PREFLAIR BETA

Preflair Privacy Approach

Core principle: hold as little as possible

Preflair is designed so that almost everything lives on your device, not on our servers. Where we unavoidably end up holding something — see "Authentication" — we say so plainly rather than claim more than is true.

What we do NOT collect

What we DO end up holding

sends them as part of proving who you are. We never ask for them, never use them, and never copy them into Preflair's own records. Sign in with Apple, with Hide My Email, avoids this entirely. See "Authentication" below.

What is stored, and where

Landing page (preflair.com)

The landing page is separate from the app and has its own minimal data handling:

GDPR position

profile stay on your device and never reach us.

(Supabase) stores your email address and display name, because Google sends them as part of the sign-in. We never ask for them and never use them. Sign in with Apple, with Hide My Email, avoids this entirely.

when, and how much. Nothing else.

and never sees your card, billing address, or full payment details.

clear consent (you submit it voluntarily).

You have the right to:

your email address, display name, account identifier, and purchase record. For an Apple sign-in with Hide My Email, it is a relay address and the same records.

your purchase record. Note that deleting your purchase record means losing access to what you paid for — we will tell you this before doing it.

Accessibility statement

Preflair is built to WCAG 2.1 Level AA, satisfying:

Accessibility features include keyboard navigation, screen reader support, sufficient color contrast, scalable text, large touch targets, and respect for prefers-reduced-motion. Issues can be reported to preflair@preflair.com.

Future changes

Any expansion of data handling (cloud sync, multi-device support, analytics) will be added here BEFORE implementation, with clear user opt-in.


Authentication and your account (Phase 2)

How you sign in

Preflair uses Sign in with Apple and Sign in with Google. There is no password and no signup form — you authenticate on Apple's or Google's servers, never on Preflair's.

Apple or Google then sends Preflair an opaque identifier: a meaningless string of letters and numbers that identifies you to Preflair and nothing else. The same identifier comes back every time you sign in, so your purchase follows you across your devices.

What Preflair sees, and what it does not

We would rather be plain about this than hide behind a technicality.

If you sign in with Google, Google passes your email address and display name to our sign-in system as part of proving who you are. We do not ask for them, we cannot switch them off, and they are stored by our authentication provider. We never use them: we do not email you, we do not build a list, we do not share or sell them, and we never copy them into Preflair's own records.

If you sign in with Apple, you can choose Hide My Email. Apple then gives us a relay address instead of your real one, and we never see your actual email at all. If you want to give us as little as possible, this is the option to take.

Preflair's own records — the part we build and control — contain only:

Preflair never receives, stores, or has access to:

Consequences you should understand before purchasing

These limitations follow honestly from the design. Read them before purchase.

**If you lose access to your Apple ID or Google account, you lose your Preflair purchase.** Your sign-in is your account. There is no password reset and no email-based recovery. This is a deliberate trade-off for privacy. If recovering access to a paid digital product matters to you, you may prefer apps that store your email and can reset it for you.

Your purchase is not tied to a platform. You buy once, and it is yours wherever you sign in — in the browser, and in the mobile apps if and when they exist. We hold the record of your purchase ourselves, so it is not locked to an app store.

Payment is handled by Paddle, our payment provider. Paddle is the seller of record: they take the payment, handle VAT, and issue your invoice. They see your payment details; we do not. Refunds are requested through Paddle, and your access is revoked once the refund completes.

Why we accept these trade-offs

A conventional app collects your email at signup, which solves all of the problems above: password resets, account recovery, support lookups. We do not ask for one, because everything we hold is something that can be lost, breached, or misused — and something you would have to trust us about.

We have to be honest about the limits of that. Sign in with Google hands us your email whether we want it or not. We never asked for it, we never use it, and we never copy it into our own records — but we have it, and we are not going to pretend otherwise. Sign in with Apple, with Hide My Email, avoids it entirely, and if you want to give us as little as possible, that is the option to take.

The principle is not "we hold nothing." It is: **hold as little as possible, use none of it, and say exactly what is true.**

The cost is that you, the user, bear the inconvenience when something goes wrong. We think it is the right trade-off, and we would rather tell you than let you find out.