Skip to content
Flight Memos
AboutPrivacySupport
By Please Don't Do It

Flight Memos · Legal

Privacy Policy

This policy explains what Flight Memos accesses, why it is needed, where it is processed, how long it remains and how you can delete it.

Contents1. Scope and controller2. Information handled3. Google user data4. Microsoft user data5. How information is used6. Processing and storage7. Sharing and transfers8. Retention and deletion9. Your choices10. Security11. Children12. Changes and contact

Effective date: August 24, 2026.

1. Scope and controller

This Privacy Policy applies to the Flight Memos iOS application, its related support communications and the Flight Memos pages on pleasedontdo.it.

Flight Memos is provided by Ilya Ilyich Rychagov, an individual entrepreneur based in Armenia (“we,” “us,” or the “Controller”), operating under the Please Don't Do It name. Contact us at [email protected].

2. Information Flight Memos handles

Journey information. Information you enter, import or confirm can include airports, routes, dates, local departure times, airlines, flight numbers and import provenance. The app may calculate statistics and estimated journey details from this information.

Connected account information. If you choose to connect an email account, the app handles the provider name, a local account identifier, a non-sensitive account label, authorization credentials, synchronization cursors, last-scan information and message identifiers or privacy-preserving fingerprints needed to avoid processing the same message again.

Support information. If you contact us, we receive the email address, message and any app, device or diagnostic details you choose to provide. Please do not send email contents, OAuth tokens, booking references, ticket numbers or other sensitive travel information unless we specifically ask for information necessary to investigate your request.

Website technical information. Our hosting and security providers may process limited request data such as IP address, browser type, requested page, timestamps and security logs to deliver and protect the website.

3. Google user data

Google access is optional and begins only when you select Gmail, choose to connect an account and approve Google's consent screen. Flight Memos requests the https://www.googleapis.com/auth/gmail.readonly scope. This allows the app to read email and attachments, but does not allow it to compose, send, edit or delete messages, change labels or administer your mailbox.

Flight Memos uses Gmail data only to search for likely flight confirmations, booking messages, itineraries, boarding passes and related attachments; extract candidate flight details on your device; show those details for your review; and continue later scans without repeatedly processing the same messages.

Candidate data can include sender and recipient information, subject lines, message dates, message identifiers, email bodies and relevant attachments such as PDF, calendar or Wallet-pass files. Search is intentionally limited by travel-related signals and the time range you choose.

Flight Memos' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This commitment applies to raw Google data and information derived from it.

We do not use Google user data for advertising, profiling, credit decisions, data brokerage, generalized AI or machine-learning model training, or any purpose unrelated to the user-facing flight-import feature. No employee or contractor reads your Gmail data except if you give affirmative permission for specific data when support is necessary, or where access is required for security or legal compliance.

4. Microsoft user data

Microsoft access is optional and begins only when you select Microsoft, choose to connect an Outlook.com, Hotmail or Microsoft 365 account and approve Microsoft's consent screen. Flight Memos uses delegated Microsoft Graph access and requests Mail.Read to read the signed-in user's mailbox and offline_access so the authorization can be refreshed without asking you to sign in before every scan. The Microsoft sign-in response may also provide a display name, email address and provider account identifier, which the app uses only to identify and distinguish the connected account.

Flight Memos uses Microsoft mailbox data only to search for likely flight confirmations, booking messages, itineraries, boarding passes and related attachments; extract candidate flight details on your device; show those details for your review; and continue later scans without repeatedly processing the same messages.

Candidate data can include sender and recipient information, subject lines, message dates, message identifiers, email bodies and relevant attachments such as PDF, calendar or Wallet-pass files. Search is intentionally limited by travel-related signals and the time range you choose.

Flight Memos does not request Microsoft Graph application permissions, Mail.ReadWrite, Mail.Send or organization-wide mailbox access. It cannot send, edit or delete email. We do not use Microsoft user data for advertising, profiling, data brokerage, generalized AI or machine-learning model training, or any purpose unrelated to the user-facing flight-import feature.

5. How information is used

We use information to provide the features you request; find and normalize flight details; present candidate journeys for your review; prevent duplicate imports; maintain incremental synchronization; display your travel history and statistics; respond to support; secure the app and website; and comply with applicable law.

Flight Memos does not create a journey from email silently. You can review, edit, exclude and confirm candidate results before they are added to your travel history.

6. Processing and storage

On-device email processing. Messages and attachments are fetched directly from Google or Microsoft to your device. MIME decoding, extraction and validation take place on the device. Flight Memos does not send raw email bodies or attachments to our backend or to an external AI provider, and does not retain them after extraction finishes.

Credentials and synchronization state. OAuth access and refresh credentials are stored in the iOS Keychain. Non-content synchronization state, such as provider cursors or delta links, timestamps and message identifiers or privacy-preserving fingerprints, is stored locally on the device. Credentials are not placed in analytics, ordinary app preferences, logs or the travel-history database.

Saved journeys. Only the normalized journey fields you review and save are added to Flight Memos' travel-history database. Flight Memos uses Apple's private CloudKit to sync the travel history across devices signed in to your Apple Account when that service is available. This means normalized flight information derived from an email may be transmitted to and stored in your private iCloud database under Apple's service terms. Raw email bodies and attachments are not included.

7. Sharing and transfers

We do not sell Google or Microsoft user data or other personal information. We do not share it for targeted advertising.

Information is disclosed only as needed to provide the service you request: Google processes OAuth and Gmail API requests; Microsoft processes OAuth and Microsoft Graph requests; Apple provides iOS security services and private CloudKit synchronization; and website or email providers process limited technical and support information. These providers operate under their own terms and privacy notices. We may also disclose information when required by law, to protect security and legal rights, or as part of a business reorganization subject to applicable safeguards.

Flight Memos does not upload Gmail or Microsoft mailbox contents to Please Don't Do It servers. Because the app is operated from Armenia and providers may operate internationally, the limited information described above may be processed in other countries subject to applicable transfer safeguards.

8. Retention and deletion

Raw email. Message bodies and attachments are kept only in temporary memory or storage needed for on-device extraction and are discarded when processing completes.

Credentials and mailbox state. OAuth credentials and provider synchronization state remain until you disconnect the account in Flight Memos, remove the app and its data, or the credentials expire or are revoked. Disconnecting removes the account's local credentials and mailbox synchronization state.

Saved journeys. Journeys you reviewed and saved remain until you delete them in Flight Memos. Disconnecting an email account does not silently delete previously confirmed journeys. If private CloudKit sync is active, deletions synchronize through your private iCloud database subject to Apple's operation and retention of that service.

Support and technical records. We retain support correspondence and limited website security records only as long as reasonably necessary to resolve requests, protect the service and meet legal obligations.

9. Your choices and controls

Email access is optional. You can use Flight Memos without connecting Gmail or Microsoft and can decline any candidate journey before saving it.

You can disconnect an account inside Flight Memos and separately revoke Flight Memos access from the third-party connections page in your Google Account, the Microsoft My Apps portal for work or school accounts, or the apps and services permissions page for personal Microsoft accounts. Revoking provider access prevents new mailbox API requests but does not automatically delete journeys you already reviewed and saved.

You can delete saved journeys in the app. You can also contact [email protected] to exercise privacy rights available under applicable law. We may need information reasonably necessary to verify your identity and scope the request.

10. Security

Flight Memos uses platform protections including OAuth authorization, iOS Keychain storage for credentials, private CloudKit for user-owned synchronization and data minimization. Logs are designed not to contain OAuth tokens, email bodies, passenger names, booking references, ticket numbers or loyalty numbers.

No storage or transmission method is completely secure. If we learn of a security incident affecting information for which we are responsible, we will respond and notify affected users or authorities where required.

11. Children

Flight Memos is not directed to children under 13, and we do not knowingly collect personal information from children through the service. If you believe a child has provided information contrary to this policy, contact us so we can investigate.

12. Changes and contact

We may update this policy when Flight Memos' features, providers or legal obligations change. We will publish the new version on this page and revise the effective date. Material changes will be communicated where required.

For questions, privacy requests or complaints, contact Ilya Ilyich Rychagov at [email protected].

Flight Memos
Privacy first, by design.
Flight MemosAboutSupport
LegalPrivacy policyTerms of use

© 2026 Please Don't Do It.