What we collect
With an account: your email (if you share it — Apple can withhold it), display name, and the Apple/Google identifier you signed in with. As you use Crow: your searches (origin, destination, dates, cabin, travelers), the results we showed, saved trips and destination guides, and any fare watches. If you import a trip: the emails you choose to forward to your private @in.flycrooked.com address (and their attachments), and the text of confirmations or itineraries you import in the app — used only to build or update your trip. Questions you ask Crow are stored with your trip so the conversation works; if you turn on memory in Profile, Crow also keeps durable preferences from those chats (switch it off anytime, which erases them). For notifications: your device push token. Automatically: basic network data such as your IP address, used transiently to rate-limit, block abuse, and set sensible defaults like currency and your nearest airport. While you're on a trip, with your permission, we use your precise location to find places near you.
What we don't collect
We do not ask for passport numbers, payment details, or government IDs to make bookings; booking happens with the airline or agency, not on Crow. Documents you choose to save may contain personal details. Signed-in account sync backs up your saved trips, Weekend plans, document-locker files, chat history and preferences so they can be restored on another device. These backups are private to your account, not public share links. We do not buy personal data from brokers. Crow uses Meta for optional advertising measurement and campaign optimization as described below; Crow does not send your trip contents, chats, saved documents, camera or microphone recordings, or precise location to Meta for advertising.
Camera & microphone
Camera and microphone data used for live menu/sign translation and conversation mode is processed on your device; account sync does not back up those live sessions. Importing a confirmation by photo or scan sends the recognized text to our servers to build your trip. If you separately save an image or PDF in your document locker, that saved file is included in your private account backup.
Legal basis (GDPR)
We process your data to perform the service you asked for (running searches, saving your trips) — that's contract. Security, abuse-prevention, and improving Crow with aggregate, de-identified stats rely on our legitimate interests. Optional affiliate tags and Meta website and app advertising measurement, attribution and personalized advertising rely on consent, including App Tracking Transparency permission on iOS. They are not required to use Crow. You can refuse or withdraw consent without losing core travel features. Withdrawal stops future consent-based processing; it does not make earlier processing unlawful or automatically delete information already shared.
Cookies & app tracking
Website: we store your cookie choice locally in your browser. Cloudflare may set strictly necessary security cookies. Our travel affiliate partner's script and the Meta Pixel load only after you accept website advertising cookies. The affiliate tag credits bookings through partner links. The Meta Pixel may set Meta cookies and sends pages viewed on flycrooked.com, completed website sign-ups, IP address and browser/device information to Meta for attribution and ad measurement. Page URLs sent to Meta use generic page names, without search parameters, private identifiers, query strings, fragments or referrers. We do not send account details or enable Advanced Matching. You can decline or withdraw this consent through Cookie preferences in the footer. iOS app: with your App Tracking Transparency permission, the Meta SDK sends app activation/session and completed purchase or subscription events to Meta, including the product identifier, amount and currency. It may also send the advertising identifier (IDFA), SDK/app-instance identifiers, IP address, device and operating-system information, app version and event timing. After opt-in, the SDK may also send crash reports and other technical data for SDK operation and analytics. Meta uses advertising data to measure which ads lead to installs and purchases, optimize campaigns and show more relevant offers, and may match it with activity across other companies' apps and websites. Crow keeps Meta app-event collection off until permission is granted and does not send these events when permission is denied, restricted or undecided. Change the app choice in iOS Settings > Privacy & Security > Tracking; Crow applies the current choice when the app becomes active and before logging events. Website cookie choices and iOS tracking permission are separate. Turning tracking off does not affect your trips, sign-in or purchases.
Who processes your data
Our service providers include Microsoft Azure (hosting, database and AI generation), Cloudflare (content delivery and security), fare and imagery providers such as SerpAPI and Google (results and place data), an email provider (sign-in, alerts and reservations you forward), and Apple Push Notification service (alerts). Search parameters go to fare providers to obtain results, not your Crow account identity. With advertising consent, Meta Platforms (Facebook and Instagram) receives the website pixel data and app-event and device data described in section 05 for attribution, advertising measurement, campaign optimization and personalized advertising. Meta may combine that information with information it holds and process it under its own Privacy Policy and applicable business-tool terms, not solely on Crow's behalf. We do not sell or rent personal data for money. Sharing identifiers and events for advertising may nevertheless be considered a sale or sharing for cross-context behavioral advertising under some US privacy laws. The choices in sections 05 and 09 apply to that sharing.
International transfers
Crow is operated by Glyphor, Inc. Your data may be processed in the United States and other countries where our providers operate; where required, transfers rely on appropriate safeguards such as the providers' Standard Contractual Clauses.
Retention & deletion
Account-linked data lives until you delete it or your account. Emails you forward are kept only long enough to file them to your trip — 30 days at most — and the incoming email attachments are removed once delivered. Files you save in the document locker have a separate private account backup until deleted. Deleting a synced item removes its backed-up content; a minimal deletion marker remains to prevent an offline device from restoring it accidentally. Signing out does not delete your account's isolated local copies. Profile → Delete account removes server account data and clears that account's local data on the device performing deletion. Anonymous searches are de-identified within 90 days. Crow deletion requests are completed within 30 days. Advertising data already received by Meta is subject to Meta's retention and deletion practices; deleting your Crow account or turning off tracking does not automatically erase it from Meta. Use Meta's privacy controls or contact privacy@flycrooked.com for help with a request.
Your rights
Depending on your location, including the EU/EEA, UK and applicable US states, you may access, correct, export or delete personal data, restrict or object to processing, withdraw consent, and opt out of sale, sharing or targeted advertising. Decline or disable Crow in iOS Settings > Privacy & Security > Tracking to stop future Meta app tracking. Website Cookie preferences controls both the affiliate tag and the Meta Pixel, not app tracking. Turn off Advertising & affiliate there to stop future website tracking. You can also email privacy@flycrooked.com to exercise your rights or appeal a response, without losing access to core services for declining optional advertising. Profile → Delete account removes Crow account data as described in section 08. You can request an account export at /api/me/export or contact us for help. EU/EEA and UK users also have the right to complain to their local data-protection authority.
Children
Crow isn't directed to children under 13, and we don't knowingly collect data from them. If you think a child has given us data, email privacy@flycrooked.com and we'll remove it.
Changes
If this policy changes in a way that matters, we'll say so on the site before it takes effect — not bury it in a changelog.
Questions · privacy@flycrooked.com
Crow is a product of Glyphor, Inc.
Advertising partner: Meta Privacy Policy
