Privacy
Privacy Policy
Sectional AI is built so that we hold as little of your data as possible. This policy describes exactly what the app sends off your device, what we store, and what we never collect. It is written to match the app's App Store privacy label.
What we collect
- Work email address — used once per sign-in to deliver a one-time verification code. We store only a cryptographic hash (HMAC) of the address to protect the delivery binding; the readable address is not retained after the code email is sent.
- Member identifier — after verification, your account is known to our servers only as an opaque token derived by keyed hash. Your employee number itself is never stored; only its keyed hash is, for the one-time roster match at sign-in.
What never leaves your device
- Your profile (name, seat, base, seniority number), schedule, logbook, pay data, and imported documents. These live on your device.
- Your calendar. The optional crew-calendar import runs entirely on-device.
- Photos and camera. The camera is used only to scan a QR code when pairing a second device; images are never stored or uploaded.
- Face ID. The optional app-lock uses the system's authentication; biometric data never reaches us (or the app).
Asking questions
Document search runs on your device. When you ask a question online, the app sends only your typed question and the retrieved document excerpts to our answering service — never your identity, schedule, employee data, or location. Questions are not logged or retained by us. Offline, answering runs entirely on your device.
Cross-device sync
If you use more than one device, your data syncs through our servers as end-to-end encrypted ciphertext, keyed on your devices. We cannot read it, and we could not produce a readable copy if asked.
What we don't do
- No analytics, telemetry, or usage tracking of any kind.
- No advertising, no data sale, no sharing with third parties.
- No tracking across apps or websites.
Service providers
Our servers run on Cloudflare. Verification-code emails are delivered through a transactional email provider, which processes the delivery address for that purpose only. Push notifications use Apple's service and carry no content — they only prompt the app to check for document updates.
Retention & deletion
Sign-in sessions expire automatically. Synced ciphertext persists so your devices can restore it; deleting the app's data from your devices and contacting support@sectionalai.app removes the server-side ciphertext and hashes associated with your opaque identifier.
Changes & contact
We'll update this page if practices change, and material changes will be noted in the app's release notes. Questions: support@sectionalai.app.