Last updated: 10 July 2026
whentofly is a flexible-date flight-search API. This policy explains, in plain terms, what the service records and why.
The data controller is Dmitry Bolonikov. For any privacy question or request, email [email protected].
/search.openai-bot, browser, or
direct). Our server-side query log and canonical event
properties do not include raw referrer or User-Agent strings.The /search API itself requires no sign-up and no
authentication. It does not set a browser identifier by itself. A caller that
sends an existing wf_aid cookie or an attributed link can be joined
to the originating browser visit. We do not ask API callers for a name, email
address, account, or payment details.
The landing page sets a first-party cookie named wf_aid. Its
value is a random identifier for a browser, not a name or account, but it is
pseudonymous data and can distinguish repeat visits. It joins landing variants,
website interactions, and attributed agent/API activity. Affiliate URLs receive
only a broad channel and landing variant, not wf_aid. The cookie
expires after up to 400 days. The
first-activation deduplication record uses the same maximum period. Clearing
site data removes the browser copy; a later visit may receive a new value.
The browser landing uses EU-hosted PostHog product analytics and Statsig experiment assignment. Concretely, we process:
wf_aid.API and MCP callers receive no browser analytics script, but the server emits the agent lifecycle events described above. We run no advertising trackers and do not sell personal data.
To run your search, cache results so the service stays fast and free, build the price history that powers the price-level verdict, measure whether the service produces a useful result, attribute affiliate outcomes, and improve the website. Our legal basis is legitimate interest in operating, securing, and improving the service.
Our application does not add a raw IP address to product-analytics events and server-side PostHog capture disables IP-based geolocation. Hosting, CDN, and analytics providers necessarily receive connection metadata while delivering a request. Other analytics and operational records are retained only as needed to operate and evaluate the service; the public code does not define one blanket expiry for every record. Deletion or access requests can be sent to [email protected].
We use PostHog (EU-hosted) as our product-analytics processor and Statsig for experiment assignment and activation measurement, as described above.
Each result includes a book_url that points to Aviasales (via our
affiliate partner Travelpayouts). Aviasales / Travelpayouts is an independent
third party: when you click a book_url and leave our service, they
may set their own cookies and process your data under their own privacy policies,
which we do not control.
Questions or requests: [email protected].