AwardWise

Privacy Policy

How AwardWise handles your data, written to match what the product actually does, in plain language.

Plain-language draft, not legal advice. This page describes AwardWise's actual data practices during its beta. It is a working draft and has not been reviewed by a lawyer; have counsel review it before any wide public launch.

Effective date: August 10, 2026

The short version

What we collect

Account & sign-in. When you create an account we use Firebase Authentication (a Google service). This gives us your account identifier and the identity details of your chosen sign-in method (for example, your email address).

What you enter to use the product. Your flight searches (origin, destination, date, cabin), and any wallet details and personal point valuations you choose to enter, are processed to return results and are stored with your profile so the app works across sessions.

Optional beta research logging (opt-in only). If and only if you turn on research logging, AwardWise records "research events" for your sessions. Based on the current implementation, these can include:

Research events are stored in our Firebase Realtime Database and are linked to your account identifier. They are therefore pseudonymous, tied to your account, not fully anonymous. That link is also what lets us find and erase your research data if you ask us to.

If you have never opted in, none of the above is written. There are no research events and no record of your sessions in our research storage.

Automated redaction (and its limits)

Before research text is stored, we automatically mask common sensitive patterns we can detect: email addresses, long card-like number sequences, access tokens and API keys, and authorization headers. This masking happens at the moment of capture, and access to research data is restricted to the development team; data is further restricted and reviewed before any research is shared publicly.

Honest limitation: this redaction is pattern-based and best-effort. It will not catch every kind of sensitive information, for example a name, an address, or an unusual number format typed into free text. Please avoid entering information you would not want logged while research logging is on.

What we don't do

Who else receives data

Flight-data providers (Seats.aero and SerpAPI). To search award and cash flights, we must send your search parameters (route, date, cabin) to these providers. This happens for every search so the product can function, whether or not you've opted into research logging.

Infrastructure providers. We use Google Firebase for authentication and data storage, and Stripe for subscription billing where applicable. These providers process data on our behalf under their own terms.

Access to research data is limited to the AwardWise development team; we do not sell it or share it publicly without the redaction and review described above.

Your choices & controls

Research logging is unchecked by default when you register. You can change it at any time:

Turning research logging off stops future collection right away. Subsequent turns are not recorded as research events. As the in-app note says, turning it off does not by itself change data already collected; see below.

Your rights

Access. To ask what data we hold about you, contact us (below).

Deletion. You can ask us to delete your data by emailing support@awardwise.ai (there is no self-serve delete button in the app yet). When we process a deletion request we:

If any individual deletion step fails (for example a transient database error), the exclusion above still applies immediately, the failure is recorded so the erasure can be retried, and anything residual is removed by the retention limit below. Data that was already excluded can never be promoted into a research dataset.

Data retention

Research events are kept for at most 24 months, then deleted. We remove research records older than that window.

Profile data (your wallet entries, valuations and settings) is kept while your account is active, and is deleted when you ask us to delete your account.

Regional privacy laws

AwardWise is a small, invite-only beta run from the United States and is not directed at residents of the EU, EEA, or UK. We are also currently below the size thresholds at which laws like the California Consumer Privacy Act apply. Rather than sorting users by region, we simply extend the same practical protections to everyone: we do not sell personal data, research logging is opt-in only, and anyone can ask what we hold about them or have it deleted (see Your rights above). If we open the beta to the public, begin charging, or start serving users in regions with specific privacy laws, we will expand this section and have it reviewed by counsel first.

Changes to this policy

As AwardWise is in active beta, these practices may change. We'll update this page and its effective date when they do.

Contact

Questions, access requests, or deletion requests: support@awardwise.ai.