Privacy Policy

CrewSchedule Pro • Version 2026.6

11 Sections
Local-First & Zero Data Monetization
Effective September 10, 2026

CrewSchedule Pro is built for professional airline pilots and flight attendants who value confidentiality. Your flight schedules, sequence pairings, OOOI timestamps, logbook hours, and personal notes remain stored locally on your device or in your private encrypted cloud vault. We never sell or monetize your data.

Hosted on Hostinger Dedicated ServerCode: 2026.6

1. Privacy Overview & Local-First Architecture

Privacy First

CrewSchedule Pro is built with a Local-First Privacy Architecture. Your flight schedules, sequence pairings, OOOI timestamps, and logbook entries are stored locally on your device (app-private IndexedDB / WebView storage, excluded from Android cloud backup).

The Application does not store your airline passwords, on the device or anywhere else, and there is no option to save them. Your DECS passcode is typed into the phone's own prompt each time you sign in to DECS, is used for that one sign-in, and is never written to storage, to a backup, or to any log. AA portal sign-in and Duo are completed by you on American's own pages inside the portal view, so the Application never receives that password. Earlier builds could save a DECS or AA password on your profile; an install upgrading from one of those builds has those fields deleted from the stored profile on first launch.

Apex Hospitality Holdings, LLC does NOT sell, rent, monetize, or trade your personal flight records or operational schedules with third-party advertisers or data brokers.

2. Categories of Data Processed

Transparency

Profile Information: Name, Employee ID, Seniority Number, Base Domicile, Fleet Equipment (E170/E175), Crew Role (Captain, First Officer, Flight Attendant), Date of Hire, and your pay settings (hourly rate and pay options). If you choose to tell us who referred you during setup, the name and/or employee number you enter is stored with your profile; it is optional and is never shown to other crew members.

Pairing Data: Flight numbers, airport station pairs, block times, layover cities, release times, and rest periods.

Logbook Records: Out-Off-On-In (OOOI) timestamps, aircraft tail numbers, flight duration, instrument approaches, and landings.

Location Data: Precise device coordinates, collected for two purposes and for nothing else. (a) The GPS Flight Matcher detects airport geofences to time your block out and in; it is off by default and collects nothing until you turn it on in Settings. (b) The Briefing map draws your own-ship position, so it takes a fix while that screen is open and again when you tap Locate Me, whether or not the GPS Flight Matcher is on; the most recent fix is kept on this device so the map can show your last known position. Both are processed on the device, and neither is sold, shared with advertisers, or uploaded with your backup.

App Usage Telemetry: While you are signed in to a CrewSchedule Pro account and setup is complete, the Application sends a presence heartbeat about once a minute while it is open, plus an event when it launches and when you switch tabs. Those records carry your base, crew position, aircraft type, device platform, device model, app version, the screen you are on, and a session identifier, keyed to a one-way hash of your sign-in account. They contain no name, employee ID, email address or IP address, and no schedule, logbook, message or location content. The Application collects no crash reports and contains no crash-reporting, advertising or third-party analytics SDK. These records are deleted automatically after 90 days, and Delete Account removes them immediately.

Server Access Logs: Every authenticated request your device makes to the CrewSchedule Pro API is recorded on the server with your sign-in account identifier, the network address (IP address) the request came from, your device's user agent string, the endpoint called and whether it was allowed or refused. No email address is stored on these rows. They exist to investigate abuse, failed sign-ins and attempts to reach data belonging to another crew member, and they are deleted automatically 30 days after they are written. Delete Account removes every one of them immediately, including the row written by the deletion request itself.

Security Incident Records: Separately from the access log above, a failed sign-in, an unauthenticated probe, or an attempt to reach an administrative endpoint without authorisation is recorded with the source network address (IP address), the user agent string, the endpoint, a short excerpt of the request and the reason it was flagged. These records are kept for 365 days. Unlike everything else described here, they are deliberately NOT removed by Delete Account, so that an account cannot erase the record of its own misuse.

3. How Your Data Is Used & Anonymized Trend Analytics

Operational Intelligence

Your data is used to: (a) calculate FAR Part 117 flight duty period limits; (b) compute CBA compensation, per diem, and premium pay estimates; (c) automate flight tracking and digital logbook records; (d) synchronize across your authorized personal devices via encrypted cloud storage; and (e) provide offline flight briefings.

Aggregated Usage Statistics: We may compute de-identified, aggregated counts from the App Usage Telemetry described in Section 2 (for example, how many crew members use the Application by base, crew position, aircraft type and device platform, and which screens are used) to plan capacity and prioritise features. No schedule, logbook, pay, trade or location content is used for this. Aggregated Data contains no personally identifiable information (PII) and cannot be reverse-engineered to identify any individual.

4. Location Services & GPS Disclosure

Location Use

The GPS Flight Matcher — the feature that times your block out and in from position fixes — collects location ONLY if you turn it on in Settings. The toggle is off by default, and while it is off nothing on the GPS Logbook screen reads your position either.

The Briefing map is the one other place the Application asks for a fix, and it does so independently of that toggle: it draws your own-ship position on the weather and chart map, so it takes a fix while that screen is open and again when you tap Locate Me. That fix draws the map and is kept on this device so the map can show your last known position; it is not written to your logbook, not uploaded with your backup, and not shared. Denying the location permission leaves the map working without an own-ship symbol.

Collection happens only while the Application is open on screen, and again the moment you bring it back to the foreground. There is no background location service and the Android build declares no background-location permission: your phone freezes the Application once it is backgrounded, so nothing is recorded while it is closed or in the background. A sit, a night at the hotel, or a leg flown with the Application closed is time it never saw, and the GPS Logbook marks those stretches as unobserved instead of guessing at them.

Location data is processed on-device and is never used for advertising, behavioral tracking, or shared with third-party tracking SDKs. You can turn the feature off at any time in Settings or revoke the permission in Android app settings.

5. Cloud Backup & Account Data

Cloud Backup

If you create an account, your profile (name, employee ID, base, seat, hire date, pay settings, and any referral you entered), schedule, and logbook are backed up to servers operated for Apex Hospitality Holdings, LLC (Firebase Authentication / Cloud Firestore by Google, and a Hostinger-hosted API) so they can be restored on another device. Data is encrypted in transit (TLS). No airline password or DECS passcode is ever part of a backup, because the Application does not store them; any password field left on a profile by an older build is stripped before the profile is uploaded.

Backups are tied to your authenticated account and are not accessible to other crew members unless you explicitly start a crew chat or schedule share.

Shared calendar feeds use a private, randomly generated link that you can regenerate at any time from the Calendar tools; anyone holding the link can read the schedule it publishes, so share it only with people you trust.

Crew messaging: direct messages and group chats are encrypted (ECDH P-256 key agreement, AES-GCM) and no other crew member can read them. Your messaging key belongs to your ACCOUNT, not to one phone: it is generated on your device and kept in your own private record so that reinstalling the app, replacing your phone or signing in elsewhere does not lose your history. Because the key is held for your account rather than only on your handset, this is not end-to-end encryption in the strict sense — the operator of the service could in principle access message content, and we tell you that plainly rather than claiming otherwise. Base channels (ORD, DFW, MIA, PHX) are open to every signed-in crew member at that base and are not private at all; treat them as a shared bulletin board.

6. Data Retention, Export & Account Deletion

Right to Erasure

You can export your complete schedule and logbook in JSON or CSV format from the Settings tab at any time.

In-app deletion: Settings > Legal & Privacy > Delete Account permanently deletes your server backup (profile, schedule and sequence backups, DECS imports, logbook backup, calendar events, and any shared calendar feed link you had published), the employee number bound to the account, your authorised-user record including the email and display name on it, your presence and app-usage telemetry rows, every server access-log row for the account, your Cloud Firestore profile document and crew directory entry, your Firebase sign-in account, and this device's app storage — profile, schedule, logbook, snapshots, calendars, settings, cached messages, the device's message encryption keys, and the employee number the DECS terminal keeps. Deletion is immediate and cannot be undone.

What deletion keeps, and why. Three things on the server survive it. First, proof that this account accepted each legal document version: the employee ID is cleared from those rows and what remains is a one-way hash, the document type, the version code and the date, kept as evidence that consent was given. Second, any record of an employee-number claim that moved a number between two accounts, because that record is evidence about the other crew member as well and is not yours alone to erase. Third, security-incident records of failed or anomalous sign-in attempts, so that an account cannot erase the record of its own; those are kept for 365 days from the attempt and then deleted. For almost every account the second and third are empty. Separately, messages you already posted to a base channel (ORD, DFW, MIA, PHX) stay in that channel, and direct messages already delivered stay in the recipient's conversation — they are his copy as much as yours. Your own messaging key is deleted with your account.

Deletion by request: if you no longer have the app installed, email info@apexhospitalityllc.com with the subject "CrewSchedule Pro account deletion" from the email address on the account, or use the request form on the Support page. Requests are completed within 30 days.

"Erase All Data" in Settings removes data from this device only and does not delete your server account; use Delete Account for that.

7. Third-Party Services & Integrations

Service Providers

The Application uses Google Firebase (Authentication and Cloud Firestore) for sign-in and cloud backup, and a Hostinger-hosted API operated for Apex Hospitality Holdings, LLC for backup and telemetry. It also connects to external aviation data feeds: NOAA Aviation Weather Center (AWC) for METAR, TAF, pilot report and SIGMET/AIRMET products; NOAA National Weather Service map services for radar imagery and warning polygons; the Iowa Environmental Mesonet at Iowa State University for archived ASOS/AWOS observations, satellite imagery and a fallback radar mosaic; atis.info for D-ATIS text; OpenStreetMap for map tiles; and FAA VFR sectional and IFR-low chart tiles served from ArcGIS Online. The FAA System Wide Information Management (SWIM) flight data feed is subscribed to by the Hostinger-hosted API on the server, not from your device. When you import a PDF, the PDF file itself is read on your device and is not uploaded.

Weather, chart and map services receive the airport identifiers and map coordinates needed to answer the request, and the network address your device connects from. They do not receive your name, employee ID, schedule or logbook.

The Application no longer routes any request through public CORS proxy services; external data is fetched directly from the provider or through the Hostinger-hosted API named above.

8. California (CCPA/CPRA) & European (GDPR) Privacy Rights

Global Rights

Under CCPA/CPRA and GDPR, crew members have the right to: (a) know what personal information is collected; (b) request deletion of personal information; (c) opt out of any sale or sharing of personal data (we do NOT sell data); and (d) non-discrimination for exercising privacy rights.

9. Texas Biometric Privacy & CUBI Safe Harbor

Texas CUBI Compliant

Pursuant to the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001), Apex Hospitality Holdings, LLC does not collect, capture, store, or sell biometric data.

CrewSchedule Pro has no biometric feature at all: it does not offer fingerprint or face unlock, contains no biometric code or library, and the Android build removes the biometric permissions so that no dependency can reintroduce them.

10. Children's Privacy

18+ Requirement

This Application is intended strictly for professional airline crew members and aviation personnel aged 18 and older. We do not knowingly collect personal information from individuals under the age of 18.

11. Privacy Officer & Contact Information

Contact

For privacy inquiries, data subject access requests, account deletion requests, or official notices, please contact:

Apex Hospitality Holdings, LLC Attn: Data Protection Officer 3120 Southwest Fwy Ste 101 PMB 250957, Houston, Texas 77098-4520 US Email: info@apexhospitalityllc.com