Privacy
Privacy Policy
Sectional AI is built so that we hold as little of your data as possible. This policy describes exactly what the app sends off your device, what we store, and what we never collect. It is written to match the app's App Store privacy label.
What we collect
- Work email address — used once per sign-in to deliver a one-time verification code. We store only a cryptographic hash (HMAC) of the address to protect the delivery binding; the readable address is not retained after the code email is sent.
- Member identifier — after verification, your account is known to our servers only as an opaque token derived by keyed hash. Your employee number itself is never stored; only its keyed hash is, for the one-time roster match at sign-in.
- Sign in with Apple (optional) — the app doesn't ask Apple for your name or email. We store only a keyed hash of the account identifier Apple provides, linked to your member identifier.
- Notification token — your device's push token, stored with your member identifier so we can prompt the app to check for document updates.
What stays on your device
- Your schedule and its calendar link, your seniority number, and the downloaded contract library. These are never uploaded; live flight lookups send only the public details described below.
- Your calendar. The optional crew-calendar import runs entirely on-device.
- Photos and camera. The camera is used only to scan a QR code when pairing a second device; images are never stored or uploaded.
- Face ID. The optional app-lock uses the system's authentication; biometric data never reaches us (or the app).
Asking questions
Document search runs on your device. When you tap Max Thrust for a cloud answer, the app sends your typed question to our answering service, which answers from its own copy of the contract documents. When the question needs it, the app also sends a short fact about your tenure that it derives on your device — for example “7th year, 737 Captain.” An opaque identifier is sent only to count your monthly limit. The app never sends your name, employee number, email, hire date, schedule, or location with a question. Questions are not logged or retained by us. Offline, answering runs entirely on your device.
Live flight information
When you're online, live flight features look up public flight status — flight numbers, airport codes, and dates — through our servers. Commute searches also send the departure-time windows the app works out from your report and release times, plus an opaque identifier used only to count your daily limit. The app never sends your name, employee number, email, or the rest of your schedule for these lookups.
Airport weather
When you open a flight while online, the app fetches the current weather observations (METARs) for its airports directly from aviationweather.gov, a U.S. government (NOAA) service. That request carries only the airport codes; like any web request, it also shows that service your device's IP address.
Cross-device sync
Whenever you're signed in, the app syncs your profile and settings (display name, seat, equipment, base, hire date, category, commute airport, and pay and tax settings), your logbook, saved answers, sick calls, and imported documents such as timecards through our servers as end-to-end encrypted ciphertext, keyed on your devices. This happens even if you use only one device, so your data can be restored. We cannot read the contents, and we could not produce a readable copy if asked; our servers see only each record's type, size, and when it changed.
What we don't do
- No analytics, telemetry, or usage tracking of any kind.
- No advertising, no data sale, and no sharing with third parties beyond the service providers below.
- No tracking across apps or websites.
Service providers
Our servers run on Cloudflare. Verification-code emails are delivered through a transactional email provider, which processes the delivery address for that purpose only. Push notifications use Apple's service and carry no content — they only prompt the app to check for document updates. Online answers are generated by Google's Gemini API, which receives the question (and the tenure fact, when used) from our server. Live flight status comes from FlightAware and adsb.lol, and airport delay status from the FAA; they receive only the public flight and airport details above from our server. Weather radar images come from Xweather, which receives only the map area being displayed. Maps are drawn by Apple Maps.
Retention & deletion
Sign-in sessions expire automatically. Synced ciphertext persists so your devices can restore it until you delete your account.
When you use Delete Account in the app's Settings, we immediately delete your synced data and its backups, your wrapped encryption keys, your devices and their notification tokens, your usage records and referral code, the link to your Apple or Google sign-in, and the link between your employee number and your work email, and we sign you out of your account on every device. The app then erases its data on that device.
Our database provider's recovery backups keep deleted records for up to 30 days, and usage counts (numbers only) expire within 40 days. We keep a referral record with no personal information to prevent abuse. Records needed to honor an App Store subscription stay linked to your anonymous identifier; contact support@sectionalai.app to have them removed. Deleting your account doesn't cancel an App Store subscription; cancel it in your Apple ID settings.
Changes & contact
We'll update this page if practices change, and material changes will be noted in the app's release notes. Questions: support@sectionalai.app.