What we collect
- Account info: your email address, a securely hashed password, when you signed up, whether your email is verified, and when you accepted these policies.
- Your plan data. Whatever you choose to enter. Depending on which features you use, that can include:
- Service record: branch, component, pay grade, rank, date of rank, TAFMSD/PEBD, retirement or separation dates, duty station and destination.
- Personal: your name (as you enter it) and date of birth.
- Health-related: your VA disability rating, the individual conditions and body sites you enter into the VA calculator, and — if you are going through a medical separation — your MEB referral date and TDRL status.
- Family: marital status, whether you have dependents, the number and school status of dependent children, spouse age and life expectancy, and (in the divorce calculator) marriage and divorce dates and support-garnishment status.
- Financial: base pay, High-3, TSP balances and contribution rates, other household income, filing status, and state of residence.
- Contacts you log: the names, phone numbers, and email addresses you record for offices and points of contact. Only enter other people's details if it's appropriate for you to do so.
- Payment info: handled by our payment processor (Stripe). We never see or store your full card number.
- Technical data: your IP address, used to rate-limit sign-up/login/reset attempts and to run the anti-bot check. It is also recorded in two places that we keep: in any feedback or support message you send us, and — as described below — alongside your acceptance of these policies.
- Feedback you send us: when you use the in-app feedback or correction form, we store the message you wrote, any reply address you gave, and the part of the app you were looking at when you sent it (the section, the regulation you were reading, and the text you flagged as wrong). We keep it in our own database — not just as an email — so that we can track whether it has been read and acted on, and so a fix can be traced back to the person who reported it. Please don't include anything in that box you wouldn't want us to keep.
- Your time zone. Your browser tells us which time zone it is set to (for example America/New_York), and we store it with your plan. By default we never ask you for it — it is read from your device automatically and updated if it changes — but you can set it yourself under Account → Email Notifications, and once you do, we stop following your device and use the zone you picked. We use it for exactly one thing: sending a reminder you asked for in the morning where you are, rather than in the middle of your night. It is a rough indication of your region, not your location — it cannot identify a city, an address, or a device.
- A record of the emails we decide to send you: for each reminder or notification, we keep which kind it was, when we considered it, and what happened — sent, or not sent and why (for example: you had switched that kind off, your address hasn't been verified, or we had already sent that one). We keep it so we never send you the same reminder twice, and so that "why didn't I get that email?" has an answer. It records the decision, not the content of your plan.
- Your agreement to these policies: when you create your account, and again whenever we update these documents and you accept the new version, we record when you accepted, which version you accepted, and the IP address you accepted from. This is the record that shows what you agreed to, and we keep it for as long as your account exists.
- Basic usage analytics: first-party, pseudonymous metrics (page/feature views, sign-up funnel, error and performance data) collected by us — no third-party analytics or advertising trackers. See Analytics & performance below, including how to opt out.
A note on sensitive data. Some of the above — disability ratings, medical-separation dates, and the conditions you enter — is health-related information, and some laws treat it as a special category. We collect it only because the calculators can't work without it, we never sell it, and you can delete it at any time. If you'd rather not store it here, you can use the calculators without saving a scenario.
What we do NOT collect
We do not ask for your Social Security Number, DoD login credentials, or other sensitive government identifiers. Don't enter them.
How we use it
Only to provide and improve the service — build your plan, run calculations, send the emails you ask for (verification, password reset, receipts, and any reminders you enable). We do not sell or rent your personal information, and we do not share it with third parties except the service providers below.
Analytics & performance
To improve WheelsUp and keep it reliable, we collect first-party analytics — meaning the data goes only to our own servers and is never shared with an outside analytics or advertising company. There are no third-party tracking scripts on the site or in the app.
- Product usage: which pages and features are opened, and anonymous sign-up/onboarding funnel steps — so we know what's useful.
- Errors & crashes: technical error details (message, source, timing) to find and fix bugs.
- Performance: page-load and request timing, plus basic server/host health.
These records are tied to a pseudonymous random identifier, not to your name. Event details are limited to a short allowlist of non-personal fields, and are filtered and size-capped before storage — but this is an automated filter, not a guarantee, so we don't send plan contents through it in the first place. We honor your browser's “Do Not Track” signal, and the public demo never sends analytics.
Your control: you can turn analytics off any time in Account settings → Privacy & Analytics. Turning it off stops your browser sending all telemetry, including error and performance data. Note that this preference is stored in the browser you set it in — if you use WheelsUp on more than one device or browser, set it on each. Our servers still record their own errors and request timings, which don't identify you and which we need to keep the service running.
Retention: raw analytics events are kept for up to 365 days and then deleted; only de-identified daily aggregates (counts and trends, with no individual identifiers) are kept longer. If you delete your account, your account identifier is removed from those rows. The pseudonymous random identifier stays attached until the row ages out, so the events remain grouped as one anonymous visitor — they are no longer connected to your email, your account, or your plan data.
Service providers
We rely on a small number of processors who handle data on our behalf. They process it only to deliver their piece of the service, and none of them are permitted to use it for their own purposes:
- Stripe (payments) — your email and payment details when you buy. Checkout is hosted on Stripe's own pages; no Stripe script runs on our site, and your card number never reaches us.
- Resend (transactional email) — your email address and the contents of account emails we send you (verification, password reset, receipts).
- Fly.io (application hosting) — hosts the app and the database your account and plan data live in.
- Cloudflare — serves and protects the site (so it sees request metadata including your IP), runs the anti-bot check on sign-up and password reset (which receives your IP), delivers messages you send through our contact form, and stores our encrypted database backups in Cloudflare R2.
- GitHub (Microsoft) — our automated backup job runs on GitHub's servers, so a copy of the encrypted database passes through it on the way to backup storage.
- Kit (formerly ConvertKit) — only if you enter your email into the waitlist form on our marketing site. That form is provided by Kit and your address goes to them so we can email you about launch. This is separate from your WheelsUp account; you can unsubscribe from any of those emails.
- Have I Been Pwned (breached-password check) — when you set or change a password, we check whether it appears in known public data breaches. Your password is never sent. We hash it on our server and send only the first five characters of that hash, which are shared by roughly one in a million passwords; the service returns a batch of possible matches and we do the comparison ourselves. It receives our server's address, not yours, and gets no information about who you are or which account is involved. If the service is unavailable we simply skip the check.
Our analytics is first-party — there is no third-party analytics or advertising vendor, and no advertising or tracking script anywhere on the site or in the app. We also self-host our webfonts rather than loading them from a font CDN, so that simply opening a page doesn't disclose your IP address to anyone else.
Security
Traffic is encrypted in transit (HTTPS/TLS) and your data is encrypted at rest. Passwords are salted and hashed — never stored in plain text. Your plan is isolated to your account. No system is perfectly secure, but we follow current best practices. See our Security page for details.
Your choices and rights
- Access and export your data at any time — the export includes your account record, your full plan data, your billing/entitlement record, and the analytics and error events still linked to your account.
- Delete your account and its data (see Data retention for the backup window).
- Turn off usage analytics in Account settings → Privacy & Analytics (or via your browser's “Do Not Track”).
- Unsubscribe from non-essential email.
Depending on where you live, you may have additional rights (e.g., under CCPA/GDPR). Contact us to exercise them.
Data retention
We keep your account and plan data while your account is active. When you delete your account, your account record, your plan data (including the time zone read from your browser), your record of which notification emails we decided to send, and your billing entitlement are removed from the live database immediately.
Two things outlive that deletion, and we'd rather say so than let you find out:
- Backups. We take an encrypted daily backup of the database and keep 30 days of them, so we can recover from a failure or a mistake. A backup taken before you deleted your account still contains your data until it ages out — up to 30 days. Backups are only ever used to restore the service, never to look anything up.
- Administrative audit log. If an administrator ever took an action on your account (for example, changing your access tier or resolving a support issue), that action is recorded in an append-only log that includes the email address it applied to. We keep it as an integrity record of who did what, and it survives account deletion by design.
Feedback you sent us is deleted with your account. If you were signed in when you sent it, the message and everything stored with it are removed when you delete your account, the same as the rest of your data. Feedback sent without being signed in isn't attached to an account, so there is nothing for a deletion to match it against. It is not anonymous either: as described above, it may include the reply address you chose to give us and whatever you wrote in the message. We keep that for up to 12 months and then delete it automatically. If you want a signed-out submission removed sooner, ask us and we will delete it.
Raw analytics events are retained for up to 365 days (de-identified daily aggregates may be kept longer); deleting your account unlinks them from you as described above. We may also retain data where the law requires it.
Children
WheelsUp is not directed to anyone under 18, and we don't knowingly let anyone under 18 create an account.
That's separate from the information you may enter about your family. Several calculators ask how many dependent children you have and whether they're in a qualifying school program, because those answers change your VA compensation and survivor-benefit figures. That data is about your dependents, entered by you, and we store no names or other identifying details for them.
Changes
We'll update this page and the "last updated" date when this policy changes; material changes will be communicated by email where appropriate.
Contact
Questions about your data? Ask a privacy question →