AERODECK
App Privacy Policy
Updated: 3 October 2026
This notice covers the AeroDeck app for iPhone and Android, its servers and support. The separate website notice describes visits to our landing page.
- The map works without an account. Location sharing is optional.
- Photos are saved to your AeroDeck account. You choose private, friends or public visibility.
- Your email is not public. Direct messages are not end-to-end encrypted.
- You can export data, remove individual items and delete your account.
- Advertising and Premium purchases are currently disabled. We do not sell your personal data.
1. Controller
Nikolai Rat
Haldenstrasse 15
8306 Brüttisellen
Schweiz / Switzerland
team@aerodeck.live
Nikolai Rat operates AeroDeck as an individual in Switzerland. Send privacy requests to the address above. This notice takes account of Swiss data protection law and the EU GDPR / UK GDPR where they apply to the particular processing.
2. Map and technical connections
Our server processes your IP address, technical request details, map area, selected airports, aircraft identifiers and rounded coordinates for weather queries. A random installation identifier supports a short-lived online counter and request limits; it is not an advertising identifier. Online entries remain in memory for about 90 seconds. Security and rate-limit information is also processed temporarily.
Your device loads tiles directly from OpenFreeMap, operated by Hyperknot Software Kft. in Hungary. Your IP address and requested map area are transmitted; an area near you can reveal your approximate whereabouts. OpenFreeMap describes temporary security logging and possible Cloudflare CDN use. See its privacy notice. Global CDN processing can take place outside Europe.
Your device stores preferences, language, cached content, viewed announcements and pending photo uploads. Sign-in credentials use protected operating-system storage. Device copies also depend on your system backup settings; uninstalling may not remove every backup or keychain entry.
3. Location, camera and sharing
With system permission, foreground location supports your map position, compass and aircraft camera alignment. AeroDeck does not request background location. The map works without location permission. You can withdraw permissions in device settings.
- Spotter location: only after you enable sharing, an approximately 0.01°-rounded position, username and avatar are shown to signed-in users nearby. Entries expire after about 30 seconds unless refreshed. Stopping removes the entry; connection loss lets it expire.
- Photo checks: precise location, accuracy, capture time and camera direction are sent to the server to compare a sighting with flight data. Raw coordinates are not retained in the database for this check. Stored results include aircraft, time, airport, rounded distance, plausibility result and XP. Raw details can remain in the device upload queue until uploaded. This is not tamper-proof image verification.
- Meetups: published meeting points are rounded to a grid of about 200 metres and visible as community content.
4. Accounts and sign-in
For accounts we store username, private email, salted password hash, birth year, accepted terms version and time. Profiles are intended for ages 16 and above; adult-only features use a conservative year-based age check. No full birth date is required. Sessions last at most 30 days and server tokens are hashed. Email verification/reset codes are hashed, expire after 15 minutes and have guessing limits. Resetting a password signs out other sessions.
Apple and Google sign-in are currently disabled on the server. Before enabling them, we will explain the relevant provider flows. AeroDeck never asks for your Apple/Google password. Sign-in currently uses your AeroDeck account.
5. Photos, collection and avatar
The camera is used for a capture or boarding-pass scan you start. The current camera takes photos and does not need the microphone. Photo selection opens only when requested. Server re-encoding removes embedded EXIF/GPS metadata from photos. Historical video files from older versions may remain in your account; metadata removal is not promised for those files.
Your private cloud collection stores photos and capture/aircraft details with XP. Choose Private, All friends or Public when sharing. Friends includes accepted friends added later; removing or blocking a friend ends their access. Public photos show your username in the community and on the aircraft; anyone with a public image URL may also open it outside the app. Copies saved by other people cannot be recalled. Your avatar is displayed beside your name in the community features you use.
6. Friends, flight log, groups and messages
Your flight log is private and stores selected flights, date, route, aircraft, seat and cabin. Boarding passes are decoded on-device; passenger name, booking reference, ticket and frequent-flyer numbers are not added to the log or sent to our server. Do not share complete boarding passes in photos or messages.
You can make your profile findable, accept friends and share flights with selected friends. A share displays username, avatar, aircraft, route and, only if you choose, seat. It ends within 24 hours and can be stopped earlier. The optional fellow-passenger feature lets participating adults see usernames, avatars, shared seat details and shared-flight history. Group members see group content, events and attendance.
Direct messages use HTTPS and are stored on our server, not end-to-end encrypted. The operator can technically access them, for example to review a report. Blocking prevents further contact. Messages remain until either participant deletes their account or moderation removes them; there is currently no automatic age-based deletion.
7. Passenger reviews and XP
Optional departure/arrival checks compare current GPS readings with received flight movements. Raw GPS readings are not retained. Your account retains the result, accuracy, distance, time, flight reference and an observation summary. This does not conclusively prove that you were onboard.
Reviews, notes and up to three evidence photos are initially private. Publishing scores and joining a leaderboard under your username are separate choices. Specific concern text and evidence remain confidential between you and the operator. Submissions are reviewed before publication/XP; XP has no monetary value. Tell the crew about urgent safety issues, not AeroDeck.
8. Optional offline cabin chat
Builds with cabin chat use Google Nearby over Bluetooth/local Wi-Fi. Starting discovery or hosting makes your nickname and session identifier visible to nearby devices. Messages are exchanged only after both sides confirm the connection code. Everyone in the room receives messages and the host relays them. History stays in memory, is discarded when leaving and is not uploaded to AeroDeck. Other participants can still save copies. Google Nearby / Play services may process SDK and device diagnostics under the relevant system privacy settings. Provider information.
9. Reporting and moderation
You can report content and block users. We store the reporting account, item, reason and handling status to prevent abuse. The operator can remove content or restrict accounts. Text is checked for abusive terms. Contact team@aerodeck.live to challenge a measure and request human review.
10. Recipients and countries
| Recipient | Purpose and data | Location |
|---|---|---|
| OVHcloud | Website, API, database, media and encrypted backup hosting | Server in London, United Kingdom |
| Resend / Plus Five Five, Inc. | Account/verification email delivery: address, message content, delivery information | USA |
| IONOS and Google/Gmail | Support forwarding to the operator mailbox: sender, content, attachments | Germany/EU and USA; further processing under provider terms |
| OpenFreeMap / Hyperknot Software Kft., potentially Cloudflare | Direct map requests: IP address and map area | Hungary and global CDN locations, including USA |
| Apple, Google | App distribution/testing; Nearby and operating-system services where used, under their own terms | Ireland/EU, USA and provider locations |
| Other users | Content you share and messages addressed to them; public content can be copied | Worldwide |
Our server obtains flight data from ADSB.lol/ADSBDB, weather from MET Norway/NOAA and place data. Sources receive our server address and required aircraft, airport or rounded location queries, not AeroDeck account data. Opening LiveATC, Apple/Google Maps directions or other external links sends the chosen service connection details and the link target; its privacy notice applies.
International transfers require the applicable adequacy decisions or contractual safeguards. Resend's data processing addendum incorporates EU standard contractual clauses with Swiss modifications and the UK Addendum. Ask the controller for information about safeguards and providers. Global service availability does not mean data stays exclusively in Switzerland.
11. Retention and deletion
- Accounts, photos, flight log, friends and preferences: until individual/account deletion; active sharing may end earlier.
- Location markers: about 30 seconds; flight sharing at most 24 hours; pending friend requests 30 days; meetups until 24 hours after their start; reports at most 30 days.
- Passenger checks: incomplete checks expire after 48 hours and are cleaned up seven days later; submitted reviews until entry/account deletion.
- Groups and events: until removed by authorised members/operator or account deletion. Only the latest 200 notifications per account are retained. Automatic age limits for group events and notifications are not currently active.
- Direct messages: as described in section 6; no automatic deadline is promised.
- Backups: seven most recent routine daily copies plus limited event-specific recovery copies. Additional recovery copies currently have no fixed age limit. Deletion does not rewrite backups. Backups are not used for normal access; known deletions must be reapplied after restoration.
- Technical logs: size-limited, rotating operational/error logs; general website access logging is disabled. No fixed number of retention days is configured.
- Email: support content for as long as needed for the request, evidence or mandatory duties. No automatic mailbox expiry is configured. The delivery provider also applies its own retention terms.
Legally required records may be retained longer for that limited purpose, with details provided for a specific access/deletion request. Device copies and recipients' copies may be outside our control.
12. Purposes, legal bases and your rights
We process data to deliver requested features, secure accounts, prevent abuse and provide support. Swiss principles include purpose limitation, proportionality and transparency. Where the GDPR/UK GDPR applies, requested services rely on contract performance (Art. 6(1)(b)), security/proportionate moderation on legitimate interests (f), mandatory duties on legal obligations (c), and processing requiring consent on your revocable consent (a). System permission is not automatically equivalent to data-protection consent.
Subject to applicable law, you can request access, correction, deletion, restriction and portability, object to processing and withdraw consent for the future. Contact team@aerodeck.live. Proportionate identity verification may be needed, never your password. We respond within statutory deadlines and explain any permitted extension.
The in-app export contains structured account data; save photos from your collection. Contact us for additional support/moderation information. You can complain to the Swiss FDPIC, your competent EU/EEA authority or the UK ICO.
13. Security and changes
Production API connections use HTTPS, passwords are salted hashes and server access is restricted. Private content requires an authorised session. No system guarantees absolute security. We update this notice and inform you, where required in advance, about material processing changes. Reading this notice does not authorise new advertising or social sign-in processing.