Effective 5 August 2026
Privacy notice
Somewhere collects only the information needed to run your account, match trips to availability, coordinate with friends, and operate the service.
Who is responsible for your data
Somewhere is a personal project rather than a company. It is built and operated by one individual based in Eindhoven, in the Netherlands, and that person is the data controller: the one who decides why and how the personal data described here is processed. There is no company behind it, so there is no registration number to quote, and no data protection officer has been appointed because processing at this scale does not require one. Everything on this page, including any request about your own data, reaches the controller at flysomewhereapp@gmail.com.
Information you provide
This can include your name, email address, password hash or Google account identifier, departure airports, availability windows, saved or hidden destinations, notification settings, feedback, waitlist city, friend connections, and group membership. Passwords are stored as one-way hashes, not readable text.
Information created by using Somewhere
The service stores the account and group records needed to deliver its features, including invitations and notification delivery history. Essential session and security cookies keep you signed in and protect authentication flows.
Why your data is used, and on what legal basis
Every use of your data has a purpose and a legal basis under the GDPR behind it. Your account, availability windows, departure airports, saved and hidden destinations, friendships and group membership are processed to perform the contract you enter into by creating an account and asking Somewhere to find trips for you; without them the product has nothing to work with. Notification emails you have switched on rest on that same contract where they are simply the service doing what you asked, and on your consent where you opted into an alert you did not have to have; either way you can turn them off in settings and every email carries an unsubscribe link. Security, abuse prevention, rate limiting, keeping records of what was sent, and generally keeping the service standing are done on the basis of legitimate interests, weighed against your own by keeping that data minimal and short lived. Analytics and error tracking cookies rest purely on your consent, and nothing analytics related runs before you give it, as the next two sections describe. Only an email address is genuinely required to hold an account; everything else is optional and only changes how well the product can serve you. Somewhere does not make automated decisions that produce legal effects for you, and does not profile you in order to make them.
Cookies and your choice
Two kinds of cookies are used, and only one of them is optional. Strictly necessary cookies keep you signed in and protect authentication flows; the service cannot work without them, so they are not offered as a choice. Analytics cookies are optional and are switched off until you accept them. A banner asks on your first visit, nothing analytics related loads before you answer, and declining is a single click that carries the same weight as accepting. Your answer is stored in your own browser. You can change it at any time using the Cookies link in the footer: withdrawing consent stops further analytics collection and clears the analytics identifiers held in your browser.
Analytics and error tracking
If you accept analytics cookies, Somewhere uses PostHog for product analytics and error tracking, and PostHog processes that data in its European Union cloud region. Cookies and browser local storage are then used to recognise a returning browser across visits. While you are signed in, your account is linked to its analytics profile, so activity from one account on several devices is understood as one person. Session replay may record how pages are used, including page views, clicks and scrolling; everything typed into a form is masked in the browser before it is sent, so field contents such as your email address, availability dates and feedback text are not recorded. Invitation and unsubscribe links contain a private token, and that token is removed from the address before any analytics event leaves your browser. Somewhere also uses Vercel Web Analytics to understand page traffic; it sets no cookies, does not track you across sites, and reports only aggregated, anonymized measurements, so it runs regardless of the choice above. Do not put personal information into URL parameters because page paths may be measured. To object to analytics or ask for analytics data to be deleted, use the email address in the requests and questions section below.
Service providers
The application is hosted on Vercel, account and preference data is stored in MongoDB Atlas, Google may provide authentication, and email delivery uses the configured mail provider. These providers process data only as needed to supply their services and under their own terms.
Where your data is processed
Application data lives in MongoDB Atlas in the Frankfurt region, inside the European Union. Product analytics and error tracking are handled by PostHog in its European Union region. The Vercel functions that serve the site and its API are pinned to Vercel’s Frankfurt region (fra1), so requests are processed there rather than at whichever location happens to be nearest. The intent is that personal data stays inside the European Economic Area. That is not a claim that nothing has ever left it: supporting services such as Google sign in and email delivery are run by companies with infrastructure outside the EEA, and where such a provider moves data abroad it does so under the safeguards in its own terms, typically the European Commission’s standard contractual clauses. If this picture changes materially, this notice changes with it.
How long data is kept
Fare data and personal data run on two different clocks, and it is worth separating them. Fare observations are not personal data at all: they describe flights, not people, and they are not attached to your account. They expire on their own. An individual fare is removed 14 days after it was last seen, the one-way fare grids behind it 21 days after they were scraped, and the scraper’s own run logs 30 days after a run started. One record is deliberately durable: a daily price summary per route, kept indefinitely so the product can tell whether a price is genuinely low, which contains no personal data whatsoever.
Personal data is kept for as long as the account exists. Your profile, availability, saved and hidden destinations, preferences, friendships and group membership stay until you change them or delete the account, and deleting the account removes them. Two notification records outlive individual fares on purpose, because they exist to protect you rather than to study you: the record of which alerts you have already been sent, which is what stops the same news arriving twice, is deleted automatically 90 days after the send, and the delivery log that can answer which emails actually reached you is deleted automatically 180 days after the send. Where something has to be kept longer to deal with abuse or to satisfy a legal obligation, it is kept only for as long as that reason lasts.
Your rights
You can ask for a copy of the personal data held about you (access), have anything inaccurate corrected (rectification), have your data deleted (erasure), ask that processing be paused rather than deleted while something is being resolved (restriction), object to processing that rests on legitimate interests, including analytics, and receive the data you provided in a portable, machine readable form (portability). Where processing rests on consent you can withdraw it at any time; withdrawal stops the processing from that moment and does not make anything done beforehand unlawful. Exercising any of these is free, and you will not be treated differently for doing so. Day to day, you can also change availability, destinations, friendships, groups and notification settings inside the app whenever you like.
Exporting or deleting your data yourself
Two of those rights need nobody’s help. While signed in, your account can export everything held about it as a machine readable file, and it can delete itself along with the personal data attached to it. Those are served by the account endpoints GET /api/users/me/export and DELETE /api/users/me. Deletion is permanent and cannot be undone. Anything that cannot be handled this way, such as correction, restriction or objection, goes through the contact address below.
Complaints
If you believe your data has been handled wrongly, raising it at the contact address below is usually the fastest way to get it fixed, but you are under no obligation to try that first. You have the right to lodge a complaint with a supervisory authority. The competent one here is the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). If you live in another European Union country, you may complain to your own national authority instead.
Requests and questions
To ask for access, correction, or deletion of personal data, email flysomewhereapp@gmail.com from the address associated with the account. Identity may need to be verified before a request is completed. Requests are answered within one month, and if one turns out to be complicated enough to need longer, you will be told why inside that month.
Changes
This notice will be updated when the product’s data practices materially change. The effective date at the top identifies the current version.