Privacy Policy

Last updated August 23, 2026

OOOIPilot (“we”, “us”), a product of AnchorfulVentures by Anchorful LLC, is built so that your logbook stays yours. This policy explains what we collect, how it’s used, and the controls you have.

What we collect

  • Account information - your name, email address, and internal user ID (including basic profile data returned by Google or Apple sign-in) used to authenticate you and sync your data.
  • Logbook data - the flights, times, routes, aircraft, crew, and notes you create.
  • Photos you scan - OOOI page images are read by OCR on your device. Two things can send a scan to us: the optional cloud-OCR rescue for a difficult page, and the scan-contribution setting described below.
  • Support reports and evidence - when you report a problem, we collect what you write, device and app context, and any screenshots, photos, or PDF documents you choose to attach.
  • Personal and credential metadata - loyalty and trusted-traveler details plus passport, medical-certificate, recurrent-training, and other credential expiry metadata when you enable the related account sync or reminders.
  • Purchase history - the store product, transaction or receipt, and resulting entitlement needed to verify and restore App Store, Google Play, or web purchases. We do not receive full payment-card details.
  • First-party product analytics - our /api/e service records app installs, pages and features used, signup and purchase events, a stable first-party installation ID, limited campaign labels, and the referring website’s origin or host when available. After you sign in, that ID and later events are linked to your account. Vercel derives a coarse country for these events; we do not store the raw IP address or precise location.
  • Diagnostics - Sentry crash reports, performance traces, and app, OS, platform, and device-model context. Sentry receives your internal user ID while you are signed in so we can connect a failure to a support report.

How your data is stored

Your logbook is stored on your device first (so the app works offline). When you sign in, it also syncs to your private account in our cloud database, protected by row-level security so it is visible only to you. We never sell your logbook data, and your flights are never used for advertising.

Helping OOOIPilot read your fleet (scan contributions)

OOOIPilot gets better at reading OOOI pages by studying real ones. This setting is on by default, and you can turn it off in two places: the checkbox on the review card every time you scan, and Settings. It only ever runs when you are signed in.

While it is on, confirming a scan uploads:

  • the page image you photographed, and
  • the parsed flight fields from that page - OUT, OFF, ON, IN, block time, departure and arrival airports, tail, and flight number - both as the OCR read them and as you corrected them, so we can see what it got wrong.

Crew names and notes are never included. Your crew never agreed to anything here, so their names stay on your device, and so does anything you typed into notes. Your loyalty numbers, documents, and trusted-traveler IDs are never part of a contribution either.

Contributed scans go to private storage only we can read, are used solely to improve OCR accuracy for every pilot, and are never sold, shared for advertising, or attached to your public profile. Once a scan has been used for that training, the image is deleted - within 30 days at the outside. We keep only the anonymous record of what the OCR read versus what it should have read.

Turning contributions off stops automatic contribution uploads. A scan can still leave your device only when you choose the cloud-OCR rescue for that image or deliberately attach it to a support report.

Support reports and attachments

Files you choose to attach to a problem report are stored in private support storage and can be opened only by authorized OOOIPilot administrators through short-lived links. We use them only to investigate and resolve the report. They are not public, used for advertising, or used to train a model. Unfinished uploads expire after 24 hours and are removed by an hourly cleanup, and submitted reports and attachments are deleted when you delete your account.

Personal and loyalty data

When personal sync is on, your loyalty numbers, hotel and rental-car memberships, trusted-traveler IDs (Known Traveler Number, Global Entry, TSA PreCheck, and Known Crewmember), and settings expiry values are stored in your own account, protected by row-level security. This can include passport and medical-certificate expiry metadata; the latter is treated as health information. Turn personal sync off and new changes stay on that device. An existing synced copy remains in your account until you delete it or delete the account.

Full document files remain on your device. If you enable expiry-reminder emails, only a document or trusted-traveler item’s label, kind, and expiry date are sent for the reminder; the document file and number remain on your device. We never sell this data, share it for advertising, or use it to train a model.

Analytics & advertising

Every surface - web, PWA, iPhone, iPad, and Android - uses our first-party product analytics described above. It is used to understand whether core flows work, improve the product, and measure signup and purchase conversion. It is separate from advertising consent and is pseudonymous until an account is linked after sign-in.

On the website only, Google Analytics, Microsoft Advertising, and Meta Pixel may measure site and campaign activity under the consent choice shown there. Those third-party tags are compiled out of the installed iOS and Android apps. Neither first-party analytics nor those web tags receive your logbook entries, scan images, document files, or support attachments. We do not sell data or use it to track you across other companies’ apps.

Email communications

We use your email, account plan and purchase state, signup and product-interaction history, stable installation ID, and acquisition or campaign segment to send account messages and OOOIPilot lifecycle marketing. The referrer host that brought you to OOOIPilot can be used for acquisition attribution and lifecycle marketing segmentation. That includes onboarding, trial-ending or upgrade messages, and occasional roadmap invitations. Resend stores the email, plan, and acquisition segment needed to route those messages.

Use the unsubscribe link in a lifecycle marketing email to stop future marketing messages; Resend’s suppression state is copied back to your account. Required authentication, security, purchase, or other service messages may still be sent when needed to operate the account.

Service providers

We use a small set of trusted processors strictly to operate the service:

  • Supabase - authentication and your private cloud database.
  • Vercel - application hosting, first-party event delivery, and coarse country derivation.
  • Apple and Google - sign-in and native-app purchase processing.
  • Stripe - web subscription payments (we never see or store your full card details).
  • Resend - authentication, service, reminder, and lifecycle marketing email plus unsubscribe handling.
  • Sentry - crash and performance diagnostics.
  • OpenAI - only if you opt into cloud-OCR for a specific image.
  • Google Analytics, Microsoft Advertising, and Meta - consent-controlled website measurement; their tags are not shipped in the installed apps.

Your controls

  • Export your entire logbook to CSV/PDF at any time.
  • Delete your data from Settings; to remove your account entirely, follow Delete your account.
  • Restore an erased flight log within 30 days from Settings, before it is permanently purged.
  • Turn off scan contributions at any time, from the review card when you scan or from Settings.
  • Turn off personal sync or reminder emails to keep future credential changes and reminder metadata on your device.
  • Access & correction - your data is editable directly in the app.

Data retention

We keep your data while your account is active. When you delete your account, we delete your associated cloud data, except where we must retain limited records (e.g., payment records) to meet legal obligations.

When you erase your flight log, it is not removed immediately: we hold it in a recoverable state for 30 days so an accidental erase can be undone (from Settings or by contacting us), and we email you to confirm the erase and explain how to restore it. After 30 days the erased flights are permanently purged and can no longer be recovered.

Security

Data is encrypted in transit. Access to your cloud data is restricted to your authenticated account. No system is perfectly secure, but we work to protect your information and limit what we collect in the first place.

Children

OOOIPilot is intended for professional pilots and is not directed to children under 16.

Changes

We may update this policy; we’ll revise the “last updated” date and, for material changes, notify you in-app or by email.

Contact

Questions about privacy? Email support@oooipilot.com.