Cookie Policy
Effective Date: January 1, 2025 | Last Updated: January 1, 2025
This Cookie Policy explains how AppFlight (https://appflight.ai) uses cookies and similar tracking technologies on our website. This policy should be read in conjunction with our Privacy Policy.
1. What Are Cookies?
Cookies are small text files that are placed on your device (computer, smartphone, or tablet) when you visit a website. Cookies are widely used to make websites work more efficiently and provide information to website owners.
Cookies can be "session cookies" (temporary, deleted when you close your browser) or "persistent cookies" (remain on your device until they expire or you delete them).
2. How We Use Cookies
AppFlight uses cookies for two primary purposes:
- Essential functionality: To provide core features like authentication, security, and session management
- Analytics and improvement: With your consent, to understand how users interact with our service and improve the user experience
3. Types of Cookies We Use
3.1 Essential Cookies (No Consent Required)
These cookies are strictly necessary to provide our service and cannot be disabled. Under GDPR and ePrivacy Directive, these cookies do not require consent as they are essential for the service to function.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
authjs.session-token | Authentication session management. Required to keep you logged in. | 30 days | NextAuth.js (First-party) |
authjs.csrf-token | Cross-Site Request Forgery (CSRF) protection. Required for security. | Session | NextAuth.js (First-party) |
authjs.callback-url | OAuth redirect handling. Required for third-party authentication flow. | Session | NextAuth.js (First-party) |
__cf_bm | Cloudflare bot management. Required for security and DDoS protection. | 30 minutes | Cloudflare (Third-party) |
3.2 Analytics Cookies (Consent Required)
These cookies help us understand how visitors interact with our website. We only use these cookies with your explicit opt-in consent, in compliance with GDPR and ePrivacy Directive.
| Cookie Name | Purpose | Duration | Provider |
|---|---|---|---|
ph_*_posthog | PostHog analytics: tracks page views, clicks, user interactions, and session recordings to improve UX. | 365 days | PostHog EU (Third-party) |
ph_*_session_id | PostHog session tracking: groups user actions within a browsing session. | 24 hours | PostHog EU (Third-party) |
PostHog Data Collection (Consent Required):
When you opt in to analytics cookies, PostHog may collect:
- Page views and navigation patterns
- Button clicks and feature interactions
- Session recordings (visual recordings of your browsing session including mouse movements, clicks, and scrolls)
- JavaScript errors and exceptions for debugging
- Device and browser information (type, OS, screen resolution)
- Anonymized IP addresses for analytics purposes
- Search queries performed on our platform
All PostHog data is stored on EU-hosted servers in compliance with GDPR. For more information, see PostHog's Privacy Policy.
4. Third-Party Cookies
Some cookies on AppFlight are set by third-party services we use:
- PostHog (EU): Analytics and session recording (consent required). Privacy policy: posthog.com/privacy
- Cloudflare: Security, CDN, and DDoS protection (essential, no consent required). Privacy policy: cloudflare.com/privacypolicy
- Google & GitHub: OAuth authentication providers (essential for login, no consent required). Their respective privacy policies apply.
We do not control these third-party cookies. Please review their privacy policies for more information about how they use cookies.
5. Managing Your Cookie Preferences
You have the right to accept or decline analytics cookies. You can manage your cookie preferences in the following ways:
5.1 Cookie Consent Banner
When you first visit AppFlight, you will see a cookie consent banner where you can choose to accept or decline analytics cookies. Essential cookies will be used regardless of your choice as they are strictly necessary for the service. Your choice is stored in your browser and will be remembered for future visits.
5.2 Browser Settings
Most web browsers allow you to control cookies through their settings. You can:
- Block all cookies
- Block third-party cookies only
- Delete cookies when you close your browser
- Delete all existing cookies
Note: Blocking or deleting essential cookies will prevent you from using key features of AppFlight, including logging in and accessing your account.
For instructions on managing cookies in your browser:
- Chrome: support.google.com/chrome/answer/95647
- Firefox: support.mozilla.org
- Safari: support.apple.com/guide/safari
- Edge: support.microsoft.com
6. Data Retention
Cookie data is retained for the following periods:
- Essential cookies: Retained for the duration specified in the cookie table (ranging from session-only to 30 days)
- Analytics cookies: PostHog analytics data is anonymized after 24 months; session recordings are deleted after 12 months
If you withdraw consent for analytics cookies, we will stop collecting new analytics data immediately, but previously collected data may be retained according to our Privacy Policy.
7. Legal Basis for Using Cookies
Under GDPR and the ePrivacy Directive, we use the following legal bases for cookies:
- Essential cookies: Legitimate interest and contract necessity (Article 6(1)(b) and 6(1)(f) GDPR). These cookies are strictly necessary to provide the service you requested.
- Analytics cookies: Consent (Article 6(1)(a) GDPR and ePrivacy Directive Article 5(3)). We only use these cookies after obtaining your explicit opt-in consent.
8. Your Rights
Under GDPR, you have the following rights regarding cookies and tracking:
- Right to withdraw consent: You can clear your browser cookies or local storage to reset your consent preferences
- Right to access: Request information about data collected via cookies
- Right to erasure: Request deletion of data collected via cookies
- Right to object: Object to processing of cookie data for analytics purposes
- Right to lodge a complaint: You have the right to file a complaint with your local data protection authority if you believe we are not complying with GDPR
To exercise these rights, contact us at privacy@appflight.ai.
9. Updates to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in our cookie practices or legal requirements. Material changes will be communicated via email notification and a prominent notice on our website. The "Last Updated" date at the top of this policy will be revised accordingly.
10. Contact Information
For questions about this Cookie Policy or to exercise your rights:
Email: arminas@appflight.ai
This Cookie Policy is compliant with GDPR, ePrivacy Directive, and other applicable data protection laws.