Privacy Policy
Last updated: August 22, 2026
paxstats ("we", "our", "us") provides a flight logging application that lets aviation enthusiasts record flights and view detailed statistics about their flight activity. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have, including the additional rights available to you under GDPR if you're in the EU, EEA, or UK.
The short version: your logbook is yours. We don't sell your data, we don't show ads, and we don't track you around the web. Your account and flights live in a database hosted in the EU, your profile stays private until you choose to publish it, and you can export or delete everything from Settings at any time.
Who Is Responsible for Your Data
paxstats is the data controller for the personal data described in this policy. You can reach the controller at contact@paxstats.app; the controller's legal identity and postal address are available on request at the same address.
Why We Are Allowed to Process Your Data
Under the GDPR, each thing we do with your data rests on one of these bases:
- Performing our contract with you — your account, your flight log, the stats and maps built from it, and the emails needed to run the service (sign-in, password reset, invite codes).
- Your consent — anything optional you switch on: a public profile, notification emails and push notifications, photos you upload, the pax-buddy and companion features, and the AI summary of your flying. You can withdraw consent at any time from Settings, and withdrawing it does not affect what was done before.
- Our legitimate interests — keeping the service secure and abuse-free (rate-limit records, sign-in logs), fixing errors (error monitoring, see below), and understanding aggregate use of the product. We only rely on this where your interests do not override ours.
Information We Collect
- Account information. When you sign in with Google or Apple, we receive your name and email address (and, for Google, a profile picture) to create and identify your account. If you use Apple's "Hide My Email" option, we only ever see the private relay address Apple generates, not your real one.
- Flight data. Flight details you enter or import, such as dates, routes, aircraft, airlines, and seats.
- Photos. Flight photos and your profile picture, if you upload one. Boarding passes you scan are read once to fill in the flight for you: we keep the flight details it produced, not the image.
- Forwarded emails. If you forward a booking confirmation or boarding pass to log@paxstats.app, we read that message to prepare a draft flight for you to confirm, and use the address it was sent from to match it to your account.
- Notification tokens. If you turn notifications on, we store the push token your browser or device issues so we can deliver them. It identifies that installation, not you, and it's removed when you turn notifications off or sign out.
- Usage and technical data. Basic technical information (device and browser type, page views, app interactions), collected through Vercel's cookieless analytics, used to keep the app working well and to see which features get used. It isn't linked to your account and doesn't follow you to other sites.
- IP address. Collected automatically on some requests solely to prevent abuse, for example to rate- limit how often the logged-out "request access" form can be submitted. We don't use it to track your location or activity.
How We Use Your Information
- To create and manage your account and authenticate you via Google or Apple Sign-In.
- To store your flight logs, photos, and generate the statistics the app displays.
- To operate, maintain, secure, and improve paxstats, including detecting and preventing abuse.
- To diagnose and fix errors, using automated crash and performance monitoring.
- To send the notifications you've chosen to turn on.
- To communicate with you about your account or the service, if needed.
We do not sell your personal information, and we do not use it for advertising.
Cookies
paxstats uses one type of cookie: a session cookie set by our authentication provider (Supabase) to keep you signed in. This cookie is strictly necessary for the app to work and doesn't require your consent under applicable law. Our analytics are cookieless, and we don't use advertising or tracking cookies or load third-party scripts that would set them. Because there are no non- essential cookies, we don't show a cookie consent banner. Two things do still run without asking you first, and we'd rather name them than imply nothing happens: cookieless page-view analytics, and — only when something goes wrong — Sentry's error session replay, which records the page around an error with all text and inputs masked (see “Error Monitoring and Session Replay” below). Neither is used for advertising, neither follows you to other sites, and neither is shared with a data broker or ad network.
How We Store and Share Information
We don't sell your personal data, and we don't share it with third parties for their own marketing purposes. We do use a small number of service providers ("sub-processors") to operate paxstats, each of whom only receives the data needed to perform their specific function and is bound by their own confidentiality and data-protection obligations:
- Supabase: database and authentication. Your account data and flight log are stored in a Supabase project hosted in the EU (Ireland).
- Cloudflare R2: stores uploaded flight photos and your profile picture.
- Google Sign-In: authenticates your identity when you sign in with Google.
- Apple Sign-In: authenticates your identity when you sign in with Apple, on web or in the iOS app.
- Flightradar24: used only when you click "autofill" on a flight; we send the flight number and date to look up schedule, route, and — when available — the real flown flight path on your behalf. Flightradar24's terms require any data we retrieve from them to be deleted within 30 days, which we do automatically.
- AeroDataBox: used only when viewing a flight's aircraft details; we send the aircraft's registration (tail number) to look up its age and flying status.
- Open-Meteo: used to show historical weather — or, for a flight today or in the next couple of weeks, the forecast — for a flight's date and airports.
- planespotters.net and logostream: supply publicly available aircraft photos and airline/ aircraft logos; no personal data is sent to them.
- Anthropic: powers the boarding-pass scanner and the optional "Ask your logbook" question box and AI flyer summary on your Pax ID card. For the question box and the summary, we send the relevant flight details (dates, routes, airlines, aircraft, seats and similar entries from your logbook) with no name, email, or account identifier attached. For a scan, the boarding pass itself is sent so its details can be read back into a draft flight. Anthropic processes each request only to answer it, and under their standard API terms your data isn't used to train their models.
- Migadu: hosts paxstats.io's mailboxes, including log@paxstats.app, so it handles any boarding pass or booking confirmation you forward there.
- Apple Push Notification service and your browser's push service: deliver notifications to your device if you turn them on. They carry the notification itself, not your logbook.
- Sentry: error monitoring and crash reporting, including limited, privacy-configured session replay (see below).
- Resend: delivers the email paxstats sends: the notifications you've enabled in Settings (such as a pax buddy request or a reaction to one of your flights), a reply if a forward to log@paxstats.app can't be matched to an account, and an internal notice when someone submits the logged-out "request access" form. Never used for marketing, and every notification type can be turned off in Settings.
- Vercel: hosts the application, and provides the cookieless analytics and performance measurements described above.
We may also disclose information if required by law, regulation, or valid legal process.
Error Monitoring and Session Replay
We use Sentry to catch and diagnose bugs. This includes session replay, which can reconstruct a short, masked recording of what happened in your browser around the time of an error, to help us fix it. Replay is configured to mask all text and block all media by default. It does not capture the literal content of your screen (your flight data, photos, or account details as displayed), only its layout and interactions.
Public Profiles
paxstats lets you optionally make your logbook public from Settings, visible to anyone with the link or browsing the community page, and discoverable via search engines. This is off by default. Turning it on is your choice, and you control exactly what's visible (your flight list, photos, and profile picture can each be shown or hidden independently). You can turn it back off, or delete your account entirely, at any time.
Google User Data
paxstats uses Google Sign-In solely to authenticate your identity and create your account. We only request the minimum profile information needed (name, email, profile photo) and do not use this data for any purpose beyond providing and personalizing the paxstats service.
Apple User Data
paxstats uses Sign in with Apple solely to authenticate your identity and create your account, on both the website and the iOS app. We only request the minimum information Apple provides (name and email, shared only the first time you sign in) and do not use it for any purpose beyond providing and personalizing the paxstats service. If you choose to hide your email from us, Apple's private relay forwards mail to your real address without ever giving it to us.
International Data Transfers
Our primary database and authentication infrastructure is hosted in the EU. Some of our sub-processors (listed above) may process data outside the EU/EEA/UK, including in the United States, under their own applicable safeguards (such as standard contractual clauses, where relevant).
Data Retention
We retain your account and flight data for as long as your account is active. If you delete your account from Settings, your account, flight log, and uploaded photos are permanently deleted, typically within minutes and no later than a reasonable period afterward, except where a copy must be retained longer for legal or legitimate business reasons (for example, abuse-prevention logs).
Boarding passes you scan aren't added to your logbook: the image is read once and only the flight details it produced are saved. An email you forward to log@paxstats.app stays in that mailbox after the draft flight has been created, and you can ask us to delete it at any time.
Concretely, for the data that is not your logbook itself:
- Beta access requests (the email you leave on the landing page) are kept until we have actioned them and for at most 12 months after they were submitted; older requests are deleted automatically.
- Rate-limit and abuse-prevention records are deleted automatically after 35 days.
- Error reports and session replays are kept by our error-monitoring provider for 90 days.
- Cached third-party lookups (flight, aircraft and weather data) are shared caches that hold no personal data and are refreshed on their own schedule.
Your Rights and Choices
You can access, export (via CSV), update, or delete your flight data at any time from within the app, and delete your account entirely from Settings.
If you're located in the EU, EEA, UK, or another jurisdiction with similar protections, you additionally have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten").
- Restrict or object to certain processing of your data.
- Port your data to another service in a structured, machine-readable format.
- Withdraw consent for any processing that relies on it, at any time, without affecting what was done before.
- Lodge a complaint with your local data protection supervisory authority — in France, the CNIL (cnil.fr).
paxstats makes no decisions about you by automated means that have legal or similarly significant effects.
To exercise any of these rights, or to ask a question about how your data is handled, contact us at the address below.
Children's Privacy
paxstats is not directed at children. You must be at least 16 to use it, or the age of digital consent where you live if that is lower (15 in France, 13 in the United Kingdom and the United States), and we do not knowingly collect personal information from anyone younger.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact Us
If you have questions about this Privacy Policy or your data, contact us at contact@paxstats.app.