Privacy at a glance
- Camera preview frames, raw motion readings and recorded tracking anchors stay on your device during ordinary use and sync. A local export you deliberately share can contain recorded route locations; photo backup you choose can include saved photo coordinates.
- New accounts start with sync and photo backup off. Choose which supported records to synchronize; existing choices are preserved.
- Route Atlas website analytics runs only after you choose to allow it.
- Native-app analytics and crash diagnostics currently start on. You can switch them off in app Settings; their identifiers are not the same as fully anonymous data.
- Avyloft has no third-party advertising and does not sell personal information.
- You can delete your account and export your journeys in the app, and email us for a copy of your cloud account data.
This summary helps explain the policy. The complete policy below controls.
1. Who we are and what this policy covers
Avyloft is operated by Alderbeam, Inc. (“Alderbeam,” “we,” “us,” or “our”). This Privacy Policy explains how we process information through the Avyloft mobile applications, the private web app at app.avyloft.com (closed while it is in development), the public website and Route Atlas at www.avyloft.com, Avyloft accounts, APIs, offline scenery, maps, scenery services and related features (collectively, the “Service”).
For personal information for which Alderbeam decides the purposes and means of processing, the controller or business is Alderbeam, Inc., 390 NE 191st St, Suite 50647, Miami, FL 33179, United States. This policy should be read with our Terms of Use and End-User License Agreement.
This policy does not control independent app stores, authentication providers, map and media sources, operating-system services or sharing destinations. Their own privacy notices govern their independent processing.
This policy describes available features; it does not mean every feature is offered on every device or in every country. Accepting Terms or reading this policy is not blanket consent to optional processing. A device permission, a sync choice and a website analytics choice serve different purposes and are not interchangeable.
2. What “collect,” “local” and “process” mean
“Local data” means information processed or stored only on your device that Alderbeam does not receive unless you synchronize, export, share, contact support or otherwise choose an action that transmits it. “Collected” means information transmitted to Alderbeam or a provider for more than the immediate on-device operation, subject to applicable law and provider practices. “Process” includes collecting, using, storing, transmitting, organizing, securing and deleting information.
Some data that is personal under privacy law may not be identified as “collected” in an app-store disclosure when it is processed only on the device or transiently to answer a request. This policy describes the broader real-world processing so you can understand both.
“Private” means access is restricted, not that the information is anonymous or protected by end-to-end encryption. An account ID, a coded installation identifier, a route linked to a request or a photograph without a name can still be personal information. Using an online feature without an account still involves network and security information.
3. Information that normally stays on your device
Journeys and local preferences
While you are signed out, saved flights, active-journey state, seat number and derived window side, route progress, diary entries, ratings, Journey Photos, summaries, history, downloaded offline scenery and app preferences are stored in Avyloft’s private local storage. Local records can remain until you delete them, clear app data, uninstall the app or the operating system removes disposable cache content, subject to device backup and restore behavior.
Signed-in users can also keep supported journey categories local by leaving their sync choices off. Account identity, preferences needed to operate the account, purchase recognition and online security requests are separate from optional journey-content synchronization.
Foreground location and device sensors
With permission, Avyloft can process foreground location, altitude, accuracy, speed and course to improve journey progress and direction. It can also process compass, accelerometer, gyroscope, device-motion and orientation readings to support journey progress, route direction and related in-flight features. Recorded tracking anchors, raw sensor readings and derived calibration remain on your device during ordinary sync. A saved Journey Photo can include its capture time, saved coordinate, position source and flight progress when you enable photo backup. Avyloft does not request background location.
A saved photo coordinate may be precise enough to identify a location even if the app describes it as an approximate route position. This is different from uploading a continuous live location stream. A local export you deliberately share can also contain recorded route locations. Review these details before exporting or backing up photos.
Camera and photo selection
Camera preview frames are processed while the camera is open and are not uploaded. A Journey Photo is created only when you capture or select an image. The app can process that image locally to resize, orient or create a thumbnail before it is stored or, when you enable Journey Photo backup, synchronized as described below. Avyloft does not use facial recognition or extract biometric identifiers from photos.
Local notifications, exports and backups
Scenery notifications can be calculated and scheduled locally. Exports, images, summaries or share cards leave Avyloft only when you choose a save or share destination. Apple, Google or another operating-system backup may include app data according to your device and cloud-backup settings.
In particular, personal photo files may be included in operating-system backups even when Avyloft Account Sync is off. Avyloft’s sync switch does not control iCloud, a computer backup, a photo library or a recipient’s copies. Downloaded public scenery is distinct from your own photographs.
4. Account information and optional synchronization
Account and authentication data
When you create or use an account, we process an internal account ID, Firebase authentication ID, email address, and—if supplied by your authentication provider—display name and profile image. We also process account creation, sign-in, last-active and deletion timestamps; language, units, time format and preferences; registered-device identifiers, platform, app version, device name and last-seen time; and security or synchronization records. Apple and Google handle their own credentials; Avyloft does not receive your Apple or Google password.
Your sync choices
In the app, open Settings → Privacy and sync to review your account’s choices after signing in.
Signing in does not enable new sync categories. New accounts start with the main sync control, memory sync and Journey Photo backup off. Choose whether to synchronize flights and history, memories and notes, or Journey Photos and supported Sightings in Account settings. With the main control and relevant category enabled, those records synchronize across registered devices and your private web Atlas. They are linked to your authenticated account so the Service can isolate and restore your records. Existing choices are preserved when you sign in again.
Private Journey Photos are stored as private image files in Cloudflare R2. Photo metadata and other synchronized records are stored in account-scoped PostgreSQL tables using our managed database infrastructure, currently PlanetScale through Cloudflare Hyperdrive. Optional Sightings records use Cloudflare D1. Firebase Authentication supplies the verified account identity. Signing out stops that session’s future sync; whether local records are retained or cleared depends on the platform and action you choose. Removing a registered device prevents further sync using that registration; it is not a remote wipe of copies already on the device.
What each category can include
- Flights and summaries: airport pair and endpoint coordinates; scheduled or actual dates and times; airline, flight number, aircraft and registration when available; seat and window side; journey status, progress and distance; countries, regions and scenery in a recap; and source or review history.
- Memories and notes: diary text, timestamps, journey progress, ratings or mood, and associations with a flight or photograph.
- Journey Photos: a normalized image for cloud backup rather than the full local camera master; dimensions and orientation; capture time and source; saved location and progress; nearby-place context; caption, favorite and cover choices; and editing, version or integrity information. Camera preview frames are not this backup.
- Sightings: the places you explicitly mark as seen, their identifiers, names and categories, associated journey, confirmation and update times, revision and deletion state. A route passing a place is not itself a confirmed sighting.
These records are private account content, not a public feed. Synchronization and backup are access-controlled, but they are not end-to-end encrypted: authorized service infrastructure processes the content to provide the requested functions. Do not put information about another person in notes or photos unless you have an appropriate basis to do so.
Sync operations
To keep devices consistent, Avyloft processes synchronization cursors, revisions, timestamps, conflict records, deletion markers and device IDs. These records help prevent duplication, restore content and apply deletions across devices. Turning a category off stops its future content transfer; deletion markers can still remove previously synchronized content while the main sync control is enabled. Turning sync off does not erase records already saved to your account. Explicit deletion remains available. Device-trusted location anchors and raw route points are excluded from ordinary flight sync. They are not used to build an advertising profile.
Private web-app storage
The web app uses persistent browser authentication and local storage, including IndexedDB or a local-storage fallback, for synchronized records, device registration and conflict or cleanup state. Personal images are requested through authenticated access and displayed using temporary browser references. Browser storage is not the same as a public server page, but someone using an unlocked, signed-in browser may see your information. Sign out on shared devices and use the app’s deletion controls and browser settings when clearing local copies.
Your synced flights and memories may be kept in this browser so they open offline. Your browser profile protects this copy; Avyloft does not encrypt it. It is removed when you sign out of the web app in this browser, which also happens when you delete your account here. While the web app is closed for development you can’t sign out of it, so clear this site’s data in your browser settings to remove that copy. Sync details that are no longer needed, such as resolved conflicts and unfinished downloads older than a day, are removed automatically before that. If your account is deleted from another device, or your sign-in in this browser ends without you signing out, the copy stays here until you clear this site’s data in your browser settings.
5. Offline scenery and route-processing data
When you request route-specific scenery or prepare it for offline use, the Service may receive origin and destination airport identifiers, a bounded set of planned-route points, optional planned altitude, scheduled date or time when supplied, scenery categories, media preference, language, platform, app version, schema version, route hash, request identifier and integrity information. We use this information to validate the route, select places, retrieve or reuse public content, prepare an offline pack, detect stale data, enforce limits and prevent abuse.
The offline scenery request does not include diary text, Journey Photos, raw camera frames, motion streams or continuous live location. Account identity is not sent to weather, map or public scenery providers. Planned routes can reveal travel context, so we treat them as personal information when they can reasonably be associated with a device, request or account.
Equivalent routes can reuse a bounded, expiring cache containing planned route geometry and generated public scenery. This reduces repeated provider calls and infrastructure cost. A shared route-cache object is not used as a per-user travel profile.
Flight and weather lookups
A flight lookup can send a flight number or airport pair to AirLabs through our server. Historical route lookups can send a flight number, airport pair, date window or provider flight identifier to Flightradar24. Forecast requests can send sampled route coordinates to MET Norway. These inputs relate to the requested flight or route; they are not a continuous transmission of your device’s location. Responses may be cached and carry provider identifiers, source dates and reliability information.
Public route addresses may contain airport codes. Those addresses can appear in browser history, ordinary request logs or a link you share. If you allow website analytics, the airport pair and an optional flight number you enter can also be measured as described below. Do not treat a public route URL or a route search as a confidential record or proof that you took that flight.
6. Technical, network and security information
When a device or browser contacts the Service, Alderbeam and its infrastructure providers may process IP address; date and time; requested page, resource or API endpoint; HTTP headers and user agent; browser, device, operating system, language, platform and app version; response status, latency and payload size; approximate country or region inferred from IP address; request, session, installation or device identifiers; and fraud, bot, rate-limit, integrity and security signals.
We use this information to deliver and secure the Service, authenticate requests, diagnose failures, measure availability, prevent fraud and scraping, control backend cost, investigate incidents and comply with law. Security records may be connected to an account when necessary to protect it.
Native journey-access requests may also use a separate installation identifier kept in device Keychain and an Apple-verified app-transaction identity. They support access eligibility and abuse prevention even without an Avyloft account. A Keychain installation identity can persist through sign-out and ordinary reinstallation; uninstalling is not a reliable way to reset that identity or included-flight eligibility.
If you use the app without signing in, the app sends Apple’s signed record of your Avyloft download so we can tell whether your free first flight has been used. We store a one-way code made from its identifier, not the identifier itself. To recognize the app between requests, we also store a one-way code of a random identifier of the app installation and of a session key that is valid for up to 24 hours. “Using the app without signing in” in section 18 says how long we keep each of these.
7. Maps, scenery sources and public media
Supported native and private web-map views use Apple Maps and MapKit. Loading these maps contacts Apple for map resources and can involve the requested map area, network address and technical device or browser information under Apple’s privacy practices. Displaying your private route as a map overlay does not publish it as a public route or social post.
Detailed online maps can use OpenFreeMap and related OpenStreetMap-derived resources. Requests for tiles, styles, fonts and sprites can reveal the visible map area, IP address, browser or device information and request time to the provider and its network. A bundled Natural Earth overview is available as an offline fallback in supported experiences.
For selected places, Avyloft may request public facts, identifiers, descriptions, source revisions, thumbnails, image metadata, license terms and credit lines from official Wikimedia services. A direct Wikimedia image request can reveal the requested public image, IP address, user agent and time to Wikimedia and its network. We retain public-source identity, provenance and licensing records independently of a user’s account because they form part of Avyloft’s global scenery catalog.
Map and photo providers receive requests according to the experience you open. An image served from our Cloudflare R2 scenery catalog is public licensed scenery, not your private Journey Photo. Opening a Wikipedia source or another external link contacts that independent website. We do not send private diary text or personal photo backups to Wikimedia to enrich the scenery catalog.
8. Website storage and optional analytics
Necessary website storage
The website can store your analytics choice in browser local storage so it remembers “Necessary only” or “Allow analytics.” Authentication, security, load-balancing and abuse-prevention providers may use necessary cookies, storage or tokens to keep a session working and protect requests. These controls are not used by Avyloft for behavioral advertising.
Necessary account and security storage is distinct from optional analytics cookies. Blocking all storage can prevent sign-in, remembering choices or synchronization; refusing optional analytics does not prevent those functions. Browser privacy settings may remove a stored choice, in which case the website may ask again.
Optional flight details can be kept in the current browser tab while you explore a route. When the handoff feature is available and you choose Add this flight in Avyloft, the Service temporarily stores the airport pair and optional flight number and date. A random token carries that intent through sign-in, without placing those flight details in the destination URL. It expires after fifteen minutes, is bound to the account that claims it, and is removed during temporary-data cleanup. This action does not purchase access, save a flight or enable account sync.
Google Analytics on www.avyloft.com
When enabled, Google Analytics loads only after you choose Allow analytics. We measure public pages visited, feature and link interactions, scroll depth, route searches and views, and whether scenery loads successfully. Route events include the departure and arrival airport codes and, if you enter one, the flight number. This helps us understand which routes people want and improve the explorer. These events do not include travel dates, booking references, account identifiers, private photos or notes, or payment details.
We send recognized public page addresses without query strings or fragments, descriptive page titles, and a referring website origin or recognized public Avyloft page. We do not send arbitrary form entries, authentication or handoff tokens, or full outbound-link addresses. Enhanced measurement stays enabled for scrolls; automatic history page views, form, site-search and outbound-link collection are disabled in favor of our controlled events. Google may also process browser characteristics, timestamps, cookies, network information and coarse location derived from IP address. Advertising personalization and Google signals are disabled.
You can refuse analytics without losing Service functionality and can reopen Analytics choices in the website footer. Withdrawing a choice stops future analytics collection through our consent component and clears accessible Google Analytics cookies; it does not automatically erase information Google processed before withdrawal.
Permission given for an earlier, more limited analytics setup does not authorize these expanded route events. The website asks for a fresh choice when the scope changes.
The native app’s diagnostics setting does not automatically change a website’s consent choice, or vice versa. Website measurements are not an account-sync log, a record of your booked travel or an entitlement requirement. Google describes its independent processing in its privacy policy.
9. App analytics and crash diagnostics
Firebase Analytics and Firebase Crashlytics are enabled by default in the apps to measure product use and diagnose failures. You can turn both off using Share diagnostics in Settings (Share anonymous diagnostics in earlier versions). Analytics may process a per-installation identifier; when you are signed in, a pseudonymous account identifier (a one-way hash of your Avyloft account ID) that links analytics to your account; app version, platform, device and operating-system characteristics; app lifecycle, screen and engagement events; product events such as flights added or saved, journeys started or completed, sign-in, sync, purchases, photos added, notes saved, stamps collected and settings changed; for flights, the origin and destination airport codes, airline code, whether the flight is domestic or international, and distance and duration bands; for scenery you open, mark as seen or share, its catalog identifier, category and country; whether you are signed in or sync is on, the app appearance, your plan type and notification permission; and general location derived by Google from a masked IP address. Crashlytics may process installation and session identifiers, crash time, stack traces, exceptions, logs, app and device state, memory or disk information and session-quality metrics.
Avyloft does not add your email, name, Firebase user ID, flight number, seat, flight date or time, GPS sample or coordinates, diary text, photo content or metadata, caption, place names, local path or exported record to analytics or crash parameters. Consent Mode denies advertising storage, ad user data and ad personalization. The apps do not show third-party advertising, do not request the advertising identifier and do not use analytics or diagnostics for cross-app tracking.
App analytics is not anonymous: installation identifiers distinguish a device, and when you are signed in the pseudonymous account identifier links analytics to your account. Disabling diagnostics does not disable essential authentication, purchase verification, security checks or the technical requests needed for a feature you use.
Turning diagnostics off stops future collection through Avyloft’s control, resets the analytics identifier, and removes unsent crash reports where the Firebase SDK supports it. It does not retroactively remove data already transmitted. Firebase controls its standard service retention and deletion processes.
10. Authentication and bot protection
Firebase Authentication supports Apple, Google and email sign-in and may process provider identity, email, authentication tokens, timestamps, browser or device information, IP address and security events. Firebase App Check helps verify that signed-in web and app API requests come from an authentic Avyloft client by processing integrity signals and issuing a short-lived token.
Cloudflare Turnstile protects live public Route Atlas requests from bots and abusive traffic. It performs browser challenges and processes signals needed to distinguish legitimate visitors from automation. The Turnstile challenge does not receive the Route Atlas form entries from Avyloft as challenge input, although the protected route request itself is separately processed as described in this policy.
The signed-in web app also uses Turnstile with App Check. Supported Apple devices can use App Attest to verify client integrity. Verification can involve device or browser characteristics, attestation responses, tokens, timing and abuse signals. These checks serve security and access control, not the optional analytics purpose. We do not receive your Apple or Google sign-in password through federated sign-in; email/password authentication is handled by Firebase.
11. Purchases and subscriptions
App Store purchases
Apple, Google or another store processes payment credentials and billing. Alderbeam may receive product identifier, purchase and entitlement status, transaction or original-transaction identifier, subscription status and expiration, storefront or country, offer eligibility, and renewal, refund, chargeback or revocation status. We use this information to validate access, restore purchases, prevent fraud, provide support and satisfy accounting or legal obligations. Alderbeam does not receive full payment-card details from an app store.
Web billing and shared access
We use RevenueCat to recognize purchases and access across supported surfaces. An account purchase identifier connects that access to your Avyloft account; it can be linked to your account and is therefore not anonymous. We also give RevenueCat your account email so we can find your purchases when you contact support. RevenueCat does not receive your routes, photos or notes.
Where web checkout is offered, RevenueCat Billing uses Stripe to process payments. The checkout may ask for your email, billing name, address, country and tax information. Payment details are entered in the provider’s payment fields; Avyloft’s application does not store full card numbers or card security codes.
Avyloft receives the product, purchase source, transaction reference and access status needed to recognize purchases, check pending payments and support your account. Billing providers may make billing contact, receipt, tax and payment-status information available for support, fraud prevention and accounting. These records are not sent to public website analytics.
Access records can include which eligible flight used included access or a Flight Pass, authorization and return history, subscription status, checkout attempts, provider callbacks and references used to resolve payment errors. An account identifier and, where supplied, customer email and checkout information are passed to the billing provider. The purpose is to deliver and reconcile access, not to provide the provider with your diary or personal photo library.
Provider processing is described in RevenueCat’s privacy notice and Stripe’s privacy notice. The transfer and retention sections below also apply. Use Plans & Billing in the Avyloft app for account-specific purchase and management options.
12. Support, feedback and communications
If you contact us, report content or request help, we process your name, email address, message, attachments, the content or error you identify, technical details you choose to provide, and correspondence history. We use this to respond, investigate, improve the Service, protect users and maintain necessary business or legal records.
Do not send passwords, authentication tokens, payment-card details, unnecessary identity documents, precise location history or sensitive photographs through ordinary email. If additional verification is needed, we will explain an appropriate method.
The native support-email flow lets you review its message and choose whether to include available issue references or app details. It does not automatically attach your full flight history or photos. Information you voluntarily include is processed for that request. We distinguish necessary service notices from promotional messages; where consent is required for marketing, we will seek it separately.
Push notifications
If you're signed in and allow notifications, the Avyloft app registers a push token for your device with Google Firebase Cloud Messaging and stores it with your account's device record. We use it to send messages about your account, such as a Flight Pass added to it. Announcements about new features and offers are sent only if you turn on News and offers in Settings, which is off by default. Notifications are delivered through Firebase Cloud Messaging and Apple Push Notification service.
The token is deleted when you sign out, remove the device or delete your account, and when Firebase reports it is no longer valid. You can turn notifications off in iOS Settings at any time.
13. How we use information
We use information described in this policy to:
- provide accounts, sync, offline scenery, maps, exports, purchases and support;
- personalize language, units, time format and requested journey features;
- authenticate users, isolate account records and restore registered devices;
- maintain, troubleshoot, test and improve reliability and accessibility;
- validate route and media data and preserve source and license attribution;
- measure product use, popular routes and scenery engagement when analytics is enabled;
- estimate how likely an account is to use Avyloft again, take a flight or make a purchase, to plan the Service (Section 25);
- detect abuse, fraud, credential misuse, scraping and security incidents;
- enforce our Terms and protect users, Alderbeam and others;
- communicate about accounts, security, purchases, service changes and legal notices; and
- comply with law and establish, exercise or defend legal claims.
We may use aggregated or de-identified information that is not reasonably linkable to an individual. We do not attempt to re-identify information that applicable law treats as de-identified except to test safeguards where law permits.
14. Sources of information
We receive information:
- directly from you when you enter, capture, upload, save, share, purchase or contact us;
- automatically from your browser, app, device and network when you use online features;
- from Apple, Google, Firebase or another provider when you authenticate or make a purchase;
- from registered devices participating in account synchronization;
- from public and licensed map, airport, geographic, weather and Wikimedia sources; and
- from security, analytics and infrastructure providers acting for us or operating their own services.
15. When we disclose information
Service providers
We disclose the minimum information reasonably needed to providers that perform functions for the Service. Current core providers include Cloudflare for website and API delivery, security, Workers, Turnstile, routing, D1 databases and R2 storage; PlanetScale for managed PostgreSQL account and catalog storage; Google Firebase for authentication, App Check, analytics, crash diagnostics and push notifications (Firebase Cloud Messaging); RevenueCat for purchase recognition and supported web billing, with Stripe for web payment processing where offered; Apple and Google for app distribution, purchases and platform services, including Apple Maps, MapKit and the Apple Push Notification service; OpenFreeMap and OpenStreetMap-derived providers for map resources; and Wikimedia Foundation services for public place facts, images and attribution.
AirLabs supports flight lookup, Flightradar24 supports available historical flight-route information, and MET Norway supports route weather information. Which provider receives a request depends on the feature and information you request. Sections 4–11 describe the relevant inputs; these providers do not all receive every category of data we hold.
Providers that process Avyloft user data for us are contractually or legally required to protect it appropriately and may process limited data for their own security, legal and service-administration purposes. Their independent activities are governed by their own notices and terms.
Authorized personnel and contractors may access information where needed for support, incident response or operating the Service, subject to appropriate restrictions. “Private” does not mean no service provider can process it. We do not give another passenger access to your account merely because they know a flight number, airport pair or account-page address.
At your direction
We disclose information when you open a source link, connect an authentication provider, save content externally, or share an export, summary, share card or photo. The destination controls the copy after receipt.
Legal, safety and rights
We may preserve or disclose information when reasonably necessary to comply with law, legal process or a valid government request; investigate fraud, abuse, security incidents or illegal activity; enforce agreements; protect rights, safety or property; or establish, exercise or defend legal claims. We may challenge requests we believe are invalid, overbroad or unlawful.
Business transactions
Information may be disclosed or transferred as part of due diligence, financing, merger, acquisition, reorganization, bankruptcy or sale of assets, subject to applicable law and appropriate confidentiality and protection.
A business transfer does not itself authorize a new incompatible use of personal information. We will provide any required notice or choice if the responsible business or the use of your information changes.
16. No sale, targeted-advertising sharing or cross-app tracking
Alderbeam does not sell personal information for money or other valuable consideration. We do not share personal information for cross-context behavioral advertising, use Avyloft information for targeted advertising, display third-party behavioral ads, or track users across apps or websites owned by other companies for advertising. We do not offer a financial incentive in exchange for personal information.
Because we do not currently sell or share personal information for those advertising purposes, an opt-out signal such as Global Privacy Control does not change those practices. If our practices materially change, we will update this policy and provide required notice, consent and opt-out controls first.
A browser’s Do Not Track setting is not the same as our analytics control. Use Analytics choices to manage optional website measurement. Applicable legally recognized opt-out signals remain effective for any processing to which the law makes them relevant; this policy does not waive those rights.
17. Legal bases for processing
Where a law such as the GDPR requires a legal basis, we rely on the basis that fits the specific processing:
- Contract: to provide accounts, synchronization, offline scenery, purchases, exports and support you request.
- Consent: for optional website analytics and other processing where consent is required. A device permission controls access to a device feature; it is not, by itself, consent to every subsequent use. You may withdraw consent without affecting prior lawful processing.
- Legitimate interests: to secure and operate the Service, prevent fraud and abuse, diagnose technical faults, preserve data and license integrity, handle legal claims, measure native product use where lawful without prior consent, and make the internal account estimates described in Section 25, balanced against your rights. This is not a claim that every analytics SDK qualifies for a consent exemption.
- Legal obligation: to comply with tax, accounting, consumer, sanctions, privacy and lawful-request obligations.
If a particular law requires consent rather than another basis, consent controls.
Contract does not cover processing merely because we describe it in Terms: it must be necessary for the requested service. Our security and reliability interests include preventing unauthorized access, protecting private records, maintaining accurate purchase entitlements and addressing genuine faults. We consider the information involved, reasonable expectations and safeguards when assessing those interests. They do not replace consent where consent is legally required, including for non-essential device storage or analytics.
You can decline optional journey sync and use supported local features. If you do not provide information necessary for a particular request—such as authentication for an account export, a route for route-specific scenery or purchase details needed to investigate a charge—we may be unable to complete that request. We explain any legally required information when it is requested.
18. Data retention
We retain personal information only as long as reasonably necessary for the purposes described, taking account of account status, feature needs, cache expiry, security risk, legal obligations, disputes, provider backup cycles and whether the information can be aggregated or de-identified.
Push tokens
A device's push token is kept while that device is signed in to your account. It is deleted when you sign out on that device, remove the device, or delete your account, and when Firebase reports it is no longer valid.
Accounts and synchronized content
Account and synchronized content is kept to provide the account and your enabled features until you remove it or request account deletion, subject to the purposes and exceptions below. Deleting an item can leave a deletion marker, revision and limited reconciliation history so devices do not restore it unintentionally. This is not a promise that every technical record disappears immediately when an item leaves your screen.
Cloud account deletion is a staged process: private photo objects and Sightings, authentication identity, and account or synchronized records are removed through separate steps. Failed steps can be retried. Limited account-deletion safety records and pseudonymized identifiers remain where needed to prevent re-creation errors, reconcile purchases, address abuse or meet legal obligations. They are not the same as keeping an active account or its private content for general use. Pseudonymized does not necessarily mean anonymous.
What account deletion keeps
When account deletion finishes, our account service keeps the records below for the periods shown, and then deletes them. Backups, provider and operational logs, support correspondence and records under a legal hold are not in this table: they follow the rules in the rest of this section and can last longer.
| Record kept after deletion | Why we keep it | How long |
|---|---|---|
| Account activity events, such as sign-in and the deletion request | Support and security questions about the deletion | 90 days after deletion |
| The completed deletion record, without your sign-in ID | To show the deletion finished | 12 months after it completed |
| A one-way hash of your sign-in ID | To stop a deleted sign-in from silently re-creating the account | 12 months after deletion |
| Purchase acknowledgements, Flight Pass credit records, and in-app purchase checks and deliveries | Tax, accounting, refunds and disputes | 7 years after deletion |
| References to a checkout that was still in progress | Support for that purchase | 30 days after deletion |
These records do not include your flights, memories, notes or photos. An internal account number with no email, name, photo or sign-in ID remains so these records stay consistent. Apple, Google, RevenueCat and our payment provider keep their own records under their own policies. A flight you saved before signing in and then moved to your account also keeps the records in “Using the app without signing in” below, for the periods shown there.
Using the app without signing in
When you use the app without signing in, we keep the records below. They are tied to a one-way code made from the identifier of your Avyloft download, not to an account.
| Record | How long |
|---|---|
| Your free first flight: that it was used, its flight ID, when you saved it, when the app first reported it finished, and when this record was created and last changed. If you moved the flight to your account, also when you moved it and a one-way code of your account ID, which we replace with a random value when you delete that account | 7 years after you saved that flight |
| That flight’s airports and the codes identifying its route and guide | Until 90 days after the app first reports the flight finished or, if that is sooner, a year and 95 days after the latest of these: when you saved the flight, when the app first sent us its route or last sent a changed route or guide settings (such as the language), and when you last prepared its guide. If you move the flight to your account, this copy is deleted within 90 days of the move if that is sooner still; your account keeps its own copy |
| A free first flight you deleted before the app first sent us its route (which it does to show the flight’s scenery or to prepare its guide): that it is available again | 90 days after you deleted it |
| App sessions: a one-way code of the app installation and of its current session key (valid for up to 24 hours), whether the app is the App Store version or a test build, and when the session started, ends and was last renewed | If you saved your free first flight, including one you then moved to your account, until that flight’s record above is deleted, 7 years after you saved it. Otherwise, or if you deleted the flight before the app first sent us its route, 90 days after that installation’s last session ended |
Once the app has sent us a flight’s route, deleting that flight no longer makes your free first flight available again: its record and your app sessions are then kept as for any saved free first flight.
After the airports and route and guide codes are deleted, the guide for a flight you did not move to your account can no longer be prepared or downloaded again.
Provider logs, isolated recovery copies and backups follow their applicable deletion cycles, which may outlast removal from active systems. We do not promise a single deletion deadline for every category or provider. Any legally required erasure deadline and permitted exception still apply. Local device copies and copies you gave to others require separate action.
Route caches and public catalog data
Route requests, hashes, pack manifests and cached public scenery remain only while useful for bounded cache reuse, integrity checks, security and infrastructure control, then expire, are replaced, aggregated or deleted. Public scenery, coordinates, facts and attribution can remain in the global catalog independently of the request that first retrieved them.
Logs, analytics and diagnostics
Operational and security logs remain for the limited period reasonably needed to troubleshoot, prevent abuse and investigate incidents, or longer when a specific legal or security matter requires it. Website and app analytics follow the configured Google Analytics retention settings. Firebase states that standard Crashlytics crash traces and associated identifiers are retained for 90 days before removal from active and backup systems begins.
This provider-specific period is not a universal 90-day promise for Avyloft accounts, billing evidence, website analytics or backups. Firebase’s privacy and retention information explains its different services. The time and settings applicable to a service can change; contact us for information relevant to a request.
Support, purchase and legal records
Account deletion does not itself cancel renewal or refund a purchase. Minimal purchase references, access history and deletion records can remain for reconciliation, fraud prevention, disputes and required accounting. They are not a retained copy of your private photos or notes. Check Plans & Billing in the Avyloft app before deleting your account.
Correspondence remains while an inquiry is active and for a reasonable follow-up period. Purchase, tax, fraud-prevention and legal records may be kept for the period required or permitted by applicable law. We may retain the minimum record needed to honor a deletion, suppression or opt-out request.
Retention is assessed by category: whether a support issue remains open; whether a purchase, chargeback or accounting obligation is unresolved; the likelihood and seriousness of abuse; applicable limitation periods or preservation duties; and whether a less identifying record is sufficient. A legal hold can delay erasure of relevant records but is not a reason to keep unrelated data indefinitely. Account deletion does not automatically erase a payment provider’s independent records.
19. Security
We use administrative, technical and organizational safeguards designed for the nature of the information, including HTTPS transport, provider encryption at rest where supported, authenticated account isolation, least-privilege access, private object storage, server-side validation, parameterized database access, rate limits, integrity checks, App Check, Turnstile, secret management, monitoring, tests and credential rotation.
In the web app, the copy of your synced flights and memories kept in your browser is protected by your browser profile, not encrypted by Avyloft, and removed when you sign out in that browser, including when you delete your account there. While the web app is closed, clear this site’s data in your browser settings instead. Section 4 explains what happens to a copy in a browser you do not sign out of.
No system is completely secure or always available. Protect your device passcode and authentication methods, keep software current, review exports before sharing and contact us promptly if you suspect unauthorized access. If a breach requires notice, we will notify affected people and regulators as required by applicable law.
Encryption in transit and provider storage encryption are different from end-to-end encryption, which Avyloft does not promise. Security controls reduce risk; they are not a guarantee against loss, unauthorized disclosure or a compromised device. Please report suspected issues to support without attempting to access another person’s data or sending live credentials.
20. International processing and transfers
Alderbeam is a United States company. The Service and its providers may process information in the United States and other countries where they operate. Privacy laws in those places may differ from those where you live. Where required, we rely on legally recognized transfer safeguards such as adequacy decisions, approved standard contractual clauses incorporated into provider agreements with applicable UK transfer provisions where required, or another valid mechanism. You may contact us for information about safeguards applicable to your information.
We do not promise that data stays in your country or that choosing a language or map region changes its hosting location. You may request information about the relevant destination categories and, where applicable, a copy or explanation of transfer safeguards with confidential terms redacted. This policy does not represent Alderbeam as certified under a cross-border certification framework. Provider arrangements must meet the requirements applicable to the actual transfer.
21. Your controls
Device permissions
You can deny or change camera, photo, foreground-location, motion and notification permissions in device settings. The related feature may stop working, while unrelated functionality remains available where possible.
Analytics and diagnostics
Use Analytics choices in the website footer for website analytics. Use Share diagnostics in app Settings (Share anonymous diagnostics in earlier versions) to control future Firebase Analytics and Crashlytics collection; turning it off also resets the analytics identifier.
Local data
In-app controls may let you delete a flight, journey, photo or offline scenery download; clear disposable caches and diagnostics; export records; or delete all local Avyloft data. Deleting offline scenery or a map cache does not intentionally delete Journey Photos. Uninstalling ordinarily removes local app data, subject to operating-system backup and restore behavior.
Account data
You can remove a registered device or initiate permanent account deletion in Account settings in the app, and request a cloud export by emailing support@avyloft.com while the web app is in development. See the Account & Data Deletion page. We may require recent authentication. Account deletion does not cancel an app-store or web subscription, issue a refund or automatically recall external copies.
A cloud export includes the supported account records and metadata held by the account service; it does not include personal image bytes, a billing provider’s complete documents or device-only records. The native app’s local export options can include local photo files and recorded route locations. Review the export type before relying on it as a backup.
Turning sync off stops future synchronization for the selected category but does not delete copies already in your cloud account. Local erasure and cloud erasure are separate: a device can be cleared without deleting cloud records, and cloud deletion cannot remotely erase an offline device or an export. Reconnecting, re-enabling sync or restoring a device backup can restore available copies. Follow the deletion guidance for both locations if you want both removed.
Communications and sharing
You can unsubscribe from marketing using the message link. Turn off News and offers in app Settings to stop announcements by notification, or turn notifications off for Avyloft in iOS Settings to stop all of them. We may still send necessary account, security, purchase, policy and service notices. You control whether to share exports; Avyloft cannot recall copies after sharing.
22. Your privacy rights
Depending on where you live and whether the relevant law applies, you may have rights to be informed; access, correct or delete personal information; restrict or object to processing; withdraw consent; receive portable data; opt out of qualifying sale, targeted advertising or profiling; appeal a denied request; and complain to a privacy or data-protection authority. We will not discriminate against you for exercising a privacy right.
Submit a request to info@avyloft.com and describe the right you want to exercise. We may ask for information reasonably necessary to verify your identity, authority and account while avoiding unnecessary collection. An authorized agent may act where law permits, subject to proof of authorization and direct identity verification. If applicable law grants an appeal right, reply to our decision or email the same address with “Privacy Appeal” in the subject.
We respond within the period required by the applicable law, explaining any permitted extension, denial or exception. Requests are generally free, subject to lawful rules for manifestly unfounded, excessive or repeated requests. We may need to retain information for a legal obligation, security, another person’s rights or a legal claim; we will explain a relevant limitation where permitted. A suggested email subject is helpful, not a condition for recognizing a valid request.
Do not email a password, full payment-card number or unnecessary identity document to prove who you are. We seek proportionate verification and can ask an agent to demonstrate authority. EEA residents can contact their local data-protection authority; UK residents can contact the Information Commissioner’s Office. U.S. residents may contact the relevant state regulator or attorney general. You do not have to use arbitration to exercise these rights.
If information exists only on your device, Alderbeam cannot access or delete it for you; use the app or operating-system controls. If an anonymous route request cannot reasonably be linked to you after identifying records expire, we may be unable to locate it and will not collect additional personal information merely to recreate that link.
23. California and other U.S. state disclosures
Subject to applicable thresholds, residents of California and states with similar privacy laws may have rights regarding the following categories processed during the preceding 12 months:
- Identifiers: account ID, email, authentication ID, IP address, request ID and installation or device identifiers.
- Internet and electronic activity: pages, API requests, app interactions, security signals, map requests, errors and diagnostics.
- Travel and geolocation context: planned airport pair, bounded planned-route geometry, flight details, route preferences and coarse region inferred from IP. Raw foreground tracking anchors stay on-device during ordinary sync, but an opted-in photo backup or a deliberately shared export can include saved coordinates.
- Commercial information: product, entitlement, transaction, subscription, refund, revocation and renewal status.
- User content: synchronized flights, history, seat and window preferences, summaries, diary entries, notes, Journey Photos, captions, support messages and attachments.
- Device information: browser, platform, device class, operating system, app version and language.
- Inferences: route and scenery rankings used to provide requested journey content, and the internal account estimates described in Section 25: how likely an account is to use Avyloft again, take a flight or make a purchase. Neither is used to infer sensitive personal characteristics.
Sources are listed in Section 14, purposes in Section 13, and recipient categories in Section 15. We do not sell or share these categories for cross-context behavioral advertising and do not use sensitive personal information to infer characteristics. To exercise an applicable right to know, access, correct, delete or obtain portability, use Section 22.
Sensitive information can include account credentials or access tokens and precise coordinates in an enabled photo backup. A note, image or support attachment you choose to provide might also reveal information the law treats as sensitive. We use these categories to provide the requested feature, authenticate and secure access, or address the purpose for which you supplied them—not to infer sensitive traits for advertising. Where a right to limit sensitive-information use applies, you may exercise it through Section 22.
Each category is disclosed only to the relevant recipient categories and for the purposes explained above. Section 18 gives retention criteria rather than an invented uniform lifespan. We do not knowingly sell or share the personal information of people under 16 for cross-context behavioral advertising. State rights depend on residency, the law’s scope and applicable exceptions; this notice does not require you to waive a right to use the Service.
24. Children’s privacy
Avyloft is a general-audience service and is not directed to children under 13. We do not knowingly collect personal information from a child under 13, and our account features are not offered as an under-13 child service. Older minors must meet applicable age and guardian-authorization requirements. This statement does not mean Avyloft verifies every user’s age or operates a child-account consent program. If we learn that prohibited child data was collected, we will take reasonable steps to delete it. A parent or guardian can contact info@avyloft.com.
25. Automated processing
Avyloft uses calculations to select and rank scenery based on route proximity, place prominence, content availability, category diversity, direction, distance, light, cloud information when supplied and similar factors. These calculations personalize journey content but do not make decisions that produce legal or similarly significant effects. We do not use Avyloft data for automated credit, employment, insurance or eligibility decisions.
Alderbeam’s internal tools can estimate how likely an account is to use Avyloft in the coming weeks and to take a flight in the coming months, and how often accounts that started using Avyloft the way it did have made a purchase. These estimates use account records described in this policy, such as when the account opened Avyloft and its synchronized flights, journey access and purchases. They do not use Firebase Analytics, so we make them under our legitimate interests (Section 17) whether or not diagnostics are on. They are calculated only when an authorized Alderbeam team member views them, are not stored or shared, and are never used to set prices, make offers, change features or decide access. They do not make decisions that produce legal or similarly significant effects. You can object to them under Section 22, and we will then leave your account out of them.
Automated security and purchase checks can reject a request, limit traffic or flag an account or entitlement for review. Contact support if you believe a result is wrong. These checks are separate from scenery ranking and do not authorize unrelated use of private content. We do not use private diary entries or personal photo backups to train general-purpose generative-AI models.
26. Third-party links and public sharing
Authentication pages, app stores, source pages, map attribution, image credits and sharing destinations are operated independently. Review their privacy settings and notices. Publicly shared travel material can reveal dates, routes, absence from home, identity, companions and habits. Avyloft does not control redistribution after you share it.
27. Changes to this policy
We may update this policy when the Service, providers, laws or processing practices change. We will change the updated date and provide additional notice when required or when a change materially affects your rights. If we introduce a materially broader practice involving continuous live location, private photo processing, behavioral advertising or account synchronization, we will provide any notice or consent required before it applies.
A new date or your continued use is not a substitute for consent where the law requires consent. We will not apply a materially incompatible new purpose to previously collected personal information without the legal basis, notice and choices required for that use. Prior lawful collection is not undone merely because the policy is updated.
28. Contact information
Alderbeam, Inc.
Avyloft
390 NE 191st St, Suite 50647
Miami, FL 33179
United States
Telephone: +1 (786) 672-5816
Privacy requests and legal notices: info@avyloft.com
Product, account, accessibility and security support: support@avyloft.com
