Need technical assistance, help importing your Monthly HI schedule, troubleshooting DECS sessions, or a data export (Google Play User Data policy, GDPR/CCPA)? The form below drafts an email to the support mailbox — it does not open a ticket, and nothing reaches us until you send it.
Delete your account
Deletes it now, from inside the app, and tells you what is kept. Same action as Settings > Legal & Privacy > Delete Account.
This section explains exactly what the app does, and does not do, when a crew member uses American Airlines' crew portal through it. It is written for crew members and for Apple's App Review team. CrewSchedule Pro is an independent product, not affiliated with, endorsed by or supported by Envoy Air or American Airlines.
1. What the portal is
Envoy pilots and flight attendants manage their schedules in DECS, the airline's crew scheduling terminal. American gives every crew member access to it through WebSabre, a web page at https://webfos.aa.com/WebSabre that opens in any web browser. The WebSabre tab in CrewSchedule Pro opens that same page inside the app, in Apple's standard web view (WKWebView), so it can be used comfortably on a phone. The page, the sign-in and the terminal are American's own, served by American directly to the crew member's phone.
2. Signing in
- The crew member signs in on American's own sign-in page with their own American ID and password, then completes Duo two-factor verification themselves.
- The app does not fill in, read, store or send the American password. It does not type, tick or click anything on the sign-in or Duo pages. That includes Duo's "Trust this browser" option, which is the crew member's own choice.
- The DECS passcode is typed into a prompt at every sign-in and passed straight to the terminal. It is removed from the terminal's input history and kept out of the app's logs. It is never saved on the phone and never sent to us.
- The only sign-in detail the app keeps on the phone is the employee number, because DECS asks for it at every sign-in. It is also part of the crew member's own profile backup (section 6).
3. Where the traffic goes
- Portal traffic goes directly between the phone and American. CrewSchedule Pro's servers never connect to American's systems, never see the session, and cannot act on anyone's account.
- The portal has no address bar and stays on American's and Duo's sites. A link to any other site opens in Safari, outside the app, so the portal is never a general web browser.
- WebSabre is built for desktop browsers, so on the terminal page the app asks for the desktop version, like "Request Desktop Website" in Safari. On the sign-in pages it identifies as the phone's normal browser. To fit a phone screen, the app hides WebSabre's page header, menus and footer around the terminal and sizes the terminal to the screen.
4. What the app types in the terminal, and when
- Only when the crew member asks, for example "import my month", "refresh this trip", "load open time" or "load the reserve list". The app then types the same display commands the crew member would type themselves (HI1 for the month, HSS for a trip's detail, N4D for open time, N6D for the reserve list) and reads American's reply off the screen.
- Commands go one at a time. The app waits for each reply, pauses between commands, and stops if the terminal stops answering.
- Nothing is sent to keep a session alive. After a period of inactivity the app signs out of DECS cleanly, and it does no work in the background on iPhone.
- The crew member can always type in the terminal directly with the app's keypad.
5. Changes to a schedule: nothing is sent without the crew member's tap
- A trip trade, an open-time pickup or a reserve proffer is entered only up to American's own confirmation screen (the trade RECAP, or the proffer's "POST THIS REQUEST" prompt), and the app stops there.
- American's own words are shown on an approval card. The key that makes the change (HZ for a trade, Y for a proffer) is sent once, and only when the crew member taps the card. Cancel sends American's own cancel keys instead.
- After a change is sent, the app reads the result back from DECS. It reports success only when American's system shows the change; otherwise it tells the crew member to check DECS.
- The app never sends one of these keys on its own. It refuses commands known to damage a trade, and it does not offer trip drops.
6. What happens to the data
- Backed up to the crew member's own CrewSchedule Pro account: their profile as their month shows it, their schedule and pairings (with the monthly schedule text they came from), their logbook, vacations and sick-call marks. It is visible only to them. Crew Chat shows other verified crew members their name, base and seat.
- Kept on the phone only: the open-time board, the reserve list, the turnback list, trade-finder results and terminal diagnostics.
- Never collected: other crew members' schedules, the American password and the DECS passcode.
- An account and its data can be deleted at any time, in the app or at /delete-account.
7. Affiliation, and the crew member's employer
CrewSchedule Pro is an independent tool built by an Envoy pilot. It is not affiliated with, endorsed by or supported by Envoy Air or American Airlines, and it says so in its App Store description, on the portal sign-in card and in its Terms of Use. It does only what the crew member's own account can already do, on that account, with their own sign-in, the same as using WebSabre in Safari. It gathers no one's credentials, gets around no security check, collects no one else's data, and has no access of its own to American's systems. A crew member's use of American's systems is still governed by their employer's policies, and the Terms of Use ask users to follow them.
8. For App Review
- We cannot give reviewers DECS access. It requires an American Airlines employee ID and Duo two-factor verification on a registered device, and no outside or demo login exists. The video attached to the submission shows the portal working live on an iPhone. Every other feature works with the test account, which holds a year of synthetic schedule and logbook data.
- Reserve proffer (Tools > Reserve List > Proffer) is new in this version and is on a staged rollout. It is on for the developer's account and the App Review account, and it will be opened to all pilots once it has been checked live during the airline's 10:00–14:00 CT proffer window. The feature is complete in the submitted build, and no code is downloaded to turn it on.
- The only other feature switched from our server, the flight attendant reserve list, is already on for every flight attendant. Nothing else in the app is hidden or switched remotely.