Skip to main content

Privacy Policy

Privacy Policy

Last updated: 16 September 2026

This policy describes the personal data Yaniv Levy actually processes, the legal basis for each use, who it is shared with, how long it is kept and how to exercise your rights. It is written to the Israeli Protection of Privacy Law 5741-1981 and, where it applies to you, the GDPR.

1. Who we are

Yaniv Levyoperates skyinfo.app ("the Service") and is the controller of the personal data described here — in Israeli terms, the owner of the database ("בעל מאגר המידע") under the Protection of Privacy Law 5741-1981.

Registered name: Yaniv Levy
Address: Tel Aviv, Israel
Contact: [email protected]

2. What we collect, and why

We do not sell personal data and we do not run advertising. What we hold:

  • Account details — if you sign in with Google we receive and store your email address, display name and Google account identifier. We never receive your Google password.
  • API credentials and usage — the API keys issued to your account, the plan you are on, and a per-request usage record (endpoint, timestamp) used to count your quota and to detect abuse.
  • Billing details — if you buy a paid plan, we store the payer email address and subscription identifier that PayPal returns to us. Card and bank details are handled entirely by PayPal and never reach our servers.
  • Support messages — anything you choose to send us by email or through the contact page.
  • Server logs — our backend records the IP address, requested path, response status and timestamp of each request, for security, debugging and abuse prevention.
  • Approximate location— only if you press the "use my location" control and your browser asks you to allow it. The coordinates are used in the page you are on and are not stored on our servers.
  • Analytics — only if you enable the Analytics category in the cookie banner. See section 5.

You can browse the public pages without signing in, and we do not require you to give a name, a phone number or an address to do so.

3. Legal basis for each use

Under the GDPR (where it applies to you) and the Israeli Protection of Privacy Law:

  • Performance of a contract — running your account, issuing API keys, metering quota, taking payment.
  • Legitimate interests — server logs, rate limiting and abuse prevention, keeping the Service secure and available.
  • Consent — analytics cookies, and browser geolocation. You may withdraw either at any time with no effect on the rest of the Service.
  • Legal obligation — keeping accounting records for the period tax law requires.

Giving us your details is voluntary; you are under no legal duty to do so. But without an account and an API key we cannot provide the metered API, and without payment details we cannot provide a paid plan.

4. Who we share it with

We use the following processors and service providers. Each receives only what it needs, and none of them is permitted to use your data for its own marketing.

  • Railway — hosting for the application and the PostgreSQL database.
  • Google Ireland Ltd. — Google Sign-In, and Google Tag Manager plus Google Analytics 4 if you opted in.
  • PayPal — payment processing and subscription management. PayPal is an independent controller of the payment data it holds.
  • Aviation Edge — the flight-data provider. When you request flight information, the query parameters (airport codes, dates, flight numbers) are forwarded to it. We do not send it your identity.
  • Flightradar24 (public endpoints) — live board and weather lookups, queried the same way.
  • CARTO and OpenStreetMap — map tiles. Your IP address reaches their servers when a map page loads.
  • jsDelivr — content delivery for the accessibility toolbar script.

We will also disclose data where we are legally required to — a court order, or a lawful demand from a competent authority.

Transfers outside Israel and the EEA.Our hosting and several of these providers operate servers outside Israel, including in the United States. Where that happens, the transfer relies on the recipient being subject to an adequate data protection regime or on the provider's standard contractual clauses, in line with the Israeli Protection of Privacy (Transfer of Data to Databases Abroad) Regulations 5761-2001 and Chapter V of the GDPR.

5. Cookies and analytics

Strictly necessary storage — your sign-in session, your consent choice, your theme and your API key — is always active, because the Service cannot work without it.

Google Tag Manager and Google Analytics 4 are not loaded at all unless you enable the Analytics category. If you do, it sets _ga cookies to produce aggregate usage statistics. IP anonymisation is enabled; Google Signals, advertising features and data sharing for advertising are not. Turning the category back off stops the tag and deletes those cookies.

The full inventory, with retention periods, is on the Cookie Policy page. Change your choice at any time via .

6. How long we keep it

  • Account and API key records — for as long as your account exists. Closing your account deactivates it and revokes every key; the record itself is retained because billing and usage history must survive, and is deleted on request (see section 7) unless we are required to keep it.
  • Usage records — kept as long as needed for quota accounting and dispute resolution.
  • Billing records — retained for the period required by Israeli tax and accounting law.
  • Server logs — short-lived, kept for operational and security purposes only.
  • Support correspondence — kept while the matter is open and for a reasonable period afterwards.

7. Your rights

You may, at any time and free of charge:

  • See what we hold about you — the right of inspection under sec. 13 of the Protection of Privacy Law, and the right of access under GDPR art. 15.
  • Have it corrected — sec. 14 of the Protection of Privacy Law, GDPR art. 16.
  • Have it deleted — GDPR art. 17, subject to records we are legally required to retain.
  • Receive a copy in a portable format — GDPR art. 20.
  • Object to, or restrict, processing based on our legitimate interests — GDPR arts. 18 and 21.
  • Withdraw consent to analytics or geolocation, without affecting anything done before you withdrew it.

You can suspend or close your account yourself from the Profile page. For anything else, write to [email protected]. We answer within 30 days. We may ask you to confirm your identity first, so that we do not disclose your data to somebody else.

If you are not satisfied, you may complain to the Israeli Privacy Protection Authority or, if you are in the EEA or the UK, to your local supervisory authority.

8. Security

Traffic is served over HTTPS. API access requires a secret key, requests are rate limited, and administrative interfaces are not exposed to the public internet. Access to the database is restricted to the people who operate the Service.

No system is perfectly secure. If we become aware of a breach that is likely to affect your rights, we will notify you and the competent authority as the law requires. If you believe you have found a vulnerability, please report it to [email protected] rather than disclosing it publicly.

9. Children

The Service is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.

10. Changes

We may update this policy. The date below the title always shows the current version. If a change materially affects how we use your data, we will say so prominently on the site before it takes effect, and — where the law requires it — ask for your consent again.

Privacy questions or a rights request?

We answer privacy requests within 30 days.

Contact us

See also our Terms of Use, Cookie Policy and Accessibility Statement.