Cookie Policy
Status: DRAFT — requires legal review before publishing. This document is unusually short compared to most cookie policies, because it describes what we actually do rather than a generic list of possible tracking technologies. Placeholders are marked <span class="doc-placeholder">[ ]</span>.
Effective date: [ ] · Last updated: [ ]
The short version
FlightDesk AI does not currently use cookies for tracking, analytics, or advertising — on the marketing website or inside the application. The only thing resembling this category is a small piece of technical storage that keeps you logged in, which is described below. There is no cookie consent banner on this site today because there is nothing beyond strictly necessary technical storage to ask consent for. If that changes, this policy — and the site — will change to add proper consent, not the other way around.
What we actually use
The FlightDesk AI application (app.flightdeskai.com)
When you log in, the application keeps you signed in using browser local storage (not a cookie) to hold your session securely. This is:
- Strictly necessary — without it, you'd have to log in again on every page. Under the ePrivacy rules that govern cookies and similar technologies, storage that is strictly necessary to provide a service you've actively requested (staying logged in) does not require consent, the same way a login cookie wouldn't.
- Not used for tracking. It holds your session token, not browsing history, advertising identifiers, or behavioral data.
- Cleared when you log out, or when the session naturally expires.
<span class="doc-placeholder">[Note the technical distinction for whoever reviews this: this is localStorage, not an HTTP cookie. Some regulators and guidance treat "similar technologies" (including localStorage) under the same strictly-necessary exemption as essential cookies when used this way — worth confirming this framing holds under Czech/EU guidance specifically, since enforcement practice on this point isn't perfectly uniform across the EU.]</span>
The marketing website (flightdeskai.com)
The marketing site — the pages describing the product, pricing, and how to get in touch — uses no cookies, no local storage, and no third-party scripts as of this draft. There is no analytics tool (no Google Analytics, no Pendo, no equivalent), no advertising pixel, and no embedded third-party widget that would set its own cookies.
<span class="doc-placeholder">[This is true as of when this policy was written. If analytics, a chat widget, or any embedded third-party tool is added to the marketing site later, this section must be rewritten before that change ships — not after. Adding tracking silently while this policy still says "we use none" would itself be a compliance problem, independent of whatever the tracking tool does.]</span>
If this changes
If we add analytics or any non-essential tracking in the future, we will:
- Update this policy to name the specific tool, what it collects, and why
- Add a proper consent mechanism (a cookie banner allowing you to accept or decline before anything non-essential loads) — not a pre-ticked box, and not a banner that only offers "accept"
- Only activate non-essential storage after you've actively consented, not before
Your browser controls
Even though we don't currently set tracking cookies, you can control local storage and cookies generally through your browser settings — clearing them will simply log you out of FlightDesk AI, since that's what the storage exists for.
Contact
Questions about this policy: <span class="doc-placeholder">[privacy email]</span>
A note on how this document was built
Most cookie policies are written defensively, listing every category of tracking technology a company might use, whether or not it actually does. This one describes what was actually verified in the codebase while drafting it: session storage uses localStorage, not cookies; no analytics or advertising scripts are present on either the app or the marketing site. If that changes, the honest move is to update this document before shipping the change, not retroactively.