Privacy

Last updated: 10 July 2026

whentofly is a flexible-date flight-search API. This policy explains, in plain terms, what the service records and why.

Who runs this service

The data controller is Dmitry Bolonikov. For any privacy question or request, email [email protected].

What we store

The /search API itself requires no sign-up and no authentication. It does not set a browser identifier by itself. A caller that sends an existing wf_aid cookie or an attributed link can be joined to the originating browser visit. We do not ask API callers for a name, email address, account, or payment details.

Pseudonymous browser identifier

The landing page sets a first-party cookie named wf_aid. Its value is a random identifier for a browser, not a name or account, but it is pseudonymous data and can distinguish repeat visits. It joins landing variants, website interactions, and attributed agent/API activity. Affiliate URLs receive only a broad channel and landing variant, not wf_aid. The cookie expires after up to 400 days. The first-activation deduplication record uses the same maximum period. Clearing site data removes the browser copy; a later visit may receive a new value.

Website analytics and experiments

The browser landing uses EU-hosted PostHog product analytics and Statsig experiment assignment. Concretely, we process:

API and MCP callers receive no browser analytics script, but the server emits the agent lifecycle events described above. We run no advertising trackers and do not sell personal data.

Why we store it

To run your search, cache results so the service stays fast and free, build the price history that powers the price-level verdict, measure whether the service produces a useful result, attribute affiliate outcomes, and improve the website. Our legal basis is legitimate interest in operating, securing, and improving the service.

Network data and retention

Our application does not add a raw IP address to product-analytics events and server-side PostHog capture disables IP-based geolocation. Hosting, CDN, and analytics providers necessarily receive connection metadata while delivering a request. Other analytics and operational records are retained only as needed to operate and evaluate the service; the public code does not define one blanket expiry for every record. Deletion or access requests can be sent to [email protected].

Third parties

We use PostHog (EU-hosted) as our product-analytics processor and Statsig for experiment assignment and activation measurement, as described above.

Each result includes a book_url that points to Aviasales (via our affiliate partner Travelpayouts). Aviasales / Travelpayouts is an independent third party: when you click a book_url and leave our service, they may set their own cookies and process your data under their own privacy policies, which we do not control.

Contact

Questions or requests: [email protected].