Privacy policy
This policy explains what personal data Drone Assistant processes, why, and what rights you have. It describes the service as it is actually implemented today.
Data controller
The controller for personal data processed through Drone Assistant is Fly-by Guys Oy, a company incorporated in Finland, operating the Drone Assistant product under the Flyby Guys brand.
Privacy contact: hello@flybyguys.com. Fly-by Guys Oy has not appointed a Data Protection Officer.
- Legal entity
- Fly-by Guys Oy
- Company type
- Finnish limited company (Oy)
- Business ID (Y-tunnus)
- 2915348-1
- VAT number
- FI29153481
- Registered address
- Antinkatu 3 D 00100 Helsinki Finland
- Domicile
- Helsinki, Finland
- Contact
- hello@flybyguys.com
What we process
Account information. Your email address, and a name if you provide one, together with account creation date and plan status.
Authentication information. Credentials and session information handled by our hosted authentication infrastructure, including sign-in with Google if you choose it.
Questions and answers. Questions you ask and the answers produced, including which sources were used and whether you marked an answer helpful. If you are signed in, these are linked to your account so your history is available to you.
Location input. Coordinates you enter, place on the map or share are used to evaluate official geographical and airspace datasets for that point. Saved locations are stored against your account.
Aircraft and preference information. Saved aircraft profiles, favourite jurisdictions and regulatory alert preferences.
Subscription and payment metadata. Plan, billing period, subscription status, payment provider customer and subscription identifiers, and the billing country used for tax. We do not receive or store full payment card details.
Support communications. Emails you send us and our replies.
Technical and log information. Our own database stores operational records such as request identifiers, session identifiers, timing and error details; it does not store your IP address or browser user-agent string. Separately, our hosting and database providers keep their own platform logs, which may include IP address, browser and device information.
Analytics information. Product usage events, collected only with your Performance consent (see Analytics below).
Why we process it, and on what basis
Providing the service — answering questions, evaluating locations, storing your history, aircraft and saved locations. Basis: performance of the contract with you, or steps taken at your request before entering it.
Account administration and authentication — creating and securing your account, signing you in, sending account emails such as confirmation and password reset. Basis: contract performance.
Billing and subscriptions — taking payment, managing renewals and cancellations, meeting accounting and tax obligations. Basis: contract performance and legal obligation.
Regulatory alerts and notifications — sending the alerts you have enabled for jurisdictions you follow. Basis: contract performance; you can turn these off in your account.
Support — responding to your enquiries and correction reports. Basis: contract performance or our legitimate interest in supporting users.
Security, abuse prevention and service reliability — logging, rate limiting and diagnosing faults. Basis: our legitimate interest in keeping the service secure and functioning.
Analytics and product improvement — Google Analytics 4 runs only if you allow Performance in the cookie preference centre. Basis: your consent. Separately, we record pseudonymous first-party product events to see which parts of the product are used and where they fail. Basis: our legitimate interest in operating and improving our own service.
Legal obligations — retaining records where required by law. Basis: legal obligation.
Where we rely on legitimate interests
Some processing rests on our legitimate interests under Article 6(1)(f) GDPR. We have carried out and documented a legitimate interests assessment (lia-1.0.0, assessed 2026-09-03) covering each of these activities, the interest pursued, why the processing is necessary and how it is balanced against your rights. It is an internal accountability record; the summary below is the public version, and you can ask us for more detail about any activity.
- Answer diagnostics — Establishing why a specific regulatory answer was produced, so that a wrong, incomplete or failed answer can be reproduced, diagnosed and corrected, and so that pipeline faults, retrieval regressions and latency problems can be found. Retention: Up to 90 days, technically enforced by the daily cleanup routine.
- First-party product analytics — Knowing which parts of the product are actually used and where they fail — for example whether jurisdiction selection, saved answers or the briefing flow are completed or abandoned — so that development effort and reliability work are directed by evidence. Retention: Up to 90 days, technically enforced.
- Public API usage records — Operating the API safely and correctly: enforcing quotas and technical rate limits, detecting abuse or credential misuse, investigating errors reported by an integrator, and understanding which endpoints carry the load for capacity and commercial planning. Retention: Up to 12 months, technically enforced.
- Answer feedback and correction reports — Detecting and investigating regulatory answers that users believe to be wrong, tracing them back to the underlying source or requirement, and correcting the corpus or the retrieval behaviour that produced them. Retention: Up to 12 months, technically enforced.
- Usage counters — Enforcing free-tier and plan quotas fairly, operating the subscription the customer bought, resolving disputes about whether a limit was correctly applied, and preventing misuse of an unmetered resource. Retention: Up to 12 months after the relevant usage period closes, technically enforced.
- Workspace audit events — Giving each customer organisation an accountable record of administrative actions inside its own workspace — who invited or removed a member, changed a role, or altered shared settings — so that an unexpected change or a suspected account compromise can be investigated by the customer. Retention: Kept for the life of the workspace; deleted when the organisation is deleted, and the actor is anonymised when that person deletes their account. No fixed expiry period; the existing model is assessed rather than replaced.
- Service security, abuse prevention and integrity — Keeping the service available and uncompromised: preventing credential abuse and request flooding, and allowing platform-level incidents to be diagnosed by the providers who run the infrastructure. Retention: Rate-limit state exists only for the length of a fixed window inside a running worker isolate and is never written to the database. Provider log retention is set by each provider: Supabase NOT VERIFIED, Lovable NOT PUBLISHED / NOT VERIFIED.
None of this processing profiles you, and none of it produces a decision with legal or similarly significant effects about you. Users should not submit personal information, and in particular sensitive personal information, that is not needed to answer a drone-regulation question. Where such content is incidentally present it is not sought, not indexed as a special category, not used for profiling and not used to make decisions about the individual, and it is removed with the surrounding record when the enforced retention period expires. Any incidental content requires appropriate handling under applicable law.
Your right to object. Where processing rests on legitimate interests, a person may object at any time under GDPR Article 21 on grounds relating to their particular situation. An objection is assessed on its own facts. Processing stops unless compelling legitimate grounds override the person's interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims. Some records — for example evidence that a statutory request was handled, or accounting material Fly-by Guys Oy is required by law to keep — may lawfully continue to be retained. An objection does not automatically require deletion or cessation in every case, and this document does not promise that it does. To object, email hello@flybyguys.com.
Google sign-in
If you choose to sign in with Google, Google authenticates you and returns basic account identity information to our authentication infrastructure — typically your email address, the fact that it is verified, a Google account identifier and, where available, your name and profile picture. This is used only to create and sign you into your Drone Assistant account.
Drone Assistant does not request or receive access to Gmail, Google Drive, Calendar, Contacts or any other Google service, and cannot read or write data in your Google account. You can revoke the connection at any time in your Google account settings.
Analytics
Drone Assistant uses Google Analytics 4 (measurement ID G-HG9X4XNTY8), and also records product usage events in its own database. Analytics only run after you give Performance consent in the cookie preference centre; if you decline or withdraw consent, they stop and queued events are discarded. Pre-consent activity is not backfilled.
The events we send use an anonymous per-session identifier and include information such as the event name, the selected jurisdiction, a question category and small numeric values such as source counts. We do not send names, email addresses, account identifiers, raw question text or precise coordinates; any location signal is coarse only. Google Analytics itself processes technical information such as IP address and device and browser characteristics for the purposes described in Google's own privacy documentation, so these analytics should not be regarded as fully anonymous.
Cookies and local storage
The cookie banner and preference centre are provided by ComplyDog, our cookie consent and preference management provider, acting as a processor under its published Data Processing Agreement. Your consent state is read in your browser; we do not copy a consent record into our own database. ComplyDog documents its primary data centre as DigitalOcean in Frankfurt, Germany, and publishes a subprocessor inventory that includes providers outside the EEA, so processing is not limited to Germany. Where ComplyDog holds a record, it documents that deleted personal data may remain recoverable for up to 90 days before permanent deletion and that backups may retain deleted customer data for up to 90 days. ComplyDog states that an appropriate transfer mechanism or safeguard is used where personal data leaves the EEA, but its documentation does not identify which mechanism applies to each recipient, so we make no claim about a specific mechanism here. You can reopen the preference centre at any time from the link in the footer.
Strictly necessary cookies and local storage keep you signed in, remember your theme choice, and remember your consent decision. These are used without optional consent. Checkout pages operated by our payment provider may also set cookies necessary for payment and fraud prevention.
Performance cookies and storage are used for Google Analytics 4 and our own product analytics, and are set only after you choose "Allow all" or enable Performance.
Functional and Targeting categories are shown in the preference centre but are not currently used.
Service providers and third parties
We use a small number of service providers and third parties. Not all of them act as our processors: some determine their own purposes for parts of the processing. The table lists the relationship where we have verified it, what each one is used for, and what it can see. Where we have not been able to verify a provider's role, processing location or transfer mechanism, we say so rather than assert it.
| Provider | Relationship | Purpose | Data involved | Outside the EEA |
|---|---|---|---|---|
| Lovable | Processor | Application hosting, build and delivery of the website and backend, and the AI gateway used for regulatory text processing. | Requests to the service, server logs, and text sent to AI models for extraction, translation and answer generation. | Yes |
| Supabase | Processor | Database, authentication and storage infrastructure behind the product. | Account identity and credentials, profile, question history, saved locations, aircraft, alerts and subscription metadata. | Not verified |
| Stripe | Payment provider | Payment processing, subscription billing, tax calculation and remittance, and invoicing. Stripe acts as our processor for parts of this and as a separate controller for its own payment, fraud and regulatory purposes. | Name and email, billing country, and subscription records. Payment instrument details are entered directly with Stripe and are handled by Stripe; Fly-by Guys Oy does not receive or store full card numbers. | Yes |
| Google Analytics 4 | Analytics provider | Product analytics, only after Performance consent. | Anonymous per-session identifier, event names, coarse usage attributes, plus technical data such as IP address processed by Google. | Not verified |
| Google Sign-In | Identity provider | Optional identity provider for signing in. Google determines its own purposes for the underlying Google account, which we do not control. | Email address, verification status, Google account identifier and, where available, name and profile picture. | Not verified |
| Google Maps Platform | Not verified | Place search and reverse geocoding when you search for a location by name. | The place text you type and the coordinates being resolved. Active only when the maps connector is configured. | Not verified |
| ComplyDog | Processor | Cookie banner, consent capture and preference centre. | Our application sends the current page URL as the widget's website parameter; the browser's own request to the widget script necessarily carries technical data such as IP address, user-agent and referer. Consent state is read client-side from the widget. We have not established from our own code what the widget itself stores or transmits. | Yes |
| AI model providers (via Lovable) | Downstream AI provider (via Lovable) | Extraction, classification, translation, embeddings and answer generation over retrieved regulatory text. Reached only through the Lovable AI gateway; we hold no direct credentials or endpoints with these providers. Several models are used, so no single provider is the exclusive recipient. | Question text, retrieved regulatory text, extraction and classification content, translation content and embeddings input. Account identifiers are not intentionally included with model requests, but question text is free text and may contain whatever a user chooses to type. | Not verified |
Our production database, authentication and storage project is hosted in Europe — Ireland (AWS eu-west-1). That verified fact concerns the production project region; it does not mean every subprocessor or support operation of that provider takes place in Ireland.
We use Lovable's AI gateway to provide AI-assisted answers. Your question and the relevant regulatory context we retrieve may be transmitted through that gateway to underlying AI model providers, which generate the response. Several models are used, so no single downstream provider is the exclusive recipient. We hold no direct accounts, credentials or endpoints with those model providers, so they sit within Lovable's downstream provider arrangements rather than as separate integrations of ours.
Under the Lovable Business plan and data processing agreement that apply to us, Customer Personal Data is not used to train, retrain or fine-tune AI models, and Lovable states that its contractual agreements with third-party AI providers restrict training on and retention of customer data. A specific AI-request retention duration has not been published or verified, so we do not state one. This processing may take place internationally: applicable contractual safeguards, including the European Commission's standard contractual clauses, are relied on, and we do not claim that AI gateway processing happens only inside the EEA.
Stripe receives your payment details directly and acts as a separate controller for parts of that processing. We do not receive or store full card numbers. We do not sell personal data and do not share it for advertising purposes.
International transfers
Some of these providers are established outside the European Economic Area, or may process data outside it. Where that happens, transfers depend on the safeguards set out in each provider's own terms, such as the European Commission's standard contractual clauses or an adequacy decision.
For our hosting, build and AI gateway provider, transfers are covered by that provider's data processing agreement, which provides contractual transfer mechanisms including EU standard contractual clauses. For payments, Stripe's published data processing terms incorporate the standard contractual clauses for applicable transfers. We do not claim that either provider processes exclusively within the EEA.
Pending confirmation: we have not yet individually verified the transfer mechanism or data residency for Supabase, Google Analytics 4, Google Sign-In, Google Maps Platform, ComplyDog, AI model providers (via Lovable). We therefore do not claim EU-only processing, and this section will name the specific mechanism for each provider once it is confirmed.
Retention
The table below sets out what we keep, why, and what actually happens today. Where a period is controlled by a third party or by a manual process, it is described as a target rather than a guarantee.
| Data | Basis | How long | How it ends |
|---|---|---|---|
| Account and profile | Contract | Duration of the account. | Account → Profile → Delete account (immediate), or by email request. |
| Authentication identity | Contract | Duration of the account. | Deleted with the account by the self-service deletion flow. |
| Question and answer history | Contract | Until deleted by you or with your account. | Account → History (per item or clear all); account deletion removes all of it. |
| Saved product data | Contract | Duration of the account. | Removed in-product, and removed entirely by account deletion. |
| Workspace membership | Contract | Membership: duration of membership. Workspace audit: retained by the workspace, de-linked from the deleted account. | Membership is removed on account deletion; audit entries are kept but the actor reference is cleared. |
| Subscription and payment metadata | Contract | Duration of the account, then only the provider reference needed for accounting. | The subscription row is removed on account deletion; the payment-provider customer reference is preserved in the deletion audit record for accounting reconciliation. |
| Invoices, accounting and tax records | Legal obligation | Financial statements, ledgers and lists of accounting records: 10 years from the end of the financial year. Accounting vouchers and related correspondence, including the invoice and payment records that evidence a transaction: 6 years from the end of the year in which the financial year ended. (set by a third party) | Not deletable on request while the statutory obligation applies. |
| Withdrawal requests and deletion records | Legal obligation | As long as needed to evidence handling of the request and any related claim. | Not deleted with the account; contains only the identifiers needed to evidence the request. |
| Operational and diagnostic records we control | Legitimate interests | Answer diagnostic records: up to 90 days. First-party product analytics events: up to 90 days. API usage records: up to 12 months. Answer feedback and reports: up to 12 months. Usage counters: up to 12 months after the relevant period closes. | Automatic daily cleanup (public.enforce_operational_retention), scoped strictly to records outside their retention window and callable only server-side. Account deletion separately removes or anonymises the records that are keyed to an account. |
| Platform and infrastructure logs (providers) | Legitimate interests | Unknown. Supabase provider log retention: NOT VERIFIED. Lovable platform log retention: NOT PUBLISHED / NOT VERIFIED. (set by a third party) | No application-level deletion mechanism exists; the providers control expiry. |
| Support, contact and regulatory correction messages | Legitimate interests | Up to 12 months after the enquiry is resolved. Longer retention may apply where reasonably necessary for an ongoing contractual matter, the establishment, exercise or defence of legal claims, a security or fraud investigation, a regulatory or compliance matter, or compliance with a legal obligation. (manual policy target) | Manual deletion by the operator, measured from resolution of the enquiry. |
| In-product answer feedback and reports | Legitimate interests | Up to 12 months. | Automatic expiry after 12 months. No per-user mechanism, because no user identifier is stored. |
| Consent records | Legal obligation | Retention of undeleted records is controlled by us as the customer, according to applicable law; once deletion is requested, up to 90 days before permanent deletion and up to 90 days in backups. (set by a third party) | Change or clear your choice in the preference centre, or clear browser storage. Where the provider holds a record, ComplyDog documents that deleted personal data may remain recoverable for up to 90 days before permanent deletion, and that backups may retain deleted customer data for up to 90 days. |
| Analytics | Consent | First-party product events: up to 90 days, enforced by us. GA4: event data 2 months; user data 14 months, reset on new activity. (set by a third party) | Withdraw Performance consent to stop collection. First-party product events expire automatically after 90 days. GA4 event-level and user-level data expire according to the property retention settings above. |
| AI provider request data | Contract | Third-party AI retention is contractually restricted through Lovable. The exact AI-request retention duration is not published and has not been verified. (set by a third party) | No application-level deletion mechanism; provider retention applies. Customer Personal Data held by Lovable is retained as necessary for the term of the agreement and can be returned or deleted following written instruction, subject to applicable exceptions; deleted data may persist in backups for a limited period whose duration is not published. |
Analytics retention: the Google Analytics 4 property is set to retain event data for 2 months and user data for 14 months, with reset on new activity enabled, so the 14-month user window restarts whenever the same visitor returns. These settings govern event-level and user-level data in the property; Google's standard aggregated reporting is not necessarily governed by the same controls.
Accounting and tax retention: Fly-by Guys Oy is a Finnish limited company and must keep accounting material under the Finnish Accounting Act (Kirjanpitolaki 1336/1997, Chapter 2 Section 10) and Finnish Tax Administration guidance. Financial statements, management reports, ledgers, the chart of accounts and lists of accounting records and materials are kept for 10 years from the end of the relevant financial year. Accounting vouchers, correspondence concerning business transactions and other supporting accounting material, including the Stripe invoice and payment records that evidence a transaction are kept for 6 years from the end of the year during which the relevant financial year ended, unless another law requires longer retention. This means certain billing, invoice and transaction records may be retained after your account is deleted, because we are legally required to keep them. The statutory period applies to the accounting material Fly-by Guys Oy is required to keep. It does not give account, profile or question-history data a six-year retention period, and it does not describe what the payment provider retains under its own legal obligations and policies.
Operational records we control: the operational records held in our own database are deleted automatically by a daily server-side cleanup. Answer diagnostic records are kept for up to 90 days, first-party product analytics events for up to 90 days, API usage records for up to 12 months, answer feedback and reports for up to 12 months, and usage counters for up to 12 months after the relevant usage period closes. Counters for a usage period that is still open are never removed. These are our own product retention controls and are separate from provider-controlled logs and from regulatory ingestion, monitoring and publication records, which serve a different purpose and are kept as evidence of how our regulatory content was produced.
Support and contact correspondence: ordinary correspondence you send to our contact and support routes, including hello@flybyguys.com, is kept for up to 12 months after your enquiry is resolved. The period runs from resolution of the enquiry, not from the date we received it. We may keep a specific message for longer where that is reasonably necessary for an ongoing contractual matter, to establish, exercise or defend legal claims, for a security or fraud investigation, for a regulatory or compliance matter, or to comply with a legal obligation.
Pending confirmation: the periods marked as third-party or manual are not enforced by the product itself. Our providers’ platform log retention periods are not visible from this project and have not been verified, so we do not state a period for them. For AI requests, training and retention are contractually restricted through Lovable, but the exact retention duration is not published.
Deleting your account
You can delete your account yourself from Account → Profile → Delete account. You will see exactly what will be removed before you confirm, and the deletion runs immediately. It removes your profile, question history, saved locations, aircraft, alerts, notifications, monitors, briefings and workspace memberships.
Some records deliberately survive deletion:
- Invoices and accounting records held by the payment provider — Retention is required by accounting and tax law and cannot be waived by request.
- The record that you requested deletion — Evidence that the request was received and carried out.
- Any withdrawal request you submitted — Evidence of how a statutory request was handled.
- Workspace audit entries and content shared into a workspace — These belong to the workspace, not to your personal account. Your identity is removed from them.
- Anonymous feedback and usage events — Recorded against a session identifier only and cannot be traced back to your account.
Deleting your account does not cancel a subscription and does not create a refund. If you have an active paid subscription, cancel it first from Account → Billing. You can also ask us to delete your account by emailing hello@flybyguys.com from the address associated with your account.
Your rights
Where the GDPR applies, you have the right to request access to your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to certain processing, to receive data you provided in a portable format, and to withdraw consent at any time where processing is based on consent — for analytics, by turning off Performance in the cookie preference centre. Withdrawing consent does not affect processing carried out before withdrawal.
To exercise any of these rights, email hello@flybyguys.com.
You also have the right to lodge a complaint with a supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Finland. You may also complain to the authority in your own country of residence.
Security
Access to production data is restricted, database access is protected by row-level security rules, and traffic is served over encrypted connections. No service can guarantee absolute security, but we take reasonable technical and organisational measures appropriate to the data we hold.
Children
Drone Assistant is intended for drone operators and professional users and is not directed at children.
Changes to this policy
We update this policy when the service or our providers change. Material changes will be reflected on this page.