← Captain Egghead

Privacy Policy

Last updated: June 2026

Captain Egghead is operated by an individual based in the United Kingdom. This policy explains what personal data we collect, how we use it, and your rights under UK GDPR.

1. What we collect

  • Email address — when you create an account.
  • Password — stored as a one-way hash. We cannot read it.
  • Airline name — optional, collected at registration to understand our users. Never shared publicly.
  • Payment information — handled entirely by Stripe. We receive a customer ID and subscription status only. We never see or store your card details.
  • Saved routes — departure and destination airport codes you choose to save, stored on our server linked to your account.
  • Favourited facts — stored locally in your browser (IndexedDB). We never receive these.

2. How we use it

  • To provide the service — authenticate you and gate access to the app.
  • To process your subscription via Stripe.
  • To send password reset emails when requested.
  • To understand who is using the service (airline field, aggregate only).

We do not sell your data. We do not share it with third parties except as described below.

3. Third parties

  • Stripe — payment processing. Stripe Privacy Policy
  • Resend — transactional email (password resets only). Resend Privacy Policy
  • Railway — hosting. Our server and database run on Railway's infrastructure in the EU/US. Railway Privacy Policy

4. Cookies & local storage

We use a single session cookie to keep you logged in. No advertising or tracking cookies are set. The app stores favourited facts and saved route preferences in your browser's local storage — this data never leaves your device.

5. Data retention

We retain your account data for as long as your account is active. If you cancel your subscription and wish to delete your account, email hello@captainegghead.com and we will delete all your data within 30 days.

6. Your rights (UK GDPR)

You have the right to access, correct, or delete the personal data we hold about you. You also have the right to object to processing or request restriction. To exercise any of these rights, contact us at hello@captainegghead.com.

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).

7. Security

All data is transmitted over HTTPS. Passwords are hashed using Django's default PBKDF2 algorithm. Payment data is handled entirely by Stripe and never touches our servers.

8. Changes to this policy

We may update this policy occasionally. Material changes will be notified by email. Continued use of the service after changes constitutes acceptance.

9. Contact

hello@captainegghead.com