← All legal documents

Privacy Policy

What personal data Alpha Sierra Pilot holds, why, who processes it, how long it is kept, and the rights you have over it.

Version 1.0 · In effect from 9 September 2026

This policy explains what we do with your personal data. It is written to be read, not to be survived — if anything here is unclear, ask us and we will explain it and fix the wording.

We are a small operation with no advertising business. We do not sell your data, we do not share it for advertising, and we run no analytics or tracking scripts on this site. The data we hold is the data the app needs to work.

1. The short version

  • We hold your email address, an optional name, and — if you supply them — your country and time zone.
  • We hold what you study: which aircraft you added, which lessons you opened, your drill answers, scores, streaks, bookmarks and your own notes.
  • We hold billing records if you buy something. We never see your card number; Stripe handles that.
  • We use no analytics, no advertising and no tracking cookies. The only cookies we set are the ones that keep you signed in and remember your light/dark preference.
  • Our database and file storage are in the EU (Ireland) and the app runs in the EU (Dublin). A few processors — email delivery, payments — are US companies, covered by the safeguards in section 7.
  • You can delete your account yourself, at any time, from Settings. It is immediate and it is real.

2. Who is responsible for your data

The data controller is the trader who operates Alpha Sierra Pilot:

Operator
— to be completed —
Legal form
egyéni vállalkozó (a sole trader registered in Hungary)
Registered seat / postal address
— to be completed —
Registration number (nyilvántartási szám)
— to be completed —
Tax number (adószám)
— to be completed —
Contact
support@alphasierrapilot.com or the contact form — for anything about your data

We are not required to appoint a Data Protection Officer: we are a small trader, our core activity is not large-scale monitoring, and we process no special-category data. Your requests go to the operator directly.

We are established in Hungary, so our lead supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH). Its contact details, and your right to complain to it or to your own national authority, are in section 9.

3. What we collect

Account data
Your email address; a one-way hash of your password (bcrypt — we never store the password itself); an optional display name; whether and when you confirmed your email; your role; your time zone (captured from your device so streaks roll over on your day, not ours); and, if you enter them in My Account, your country and whether you want product-update emails.
Sign-in with Google (optional)
If you choose Google sign-in, Google gives us your email address, name and profile picture URL, plus the identifiers and tokens needed to keep the link working. We ask Google for nothing else and we cannot see your Google account.
Session data
The one active session your account is allowed, when it expires, and a short human label for the device holding it ("Chrome on macOS"), derived from your browser's user-agent string. It is what makes the single-device rule and the "signed in somewhere else" message work.
Study data
The aircraft you added; which lessons and diagrams you opened and when; which lesson cards you marked; your drill and exam sessions, the questions in them, every answer you gave, whether it was right, how long you took and any confidence rating; your per-item progress and strength; your bookmarks, question flags and your own notes; and your streak and aggregate statistics.
Content reports
When you report a lesson or question, the item, the reason, anything you wrote, and the fact that it came from your account — we need that last part to come back to you about it.
Billing data
If you buy a plan: the plan, your subscription status, the current period end, and Stripe's customer and subscription identifiers. Card numbers, expiry dates and security codes are entered on Stripe's own page and never reach us.
Messages you send us
The name, email address and message you submit through the contact form, and anything you send by email. Contact-form messages are relayed straight to our support mailbox; they are not stored in the app's database.
Technical and security data
Ordinary server and platform logs — IP address, request path, timestamp, user agent, error details — generated by our hosting provider, and short-lived counters used to enforce rate limits (keyed to your account id or, for sign-up and sign-in, your IP address).

4. Why we use it, and on what legal basis

What we doData usedLegal basis
Create and run your account; sign you in; confirm your email; reset your passwordAccount data, session dataContract (Art. 6(1)(b))
Give you access to the library and drills for the aircraft you added or boughtAccount data, aircraft, billing dataContract (Art. 6(1)(b))
Record your answers, progress, streaks and statistics, and show them back to youStudy dataContract (Art. 6(1)(b))
Take payment, manage subscriptions, and honour cancellationsBilling dataContract (Art. 6(1)(b))
Keep accounting and tax records of what was soldBilling dataLegal obligation (Art. 6(1)(c))
Send you service email: confirm your address, reset your password, tell you about a change to these terms or a security matterAccount dataContract (Art. 6(1)(b))
Send you a reminder when a study streak you have going is about to lapseAccount data, streak statisticsLegitimate interests (Art. 6(1)(f)) — running a feature you are using. Every one of these emails carries an unsubscribe address: write to us and we stop sending them, with no reason needed. See section 9
Send you product-update emailAccount dataConsent (Art. 6(1)(a)) — off by default, switched on by you in My Account, withdrawable there at any time
Investigate a content report and correct the contentReport data, account dataLegitimate interests (Art. 6(1)(f)) — content accuracy in a safety-adjacent product
Keep the service secure and available: rate limits, abuse and fraud prevention, the single-device rule, error diagnosisTechnical and security data, session dataLegitimate interests (Art. 6(1)(f)) — protecting the service and its users
Understand which content works: which questions are too easy or too hard, which lessons are readStudy data, used in aggregateLegitimate interests (Art. 6(1)(f)) — improving the content. Results are aggregate, never a profile shown to anyone
Establish, exercise or defend legal claimsWhatever the claim concernsLegitimate interests (Art. 6(1)(f))
Processing purposes and their GDPR Article 6 basis

Where we rely on legitimate interests we have weighed them against your rights, and you can ask us for that assessment. Where we rely on consent you can withdraw it at any time, without affecting anything done before you withdrew it.

5. Adaptive drills, and what we do not do

The app decides which question to show you next from your own answer history — items you got wrong or rated shaky come back sooner. That is the product working, and it affects nothing outside your study session.

We do not make automated decisions that produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR. Nothing in the app judges your fitness to fly, reports on you to anyone, or is shared with an instructor, school, employer or authority. No instructor or third party can see your progress — the instructor features in our roadmap are consent-first by design and none of them are live.

6. Who else processes your data

We use a small number of service providers, each under a data-processing agreement and each limited to what it needs. We do not sell personal data, do not share it for advertising, and do not disclose it to anyone else except where the law requires it or to establish or defend a legal claim.

ProviderWhat it does for usWhereTransfer safeguard
SupabaseThe database holding your account, study and billing records, and the storage holding lesson images and audioEU — AWS Ireland (eu-west-1)No transfer outside the EEA for stored data
VercelHosting: runs the app and generates request and error logsApp runs in the EU (Dublin); the provider is a US companyStandard Contractual Clauses / EU–US Data Privacy Framework
StripePayments, checkout, the billing portal and subscription state. Stripe receives your card details directly and is a controller in its own right for themEU (Stripe Payments Europe) and USStandard Contractual Clauses / EU–US Data Privacy Framework
ResendDelivers our transactional email — verification, password reset, streak reminders. Receives your email address and the messageUSStandard Contractual Clauses / EU–US Data Privacy Framework
UpstashShort-lived counters that enforce rate limits. Holds a key derived from your account id or IP address and a count, for minutes to a dayRegional Redis; US companyStandard Contractual Clauses
GoogleOnly if you choose "Sign in with Google": authenticates you and returns your email, name and pictureGoogle Ireland Limited, EUGoogle's own terms; used for sign-in only
Sub-processors

7. International transfers

Your account, study and billing records are stored in the European Union (Ireland) and the application runs in the European Union (Dublin).

Some providers in the table above are US companies and may access data from the United States for support and operations. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework, together with the technical measures in section 10. You can ask us for a copy of the safeguards that apply to a particular provider.

8. How long we keep things

DataKept for
Account, study, progress, bookmarks, notes and reportsAs long as your account exists. Deleting your account deletes them.
Unverified accountsDeleted if the email address is never confirmed and the account is not used.
Email verification and password-reset tokensStored hashed; expire within 24 hours and are then removed.
Session recordsUntil you sign out, sign in elsewhere, or the session expires (30 days).
Rate-limit countersMinutes to one day, then they expire on their own.
Billing and accounting records of a purchase8 years from the end of the relevant year, as Hungarian accounting law requires. This is a legal obligation and it survives account deletion.
Support and contact-form emailUp to 24 months in our support mailbox, then deleted.
Server and security logsShort platform-retention windows set by our hosting provider (typically weeks).
BackupsSee below — user data can persist in a backup for up to 30 days after deletion.

Deleting your account. Settings → Delete account removes your user record and everything that hangs off it — study history, drill attempts, progress, bookmarks, notes, flags and reports — immediately, and cancels any active subscription. It cannot be undone. Statistics that are already aggregated and carry no identifier (for example "this question is answered correctly 61% of the time") remain, because they are no longer personal data.

9. Your rights

Under the GDPR you have the right to: access your data and get a copy; have it corrected; have it erased; restrict or object to processing we base on legitimate interests (including streak reminder emails, which we will stop on request); receive your data in a portable format; and withdraw consent where we rely on it. You are never required to give a reason for objecting to direct marketing, and we will always honour it.

  • Access, correction and deletion, immediately: most of this is in the app. My Account edits your name, email, country and email preferences; Settings → Delete account erases everything.
  • A copy of your data: email support@alphasierrapilot.com from your account address and we will send you a machine-readable export.
  • Stop streak reminder emails: every reminder carries an unsubscribe address in its footer (and a List-Unsubscribe header your mail client may surface as an Unsubscribe button). Email us and we take you off the list — no reason needed, and it does not affect anything else about your account.
  • Anything else: the same address. We answer within one month, and tell you if a complex request needs longer (up to two further months, as the GDPR allows). It costs nothing unless a request is manifestly unfounded or excessive.

Complaints. If you think we have handled your data badly, tell us first — we would rather fix it. You can also complain to a supervisory authority: ours is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11., postal address 1363 Budapest, Pf. 9, ugyfelszolgalat@naih.hu, naih.hu. You may also complain to the authority in the EU country where you live or work.

10. How we protect it

No system is perfectly secure, and we will not pretend otherwise. What we actually do:

  • Passwords are stored only as bcrypt hashes — we cannot read them, and neither can anyone who obtains the database.
  • All traffic is over HTTPS, with strict transport security and a content security policy that carries a fresh per-request nonce.
  • The database is closed to public API access by a deny-by-default row-level security posture; only our server reaches it.
  • Every request for content and for your own records is authorised on the server against the signed-in user — hiding a button is never how access is controlled here.
  • Images and audio are served through short-lived signed URLs issued only after that check.
  • One active session per account, plus rate limits on sign-up, sign-in, password reset and answer submission, to blunt brute force and abuse.
  • Secrets and API keys exist only in server-side configuration, never in anything sent to your browser.
  • Administrative access is limited to the operator, and every administrative endpoint re-checks that role on the server.

If a personal data breach occurs that is likely to result in a risk to your rights, we will notify NAIH within 72 hours of becoming aware of it and tell you directly where the law requires it.

11. Children

The service is not intended for anyone under 16 and we do not knowingly hold their data. If you believe a child under 16 has given us personal data, write to support@alphasierrapilot.com and we will delete it promptly.

12. If you are in the United States

We apply the same standard to everyone, so most of this policy already covers you. In the language of California's CCPA/CPRA and similar state laws:

  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no opt-out to click because there is nothing to opt out of.
  • The categories we collect are identifiers (email, name, IP address), commercial information (what you bought), internet activity (what you studied), and geolocation only at country level if you type it in — collected for the purposes in section 4 and disclosed only to the service providers in section 6.
  • You may request to know, to access, to correct, to delete and to obtain a portable copy — all through the routes in section 9. We do not discriminate against anyone for exercising a privacy right.
  • We do not use or disclose sensitive personal information for any purpose that would give you a right to limit it.

13. Changes to this policy

We update this policy when what we do changes. The version and effective date at the top identify the current text. For changes that materially affect how we use your data we will email you before they take effect. If a change requires your consent, we will ask for it rather than assume it.