Privacy & GDPR
Last updated 28 August 2026 · Contact: gdpr@crewbag.app
CrewBag is built by a working airline pilot on a simple rule: your data is yours, we keep as little of it as possible, and you can see and delete everything. Everything we run is hosted in the EU.
This website
- No cookies. No trackers. No analytics. The site loads nothing from anyone else — you can verify that in your browser's network inspector.
- If you request a TestFlight seat, we store: your email, base, operator, platform, and your two consent choices. Purpose: arranging your testing seat and, only if ticked, the emails you chose. Legal basis: consent.
- Referrals: every seat gets a random invite code. If you joined through someone's link we store that code (never their email) against your entry, and they earn points when you confirm your seat. If you set a handle, it is shown to colleagues who open your invite link ("Invited by …") and — with your points — on the base list visible to signed-in crew at your own base and airline only. Invite links carry only the random code, never a name or email.
- Polls: optional weekly questionnaires. Your answers are stored with your seat, visible only to you, analysed only as per-airline/per-base aggregates (never shown below 8 people), and erasable by you at any time — the points you earned stay.
- Notifications: if you enable them in the app, we store a push token for your device. Referral-activity pushes can be muted separately; deleting the app or signing out stops them.
Your account
- Sign-in is by email code — we never store passwords.
- See everything: your account page shows every row we hold against your email — Apple-style, complete.
- Delete my account: the same page has a one-click, instant, no-questions erasure of your account and everything linked to your email. Encrypted backups age out automatically (14–90 days).
The app
- Your roster, briefings and logbook live on your device and in your own iCloud — not on our servers.
- Bug reports are opt-in and only sent when you choose the files to include (each item is a tick-box). Roster documents can contain colleagues' names — we minimise by design, purge server copies within ~30 days of retrieval, and analyse only to fix problems, including automated analysis.
- Reports are keyed to an anonymous reporting identity you can reset in the app, which orphans all previous reports.
Usage signals
- As of the current version, the app sends one minimal signal — pseudonymous usage events (like "the app was opened on a duty day") on a random identity never linked to your account, resettable in the app's Privacy settings, and switchable off entirely with one tap.
- No advertising IDs, no cross-app tracking, no location, no selling — ever. When this switches on, this page and the App Store privacy label change first, and the changelog says so in plain language.
Who processes what
- Hetzner (Germany) — our server hosting, EU.
- Brevo (France) — sends verification codes and, with your consent, updates. EU.
- Apple — TestFlight distribution and, for your own data, your personal iCloud.
- Nobody else. We sell nothing to anyone.
If something goes wrong — breach protocol
If we ever suffer a personal-data breach, we commit to:
- Assess within 24 h of discovery — what leaked, whose, how.
- Notify the supervisory authority within 72 h where required (GDPR Art. 33).
- Tell affected users directly and plainly — what happened, what we did, what you should do (Art. 34).
- Publish a post-mortem once resolved.
Report a suspected breach or vulnerability: security@crewbag.app. We answer fast and we don't shoot messengers.
What survives deletion
Three things, by design and legal obligation: the security audit trail (who created/deleted an account, sign-ins with IP address, consent changes — kept 2 years, containing only your email and the event); your handle, retired forever so nobody can impersonate you after you leave; and — only if you asked us to build or curate an airline setup — the record of that contribution (your account, the setup, the dates of our checks), kept for the defence of legal claims (GDPR Art. 17(3)). Nothing beyond the provenance itself. Sign-in IPs are stored for account security; we never store or derive your location.
Your rights
Access, rectification, erasure, restriction, portability, objection — GDPR Arts. 15–21. Most are self-service on your account page; for anything else, gdpr@crewbag.app, answered within 30 days. You may also complain to your national data-protection authority.