Skip to content
AvFees

Privacy notice

What AvFees collects, why, where it is kept and who processes it. AvFees shares what a stop costs, never who flew it.

Who runs AvFees

AvFees (avfees.com) is a VOL and ForIT company, operated by VOL Private Aviation Inc. (“VOL”) and ForIT LLC (“ForIT”; together “we”). ForIT builds and runs the site, the API and the MCP server. Questions about this notice or your information go through the contact page.

Your account, from Microsoft sign-in

You sign in with a work Microsoft account. We do not see or store your password. From the sign-in we keep your Microsoft object ID and tenant ID, your email address and display name, when the account was created and when you last signed in, whether your email address was verified by the sign-in, your plan (credits or subscription) and whether the account is active.

A signed-in session is a signed cookie (avf_session) that lasts up to 30 days. Azure App Service authentication, which handles the Microsoft sign-in, sets its own sign-in cookie. When you connect an AI assistant through the MCP server, a short-lived cookie (avf_oauth_req, 15 minutes) holds the pending request while you approve it. AvFees uses no advertising or analytics cookies and no third-party trackers.

API keys and connected apps

An API key is shown once, when it is created. We store only a SHA-256 hash of it, its prefix, the account and email that created it, its scopes, when it was created and last used, and when and why it was revoked. When an AI assistant connects through OAuth, we store the app's registered name and redirect addresses and hashes of the access and refresh tokens issued to it, with their expiry and revocation times.

Invoices you send, and the email they arrive in

You can upload an invoice through the API or forward it to invoices@avfees.com. That address is a Microsoft 365 mailbox; the email you forward, with its attachments, stays in that mailbox. AvFees reads it and does not move or delete it. For each email we record its message ID, the sender's address, when it arrived, whether it matched a verified account, and the result or error. We send a receipt to the sender through Azure Communication Services Email.

An invoice is first read by software running inside AvFees. When that cannot find the fee lines, the invoice (the PDF, image or email text) is sent to Anthropic's API, where a Claude model reads the fee lines out of it. The model's output goes through the same checks as every other contribution, and any identifying terms it reports are used only to scrub the FBO name and are never stored.

The fee database does not keep the invoice file. It keeps a SHA-256 fingerprint of it, used to spot duplicates, and a record of the submission: the key that sent it, its status, how many lines it had and the credits it earned.

Fee observations

Each fee line is stored as an observation: airport (ICAO) and region, FBO or airport authority, aircraft class, fee type, amount and currency, the date it was observed, any fuel volume that waives the fee, and the fingerprint of the invoice it came from. Tail numbers, operator, customer, crew and passenger names, trip and account numbers and free-text notes are stripped before storage. The Data & privacy page lists exactly what is kept and dropped.

Credits are kept in a ledger: each grant, contribution and lookup, with the change in credits.

Messages to us

A message sent through the contact form is emailed to the AvFees team at VOL and ForIT through Azure Communication Services Email with your name, email address, topic, message and, if you are signed in, your account email. AvFees does not store it in its database. To limit abuse, the site counts how many messages each IP address has sent in the last hour, in memory only.

Where it runs and who processes it

AvFees uses these service providers to run:

  • Microsoft Azure (App Service, Azure SQL Database and Key Vault, in the Central US region) hosts the site and the database. The app reaches the database through a managed identity rather than a stored password.
  • Microsoft Entra ID handles sign-in, and Microsoft 365 Exchange Online holds the invoices@avfees.com mailbox.
  • Azure Communication Services Email sends receipts and contact messages.
  • Anthropic reads invoices the built-in parser cannot, as described above.

We do not sell personal information and do not use it for advertising.

What other users see

A lookup returns published fee observations: an observation ID, fee type, amount, currency, any fuel waiver, FBO, airport, aircraft class, date, and whether it came from an invoice or a single reported line. It never returns who contributed a line, the key or account behind it, or anything from the email it arrived in. Subscribers also receive projected figures, which are built from published observations and labeled as projected.

Access, correction and deletion

You can see your account, keys, credit balance and consent on your account page, and revoke a key there at any time. To ask for a copy of your information, a correction, deletion of your account, or removal of your contributions or forwarded emails, choose the privacy topic on the contact page and include the email address on your account. We keep information for as long as the account is active or it is needed to run the service, and delete it on a verified request unless we must keep it by law.

Changes to this notice

When this notice changes, the date below changes with it. Significant changes are also noted on this page.

Last updated 2026-09-25.

Privacy notice | AvFees