onair.

YOUR DATA & CHOICES

Privacy policy.

Effective October 6, 2026 · Operator: OnAir

OnAir provides TV episode schedules, release-time estimates and a personal watchlist. This policy describes the current service at onair-tv-schedule.pages.dev. For privacy questions or requests, email holicoli304@gmail.com.

Browsing without an account

You can browse public schedules without signing in. Your browser’s timezone is used to display local times; OnAir does not store it in your account. Cloudflare hosts the website and processes connection information such as IP addresses, request details and browser information to deliver and protect the service. Infrastructure logs may be processed under Cloudflare’s own retention policies.

Information used for your personal space

  • Account: a username, account identifier, creation date, public passkey credentials and associated verification information. Your private passkey, fingerprint, face scan and device PIN stay with your device or passkey provider; OnAir does not receive them.
  • Sign-in: hashed session tokens and temporary, single-use verification challenges. Your browser holds an essential sign-in cookie.
  • Watchlist: the shows you save and when you save them, linked to your account.
  • Optional alerts: your browser’s push subscription endpoint and encryption keys, linked to your account. These allow notifications for followed shows.
  • Abuse prevention: short-lived hashed rate-limit identifiers derived from your IP address and a time window. OnAir does not put the raw IP address in its account database for this purpose.
  • Privacy inquiries: your email address and any information you choose to include when contacting us.

Why we use this information

We use account and watchlist information to provide the personal features you request. We use session and security information to verify sign-in and prevent abuse. Browser alerts require your permission and can be disabled at any time. Where applicable, these activities rely on providing the requested service, our legitimate interest in keeping it secure, and your consent for optional alerts. We use privacy correspondence to answer your inquiry or fulfill your request.

Cookies and browser storage

Essential OnAir cookies
CookiePurposeLifetime
onair_sessionKeep you signed inUp to 30 days; revoked on sign-out
onair_challengeVerify a single passkey operationUp to 5 minutes

Cloudflare may also set necessary security cookies when its protection features are used. See Cloudflare’s cookie information. Blocking essential cookies prevents account features from working. A service worker and push subscription are registered when you enable browser alerts. The current app does not use advertising cookies or add a third-party analytics script.

Services that process information

  • Cloudflare: hosts OnAir, stores account data in D1 and runs the notification service. Its network and service providers can process data internationally. See Cloudflare’s privacy policy.
  • TVmaze and image hosts: provide TV metadata and posters. Catalog searches are sent directly from your browser to TVmaze, which receives the search query and standard connection information. Loading remote posters also sends connection information to their hosts. See TVmaze’s privacy policy.
  • Your browser’s push provider: processes delivery information when you opt into alerts. The provider depends on your browser or device, such as Google, Mozilla, Apple or Microsoft. Notifications may display show names on your lock screen, depending on your settings.
  • Email: privacy messages sent to the Gmail address above are processed by Google’s email service. See Google’s privacy policy.

OnAir does not sell personal information or share your watchlist with advertisers. Information may also be disclosed when legally required or necessary to protect the service.

How long information is kept

Your account, public passkey records and saved shows remain until you delete the account or remove the relevant saved shows. Push subscriptions remain until you disable them, delete your account, or the push provider reports they have expired. Sessions expire after 30 days, challenges after 5 minutes and rate-limit records after their 10-minute window; expired records are removed during routine cleanup. Notification events are kept for up to 7 days before routine cleanup. Cloudflare backups and infrastructure logs can have separate retention periods. Privacy correspondence is kept for as long as needed to resolve your request and meet applicable obligations.

Your controls and rights

Open your account controls to export your saved list, turn off browser alerts or delete your account. Deleting your account removes its active account records, passkeys, sessions, favorites and push subscriptions. You can also revoke notification permission in your browser. This does not automatically remove copies retained in provider backups, which expire under the provider’s retention rules.

Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, request portability, withdraw consent, or complain to your local data protection authority. Email holicoli304@gmail.com for requests not covered by the account controls. We may need to verify ownership before changing account information. Keep a synced or backup passkey: there is no password or email-based account recovery.

Changes to this policy

We will update this page and its effective date when the service’s data practices change.