Privacy Policy
1. Who we are
CrewStory (“CrewStory”, “we”, “us”) is a private aviation career journal and logbook for pilots and cabin crew. CrewStory is currently operated by Sammie Haegeman, trading as CrewStory. CrewStory may later be operated by SHCF LLC or another legal entity; if this changes, this page will be updated. We are the controller of your personal data; the providers listed in §6 process data on our behalf and on our instructions.
Privacy contact: privacy@getcrewstory.com
2. What we collect
Account details. Your email address and an encrypted password, managed by our authentication provider (Supabase Auth). You can also sign in with Apple or with Google. When you do, we receive only the sign-in token and the email address the provider releases — never your password with them. If you use Apple’s “Hide My Email”, we only ever see the relay address.
Crew profile (optional, private by default). Display name, first/last name, airline(s), rank, home base(s), staff number, nationality, date of birth, phone, home address, licence number and countries, medical expiry, type ratings, instructor/examiner qualifications, profile photo, bio, languages, social handles and joining hours. You choose what to fill in; sensitive fields are shared with nobody unless you explicitly enable a share toggle for your crew card.
Flight and logbook data. Flights and simulator sessions you enter or import: dates, routes, scheduled and actual times, aircraft type and registration, function times, take-offs/landings, approaches, PF/PM, duty inputs, fuel, pax, notes and milestones — plus a tamper-evident edit history of your hours (“Verified Hours”) so your own record can demonstrate integrity.
CSV imports. If you import a logbook (e.g. from another app), CrewStory reads the file on your device to create flight entries and, optionally, private crew contacts. The raw file is not stored on our servers; only the resulting entries you choose to import are saved.
Roster / calendar import. If you use roster import, CrewStory reads only the single device calendar you select, on your device, to recognise flight events. The raw calendar is not uploaded; only the resulting flight entries are.
Crew / colleague data you enter. Names, airline, position, staff number, phone, photo and notes about colleagues you fly with. This is private to you and is never shown to those colleagues or made public.
Layover memories. Photos, captions, titles, notes, tags, companions, dates and airports for layovers you choose to record. Photo metadata (EXIF): before a photo is uploaded, CrewStory strips embedded location (GPS) and camera metadata on your device, so precise capture coordinates are not sent to our storage.
Hotel and layover details you save (hotel names, facilities, Wi-Fi notes, locations).
Document Vault. Documents you choose to upload (licences, medicals, certificates) and expiry items you track. These are private to your account and access-controlled per user.
Wrapped / recap data. Monthly and yearly statistics computed from your flights, plus your presentation choices (chosen photos, hidden slides, edited text) for your Wrapped recaps. Recaps are generated for you and are not shared unless you choose to share them.
Subscription / entitlement data. If paid features are offered, we (and the app store / payments processor) process the fact of your entitlement (e.g. active/expired) to unlock features. We do not receive or store your full card number.
Diagnostics. Limited crash and error diagnostics (via Sentry) to keep the app stable. These are engineered to avoid your personal content; they carry technical context (error type, screen, operation), not your logbook, notes, photos or crew data.
3. How we use it
To provide the app’s features (logbook, roster/CSV import, currency and duty tracking, memories, map, Wrapped, Document Vault), to keep your account secure, to fix bugs and prevent abuse, and to respond to your support and privacy requests. We do not sell your data and we do not show advertising.
4. Sharing
Nothing is public by default. We share your personal data only with the processors in §6 (to run the service), when you explicitly choose to share something (e.g. a crew card field or a Wrapped recap), or where required by law. We never sell your data.
5. Your data export & deletion
You can export a full copy of your data from inside the app, and you can permanently delete your entire account and its data from inside the app (see Deleting your account).
6. Processors and third-party services
Processors who run the service. These handle your personal data on our instructions.
- Supabase — authentication, database and file storage (your app data is stored in the EU).
- Sentry — crash/error diagnostics (privacy-scrubbed).
- Apple / Google — app distribution and, if paid features are offered, payment processing and subscription entitlement.
Reference services your device contacts directly. To draw a map or show an aircraft photo, your device has to ask the service that holds it. Those services see the request and, unavoidably, your device’s IP address. They do not receive your logbook, notes, photos, documents or crew data, and they are not told who you are.
- Mapbox — route and layover maps, and place search when you look up a hotel. A hotel name or address you type into the search box is sent to Mapbox to find it on the map.
- Planespotters — aircraft photos, requested by registration.
- Aviation Weather Center (US NWS) and the Iowa Environmental Mesonet — airport weather, requested by airport code.
Lookups our server makes for you. Aircraft details and layover hotel information are fetched by CrewStory’s own server rather than by your phone. This is deliberate: the service being queried sees our server, never your device or your IP address, and the answer is cached so the same question is not asked twice. These services receive only an aircraft registration or a hotel name and city.
- ADSBdb, adsb.lol, airframes.io, hexdb.io, airport-data.com, Planespotters — aircraft type, operator and photo lookups by registration.
- Anthropic — generates practical layover hotel information (breakfast times, gym hours, shuttle) from a hotel name and city. No personal data is sent, and the answer is stored in a shared reference table so it is generated once for everyone rather than per user.
None of the services in the last two groups receive your account details, logbook, memories, photos, documents or crew records. Some providers may process limited data outside the EU; where they do, appropriate safeguards apply.
7. Retention & deletion
Your account and content (profile, flights, memories, photos, hotels, documents, summaries) is kept for as long as your account exists, and deleted when you delete your account.
- Support emails — kept for up to 12 months after your question is resolved, then deleted.
- Security, platform and error logs — kept only for abuse prevention and debugging, and never longer than 90 days. Our hosting and diagnostics providers expire them automatically; in practice most expire well before that.
- Database backups — our database provider keeps at most the last 7 days of automatic backups; each new one replaces an older one. Backups are never used to bring a deleted account back.
Deleting your account removes your data from the live service straight away. A copy may survive in a backup until that backup rolls off on the schedule above, which is a limitation of how backups work rather than a copy we keep on purpose.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your data, and to object to or restrict certain processing. Use the in-app export/delete tools, or contact privacy@getcrewstory.com.
9. Age
You must be at least 16 years old to use CrewStory. If you are under 18, you may use CrewStory only with permission from a parent or legal guardian, and you should not upload licence, medical, passport, identity or other sensitive documents unless your parent or legal guardian has approved it. CrewStory is not intended for children under 16.
10. Changes
We will announce material changes in the app before they take effect. The current version is always available at getcrewstory.com/privacy.
11. Contact
Sammie Haegeman, trading as CrewStory — privacy@getcrewstory.com.