Preflair Privacy Approach
Core principle: hold as little as possible
Preflair is designed so that almost everything lives on your device, not on our servers. Where we unavoidably end up holding something — see "Authentication" — we say so plainly rather than claim more than is true.
What we do NOT collect
- Behavioral analytics that identify individual users
- Payment information (handled entirely by Paddle, our payment provider)
- Location data
- Device identifiers beyond what the platform stores
- Contact lists, photos, calendar, or any device permissions beyond what's strictly needed
- Your checklists, events, or task data — these never leave your device
What we DO end up holding
- If you sign in with Google: your email address and display name. Google
sends them as part of proving who you are. We never ask for them, never use them, and never copy them into Preflair's own records. Sign in with Apple, with Hide My Email, avoids this entirely. See "Authentication" below.
- Contact form submissions (email + message), only if you voluntarily send one.
What is stored, and where
- On user's device only (localStorage / IndexedDB):
- User's chosen name and gender (for in-app addressing)
- Profile conditions (
has_children,has_pets, etc.) collected through progressive profiling - Created events and their checklists
- Task completion state
- Visual style preference (Phase 2)
- All other usage data
- By Paddle:
- Purchase history, refund status, country, payment status
- Paddle handles the transaction. We see what Paddle shows us about orders; we never see your card details.
- Preflair is a data controller under GDPR for what we receive
- By Cloudflare (hosting for preflair.com):
- Anonymized request logs and analytics (no personal identification)
- Standard CDN operation data
Landing page (preflair.com)
The landing page is separate from the app and has its own minimal data handling:
- Contact form (via FormSpree): collects email and message when users voluntarily submit. Used only to respond to the user. Not added to mailing lists. Not shared.
- No tracking cookies are set by Preflair. No Google Analytics. No advertising pixels.
- Cloudflare anonymized analytics only (does not require cookie banner under GDPR).
- Privacy contact: preflair@preflair.com
GDPR position
- Preflair stores almost nothing server-side. Your checklists, events, and
profile stay on your device and never reach us.
- Sign-in data: if you sign in with Google, our authentication provider
(Supabase) stores your email address and display name, because Google sends them as part of the sign-in. We never ask for them and never use them. Sign in with Apple, with Hide My Email, avoids this entirely.
- Purchase data: we store an opaque account identifier, whether you paid,
when, and how much. Nothing else.
- Paddle handles payment data; Preflair receives only aggregated information
and never sees your card, billing address, or full payment details.
- The landing page contact form processes email addresses temporarily, with
clear consent (you submit it voluntarily).
You have the right to:
- Request what data Preflair holds about you. For a Google sign-in, that is
your email address, display name, account identifier, and purchase record. For an Apple sign-in with Hide My Email, it is a relay address and the same records.
- Request deletion. We will delete your account, your sign-in record, and
your purchase record. Note that deleting your purchase record means losing access to what you paid for — we will tell you this before doing it.
- Contact our privacy address: preflair@preflair.com
Accessibility statement
Preflair is built to WCAG 2.1 Level AA, satisfying:
- US: ADA, Section 508
- EU: European Accessibility Act (enforced June 28, 2025)
Accessibility features include keyboard navigation, screen reader support, sufficient color contrast, scalable text, large touch targets, and respect for prefers-reduced-motion. Issues can be reported to preflair@preflair.com.
Future changes
Any expansion of data handling (cloud sync, multi-device support, analytics) will be added here BEFORE implementation, with clear user opt-in.
Authentication and your account (Phase 2)
How you sign in
Preflair uses Sign in with Apple and Sign in with Google. There is no password and no signup form — you authenticate on Apple's or Google's servers, never on Preflair's.
Apple or Google then sends Preflair an opaque identifier: a meaningless string of letters and numbers that identifies you to Preflair and nothing else. The same identifier comes back every time you sign in, so your purchase follows you across your devices.
What Preflair sees, and what it does not
We would rather be plain about this than hide behind a technicality.
If you sign in with Google, Google passes your email address and display name to our sign-in system as part of proving who you are. We do not ask for them, we cannot switch them off, and they are stored by our authentication provider. We never use them: we do not email you, we do not build a list, we do not share or sell them, and we never copy them into Preflair's own records.
If you sign in with Apple, you can choose Hide My Email. Apple then gives us a relay address instead of your real one, and we never see your actual email at all. If you want to give us as little as possible, this is the option to take.
Preflair's own records — the part we build and control — contain only:
- Your opaque identifier
- Whether you have paid (yes / no)
- The date you paid, and the price you paid
Preflair never receives, stores, or has access to:
- Your phone number
- Your credit card or payment information
- Your billing address
- Your behavior in the app
- Your checklists (these stay on your device and never reach us)
Consequences you should understand before purchasing
These limitations follow honestly from the design. Read them before purchase.
**If you lose access to your Apple ID or Google account, you lose your Preflair purchase.** Your sign-in is your account. There is no password reset and no email-based recovery. This is a deliberate trade-off for privacy. If recovering access to a paid digital product matters to you, you may prefer apps that store your email and can reset it for you.
Your purchase is not tied to a platform. You buy once, and it is yours wherever you sign in — in the browser, and in the mobile apps if and when they exist. We hold the record of your purchase ourselves, so it is not locked to an app store.
Payment is handled by Paddle, our payment provider. Paddle is the seller of record: they take the payment, handle VAT, and issue your invoice. They see your payment details; we do not. Refunds are requested through Paddle, and your access is revoked once the refund completes.
Why we accept these trade-offs
A conventional app collects your email at signup, which solves all of the problems above: password resets, account recovery, support lookups. We do not ask for one, because everything we hold is something that can be lost, breached, or misused — and something you would have to trust us about.
We have to be honest about the limits of that. Sign in with Google hands us your email whether we want it or not. We never asked for it, we never use it, and we never copy it into our own records — but we have it, and we are not going to pretend otherwise. Sign in with Apple, with Hide My Email, avoids it entirely, and if you want to give us as little as possible, that is the option to take.
The principle is not "we hold nothing." It is: **hold as little as possible, use none of it, and say exactly what is true.**
The cost is that you, the user, bear the inconvenience when something goes wrong. We think it is the right trade-off, and we would rather tell you than let you find out.