Skip to content

Privacy

Privacy Policy

Last updated: 2026-07-11

1. Local-first by design

Aviator Archive is a local-first application. Your flight logs, currency state, documents, and personal records live on the device you installed the app on, in a single encrypted file. We don't run a cloud database of your flight data, and we don't want one — keeping it on your device is the whole point.

There is exactly one feature that sends your logbook content off your device: AI Scan (section 4), which only runs when you choose to use it and after you accept a disclosure. Everything else in this policy is about the small, boring account and licensing data we need to sell you the app and keep your Lifetime unlock working.

2. Sync between your own devices

When two of your devices are on the same local network, they discover each other via mDNS / Bonjour and establish a direct, mutually-authenticated TLS (mTLS) channel using a private certificate authority bundled with the app. Each device holds its own leaf certificate, issued during a one-time enrollment.

Sync traffic stays on the local network. There is no relay server. We do not observe, store, or proxy your flight data during sync. The one server touchpoint is a short-lived, zero-knowledge pairing mailbox used only to introduce two devices to each other; it holds ephemeral key material for a few minutes and never sees your logbook.

3. What our cloud actually does

We run three narrow cloud services, and nothing more:

  • Federated sign-in — when you sign in, our server validates your auth provider's token and returns a session.
  • License entitlement — when you buy Lifetime, the entitlement record that unlocks premium features and unlimited logging lives in our database, keyed to your user ID.
  • AI Scan — an optional image-extraction service that reads a photo of a paper logbook page. This is the only one that touches your logbook content, and only when you use it. Details are in section 4.

Apart from AI Scan — which you trigger yourself and consent to before it runs — none of your logbook content passes through our cloud.

4. AI Scan — optional image extraction

AI Scan lets you photograph a paper logbook page and have it read and turned into structured entries, so you don't have to type them by hand. It is entirely optional. If you never use it, no logbook content ever leaves your device through it.

Before your first scan, the app shows a disclosure screen naming exactly who will process the image. Nothing is uploaded unless you accept, and nothing is added to your logbook until you review and confirm the result.

When you do use it:

  • The page image is sent to our AI processing provider — currently Google Gemini, running on the Gemini Enterprise Agent Platform (Google Cloud) — which extracts the text and returns it to you. The provider does not use your images to train its AI models, and deletes the image after processing.
  • We never store the image itself. Our extraction service keeps only technical metadata (timestamps, token counts, cost, success or failure). A short-lived copy of the extracted text is retained for up to 7 days so an accidental repeat of the same request isn't billed twice, then it is removed.
  • We keep a small number of alternative providers configured as fallbacks for reliability. The disclosure screen always names the one actually handling your scan, so what you see is what's used.

Where it's processed: we route by your region. If you're in the EU/EEA, the UK, or Switzerland, your page is processed on Google's EU-resident endpoint — inside the European Union — under Google's Cloud Data Processing Addendum. Everywhere else, it's processed on Google Cloud in the United States under the same Addendum and the transfer safeguards in section 11. Your region is set at sign-in from your connection's country. The app's Settings → Privacy → Image Processing screen always shows the current provider, model, and processing region live — that screen is the authoritative, up-to-the-minute answer.

If any page you scan happens to contain someone else's details (for example a signature or an instructor's name), the same handling applies. Please only scan pages you're comfortable processing this way — and if a document is sensitive, such as a medical certificate, keep it on-device rather than scanning it.

5. The minimum we store on our servers

For account management and licensing, our database holds:

  • Your email address (sign-in identifier).
  • An internal user ID and your sign-in provider's subject identifier.
  • Your Lifetime license status and the transaction ID from your purchase.
  • The public certificate fingerprint of each device you've enrolled, so we can validate sync handshakes.

This account database does not contain your flight totals, aircraft, crew names, currency state, or any other logbook contents. The only place any of that is ever processed by us is the optional AI Scan flow described in section 4, under the retention limits stated there.

6. Keeping & deleting your data

On your device: your logbook is yours. It stays on your device until you remove it. Deleting a profile in the app (Settings, then "Delete Profile — permanently erase all data") or uninstalling the app removes the local copy, including all documents and media. We can't recover it, because we never had a copy.

On our servers: the minimal account record described above (your email, internal user ID, license status, and enrolled device fingerprints) is kept for as long as your account exists, so your Lifetime unlock keeps working on every device you sign in on. AI Scan data is held only for the short windows described in section 4 (image never stored; extracted text up to 7 days, then deleted). You can ask us to delete your account record at any time — email daniel [at] aviatorarchive [dot] com and we'll erase it, normally within 30 days. The only thing we may keep afterwards is the bare transaction reference our payment provider is required to retain for tax and accounting law, which contains no flight data.

7. Purchases & payments

We don't process payments ourselves. Depending on where you buy, one of the following handles the transaction and its global sales-tax / VAT compliance:

  • Lemon Squeezy — our Merchant of Record for direct web purchases. They handle the payment, your card details, and tax compliance. We never see your card number.
  • Apple App Store & Google Play — the Merchant of Record for in-app purchases on iOS and Android. We use RevenueCat to validate those store receipts and manage your entitlement; it receives the transaction identifier and an app user ID, never your payment card.

When a purchase completes, the provider sends a webhook with a transaction ID and buyer reference. We use only that to flip your license status to Lifetime across every device you sign in on — nothing else about the payment reaches us.

8. Crash reporting (opt-in)

If something crashes, an anonymized diagnostic report helps us fix it. Crash reporting is handled by Sentry and is opt-in — you can turn it on or off in Settings at any time. Reports contain the error type and a technical stack trace, with personal and logbook details scrubbed before they leave the device. We do not use it to track what you do in the app.

9. Website analytics

This marketing site uses a server-side, cookie-free analytics tool that respects your privacy. We do not load Google Analytics, Facebook Pixel, or any third-party tracking script. We do not build a user profile about you. Inside the app, we count only aggregate, anonymized usage (such as monthly active devices) using a privacy-preserving token that cannot be tied back to you.

10. Who processes data for us

We keep our list of service providers ("subprocessors") short and name them plainly. The ones that may handle your personal data are below; the always-current version, with each provider's data terms and processing location, lives on our Subprocessors page:

  • Google — federated sign-in, and (for AI Scan) image extraction via Google Cloud / Gemini.
  • Apple — Sign in with Apple.
  • Cloudflare — hosting for our sign-in, licensing, and AI Scan services, and for this website.
  • RevenueCat — validates App Store / Play receipts and manages your entitlement.
  • Lemon Squeezy — Merchant of Record for web purchases (see section 7).
  • Sentry — opt-in crash reports only (see section 8).

A few additional AI providers are configured as fallbacks for AI Scan but are not active by default; whenever one is used, the in-app disclosure names it before any image is sent. Each provider is engaged under a data-processing agreement that binds it to handle your data only on our instructions.

11. Where your data is processed

Aviator Archive is operated from Canada, whose federal privacy law (PIPEDA) the European Commission recognizes as providing an adequate level of data protection. Some of the providers above run on infrastructure in the United States and elsewhere.

Where personal data of users in the EU, EEA, UK, or Switzerland is transferred outside those regions, it is protected by the appropriate legal safeguards — chiefly the European Commission's Standard Contractual Clauses (built into our providers' data-processing agreements) and, in Google's case, its certification under the EU–US Data Privacy Framework. For AI Scan specifically, images from users in the EU/EEA, UK, or Switzerland are processed on Google's EU-resident endpoint inside the European Union — so those images aren't transferred out — while images from other users are processed on Google Cloud in the United States under the safeguards above.

12. Your privacy rights

Depending on where you live (including under the EU/UK GDPR and Canada's PIPEDA), you have rights over your personal data: to access it, correct it, delete it, receive a portable copy, object to or restrict certain processing, and withdraw consent you've given.

Most of your data is already in your hands — it lives on your device, where you can view, edit, export, or permanently delete it directly. For the account record we hold on our servers, or for anything you'd like a copy of or removed, email daniel [at] aviatorarchive [dot] com and we'll act on it, normally within 30 days, at no charge. You can withdraw consent for AI Scan (by not using it) or crash reporting (in Settings) at any time, without affecting anything else.

If you're in the EU, EEA, or UK, you also have the right to lodge a complaint with your local data-protection supervisory authority; if you're in Canada, with the Office of the Privacy Commissioner of Canada. We'd appreciate the chance to sort it out first, though.

13. Open data we ship

Aviator Archive bundles the airport, aircraft type, manufacturer, and map data it needs to work offline. Those datasets come from public-domain and open-data communities — OurAirports, OpenSky Network, and OpenStreetMap. See the credits page for source links, licences, and instructions if you ever want to refresh your local copy from the upstream.

14. Contact

Aviator Archive is the data controller for the personal data described here. Questions, requests, or concerns? daniel [at] aviatorarchive [dot] com . A real human responds, usually inside 24 hours.