# Privacy Policy

**Effective Date:** July 23, 2025

This Privacy Policy explains what information Northlog collects, why we collect it, and how you can access, manage, export, and delete your data.

### Service Provider

The **Northlog** application (the “App”), available at [web.northlog.app](https://web.northlog.app), the Apple App Store, and other app stores, is owned and operated by **Northlog** (“**Northlog**,” “**we**,” “**us**,” or “**our**”).

Northlog is a digital pilot logbook that helps pilots log flights, track currency, generate professional PDF exports, and sync data across devices. The App is available on iPhone, iPad, and the web, with Android support coming soon.

This Privacy Policy applies to all users of Northlog, whether you are using a free account, a guest account, or a Pro subscription. The personal information we collect is used to provide and improve the service. We will not use or share your information with anyone except as described in this Privacy Policy.

---

### 1. Information We Collect and Receive

We only collect and use your personal information for legitimate reasons. We collect personal information that is reasonably necessary to provide our services to you. All personal data is processed electronically and stored securely.

#### 1.1 Account & Profile Data

When you create an account or use Northlog, we collect information you provide during onboarding and in your profile settings, including your email address, name, profile image (from your auth provider), pilot role, home base, and fleet entries.

You can update your name and profile image at any time in your profile settings.

#### 1.2 Flight Data

Northlog is a pilot logbook. The core data you store includes your flight records (block times, flight time breakdowns, landings, takeoffs, approaches, and notes), crew members, aircraft, aerodromes, custom groups, daily statistics, and derived currency status. All flight data is linked to your user account and is not shared with other users or third parties.

#### 1.3 Export Data

When you generate a PDF export, we store the export format, date range, page count, and the generated PDF file itself in InstantDB Storage under a path specific to your user ID. Export PDFs are only accessible to you and are deleted when you delete your account.

#### 1.4 Settings

We store your preferences, including which logbook fields you choose to display and your preferred regulatory region for currency tracking.

#### 1.5 Log Data

When you use our service, or in the event of an error, we collect device information (type, OS version, app version), connection status, IP address, and usage details.

#### 1.6 Guest Accounts

You can use Northlog as a guest without providing an email address. Guest accounts store all the same flight data and sync it to InstantDB under a guest user ID. If you later sign in with email, Google, or Apple, your guest data is preserved and linked to your new account.

#### 1.7 Authentication

We offer three authentication methods: email magic code, Google Sign-In (OAuth 2.0 with PKCE), and Apple Sign-In. We do not have direct access to your passwords. All authentication is handled by InstantDB, Google, and Apple.

---

### 2. How We Use Your Information

We use your information to:

- **Provide and maintain the service** — store your flights, sync across devices, and render exports
- **Authenticate your account** — verify your identity and prevent unauthorized access
- **Generate PDF exports** — render your flight data into professional logbook formats
- **Track currency** — calculate FAA and EASA currency status from your flight data
- **Display statistics** — show your flight hours, routes, and trends
- **Improve the service** — analyze usage patterns and fix bugs
- **Send notifications** — account-related updates (you can disable these)
- **Support you** — respond to your questions and resolve issues

We do not sell, rent, or share your personal data with third parties for their marketing purposes.

---

### 3. Legal Basis for Processing (EEA & UK Users)

If you are located in the European Economic Area or the United Kingdom, we only process your personal data when we have a valid legal basis:

- **Contractual Necessity** — processing is necessary to provide our services (e.g., storing your flights, generating exports)
- **Legitimate Interests** — processing is necessary for our legitimate interests (e.g., service analytics, security, bug fixes), provided your rights are not overridden
- **Consent** — we may process data based on your consent (e.g., marketing communications), which you can withdraw at any time
- **Compliance with Legal Obligations** — processing is necessary to comply with applicable laws

---

### 4. Third-Party Services

We use the following third-party services to operate Northlog. Each provider is carefully selected and contractually bound to protect your data:

#### 4.1 InstantDB

**InstantDB** is our primary backend. It provides real-time database synchronization, user authentication, and file storage for PDF exports.

- **Data processed:** All user data (flights, profile, exports, settings)
- **Data location:** United States
- **Compliance:** InstantDB is GDPR-compliant and uses Standard Contractual Clauses (SCCs) for international transfers
- **Privacy Policy:** [https://instantdb.com/privacy](https://instantdb.com/privacy)

InstantDB permissions ensure that each user can only access their own data. No other user or third party can view your flights, profile, or exports.

#### 4.2 RevenueCat

**RevenueCat** manages our Pro subscriptions, including purchases, billing, and receipt validation.

- **Data processed:** Email address (for receipt lookup), purchase history, subscription status, device identifiers
- **Data location:** United States
- **Compliance:** RevenueCat is GDPR-compliant and uses SCCs for international transfers
- **Privacy Policy:** [https://www.revenuecat.com/privacy](https://www.revenuecat.com/privacy)

We never have access to your full payment card details. All payments are processed by Apple App Store, Google Play, or Stripe (depending on platform), and RevenueCat handles receipt validation.

#### 4.3 OpenAIP

**OpenAIP** provides our aerodrome database, which includes airport names, ICAO/IATA codes, coordinates, and country information.

- **Data processed:** Search queries (e.g., airport codes or names you search for)
- **Data location:** Germany
- **Privacy Policy:** [https://openaip.net](https://openaip.net)

Search queries are sent to our Cloudflare Worker, which proxies the request to OpenAIP. Your IP address is not forwarded to OpenAIP.

#### 4.4 Cloudflare Workers

**Cloudflare** hosts our backend server, which handles aerodrome search, aircraft search, and PDF rendering.

- **Data processed:** Search queries, HTML content for PDF rendering, IP addresses (for security)
- **Data location:** Global (Cloudflare’s edge network)
- **Privacy Policy:** [https://www.cloudflare.com/privacypolicy](https://www.cloudflare.com/privacypolicy)

#### 4.5 Cloudflare Browser Rendering (PDF Generation)

When you generate a PDF export, we use Cloudflare’s headless Chromium service to render your HTML into a PDF.

- **Data processed:** The HTML content of your export (which includes your flight data)
- **Data location:** Global (Cloudflare’s edge network)
- **Privacy Policy:** [https://www.cloudflare.com/privacypolicy](https://www.cloudflare.com/privacypolicy)

The HTML is generated client-side from your data and sent to our server for rendering. The PDF is returned to you and then uploaded to InstantDB Storage. We do not store the HTML or PDF on our server beyond the duration of the request.

#### 4.6 Google (Google Sign-In)

If you sign in with Google, we use OAuth 2.0 with PKCE to authenticate you.

- **Data processed:** Email address, name, profile image
- **Data location:** United States
- **Privacy Policy:** [https://policies.google.com/privacy](https://policies.google.com/privacy)

#### 4.7 Apple (Apple Sign-In)

If you sign in with Apple (iOS only), we use Sign in with Apple.

- **Data processed:** Email address, name (if provided)
- **Data location:** United States
- **Privacy Policy:** [https://www.apple.com/privacy](https://www.apple.com/privacy)

#### 4.8 Expo (App Framework)

We use Expo to build and distribute the app across platforms.

- **Data processed:** Device identifiers, crash reports (in development mode only)
- **Privacy Policy:** [https://expo.dev/privacy](https://expo.dev/privacy)

---

### 5. Data Security

We take data security seriously. Your data is protected with:

- **Encryption in transit** — all connections use TLS 1.2+
- **Encryption at rest** — InstantDB encrypts data at rest
- **Access controls** — InstantDB permissions ensure you can only access your own data
- **Secure authentication** — magic codes, OAuth 2.0 with PKCE, and Sign in with Apple
- **Regular security reviews** — we monitor for vulnerabilities and update dependencies

Payment information is never stored on our servers. All payments are processed by Apple, Google, or Stripe, which are PCI-DSS compliant.

---

### 6. Data Retention & Deletion

#### Account Deletion

You can permanently delete your account at any time from your profile settings. When you delete your account:

1. Your user record is immediately removed from active systems
2. All flight data, fleet entries, groups, settings, and daily stats linked to your account are deleted
3. Export PDFs stored in InstantDB Storage under your user path are deleted
4. For up to **30 days**, your data may remain in system backups for recovery purposes, but is not accessible
5. After 30 days, your data is permanently deleted from all systems and backups

#### Guest Accounts

Guest accounts are retained indefinitely as long as you continue using the app. If you sign in with an email, Google, or Apple account, your guest data is migrated to your new account.

#### Export History

Export records (format, date range, page count) are deleted when you delete your account. The generated PDF files are also deleted from storage.

#### Analytics Data

Aggregated, anonymized usage data may be retained for longer periods for product improvement purposes. This data does not contain any personally identifiable information.

---

### 7. International Data Transfers

Your data is stored in the United States (via InstantDB) and processed globally (via Cloudflare’s edge network). When transferring personal data outside the EU/EEA/UK/Switzerland, we ensure appropriate safeguards:

- **Standard Contractual Clauses (SCCs)** — used with InstantDB and RevenueCat
- **Adequacy decisions** — where available
- **Service provider commitments** — Cloudflare and other providers maintain strong privacy frameworks

---

### 8. Your Rights

Depending on your location, you may have the right to:

- **Access** — request a copy of the personal data we hold about you
- **Rectification** — correct inaccurate or incomplete data
- **Erasure** — request deletion of your data
- **Restriction** — request limitation of processing
- **Data portability** — receive your data in a structured, machine-readable format
- **Object** — object to processing based on legitimate interests
- **Withdraw consent** — withdraw any consent previously given (this does not affect lawfulness of processing before withdrawal)
- **Opt out of sale/sharing** — opt out of any sale or sharing of data (California, Virginia, Colorado, and other applicable states)
- **Lodge a complaint** — file a complaint with your local data protection authority

You can exercise these rights by contacting us at [support@northlog.app](mailto:support@northlog.app). We will respond within 30 days.

**Note:** Some rights (such as data portability) can be fulfilled directly through the app by exporting your data as a PDF. Account deletion is also available in your profile settings.

---

### 9. Cookies & Tracking

Northlog does not use cookies for tracking or marketing purposes. We do not use Google Analytics, Facebook Pixel, or any other third-party analytics or advertising trackers.

The web app uses minimal local storage to cache your preferences and offline data. This data is stored locally on your device and synced to our servers.

If we introduce analytics or marketing cookies in the future, we will update this policy and ask for your consent where required by law.

---

### 10. Links to Other Websites

Our App and website may contain links to third-party sites (e.g., the Apple App Store, Google Play Store, or our export format documentation). If you click on a third-party link, you will be directed to that site. We are not responsible for the content, privacy policies, or practices of any third-party sites or services. We strongly encourage you to review the privacy policies of those sites.

---

### 11. Age Limitations

Northlog is not intended for children under the age of 16. We do not knowingly collect personal data from children under 13 (COPPA). If we discover that we have collected personal data from a child under 13, we will delete it immediately. If you believe we have collected data from a child under 13, please contact us at [support@northlog.app](mailto:support@northlog.app).

---

### 12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will:

- Post the updated policy here with a revised effective date
- Notify you through the app or by email for material changes
- The revised policy takes effect immediately upon posting

We encourage you to review this page periodically for any changes.

---

### 13. Contact

If you have any questions about this Privacy Policy, your data, or your rights, please contact us:

**Northlog**

Email: [support@northlog.app](mailto:support@northlog.app)