hours.

  • Delete trips in the Trips list, or delete the app to remove the data on your device.
  • Turn off notifications in iOS Settings.
  • Manage or cancel a ffly Pro subscription in your Apple ID account settings.
  • Ask us to delete feedback you sent and the email address you added. Write from that address, or tell us roughly when you sent it, so we can find it.

To make a request or ask a question, email support@overx.ai. You also have the right to lodge a complaint with your local data protection authority.

16Children's Privacy

ffly is not directed to children, and we do not knowingly collect personal information from children under 13 (or the higher age set by your local law). If you believe a child has given us personal information, contact us and we will delete it.

17Security and International Transfers

All traffic between ffly and our servers is encrypted with HTTPS. Our servers may be located in a country other than yours. Where data protection law requires it, we protect such transfers with appropriate safeguards.

19This Website

This website is static. It sets no cookies, runs no analytics and loads no third-party scripts. It is hosted by Vercel, which processes the IP address and request details of each visit to deliver the page and protect the service, and keeps those logs for a short period under the Vercel Privacy Policy.

20Changes to This Policy

We may update this policy as ffly changes. We will post the new version on this page with a new effective date. If we start collecting a new kind of data, we will update this policy before the app version that collects it is released.

21Contact Us

Questions about this policy or ffly's data practices: