Skip to content

Privacy

Privacy Policy

Last updated: 2026-10-08

1. Local-first by design

Aviator Archive is a local-first application. Your flight logs, currency state, documents, and personal records live on the device you installed the app on, in a single encrypted file. We don't run a cloud database of your flight data, and we don't want one — keeping it on your device is the whole point.

There is exactly one feature that sends your logbook content off your device: AI Scan (section 4), which only runs when you choose to use it and after you accept a disclosure. Everything else in this policy is about the small, boring account and licensing data we need to sell you the app and keep your Lifetime unlock working.

2. Sync between your own devices

When two of your devices are on the same local network, they discover each other via mDNS / Bonjour and establish a direct, mutually-authenticated TLS (mTLS) channel using a private certificate authority bundled with the app. Each device holds its own leaf certificate, issued when you sign in on that device and renewed before it expires.

Sync traffic stays on the local network. There is no relay server, and no server takes part while a sync runs: we do not observe, store, or proxy your flight data during sync. Devices that have synced before go on syncing with the internet off.

Three things around sync do use our servers. None of them carries your logbook:

  • Enrolment — a device gets its certificate from our server when you sign in on it, and again when the certificate is due for renewal. What this records is listed in section 5.
  • Your device list — while you're signed in, a device fetches the list of devices on your account, and which of them you've removed, so it can refuse a removed one. When you remove a device, our server records that, and a removed device can enrol again only after someone signs in on it.
  • The pairing mailbox — pairing over the air uses a short-lived, zero-knowledge mailbox to introduce two devices to each other. It holds ephemeral key material and the name of the device sending the invitation, deletes them within twenty minutes, and never sees your logbook.

Which devices may sync a logbook is kept in the logbook itself, as a list your devices sign and pass to each other when they sync. That list never goes to our servers.

3. What our cloud actually does

We run six narrow cloud services, and nothing more:

  • Federated sign-in — when you sign in, our server validates your auth provider's token and returns a session.
  • Sync certificates — issues each device's sync certificate, keeps the list of devices on your account, and records the ones you remove. Details are in section 2.
  • Pairing mailbox — the short-lived mailbox that pairing over the air uses to introduce two devices. It never sees your logbook. Details are in section 2.
  • License entitlement — when you buy Lifetime, the entitlement record that unlocks premium features and unlimited logging lives in our database, keyed to your user ID.
  • Usage counts — while you're signed in, the app tells us once a month that it is in use, and counts which features you use (sync, export, AI Scan, QR pairing, FMC capture). It is on by default, and you can switch it off in Settings under "Send usage counts". Details are in section 9.
  • AI Scan — an optional image-extraction service that reads a photo of a paper logbook page. This is the only one that touches your logbook content, and only when you use it. Details are in section 4.

Apart from AI Scan — which you trigger yourself and consent to before it runs — none of your logbook content passes through our cloud.

4. AI Scan — optional image extraction

AI Scan lets you photograph a paper logbook page and have it read and turned into structured entries, so you don't have to type them by hand. It is entirely optional. If you never use it, no logbook content ever leaves your device through it.

Before your first scan, the app shows a disclosure screen naming exactly who will process the image. Nothing is uploaded unless you accept, and nothing is added to your logbook until you review and confirm the result.

When you do use it:

  • The page image is sent to our AI processing provider — a frontier AI model operated by Google Cloud — which extracts the text and returns it to you. The provider does not use your images to train its AI models, and deletes the image after processing.
  • We hold the page image only while the scan is running. Your page is queued for extraction, which means the image is staged in our storage until the result comes back, then deleted — usually a minute or two later. If a delete misses, a sweep every day at 04:00 UTC clears what is left, so the outside limit is 48 hours. Scans from the EU/EEA, the UK, and Switzerland take a direct path instead, where the image is never written to our storage at all.
  • The extracted text is a separate thing, and kept longer. A short-lived copy is retained for up to 7 days so an accidental repeat of the same request isn't billed twice, then it is removed. That window is the text's, not the image's. Beyond it we keep only technical metadata about each scan (when it ran, token counts, cost, success or failure), linked to your account until you delete it.
  • If the primary model is unavailable we fall back to an alternative model on the same processor, so your page does not travel anywhere new. The disclosure screen always names the model actually handling your scan, so what you see is what's used.

Where it's processed: we route by your region. If you're in the EU/EEA, the UK, or Switzerland, your page is processed on Google's EU-resident endpoint — inside the European Union — under Google's Cloud Data Processing Addendum. Everywhere else, it's processed on Google Cloud in the United States under the same Addendum and the transfer safeguards in section 11. Your region is set at sign-in from your connection's country. The app's Settings → Privacy → Image Processing screen always shows the current provider, model, and processing region live — that screen is the authoritative, up-to-the-minute answer.

If any page you scan happens to contain someone else's details (for example a signature or an instructor's name), the same handling applies. Please only scan pages you're comfortable processing this way — and if a document is sensitive, such as a medical certificate, keep it on-device rather than scanning it.

5. The minimum we store on our servers

For account management and licensing, our database holds:

  • Your email address (sign-in identifier), and the name on your Google account if you sign in with Google. Apple sends us a name only when your account is created by signing in with Apple on our website, and then only the name you chose to share. The app doesn't ask Apple for your name, so signing in with Apple in the app gives us none.
  • An internal user ID and your sign-in provider's subject identifier.
  • Your Lifetime license status, the transaction ID from your purchase, and your AI Scan page balance.
  • The random ID of the logbook your account is linked to, when it was linked, and a history of any moves to a different logbook. Each account has one logbook; we use this to tell you when you sign in on a different one, and to apply Pro to the right logbook. The ID is a random string the app creates. It reveals nothing about what is in the logbook.
  • For each device you enrol for sync: its public certificate fingerprint, a random device ID, the device name set in that phone's or computer's settings, and its model and operating system version. We use them to validate sync handshakes and to list your devices for you.
  • Your AI Scan region (US or EU), if you have chosen one.
  • A secret stored with your licence, which keys your usage counts (section 9).

This account database does not contain your flight totals, aircraft, crew names, currency state, or any other logbook contents. The only place any of that is ever processed by us is the optional AI Scan flow described in section 4, under the retention limits stated there.

5a. Our legal basis for each use

If you're in the EU, EEA, or UK, the law requires us to say which legal basis we rely on for each thing we do with your personal data. In plain terms:

What Legal basis Why
Account, sign-in and licence status (section 5) Performance of a contract We can't unlock the software you bought without knowing who you are and what you bought.
AI Scan — the pages you choose to scan (section 4) Consent Entirely optional, off unless you use it, and the app shows you what it sends before the first upload. Stop using it and the processing stops.
Crash and error reports (section 8) Legitimate interests Our interest in shipping software that doesn't lose your logbook. Scrubbed of personal data, and switchable off per device — section 8 shows you where.
Usage counts from the app (section 9) Legitimate interests Knowing how many devices are in use and which features are used, so we build the right things. On by default, and switched off per device in Settings.
Device certificates for sync (section 2) Performance of a contract Device-to-device sync is a feature of the licence; the certificates are what stop a stranger's device joining your logbook.
Purchases, tax and invoicing (section 7) Legal obligation, and performance of a contract Handled by Paddle as merchant of record, who must keep tax records whatever we would prefer.
Website analytics (section 9) Legitimate interests Knowing which pages help people and how they find this site. Kept to page views and load times in the EU, EEA, UK and Switzerland, and you can object at any time: Global Privacy Control, Do Not Track, or the switch in section 9 each stop it.
Answering you when you write to us (section 14) Legitimate interests You asked us a question; we need your message and a way to reply to it.

Where we rely on consent, you can withdraw it at any time, and that doesn't affect anything done before you withdrew it. Where we rely on legitimate interests, you can object — see section 12.

6. Keeping & deleting your data

On your device: your logbook is yours. It stays on your device until you remove it. Deleting a profile in the app (Settings, then "Delete Profile — permanently erase all data") or uninstalling the app removes the local copy, including all documents and media. We can't recover it, because we hold no copy of your logbook — the only exception being the short-lived AI Scan data described in section 4.

On our servers: the minimal account record described in section 5 is kept for as long as your account exists, so your Lifetime unlock keeps working on every device you sign in on. AI Scan data is held only for the short windows described in section 4 (the page image only while the scan runs, 48 hours at the outside; extracted text up to 7 days, then deleted).

Deleting your account: you can do it yourself in the app, under Settings, then "Delete Account". You sign in once more to confirm it's you, and the account record is erased straight away. If you can't sign in any more, ask through the contact form and we'll erase it, normally within 30 days; Delete your account has both sets of steps. Either way, we also delete RevenueCat's record of your account, and if you signed in with Apple we tell Apple to remove this app's access to your Apple ID. AI Scan's records of the pages you scanned stay in our accounts as a count and a cost, with nothing left in them that points to you. Our database provider keeps restore points for up to 30 days, so an erased record leaves those within 30 days of the erasure; if we ever had to restore from one, we would erase again every account deleted since. What we keep afterwards: the bare transaction reference our payment provider is required to retain for tax and accounting law, and our own record of the sale (product, amount, date and store), which carries no user ID or email. Neither contains flight data. For 31 days we also keep a one-way fingerprint of the deleted account's ID, which turns away any sign-in still open on your other devices (AI Scan keeps its own for a day or two, so a scan already running can't write anything back); it can't be turned back into the ID. And an AI Scan page purchase made on our website that was never added to an account isn't part of one, so it stays claimable by the email it was bought with.

7. Purchases & payments

We don't process payments ourselves. Depending on where you buy, one of the following handles the transaction and its global sales-tax / VAT compliance:

  • Paddle — our Merchant of Record for direct web purchases. They handle the payment, your card details, and tax compliance. We never see your card number.
  • Apple App Store & Google Play — the Merchant of Record for in-app purchases on iPhone, iPad, Mac and Android. We use RevenueCat to validate those store receipts and manage your entitlement; it receives the transaction identifier and an app user ID, never your payment card.

When a purchase completes, the provider sends a webhook with a transaction ID and buyer reference. We use only that to flip your license status to Lifetime across every device you sign in on — nothing else about the payment reaches us.

8. Crash and error reporting (on by default)

If something crashes — or fails in a way the app can detect but you might not — an anonymized diagnostic report helps us fix it. Crash reporting is handled by Sentry and is on by default during the beta — a beta that cannot see its own crashes takes far longer to stabilise. You can switch it off in Settings at any time, on each device, and nothing further is sent from it.

A report carries the error type, a technical stack trace, which part of the app it happened in, your platform, and the app version. It does not carry the error's message text — that is stripped on your device before sending, because an error message often quotes the very data that caused it. No logbook entries, no account or email address, no location, and your IP address is not attached to the report. We do not use any of it to track what you do in the app.

One kind of report is put together differently, and it is worth naming. A crash low enough to take the whole app down is caught by the reporting tool's own low-level handler, before any of our code gets to run — so that report is stripped when it reaches Sentry rather than before it leaves your device, and on the way it carries some device details our own reports never send: memory and storage, screen size, language and time zone, and a random identifier that is created on install and erased when you uninstall. It is not tied to your hardware, your account, or you. Those details are dropped and that identifier replaced on arrival, before the report is stored. What stays is basic hardware description — the phone's make and model, its processor, battery level, and whether it was charging or online — which says what kind of device crashed, not whose. It is the one case where the stripping is done by our processor rather than by the app on your device.

While crash reporting is on, the app also tells Sentry each time it is opened and closed: a "session", carrying the app version and the random install identifier described above. That is how we can tell what share of uses end in a crash. It carries nothing else, and it stops when you switch crash reporting off.

9. Website analytics

To learn which pages are useful and how people find this site, we count visits with Umami, an open-source analytics tool. No analytics company receives your data, and it is stored only in Canada. Requests reach us through Cloudflare, which carries them (section 10). We do not load Google Analytics, Facebook Pixel, or any third-party tracking script, and nothing here is used to advertise to you.

A page view records:

  • the page's path, and none of the rest of its address. Anything after a ? is removed in your browser and again on our side, apart from our own campaign labels (below);
  • the website that sent you here, as its name only (for example https://example.com/);
  • your screen size, rounded to one of five standard sizes, and your browser's language without its regional part (fr, not fr-CA);
  • your browser, operating system and type of device, read from the description your browser sends with every request;
  • your country and region, worked out from your shortened IP address. The tool also works out a city; we delete it within a day, and it is never backed up or archived;
  • how quickly the page loaded;
  • three actions, and no others: clicking a buy button (which product), clicking a store or download link (which store), and signing up to be notified (which list).

Your IP address is shortened before it reaches our analytics. On the way, the last part is removed: the final number of an IPv4 address, or everything after the network part of an IPv6 address. The analytics use only that shortened form, to look up your country and region and, together with your browser's description, to form a visit identifier that changes every month. Neither the full address nor the shortened one is stored. The full address is also used briefly for security, and is never written down.

No cookies, and nothing stored on your device, except the off switch below if you choose to use it.

Pseudonymous, not anonymous. The visit identifier lets the tool group one visit's page views together. It is not linked to your name, email address or account, and we never combine these records with anything else we hold. It is still a record of one visit, so we treat it as personal data and keep it briefly: visit-level records are deleted after 90 days, and the backups holding them are gone within a further 60. After that we keep only daily and monthly totals, in which any count under five is merged into "other". We do not build a profile of you.

Backups are encrypted before they leave our systems, and stored in Canada by the backup provider named in section 10.

Campaign labels. Some links we publish carry three labels in their address (utm_source, utm_medium and utm_campaign) naming where the link was posted. When all three are present and are labels we use, they are recorded with the page view.

Short links. Addresses on go.aviatorarchive.com are short links to pages of this site, for posters and other places where a long address does not fit. Following one takes you to its page, adding its campaign labels (except in the regions below) and sometimes a discount code. The short link itself keeps no record: no click count, no log and no cookie. Your arrival is counted like any other page view.

Links from the app. When you open this site from inside Aviator Archive, from the user guide, the terms you accept at first start or, on a computer, a purchase page, the link carries the same three labels: the app as its source, and which of those screens you came from (for example, the PDF export upgrade). They say nothing else about you or your logbook, and the regional rule below applies to them too.

In the EU, the EEA, the UK and Switzerland, campaign labels and the three actions are not recorded at all: only page views and load times. A visit whose country cannot be told is treated the same way.

Pages with no analytics at all: the purchase confirmation, payment and welcome pages, where you have just paid or signed up. Sales are counted from our own sales records.

Saying no. If your browser sends Global Privacy Control or Do Not Track, nothing is recorded. You can also switch analytics off for this browser below. That saves one setting in your browser's storage, which tells the tracker not to send anything; switching it back on removes the setting.

This switch needs JavaScript. With JavaScript off, the tracker cannot run either.

Why we can't look up your records. They contain no name, email address or account, so nothing you could send us would let us find yours without asking for more of your data, such as your IP address. We won't ask for that. The switch, Global Privacy Control and Do Not Track stop new records from being made, and records already made are deleted after 90 days in any case.

In the app: while you're signed in, the app sends us a check-in once a month (your tier, platform, app version and the month you first activated) and a count each time you use sync, export, AI Scan, QR pairing or FMC capture. It never sends logbook contents. Each record is labelled with a code that changes every month, made from a secret stored with your licence. We don't use it to follow individuals, but because we hold that secret we could link the counts to your licence, so we don't call them anonymous. It is on by default; switch it off in Settings under "Send usage counts" and that device sends nothing further.

10. Who processes data for us

We keep our list of service providers ("subprocessors") short and name them plainly. The ones that may handle your personal data are below; the always-current version, with each provider's data terms and processing location, lives on our Subprocessors page:

  • Google — federated sign-in, and (for AI Scan) image extraction via Google Cloud. When you sign in with Google, Google may use your IP address to estimate your general location, to prevent fraud. On Android and iPhone, the app's text recognition also comes from Google (ML Kit), as does its QR-code reading on Android: it runs on your device and the images it reads stay there, but it reports usage statistics and basic device details to Google. On Apple devices, QR codes are read by Apple's own on-device framework.
  • Apple — Sign in with Apple.
  • Cloudflare — hosting for our sign-in, licensing, and AI Scan services, and for this website, and carrying website analytics to us (section 9).
  • Backblaze — stores the encrypted backups of our website analytics, in Canada (section 9).
  • RevenueCat — validates App Store / Play receipts and manages your entitlement.
  • Sentry — scrubbed crash reports, on by default and switchable off per device (see section 8).

AI Scan may fall back to an alternative model for reliability; it runs on the same processor, and the in-app disclosure names the model before any image is sent. Each provider above is engaged under a data-processing agreement that binds it to handle your data only on our instructions.

Not on that list, deliberately: the companies that sell you the product. Paddle is our Merchant of Record for web purchases, and Apple and Google are the sellers for in-app purchases. They are the seller in that transaction, not a supplier acting on our instructions — so each decides for itself how it handles your payment data, under its own privacy policy, and is independently answerable to you for it. We describe what that means for your purchase in section 7.

11. Where your data is processed

Seneboy Ventures Inc. operates from Canada, whose federal privacy law (PIPEDA) the European Commission recognizes as providing an adequate level of data protection. Some of the providers above run on infrastructure in the United States and elsewhere.

Where personal data of users in the EU, EEA, UK, or Switzerland is transferred outside those regions, it is protected by the appropriate legal safeguards — chiefly the European Commission's Standard Contractual Clauses (built into our providers' data-processing agreements) and, in Google's case, its certification under the EU–US Data Privacy Framework. For AI Scan specifically, images from users in the EU/EEA, UK, or Switzerland are processed on Google's EU-resident endpoint inside the European Union — so those images aren't transferred out — while images from other users are processed on Google Cloud in the United States under the safeguards above.

Website analytics (section 9) are stored only in Canada, and so are their encrypted backups. Cloudflare carries the requests through its global network on the way.

12. Your privacy rights

Depending on where you live (including under the EU/UK GDPR and Canada's PIPEDA), you have rights over your personal data: to access it, correct it, delete it, receive a portable copy, object to or restrict certain processing, and withdraw consent you've given.

Most of your data is already in your hands — it lives on your device, where you can view, edit, export, or permanently delete it directly. You can also delete your whole account yourself, in the app (section 6). For the account record we hold on our servers, or for anything you'd like a copy of or removed, ask through the contact form and we'll act on it, normally within 30 days, at no charge. You don't have to delete your account to have something removed. The one exception is the record of your Pro licence: it is how we know you bought it, so removing it means deleting your account, and you would lose Pro. If something you ask us to remove is that record, we'll tell you before we act and let you choose. You can withdraw consent for AI Scan (by not using it) or crash reporting (in Settings) at any time, without affecting anything else.

If you're in the EU, EEA, or UK, you also have the right to lodge a complaint with your local data-protection supervisory authority; if you're in Canada, with the Office of the Privacy Commissioner of Canada. We'd appreciate the chance to sort it out first, though.

13. Open data we ship

Aviator Archive bundles the airport, aircraft type, manufacturer, and map data it needs to work offline. Those datasets come from public-domain and open-data communities — OurAirports, OpenSky Network, and OpenStreetMap. See the credits page for source links, licences, and instructions if you ever want to refresh your local copy from the upstream.

14. Contact

We are the controller for the personal data described in this notice. That controller is Seneboy Ventures Inc., a corporation incorporated under the Canada Business Corporations Act, operating from the Province of Alberta, Canada under the trade name Aviator Archive. Questions, requests, or concerns? Use the contact form. A real human responds, and we aim to reply inside one business day.

By post: Seneboy Ventures Inc., 539 23 Ave NW, Calgary, Alberta T2M 1S7, Canada. You can use this address for privacy queries as well as the contact form above.