FlightGuard legal
Privacy Policy
Effective: 26 August 2026
In short: FlightGuard processes the information needed to operate your account, keep aircraft records synchronized, manage subscriptions and provide the features you choose. We do not sell personal data or use it for third-party advertising.
1. Controller and contact
The controller responsible for FlightGuard is:
Isabelle Spandl, B.Sc.
FlightGuard
Rauhholzstraße 54c, 6971 Hard, Austria
Email: hello@flightguardapp.com
This policy applies to the FlightGuard mobile apps, the FlightGuard Web App at app.flightguardapp.com, and the FlightGuard public website.
2. Data we process
2.1 Account and authentication data
- User ID, email address, display name and profile image, where provided
- Authentication provider and technical authentication information
- Sign-in information processed through email/password, Apple Sign-In or Google Sign-In
2.2 Aircraft and maintenance records
Depending on the features you use, this can include:
- Aircraft registration, type, regulatory authority, model and serial number
- Engine and propeller details, serial numbers, operating times and component-change history
- Flight times, landings, maintenance schedules, due values and maintenance history
- Airworthiness Directives, applicability reviews, scan selections and overrides
- Defects and HIL items, life-limited parts, repairs, alterations and equipment records
- Documents, photos, PDFs, notes, checklists and generated report settings
2.3 Sharing, social and activity data
- Aircraft owners, editors and invited users
- Friend relationships and pending invitations
- Activity information showing which signed-in user created or changed a record
2.4 Subscription data
RevenueCat and the applicable store provide entitlement information such as subscription status, product, renewal state, trial eligibility and transaction references. FlightGuard does not receive your full card or bank details.
2.5 Support, feedback and website-contact data
If you contact us or submit feedback, we process the information you provide, such as your name, email address, account identifier, message, selected topic and related support information. The public website contact form is processed through the website hosting and form provider.
2.6 Device, notification and security data
We may process device and app version, platform, notification token, language or time-zone preferences, IP address, request timestamps and technical error or security information where needed to deliver notifications, maintain sessions, prevent abuse and operate the service reliably.
2.7 AI logbook scanning
When you choose the AI logbook scanner, the selected image and your authentication token are sent to a FlightGuard server function. The image is then sent to OpenAI to extract proposed flight data. The extracted result is returned to you for review.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Create and operate your account and synchronize records | Performance of a contract, Article 6(1)(b) GDPR |
| Provide maintenance calculations, reports, sharing, Web App access and requested features | Performance of a contract, Article 6(1)(b) GDPR |
| Manage subscription entitlements | Performance of a contract, Article 6(1)(b), and legal obligations, Article 6(1)(c) |
| Provide support and respond to enquiries | Contract or pre-contractual steps, Article 6(1)(b), and legitimate interests, Article 6(1)(f) |
| Secure the service, prevent abuse and diagnose failures | Legitimate interests in security and reliable operation, Article 6(1)(f) |
| Process a logbook image you actively submit for AI extraction | Performance of the requested feature, Article 6(1)(b); device permissions or optional processing may additionally rely on consent, Article 6(1)(a) |
| Comply with accounting, tax and other legal requirements | Legal obligation, Article 6(1)(c) |
4. Service providers and recipients
We use providers only where needed to operate FlightGuard:
| Provider | Purpose | Further information |
|---|---|---|
| Google Firebase / Google Cloud | Authentication, cloud database, file storage, server functions and push messaging | Firebase privacy |
| RevenueCat | Subscription and entitlement management across supported platforms | RevenueCat privacy |
| Apple | Sign-in, app distribution, purchases and store services | Apple privacy |
| Sign-in, Google Play distribution, purchases, fonts and related platform services | Google privacy | |
| OpenAI | AI extraction from logbook images you choose to scan | OpenAI privacy |
| Netlify | Public website hosting and contact-form processing | Netlify privacy |
| YouTube / Google | Embedded product video on the public website | Google privacy |
Authorised FlightGuard personnel may access data only where needed for operations, security, support you request or legal obligations. Aircraft data is also disclosed to users whom an aircraft owner authorises through the sharing feature.
5. AI logbook scanning
The AI scanner is optional. Do not submit an image unless you are authorised to process all information visible in it. Always verify extracted values before saving them.
The selected image is sent through an authenticated FlightGuard server function to the OpenAI API. FlightGuard does not intentionally save the source image as part of the scanner request. OpenAI states that API inputs are not used to train its models by default. Under OpenAI's standard API data controls, abuse-monitoring logs may retain content for up to 30 days unless a different approved data-control arrangement applies.
6. Shared aircraft access
When an aircraft owner grants another user access, that user can view and, depending on the assigned role, edit the aircraft's records. Activity information may identify the user who made a change. The owner can revoke access. Only share aircraft records with people who are authorised to receive them.
7. International transfers
Primary aircraft records may be configured in European Firebase regions, but some providers and server functions may process data outside Austria or the European Economic Area. Where required, transfers are protected through an adequacy decision, Standard Contractual Clauses or another lawful safeguard. Further details or a copy of relevant safeguards can be requested using the contact details above.
8. Retention and deletion
- Account and aircraft records: kept while your account is active and as needed to provide the service.
- Account deletion: deleting your account from Profile removes your FlightGuard authentication account and aircraft records you own from the active service. Access to aircraft owned by others is removed. Limited backups, security records or processor records may remain temporarily where technically necessary or legally required.
- Subscription and transaction records: retained by FlightGuard or the applicable processors as required for accounting, tax, fraud prevention and their independent legal obligations.
- Support, feedback and contact messages: kept as long as needed to handle the request and protect or establish legal claims.
- Technical and security logs: kept only for the period needed for reliability, security and abuse prevention.
- OpenAI API data: subject to the API data controls described in Section 5.
9. Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction, data portability or objection. Where processing relies on consent, you may withdraw that consent for the future. You may also lodge a complaint with the Austrian Data Protection Authority or another competent supervisory authority.
To exercise a right, contact hello@flightguardapp.com. We may need to verify your identity before completing the request.
10. Exporting and deleting your data
You can generate several aircraft reports directly in FlightGuard. For a broader access or portability request, contact us. You can delete your account and owned data from Profile → Delete Account & Data. Cancelling a subscription does not itself delete your account, and deleting the account does not automatically cancel a store subscription.
11. Website storage, cookies and external content
The public website does not operate an advertising profile. The Web App may use browser storage, authentication state and technically necessary identifiers to keep you signed in and provide requested functions.
The public website currently uses externally delivered fonts and an embedded YouTube video. Loading these resources may disclose your IP address, browser information and request details to the relevant provider; YouTube may also use cookies or similar technologies. The contact form sends the information you enter to Netlify for delivery to FlightGuard.
12. Security
We use reasonable technical and organisational measures, including encrypted network connections, authenticated access and access controls. No online service can guarantee absolute security or uninterrupted availability.
13. Children
FlightGuard is not directed to people under 18. We do not knowingly create accounts for children. Contact us if you believe a minor has provided personal data without appropriate authorisation.
14. Changes to this policy
We may update this policy when FlightGuard, our providers or legal requirements change. Material changes will be communicated in the app, on the website or by another appropriate method before they take effect where required.