PRIVACY
Privacy Policy
This Privacy Policy ("Policy") states how FlightWay, Inc. collects, uses, discloses, and retains Personal Data in connection with the Service. It constitutes the whole of FlightWay's representations regarding its Processing of Personal Data. Capitalized terms have the meanings given in Section 1 (Definitions). Your use of the Service is also governed by the Terms of Service and the Security statement.
1. Definitions
In this Policy:
- "FlightWay," "we," "us," or "our" means FlightWay, Inc.
- "Service" means flightway.ai and every application and feature offered through it, including the career quiz, your home page, the career hub, the roadmap, the resume builder, mock interviews, simulations, and Marco (the AI coach), together with the emails we send you.
- "you" or "User" means the individual who accesses the Service or holds an Account.
- "Account" means the credentialed profile a User creates to access the Service.
- "Personal Data" means information that identifies, relates to, or could reasonably be linked to an identified or identifiable individual.
- "Process" or "Processing" means any operation performed on Personal Data, including its collection, use, storage, disclosure, and deletion.
- "Service Provider" means a third party that Processes Personal Data on our behalf to deliver the Service, as enumerated in Section 6.
- "Usage Data" means the events and identifiers recorded automatically, as described in Section 2.
- "O*NET" means the Occupational Information Network database published by the U.S. Department of Labor.
2. Scope and data controller
FlightWay develops career-development software for students. This Policy applies to flightway.ai, to all functionality accessible once signed in, and to the emails we send. For Personal Data Processed through the Service, FlightWay is the controller and is responsible for that Processing. Requests concerning your Personal Data are governed by Section 10 (Your rights and choices).
Matching a person to a career requires holding a detailed record of that person. The categories in Section 3 constitute that record in full.
3. Categories of data collected
We collect Personal Data in three categories: data you provide, data we generate from it, and Usage Data recorded automatically.
| Category | Type | Detail |
|---|---|---|
| Provided by you | Account | Your email address and a hashed form of your password. We do not store the password itself and cannot recover it. |
| Provided by you | Quiz answers | Every answer submitted in the career quiz, including free-text answers you compose. |
| Provided by you | Profile attributes | Name, school, the city of your school, year, GPA, subjects or majors, and the career you are leaning toward. |
| Provided by you | User-authored text | Free-text academics notes, your career focus and the history of changes to it, artifacts you log (a short title and a note), and every message you send to Marco or enter into a roadmap or career chat. |
| Provided by you | Resumes | Resume text you paste, resume files you upload, the resume documents you build on the Service — which contain your name, email, phone number, city and state, and up to five links such as LinkedIn or a portfolio — and any job posting you paste to tailor a resume against. |
| Provided by you | Support messages | Through the contact form: the email address for reply, your name if supplied, the topic selected, and your message of up to 4,000 characters. Two abuse- and diagnostics-related signals are stored alongside it — a peppered SHA-256 hash of your IP address, never the address itself, and a truncated copy of your browser's User-Agent string. If you were signed in when you sent it, your Account email is also recorded. |
| Generated by us | Vectors | A personality vector and an objective vector, each in O*NET coordinates, together with a weekly snapshot of each recording change over time. |
| Generated by us | Fit and analysis | Career fit scores, the written career analyses you open, and your sector fit sheet. |
| Generated by us | Plans | Your roadmap — waypoints, steps, branches, and completion state — and your weekly Flight Plan. |
| Generated by us | Coach memory | A dossier — a short set of durable facts about you that Marco retains between conversations — and your chat history with Marco. |
| Generated by us | Practice results | Mock-interview scores and the written debrief. The interview transcript itself remains on your device and is not stored on our servers. |
| Recorded automatically | Usage events | An event name drawn from a fixed allowlist, the page path with the query string removed, the host
of the referrer that first directed you to the Service, first-touch utm_source,
utm_medium, and utm_campaign values, and a device class of mobile,
desktop, or bot. |
| Recorded automatically | Identifiers | A random identifier generated by your browser and held in its local storage and — only when you are signed in — your Account email, read server-side from your session cookie rather than accepted from the request. |
| Recorded automatically | IP address | We do not store your raw IP address. The rate limiter that counts requests to prevent abuse keys on a peppered SHA-256 hash of your IP address, never the address itself, and those counters delete themselves one hour after they are written. The two forms that retain an IP signal longer — the pricing-interest form and the contact form — likewise store the hash, not the address. Cloudflare, as the network in front of the Service, receives the actual address to route your request; that record is held by Cloudflare, not by us. |
| Recorded automatically | Browser User-Agent | Analytics retains only a device class of mobile, desktop, or bot, derived from the string and then discarded. Two contexts retain the string itself, truncated to 200 characters: a message sent through the contact form, and the pricing-interest form on our pricing page. Both use it to distinguish a person from a script and to reproduce a reported problem. |
| Recorded automatically | Session cookie | Exactly one cookie, fw_session. See Section 8 (Cookies). |
3.1 Client-side storage
A substantial portion of the Service operates on your own device. The working copy of your profile, your queued events, and your cached scores reside in your browser's local storage, under keys you may inspect:
fw_user_v1— your working profile: name, school, year, GPA, subjects, career leaning, vectors, quiz scores and traits, resume text, and your position in the Service.fw_anon_v1— the random browser identifier used for analytics. It identifies a browser, not a person.fw_anon_sess_v1— a coarse session marker; a new session begins after a 30-minute gap.fw_attr_v1— first-touch referrer and utm values, written once and not overwritten.fw_evq_v1— the queue of events awaiting transmission, so navigation mid-batch does not lose them.
Additional minor keys exist — a local mirror of your roadmap, cached fit scores, resume drafts, simulation history, and your light/dark theme selection. Clearing your browser's site data for flightway.ai erases all of it, without action on our part.
4. Purposes of processing
We Process your Personal Data to operate the Service you signed up for, and for the limited purposes set out below:
- Matching. Your quiz answers, academics, and resume are converted into the two vectors that place you on the O*NET career map and produce your fit scores and sector fit sheet.
- Roadmaps. Your career focus, school, year, and current standing are supplied to the roadmap generator so that waypoints reflect your actual circumstances rather than a generic template.
- Coaching. Your dossier, focus, and recent progress are assembled into the prompt each time you interact with Marco.
- Resumes and practice. Extracting a resume you upload, tailoring it against a job posting, scoring it, and conducting mock interviews and simulations.
- Weekly email. Where enabled by you, delivery of three tasks drawn from your own roadmap.
- Support. Responding to messages you send us, using your message and email.
- Product measurement. Aggregate, de-identified usage counts indicating which parts of the Service are used. See Section 5 (Analytics).
- Payments and account state. Where you subscribe, as described in Section 6.
- Safety and abuse prevention. Rate limiting, spam prevention, and protection of Accounts against takeover.
We do not sell your Personal Data and do not construct advertising profiles from it. See Section 13 (Practices we do not engage in).
5. Artificial-intelligence processing
FlightWay operates no artificial-intelligence models of its own. Every AI feature transmits a prompt to the Google Gemini API and uses the response. That prompt is constructed from your actual profile.
5.1 Data transmitted to Google. Depending on the feature, the prompt context may include your name, school, year, GPA, subjects and major interests, and the career you are leaning toward (assembled into a shared context block used across features), together with your dossier text, your chat messages, your quiz answers, your resume text, and — where you upload a resume file — the contents of that file, encoded and transmitted with the prompt.
5.2 Features that call the API. Any feature of the Service that composes written text for you is a Gemini call. For the avoidance of doubt, these include: Marco and the coach chats; career analysis and the career-switch chat; career roadmap generation, step-by-step elaboration, and the personalized gap checklists; the Profile Builder (which transmits the free-text answers you enter there together with your dossier); resume extraction from an uploaded file; resume drafting; resume tailoring and scoring against a job posting; mock interviews; day-in-the-life simulations; the Opportunity Finder; your weekly Flight Plan; the written summary on your home page; your sector fit sheet; the stretch-fit explanations; and the patches that adjust your vectors after you provide new information.
5.3 Web grounding. Where the Opportunity Finder is enabled, it directs Gemini to perform a Google Search as part of answering. A research query — constructed from your question, normalized and length-capped, and which may contain names you mentioned, such as a school or firm — is thereby transmitted to Google Search. The sources returned arrive as Google redirect links, which we resolve server-side before display.
5.4 No model training. We do not train, fine-tune, or build any model. Your data is used to answer your own prompt and to populate the caches described in Section 9 (Data retention), so that the same question need not be re-answered.
5.5 Google's handling. Google's treatment of data submitted to the Gemini API is governed by Google's terms for the Gemini API. We can state what we transmit; we cannot make commitments on Google's behalf.
5.6 Optionality. Every AI feature is optional; to withhold a detail from Google, do not enter it into the Service. Quiz scoring and the computation of your fit values are performed by our own calculation, without any model. Only the subsequent patches, which adjust your vectors from your resume and your authored text, are transmitted to Google.
6. Analytics
Our analytics are self-hosted. The Service uses no Google Analytics, Segment, Mixpanel, Meta pixel, or any third-party analytics provider. Events pass from your browser to our own endpoint and into our own database, and no further. Specifically:
- No tracking cookie. The analytics identifier is a random value in your browser's local
storage (
fw_anon_v1), never a cookie, and never shared with any other site. - Do Not Track is honored. Where your browser reports
navigator.doNotTrack === "1", the beacon is not armed and nothing is sent. As a second control, a request arriving with aDNT: 1header is discarded server-side without being written. - Bot traffic is discarded rather than counted — crawlers, previewers, headless browsers, and requests bearing no user agent.
- Event properties are scrubbed of Personal Data server-side before any write; the scrub runs on our side, and the client only limits the size of a property. Values keyed as email, name, phone, address, school, GPA, message, note, query, password, or token are dropped, as is any value resembling an email address, any string exceeding 64 characters, and any nested structure.
- Paths are reduced to the path alone, with query strings removed, and referrers are reduced to the host rather than the full URL.
- Your IP address is never written to the analytics table in any form, raw or hashed. The one-hour abuse counter described in Section 3 is the only point at which the analytics endpoint touches it.
- Raw events are deleted after 90 days. What remains is a daily count per event name, containing no identifiers.
- Event names are fixed labels, never text you authored. Most derive from a fixed
allowlist; the remainder must begin with one of approximately forty known prefixes
(
quiz_,resume_,marco_) and match a strict slug format. In either case the name is one entered into our source code by a developer, so no text you write in the Service can enter analytics within a name.
7. Service providers and disclosures
Four Service Providers Process your data, and no others. Each is engaged because the Service cannot operate without it.
| Provider | Data received | Purpose |
|---|---|---|
| Cloudflare | All data, in its capacity as host. The site, our server code, our database, and our caches operate on Cloudflare's platform. As the reverse proxy in front of the Service, Cloudflare also receives the raw IP address and headers of every request, including requests that we ourselves store only as a hash. | Hosting, the database, caching, and network-level protection against attack. |
| Google (Gemini API) | The prompt context described in Section 5, which may include your name, school, year, GPA, subjects, career leaning, dossier, chat messages, resume text, and uploaded resume files. | All AI-generated functionality: coaching, analyses, roadmaps, resume work, interviews, and simulations. |
| Stripe | Your email address, your plan tier, and a customer identifier linking your Account to Stripe's record. We do not receive or store your card number; checkout and billing management occur on Stripe's own pages. | Processing payments and managing subscriptions. |
| Resend | Your email address, the link being sent, and — for the weekly digest only — up to three short task labels from your own roadmap and the waypoints they sit under. When you use the contact form, the notification we receive carries your message in full: the reply address, your name if supplied, the topic, your Account email if you were signed in, and the text you wrote, up to 4,000 characters. We do not ourselves place resume text, GPA, or dossier content into an email; the contact form, however, transmits whatever you enter into it, and content entered there will reach an inbox. | Sending the quiz-results email, password resets, the optional weekly Flight Plan digest, and the contact-form notification to our support inbox. |
Each Service Provider is an independent company with its own privacy policy and its own commitments, which are that company's to make and not ours to guarantee. We have not, as of the date of this Policy, executed a data processing agreement with each of them; doing so is an outstanding item, and we will state here when it is complete.
We may also disclose data where required by law, or to protect the safety of any person. Where such a disclosure occurs and we are permitted to inform you, we will. If FlightWay is acquired or merged, your data would transfer with the company, and we will state so here before that occurs.
8. Cookies
FlightWay sets one cookie, which exists solely to maintain your signed-in state.
- Name:
fw_session. - Contents: a long random token. Only a hash of the token is stored on our side; the raw token does not reach our database.
- Flags:
HttpOnly(no page script may read it),Secure(HTTPS only),SameSite=Lax, andPath=/. - Lifetime: 30 days, enforced on our server as well as in your browser. Signing out clears it immediately.
The Service sets no advertising cookies, no analytics cookies, and no third-party cookies. Because the sole cookie we set is strictly necessary to deliver a service you requested, no consent is required for it, and the Service presents no cookie banner.
9. Data retention
| Data | Retention period |
|---|---|
| Account, profile, quiz answers, roadmap, career analyses, artifacts, vector snapshots | Until you delete your Account. No automatic expiry. |
| Saved resume documents, tailored versions, mock-interview results | Until you delete them, and removed when you delete your Account. |
| Marco's dossier and chat history | No expiry; removed when you delete your Account. |
| Contact-form messages | Until you delete your Account, or until we clear them manually. There is no automatic prune: a support message from a year ago remains in our database unless one of those events has occurred. Deleting your Account removes both the messages sent from that address and any you sent while signed in under a different reply address. |
| Sign-in sessions | 30 days, after which they are invalid. |
| Password-reset links | One hour; requesting a new link invalidates the prior one. |
| AI caches (to avoid re-answering the same question) | These expire automatically: opportunity results after one day; personalized checklists and resume tailoring after one week; weekly plans after three weeks; step explanations after one month; waypoint plans after three months; a saved resume draft after six months. |
| Raw analytics events | 90 days, then deleted by a nightly job. |
| Daily analytics counts | Retained indefinitely. These are counts per event name, containing no email, browser identifier, or other data that identifies a person. |
| Server error logs | A route, a truncated error message, and a timestamp. No raw request body. |
10. Your rights and choices
10.1 Deletion of your Account
You may delete your Account yourself, without contacting us or waiting. Open your home page, scroll to the bottom, and use the delete control. It requires a single confirmation and then permanently erases your Account from our systems: your profile, quiz answers and scores, your vectors and their weekly snapshots, your roadmap, your career analyses, your artifacts, Marco's dossier and all chat history, the resumes you built on the Service and every saved version of them, your mock-interview transcripts and scores, any complimentary plan attached to your address, your saved weekly plans, and every active session. It further sweeps every working cache keyed to your address — tailored-resume results, step explanations, waypoint plans, Opportunity Finder results, a pending profile-alignment proposal, your career-match rankings, and the usage counters underlying your plan limits — and clears all data FlightWay has stored in your browser. You may register again with the same email address as a new User.
Two exceptions apply:
- Analytics records are anonymized, not deleted. Your Account identifier is set to null and the record remains as an unattributed count containing no name, message text, or IP address. Deleting these records would distort every funnel and retention figure for other Users. They age out on the standard 90-day schedule in any event, and the daily counts that outlast them never held an identifier.
- The administrative audit log is retained. If an administrator granted or revoked anything on your Account, that action remains in our security log with your address recorded. An audit trail that a subject could erase by deleting their own Account would be worthless in the sole case for which it exists. It is used for no other purpose and is the only record of you that survives.
Stripe additionally retains its own records of any payments, as payment processors are generally required to. That data is held by Stripe under its policy, and deleting your FlightWay Account does not erase it.
10.2 Withdrawal of email
Each weekly digest carries a one-click unsubscribe link that operates without a sign-in and takes effect immediately, with no confirmation step. You may also disable the weekly email in your notification settings.
10.3 Access, correction, and portability
To request a copy of your data, a correction, or the deletion of a specific item, email [email protected] or use the contact form and select the privacy topic. Send the request from the address on the Account, so that we do not disclose your file to another person. Depending on your jurisdiction, you may hold statutory rights of access, correction, deletion, and portability, and a right against retaliation for exercising them; we intend to honor these rights regardless of your location.
10.4 Client-side deletion
A substantial share of your data resides in your own browser and may be removed without our involvement. Clearing site data for flightway.ai deletes every key listed in Section 3. Enabling Do Not Track in your browser stops analytics from being transmitted.
11. Minors
FlightWay is intended for students aged 13 and over. If you are under 13, do not create an Account. We do not knowingly collect Personal Data from children under 13, and we will not open an Account for one.
If we learn that an Account belongs to a person under 13, we delete the Account and its associated data. A parent, guardian, teacher, or counselor who believes a child under 13 holds an Account may notify us at [email protected], and we will remove it.
The Service performs no age-verification step. We do not request your date of birth or age, and no control in the sign-up process checks either. The 13-and-over requirement is enforced upon report, not by a gate imposed by the software. If you use FlightWay through your school, your school may impose additional requirements.
12. Security
Your session token, your password, and your IP address are each stored only as a hash — including in the one-hour abuse counters described in Section 3 — and the Service operates on Cloudflare's platform over HTTPS. The full description of our security controls, of the controls we have deliberately not yet implemented, and of how to report a vulnerability appears in the Security statement.
13. Email communications and CAN-SPAM
We send three categories of email and no others:
- Quiz results — sent only upon your request on the results screen. It contains a link to your hub and nothing further about you.
- Password reset — sent only when you request one. The link is valid for one hour.
- The weekly Flight Plan digest — optional, disabled unless you enable it, sent once per week, and containing up to three short task labels from your own roadmap together with a link to the Service.
The first two are transactional; they respond to an action you took and therefore carry no unsubscribe link. The weekly digest is the only recurring email and carries a one-click unsubscribe link in every send, operable without a sign-in. None of our emails contains a tracking pixel, and we do not measure whether an email was opened.
Outstanding item. The weekly digest is required by CAN-SPAM to carry a valid physical postal address, and that address is not yet configured on our systems; our sending code presently warns of this condition. We will resolve it before any bulk send, and the address will appear in the footer of that email and in this Policy once settled. We will not print a placeholder address in the interim.
14. Practices we do not engage in
- We do not sell your Personal Data — not to schools, recruiters, or any other party.
- We deploy no ad networks, advertising pixels, or retargeting tags. None are present on the Service.
- We use no third-party analytics. Our analytics are self-hosted and the data remains in our own database.
- We conduct no cross-site tracking. The analytics identifier is per-browser, per-origin, and shared with no other site.
- We place no open-tracking pixels in email.
- We employ no dark patterns on cancellation. Cancellation of a subscription occurs in Stripe's own billing portal, one click from your Account, with no retention interstitial and no telephone call. Deletion of your Account is a control on your home page, not a support ticket.
- We do not train AI models on your data, and we do not train models at all.
- We do not access your data gratuitously. Access to production data is limited to what is required to operate the Service and to answer your support requests.
Each statement above is verifiable: the Service issues no third-party requests that are not visible in your browser's network inspector.
15. Governing law
This Policy is governed by the laws of the state in which FlightWay, Inc. is incorporated, without regard to its conflict-of-law rules. The specific state and the venue in which disputes would be heard remain to be settled with counsel; accordingly, we name neither here rather than state one that is unconfirmed. This Section will be amended when both are settled.
16. Amendments
We will amend this Policy as the Service changes, and the date at the top of the page will be updated. For an amendment that materially affects you — a new company receiving your data, a new category of data collected, or a materially shorter or longer retention period — we will notify you before it takes effect, by email to the address on your Account or by notice within the Service.
The outstanding items identified at the top of this page will be resolved by amending this text, and we will note what changed.
17. Contact
Email [email protected], or use the contact form and select Privacy, my data, or deleting my account. A member of our team reads each message. We aim to respond within two business days.
Contact us to request a copy of your data, to correct information in your file, to delete a specific item, to report that a child under 13 holds an Account, or to report a statement here that does not match the operation of the Service.
A postal address will be listed here once settled — see the notice at the top of this page.