VS Points

Privacy Policy

Last updated: 3 August 2026

This policy describes how the VS Points iOS app ("VS Points", "the app", "we", "us") handles information. The app is listed on the App Store as VS Points and appears as Points on your home screen — both names mean the same app. It is made by Sam Davis, an independent developer based in the United Kingdom.

The short version: you never create an account or sign in, and we never ask for your name, email or payment details. Your saved flights stay on your device. What does leave it — including how you use the app — is listed below, in full.

What stays on your device

The flights you bookmark are held in the app's own storage on your iPhone, and are removed when you delete the app. We never receive which flights they are. Your Points Plus subscription status is cached there too, so the app knows what to unlock before it can reach the App Store.

Two things qualify that. Price alerts are stored on our servers as well as your device — they have to be, because our servers are what check prices while the app is closed; see below. And our analytics record how many flights you have saved, how many alerts you have, and whether you subscribe — never which flights are involved.

What leaves your device

Your installation identifier

The first time the app runs it creates a random identifier for your installation. It is not your name or your email address, and you never create an account or sign in to get one. It is held in your device's keychain, which means it survives deleting and reinstalling the app.

Everything described below that leaves your device is recorded against this identifier: your price alerts, your analytics activity, and the affiliate links you tap.

Your Apple Account

On its first launch that can reach us, the app also sends Apple's signed app transaction for your installation to our server. Apple issues an app transaction to every installation of an app, whether or not anything has ever been purchased. Our server verifies it with Apple and records the identifier it contains — Apple's appTransactionId — against the installation identifier above.

That identifier is assigned by Apple and is tied to the Apple Account that downloaded the app. It is not your Apple Account itself, your name, or your email address, and it gives us no access to your Apple Account. We hold it so that a Points Plus subscription bought on your Apple Account can be matched to your installation — which is how our servers know whether your subscription is active when they decide whether to send you a notification.

Flight searches

Reward seat availability is served from our own database, and a search reads from it rather than writing to it. The search is still recorded in our analytics, however: the routes, dates and cabin classes you searched for are sent to the providers listed under Analytics below, against the installation identifier described above.

As with any internet request, our hosting provider (Google, see below) processes technical connection data such as your IP address in order to serve the response.

Price alerts and notifications

Once you allow notifications — which the app asks for when you create your first alert — a push notification token issued by Apple is stored against your installation identifier, so that a notification can reach your device. It is replaced whenever Apple issues a new one, and it stays on our servers until then. Deleting your alerts does not remove it.

If — and only if — you create a price alert, the app also sends the following to our database, so that our servers can check prices while the app is closed and notify you:

Deleting an alert in the app removes its record. Alerts also expire automatically once the flights they watch have departed.

Intelligent search (Points Plus)

When you describe a trip in your own words, the text you type is sent to Google's Gemini models, via Firebase AI Logic, to be turned into a structured search. Only your typed request and the current date are sent to the model. Your typed request is also recorded in our analytics, as described below. Please do not type personal or sensitive information into this field.

Analytics

The app uses PostHog, hosted in the European Union, and Firebase Analytics for product analytics. Both receive the same events, recorded against the installation identifier described above, so that activity from a single installation can be followed over time.

These events describe how the app is used: the app being opened, finishing the welcome screen, the screens you visit, searches performed and how many results they returned, how you sort them, flights viewed and saved, price history ranges opened, alerts created and removed, whether you allowed notifications and when you tap one, booking links opened, paywalls shown, and subscriptions started, cancelled or lapsed. Search events include the routes, dates and cabin classes you searched for.

We also record a handful of properties describing the installation itself: whether you subscribe to Points Plus and on which plan, how many flights you have saved, how many alerts you have, and whether you have allowed notifications.

For intelligent search, the words you type are recorded verbatim in PostHog — though not in Firebase Analytics — so that we can see what people ask for and improve how the app understands it.

Errors are captured automatically. Screen recording, automatic tracking of taps and other element interactions, and rage click detection are all switched off.

Crash and error reporting

The app uses Firebase Crashlytics to report crashes and handled errors, so that failures can be found and fixed. These reports include technical information such as your device model, iOS version, and where in the app the failure occurred. When an intelligent search fails, the report also carries the model's raw response, which can repeat back part of what you typed.

Booking links

When you tap through to book a flight, the app opens Virgin Atlantic's website through CJ Affiliate, an affiliate network. This link carries the installation identifier described above, so that a completed booking can be matched to the journey that led to it. We may earn a commission on bookings made this way, at no extra cost to you. Once you arrive on Virgin Atlantic's website, their own privacy policy applies to anything you do there.

Subscriptions

Points Plus subscriptions are sold and processed entirely by Apple. We never see or receive your payment details. The App Store tells the app whether a valid subscription exists — nothing more. Our servers learn the same thing through the Apple Account link described above, so that notifications can be paused when a subscription ends.

If you email support

Nothing is sent anywhere unless you choose to email us. When you tap the support email link in the app, your mail app opens with a message already started, and the app fills in your app version and the installation identifier described above, so that we can find the right alerts and subscription state when investigating. The subject line also indicates whether you hold a Points Plus subscription. You can see all of it before you send, and you can delete any of it.

If you do send it, we then hold that email — including your email address and anything you write or attach — in our mailbox, for as long as we need it to deal with the problem and to keep a record of what was reported. We use it only to answer you and fix the issue, and we don't add you to anything.

What we never collect

Service providers

We use the following providers, each of which processes data on our behalf:

We do not sell your information, and we do not share it with anyone for their own marketing.

Retention

Alert records live until you delete the alert, or until the flights they watch have departed, whichever comes first. Your installation identifier, your push notification token, and the Apple app transaction identifier held against them remain until they are replaced or until you ask us to remove them — deleting the app does not clear them, because the installation identifier survives in your device's keychain. Analytics and crash reports are retained according to the providers' standard retention periods. Your saved flights and everything else held in the app's own storage are erased when you delete the app; the installation identifier in the keychain is the one exception.

Your rights

Depending on where you live, you may have the right to access, correct, or delete information relating to you. Because the app holds no accounts and no contact details, the practical route is to contact us and describe what you would like removed — see below. Deleting the app removes your saved flights and everything else in the app's own storage immediately, though the installation identifier stays in your device's keychain.

Children

VS Points is not directed at children under 13, and we do not knowingly collect information from them.

Changes

If this policy changes, the date at the top of this page changes with it. Material changes will be called out in the App Store release notes for the update that introduces them.

Contact

Sam Davis
sam@samapps.co.uk