Public policy

Last updated August 2, 2026

Privacy Policy

This policy explains what personal data LaniGo uses today to provide flight search, saved alerts, account access, and email notifications during the beta.

1. Introduction

LaniGo helps users search for flights, compare current offers, create personal flight alerts, monitor alert execution, and receive email notifications when matching fares are found. This Privacy Policy describes the data used by the current beta product.

Alert Health and monitoring features are informational. They do not change how alerts are searched, matched, or scheduled.

2. Who Operates LaniGo

LaniGo is currently operated by Oniga Madalin.

3. Information We Collect

  • Account information such as name, email address, email verification state, and profile image.
  • Google account information made available during authentication, together with the authentication data required by Better Auth to maintain your session.
  • Session information, including session token, expiry, IP address, user agent, and timestamps.
  • Account state such as beta cohort, role, active or deactivated status, and deactivation time.
  • Optional preferences stored for future product phases, including preferred origin and currency.
  • Alert settings such as route, dates, budget, currency, stops, plan, status, health state, and schedule timestamps.
  • Flight search records, offers, matches, notification candidates, delivery attempts, errors, and provider message ids.
  • Operational logs and errors needed to run, secure, debug, and monitor the service.

4. Google Sign-In

LaniGo currently uses Google OAuth through Better Auth as the sign-in method. When you sign in with Google, LaniGo may receive and store account information made available by Google, such as your name, email address, profile image, provider account id, verification state, OAuth scopes, and OAuth tokens.

5. Alert And Flight Search Information

Public manual flight search does not require an account. Saved alerts require authentication and are linked to your user account. Alerts store the route, trip type, dates, budget, currency, stop preference, email notification setting, lifecycle status, search schedule, and the latest Alert Health information.

Flight searches and alert executions store provider, status, criteria, timestamps, errors, normalized offers, prices, routes, stop counts, expiry information, matches, Deal Score when available, and internal provider data. Provider raw data is not exposed through the public UI.

6. Technical And Session Information

LaniGo stores Better Auth sessions in PostgreSQL. Session records may include IP address, user agent, token, expiry, creation time, and update time. The API uses authentication cookies to validate sessions and protect account, alert, dashboard, and profile routes.

7. How We Use Personal Data

  • Authenticate users and maintain secure sessions.
  • Create, display, update, pause, resume, and expire user-owned alerts.
  • Run scheduled alert searches and store execution history.
  • Compare flight offers against alert budgets and stop preferences.
  • Send offer notifications and Alert Health advisory emails when enabled and configured.
  • Operate beta credits, account status, admin access, abuse protection, logging, and troubleshooting.
  • Improve reliability and product behavior based on aggregate operational metrics.

LaniGo does not sell personal data based on the current codebase and documentation.

8. Legal Bases For Processing

Depending on your location, LaniGo may rely on different legal bases, including providing the service you request, legitimate interests in running and securing the beta, compliance with legal obligations, and consent where required.

9. Cookies And Similar Technologies

The codebase uses Better Auth cookies for authentication. These cookies are configured as HTTP-only, SameSite=Lax, and secure in production. Better Auth sessions currently expire after 30 days and may be refreshed during use.

Hosting or infrastructure providers may set strictly necessary security, routing, or operational cookies. LaniGo does not currently use analytics or marketing cookies.

10. Service Providers And Third Parties

  • Google OAuth for sign-in.
  • Flight data services for live flight offer requests and airport discovery when configured.
  • Resend for transactional alert and advisory emails when configured.
  • PostgreSQL for application persistence.
  • Vercel for hosting the web application.
  • Railway for hosting backend services.

11. International Data Transfers

Some of our service providers may process data outside your country of residence. Where applicable, we rely on the safeguards provided by those service providers and applicable data protection laws.

12. Data Retention

Personal data is retained only for as long as necessary to operate the service, maintain account functionality, comply with legal obligations, and resolve disputes. Because LaniGo is currently in beta, retention periods may change as the service evolves. If you deactivate your account, your information is retained so that your account can be reactivated later unless you request deletion.

13. Account Deactivation And Deletion

The beta currently supports account deactivation and reactivation. Deactivation marks the account as deactivated, records the deactivation time, revokes active sessions, signs the user out, and stops alert execution while the account is deactivated.

Deactivation does not delete the user record, email, preferences, alert credits, alerts, searches, offers, matches, notification candidates, or timestamps. LaniGo does not currently provide a self-service account deletion feature.

14. Data Security

LaniGo uses authenticated routes for personal alert management, server-side ownership checks, HTTP-only authentication cookies, environment variables for secrets, and backend provider integrations. No system can be guaranteed perfectly secure. Users are also responsible for keeping their account credentials secure.

15. User Rights

Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, objection, or withdrawal of consent.

16. Children

LaniGo is not intended for children under the age of 16. If we become aware that we have collected personal information from a child below this age without appropriate authorization, we will take reasonable steps to remove such information.

17. Changes

LaniGo may update this policy as the beta changes, including when new notification, payment, analytics, or account management features are introduced. The page will show the latest update date.