Back to search

Privacy Policy

Effective and last updated October 8, 2026 · Version 2026-10-08

This Policy explains how Sweep Flights LLC collects, uses, discloses, and retains information when you use Sweep.

Scope and operator

Sweep Flights LLC, a Michigan limited liability company, operates the Sweep website and is responsible for the information practices described here. Sweep is intended for adults in the United States. This Policy applies to the website, account features, flight search, Ask Sweep, saved flights, price alerts, shared links, and feedback.

Information you provide

  • Account information: name, email address, password credentials stored in protected form when used, linked sign-in provider identifiers, verification status, and account-security records.
  • Trip and preference information: airports, dates, trip length, travelers, cabin, currency, timing requirements, saved flights, alert settings, and usual departure location.
  • Ask Sweep content: messages, conversation context, tool results, and supported changes you ask the assistant to make.
  • Account activity: usage allowance, saved and shared items, price checks, booking-link selections, and newsletter consent and legal-acceptance records.
  • Feedback: the category, title, details, page address, browser user-agent string, and application version included with a submission.

Sweep does not currently take payment or issue tickets, and it does not request or provide dedicated fields for passport numbers or airline payment-card details. Ask Sweep accepts free-form text, so do not include that information in a message. Information you enter after leaving Sweep is governed by the destination provider.

Information collected automatically

  • session, verification, security, guest-trial, and theme identifiers stored in cookies or browser storage;
  • IP address, request timing, requested route, and limited device or browser information needed to operate, secure, and rate-limit the service; and
  • provider request counts, errors, and technical records needed to prevent duplicate work and protect paid integrations.

When you have not saved a usual departure location, Sweep may send your public IP address to ipwho.is to infer a city and suggest a nearby departure airport. This does not use browser GPS permission. The in-process location result is cached for up to six hours and does not replace a location you choose.

How Sweep uses information

  • provide, personalize, and maintain flight-search features;
  • create accounts, verify email, and secure sessions;
  • preserve a trip through signup and restore saved work;
  • operate Ask Sweep and interpret natural-language date rules;
  • send requested account, security, and price-alert email;
  • remember newsletter choices without sending campaigns yet;
  • enforce usage limits, prevent fraud, and investigate failures;
  • respond to feedback and improve reliability and ranking;
  • measure and improve Sweep’s advertising; and
  • comply with law and protect users, Sweep, and third parties.

Product analytics

Sweep uses PostHog to measure site visits, search completion, speed, provider request counts, saved-flight use, booking-link handoffs, and account signup. These events use pseudonymous account and planning identifiers and limited counts and status information. When you open Sweep from outside the site, the visit records only the kind of page opened, the referring site’s domain if your browser shares it, and whether you followed a Facebook or Instagram link; it is not linked to you or your later activity. Search, booking-link, and signup events note whether your browser arrived from a Facebook or Instagram link, unless you have opted out below. Guest activity in the browser where you sign up or sign in may be linked to your member account.

These analytics do not include your name, email address, search airports or dates, conversation text, booking URLs, or payment information. Sweep does not send your IP address to PostHog or use PostHog session recording, automatic click collection, or analytics cookies. Analytics records are separate from your saved flights and booking history and may remain under the analytics retention settings after those items or your account are deleted.

Advertising measurement

Sweep advertises on Facebook and Instagram. If you arrive at Sweep by following a link from Facebook or Instagram, such as one of our ads, Sweep’s server tells Meta when you run a Sweep with results, open a booking link, or create an account. Meta uses this to measure which ads work and to choose who sees Sweep’s ads, and it may connect this information to your Facebook or Instagram account.

For those events, Sweep sends the event type and time, the Sweep page address without search details, Meta’s ad-click and browser identifiers, your IP address and browser user-agent string, and a hashed Sweep account identifier. When you create an account, it also sends a hashed copy of your email address. Sweep does not send your name, airports, dates, prices, conversation text, or booking URLs. Meta processes this information under its own terms and policies.

Nothing is shared about visitors who did not arrive from Facebook or Instagram, or about anything members do after creating an account. To credit a new account to the ad that led to it, Sweep keeps the ad-click identifier, IP address, and browser details from the signup browser until the account is verified, and deletes them when the event is sent or after 30 days.

To opt out, select “Do Not Sell or Share My Info” at the bottom of the search page, or enable Global Privacy Control in your browser. Sweep then stops saving Meta’s ad-click identifier in that browser and sends Meta nothing about your visit. You can also manage how Meta uses information for ads in your Facebook or Instagram ad preferences, or through the Digital Advertising Alliance.

AI-assisted features

Ask Sweep messages and relevant trip context are sent to OpenAI’s API to generate responses, structured edits, and travel research. Sweep stores a bounded recent conversation for a rolling 24-hour period by default so the workspace can continue across requests.

The current integration asks the OpenAI Responses API to store response state. OpenAI states that API data is not used to train its models by default unless the customer opts in. Under the standard configuration, stored Responses API state is retained for at least 30 days, while abuse-monitoring logs may be retained for up to 30 days, subject to OpenAI’s stated exceptions. OpenAI’s current practices are described in its API data-controls documentation. Do not put passport numbers, payment-card information, health records, or other highly sensitive information in Ask Sweep.

When information is disclosed

Sweep discloses information only as reasonably needed to:

  • Hosting and storage providers that run the website and Postgres database, currently including Railway;
  • Identity providers, currently Google, for optional account sign-in;
  • Email providers, currently Resend, for verification, recovery, and requested price-alert messages;
  • Flight and location providers, including SerpApi and ipwho.is, to return airport and flight information or infer a starting city;
  • AI providers, currently OpenAI, for the features described above;
  • Product analytics providers, currently PostHog, for the limited usage measurements described above;
  • Advertising platforms, currently Meta, for the advertising measurement described above;
  • Booking destinations you choose to open, such as an airline or Google Flights; and
  • authorities, advisers, or transaction participants when reasonably necessary for legal compliance, safety, fraud prevention, or a merger, financing, or transfer of the business.

These providers process information under their own agreements and policies. Sweep does not sell personal information for money. Its Meta advertising measurement may be considered “sharing” for cross-context behavioral advertising under some U.S. state laws; you can opt out as described above.

Public shared links and third-party sites

When you create a shared-flight link, anyone with the link can view the saved itinerary and recorded price until the link expires. The page does not display your name or account identity. Do not share a link with anyone you do not want to receive it.

When you open a third-party booking or research site, that site receives information normally sent by your browser and may receive itinerary details encoded in the destination link. Its privacy policy—not this Policy—governs what happens there.

Cookies and browser storage

  • essential authentication cookies keep you signed in and protect account access;
  • a signed guest-trial cookie remembers a browser’s allowance for up to one year;
  • a one-year theme cookie and matching local-storage value prevent a light/dark theme flash;
  • temporary session storage may remember an email address long enough to make verification easier;
  • when you arrive from a Facebook or Instagram link, a first-party ad-click cookie (_fbc) for up to 90 days, unless you have opted out; and
  • a one-year cookie that remembers an advertising opt-out.

Sweep does not currently load third-party advertising scripts or cross-site behavioral analytics in your browser. Blocking essential cookies may prevent account and guest features from working.

Retention

  • active workspace checkpoints, recent trusted search results, and Ask Sweep sessions generally expire after 24 hours;
  • public shared-flight links generally expire after seven days;
  • saved flight information is retained through the itinerary’s final travel date unless you remove it sooner;
  • account, profile, booking-handoff history, feedback, legal acceptance, and email-preference records remain while the account exists unless you delete the affected item or account;
  • hashed rate-limit counters expire with their applicable security window; Sweep does not store raw IP addresses or email addresses in those counters;
  • signup advertising-attribution records are deleted when the account conversion is sent to Meta, or after 30 days; and
  • anonymous guest-allowance records may be retained to enforce the one-time trial but do not contain a guest’s name or email address.

Sweep may retain information longer when reasonably necessary to resolve a security incident, enforce an agreement, comply with law, or preserve a legal claim. Service providers may apply their own retention periods.

Your choices

  • edit your name and travel preferences in Profile;
  • turn product-news email on or off independently of operational email;
  • pause or remove configured price alerts;
  • opt out of sharing for advertising with “Do Not Sell or Share My Info” on the search page or with Global Privacy Control;
  • remove saved flights and booking-history entries; and
  • delete your account from Profile, which removes the account and its Sweep-controlled saved flights, history, preferences, assistant conversations, and feedback.

Browser controls can remove cookies and local storage, although doing so may reset presentation preferences or require another sign-in. Signed-in users may also use Feedback for questions about Sweep’s data practices.

Security

Sweep uses technical and organizational safeguards designed to protect information, including access controls, protected credentials, authenticated account mutations, rate limits, and encrypted network transport in production. No service can guarantee absolute security.

United States processing

Sweep and its providers process information in the United States and other locations where they operate. The service is not currently directed to residents of the European Union, United Kingdom, or Canada. Broader regional availability will require updated disclosures and controls.

Children

Sweep is for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children under 13. If we learn that we have done so, we will take reasonable steps to delete it.

Changes to this Policy

Sweep may update this Policy as its data practices or legal obligations change. The current version and effective date will remain available here. Account holders will be asked to acknowledge material updates before continuing to use authenticated features when appropriate.