Privacy Policy

Last Updated: 04/08/2026

1. Introduction and scope

At Pilotflows, a service provided by Tegi S.à r.l.-S. ("we", "our", or "us"), we are committed to protecting your privacy and personal data. This policy explains how we collect, use, disclose, and safeguard information when you use the Pilotflows website, web application, related APIs, and other services we offer (collectively, the "Services"), in compliance with the General Data Protection Regulation (GDPR), applicable Luxembourg data protection law, and other applicable laws.

If you use our Services through a mobile or desktop client that connects to the same platform, this policy applies to that use as well. Device permissions, on-device storage, identifiers, purchases, and tracking for the publicly available Pilotflows mobile apps are described in section 5.

2. Controller / company information

Tegi S.à r.l.-S.
Luxembourg
Email: [email protected]

3. Personal information we collect

We collect and process personal information that you provide or that relates to you, including:

  • Account information: name, email address, password (stored in encrypted form)
  • Profile information: profile picture, date of birth, gender, contact information
  • Professional information: certifications, pilot status, organization affiliations
  • Contact details: address, phone number, emergency contact information
  • Payment information: payment method details processed securely through our payment provider (we do not store full card numbers on our own servers)
  • Organization data: company details, VAT ID, organization size
  • Documents: certificates and other files you upload

4. Non-personal and technical information

When you use the Services, we automatically collect certain technical and usage information, such as IP address, browser type and version, device information, cookies and similar technologies, login times, feature usage, and preferences. We use this information to operate, secure, and improve the Services, to detect abuse, and to generate aggregated or statistical insights. Where this information does not reasonably identify you, we may treat it as non-personal information; where it can be linked to you, we treat it as personal data as described in this policy.

5. Mobile applications

This section describes how the publicly available Pilotflows mobile applications collect and use information in addition to the rest of this policy. The apps are published as:

  • Pilotflows for iOS on the Apple App Store (bundle ID com.pilotflows.app)
  • Pilotflows for Android on Google Play (package com.pilotflows.app)

Account data, logbook content, and other information you sync with our platform are processed as described elsewhere in this policy. The disclosures below cover device permissions, on-device storage, identifiers sent to us, in-app purchases, and (on iOS) advertising measurement. They are intended to match the App Store privacy labels and Google Play Data Safety declarations for these apps.

5.1 Pilotflows for iOS

Permissions and why we ask

  • Contacts: with your action only, via the system contact picker, to prefill people you add to your logbook. We do not upload your full address book.
  • Location (when in use): a one-shot approximate location (kilometer-level accuracy) to find the nearest airport for weather and logbook entry helpers. We do not use background location.
  • Photo library (add only): to save shared flight images you choose to export to Photos. We do not read your existing photo library for this purpose.
  • App Tracking Transparency: optional permission used only for advertising measurement described under Tracking below. You can deny tracking and still use the app.
  • Notifications: optional push notifications delivered through Apple Push Notification service (APNs) when you enable them.

On-device storage

The iOS app is offline-first. On your device we store:

  • Access and refresh tokens in the iOS Keychain with accessibility kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly (not synced via iCloud Keychain)
  • An offline SwiftData store of your logbook and related local data
  • Cached avatars and map thumbnails for performance
  • Widget timeline snapshots in the App Group container (group.com.pilotflows.app) so Home Screen widgets can update without re-downloading your full account

Identifiers transmitted to us

  • APNs device token (when you allow notifications), so we can deliver pushes to that device
  • identifierForVendor (IDFV), sent with push-token registration to distinguish installs on the same vendor
  • Device name (UIDevice.current.name) as deviceName at login, so you can recognize sessions and security devices in your account

Purchases

Personal subscriptions purchased in the iOS app are processed through Apple's StoreKit (StoreKit 2) and RevenueCat. We receive entitlement status for the Personal product so we can unlock paid features. Apple processes payment credentials; we do not receive your full card number from App Store purchases. You can manage or cancel App Store subscriptions in your Apple ID settings or via in-app subscription management where available.

Tracking and advertising measurement

Pilotflows for iOS integrates Meta's Facebook App Events SDK (facebook-ios-sdk) for install, open, and automatic in-app purchase event measurement, including SKAdNetwork. It also integrates Google's Firebase Analytics SDK (firebase-ios-sdk / Google Analytics for Firebase) for app usage analytics. Where required, we present Apple's App Tracking Transparency prompt before using the advertising identifier for cross-app tracking. If you decline, we limit tracking accordingly while continuing to operate the app. Tracking domains used for these purposes include ep1.facebook.com and app-measurement.com.

App Store privacy labels (summary)

Consistent with our App Store privacy nutrition labels and privacy manifest, data types associated with the iOS app include (linked to your identity where applicable): name, email address, phone number, coarse location, contacts (user-selected), other user content (e.g. logbook), user ID, device ID, and purchase history. User ID and device ID may be used for tracking (advertising measurement) when you grant ATT permission. Purposes are primarily app functionality, with analytics and third-party advertising measurement only where described above.

5.2 Pilotflows for Android

The Android app provides access to the same Pilotflows Services on Google Play. Account, logbook, and other synced data are processed under this policy in the same way as the website and web application. Platform features such as passkeys and deep links may use Android system APIs and Digital Asset Links for com.pilotflows.app.

Google Play's Data Safety section for Pilotflows discloses that the app may share location and personal information (and related categories) with third parties as needed to operate the Services, may collect photos and videos you choose to upload or save through the product, encrypts data in transit, and supports deletion requests. Prefer that Play Store listing for the current Android Data Safety labels; this policy remains the controlling description of how Tegi S.à r.l.-S. processes personal data.

In-app or Play Billing purchases, where offered, are processed by Google and/or our payment partners (see also section 8). Device identifiers and push tokens may be processed to deliver notifications and secure your sessions, analogous to the iOS identifiers above.

6. Use and processing of information

We use personal data for purposes including:

  • Providing and managing your account and our services
  • Processing and managing subscriptions and payments
  • Storing and managing your certificates and documents
  • Enabling two-factor authentication for account security
  • Sending service-related communications and updates
  • Managing organization memberships and permissions
  • Analyzing platform usage to improve our services
  • Ensuring platform security and preventing fraud
  • Complying with legal obligations

Legal bases (GDPR)

Where GDPR applies, we rely on one or more of the following legal bases:

  • Performance of a contract: processing necessary to provide the Services you request
  • Legal obligation: processing required to comply with applicable law
  • Legitimate interests: for example improving the Services, ensuring security, and operating our business, where not overridden by your rights
  • Consent: where you have given clear consent for specific processing (you may withdraw consent at any time where processing is based on consent)

7. Storage, retention, and international transfers

We implement technical and organizational measures to protect data, including encryption of data in transit and at rest, access controls and authentication mechanisms, two-factor authentication support where enabled, regular backups, and security monitoring. Infrastructure and related processing may be provided by third parties listed in section 8.

We retain your data for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. After account deletion, we may retain certain information where required or permitted by law or for legitimate business purposes (for example fraud prevention or legal claims).

Your information may be processed in countries outside the EU/EEA. Where we transfer personal data to such countries, we use appropriate safeguards such as Standard Contractual Clauses or other mechanisms recognized under applicable data protection law.

8. Third-party service providers

We use trusted third-party services that may process personal data. They are listed below by purpose. Providers are contractually bound to protect your data and use it only for specified purposes. A current list is also published on our What Powers Us page and in Annex A of our Data Processing Agreement.

Infrastructure and hosting

  • AirNav Radar: Flight and aircraft data enrichment for logbook and hangar features
  • Amazon Web Services (AWS): Object storage and related cloud services for files and application data
  • Apple: App Store distribution and authentication when you use Sign in with Apple
  • AVWX: Aviation weather (METAR/TAF) data for tools and in-product weather
  • Cloudflare: DNS, CDN, edge security, and bot protection (e.g. Turnstile) where you submit data
  • Hetzner: Server hosting and compute where the service and your data are processed
  • Mapbox: Maps and location-related features in the product
  • MongoDB: Primary database for accounts, organizations, logbooks, and related application data
  • Upstash: Managed Redis for caching, job queues, and related application data

Payments and billing

  • Apple In-App Purchase: In-app subscription and purchase processing on Apple platforms
  • Google Play Billing: In-app subscription and purchase processing on Google Play for the Pilotflows Android app
  • RevenueCat: In-app subscription management and receipt validation
  • Stripe: Payment processing and billing

Communications and notifications

  • Apple Push Notification service (APNs): Delivery of push notifications to Apple devices
  • Calendly: Scheduling and meeting booking
  • Expo Push: Push notification delivery for Expo / React Native mobile clients
  • SendGrid: Transactional and notification email to your email address
  • Twilio: SMS delivery to you when we send text messages
  • Web Push: Browser push notification delivery via the Web Push protocol

Analytics and advertising

  • Firebase Analytics (iOS SDK): Mobile app usage analytics on Pilotflows for iOS (Google Analytics for Firebase via firebase-ios-sdk)
  • Google Ads: Advertising measurement: browser tags with Consent Mode (marketing consent) and server-side offline conversion uploads of SHA-256 hashed email plus click IDs (gclid / gbraid / wbraid)
  • Google Analytics: Website and product usage analytics (Google Analytics 4 via gtag), loaded only after analytics cookie consent; related Firebase Analytics streams power mobile measurement where configured
  • Meta (Pixel and Conversions API): Advertising measurement: Meta Pixel in the browser (marketing consent) and Conversions API server-side events with SHA-256 hashed email, external ID, IP address, and user agent
  • Meta Facebook iOS SDK: Mobile advertising and attribution events on iOS (consent-gated)

Artificial intelligence

  • xAI: AI-assisted processing of logbook and import content you choose to submit (images/PDFs processed in-request and not retained on Pilotflows; temporary xAI Files API upload then deleted; in-memory extraction session ~15 minutes)

Monitoring and observability

  • Better Stack: Centralized application logging and operational observability
  • Sentry: Error and performance monitoring, including Session Replay sampled at 10% of sessions with all text masked and all media blocked

Advertising and analytics

Browser tags (consent)— Meta Pixel, Google Ads gtag (with Google Consent Mode), and related marketing scripts load only after you grant Marketing cookie consent. Google Analytics 4 loads only after Analytics cookie consent. These choices are stored as described in our Cookie Policy. Legal basis: consent.

Server-side conversion matching— When you complete a purchase, our servers may transmit SHA-256 hashed email and related identifiers to advertising platforms for conversion measurement: Google Ads offline conversions (hashed email plus click IDs such as gclid, gbraid, or wbraid) and Meta Conversions API (hashed email, hashed external ID, IP address, and user agent). Hashed email remains personal data under the GDPR. These server-side events are not gated by the browser cookie banner; they run from our backend when a qualifying conversion occurs. Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in measuring advertising effectiveness and attributing completed purchases to campaigns. You may object under sections 11 and 12.

Google Analytics 4— We use Google Analytics 4 for website and product usage analytics (page views and aggregate events via gtag). It loads only after Analytics consent. On Pilotflows for iOS we also use the Firebase Analytics SDK (Google Analytics for Firebase) for app usage measurement. Legal basis: consent for website tags; legitimate interests (Art. 6(1)(f) GDPR) and, where required, App Tracking Transparency for advertising identifiers on iOS.

Session replay and error monitoring

We use Sentry for error and performance monitoring. On marketing, dashboard, and admin clients we may also enable Session Replay at a session sample rate of 0.1 (10% of sessions), with maskAllText and blockAllMedia so replay content is masked and media is blocked. Legal basis: legitimate interests in diagnosing defects and improving reliability (sections 11 and 12 for objection).

Artificial intelligence processing

When you choose to use AI-assisted logbook import, we send the content you submit (for example screenshots or PDFs) to xAI for extraction. Uploaded images, screenshots, and PDFs are not persisted on Pilotflows for this flow: they are processed in-request (PDFs may be temporarily uploaded to the xAI Files API and then deleted). The in-memory extraction session is retained for about 15 minutes or until you confirm the import. Confirmed logbook entries become your account data under normal retention. Legal basis: performance of a contract (providing the import feature you request) and, where required, consent for submitting content to the AI processor.

9. Information security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, and disclosure. No method of transmission over the Internet or electronic storage is completely secure; you acknowledge that we cannot guarantee absolute security, and you use the Services at your own risk to that extent.

10. Data breach

If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data, we will investigate, take reasonable steps to mitigate harm, and notify supervisory authorities and/or affected individuals where required by law or where we otherwise consider notification appropriate based on the risk to your rights and freedoms. We may cooperate with law enforcement and regulators as appropriate.

11. Your rights

Depending on your location and applicable law (including GDPR and applicable Luxembourg law where relevant), you may have the right to:

  • Access: obtain confirmation of whether we process your personal data and receive a copy in many cases
  • Rectification: request correction of inaccurate or incomplete data
  • Erasure: request deletion of your personal data, subject to legal exceptions
  • Restriction: request that we limit processing in certain circumstances
  • Data portability: receive your data in a structured, commonly used format where technically feasible
  • Object: object to processing based on legitimate interests (see also section 12)
  • Withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal
  • Lodge a complaint: with a data protection supervisory authority in your country or region

Where Luxembourg law applies, your rights under the GDPR are supplemented by national provisions. In Luxembourg, the supervisory authority is the Commission nationale pour la protection des données (CNPD); see the "Lodge a complaint" bullet above and section 13 for how to reach us.

12. Right to object

Where we process personal data based on legitimate interests, you may object to that processing on grounds relating to your particular situation. We will stop unless we demonstrate compelling legitimate grounds that override your interests or rights, or processing is needed for legal claims.

If we ever use your personal data for direct marketing, you may object to such processing at any time without providing a reason. Service emails about your account, security, or the Services are not considered marketing unless they promote third-party products or optional add-ons beyond core service communications.

13. How to exercise your rights

To exercise any of these rights, contact us at [email protected]. We will not charge a fee for fulfilling GDPR requests unless they are manifestly unfounded or excessive. We will respond within one month where GDPR applies, or as otherwise required by applicable law; that period may be extended by up to two further months for complex requests, in which case we will inform you of the extension.

14. Children's privacy

The Services are not directed at children under 16. We do not knowingly collect personal information from anyone under 16. Separately, our Terms of Service require you to be at least 18 (or the age of majority in your jurisdiction, if higher) to create an account or use the Services. If you believe a child has provided us with personal data, please contact us and we will take steps to delete such information where required by law.

15. Links to third-party websites and services

The Services may contain links to third-party websites, integrations, or services that we do not operate. This policy does not apply to those third parties. We encourage you to read their privacy policies before providing any information to them.

16. Changes to this policy

We may update this policy from time to time. We will post the updated policy on our website and, where changes are material, notify you through the Services or by email where appropriate. The "Last updated" date at the top reflects the latest revision.

17. Acceptance

By accessing or using the Services, you acknowledge that you have read this policy. If you do not agree, you should not use the Services. Where we rely on consent, we will obtain it separately as required. Continued use of the Services after we post changes to this policy constitutes your acknowledgment of the updated policy, subject to your statutory rights and any additional agreements between us.

18. Contact us

For privacy-related inquiries or to exercise your rights, contact us at: [email protected]

Data Protection Officer
Tegi S.à r.l.-S.
Luxembourg