CrewSync
Privacy Policy
Last updated: July 19, 2026
CrewSync values your privacy and is committed to protecting your personal data. This Privacy Policy explains how information is collected, used, stored and protected when you use the CrewSync app, available for iPhone, Apple Watch, Android, Wear OS, Garmin watches (Connect IQ), Alexa skills and Android Auto.
1. Data Collection
CrewSync collects only the information strictly necessary for the app to function.
1.1 Data provided by the user
- Flight rosters and related information, imported from the airline's official PDF, via IADP (GOL and ABX Air), via iFlight Crew (LATAM), or entered manually.
- Optional profile information (name, photo, position).
- Connections added by the user (friends, family or other crew members), always with the other party's explicit consent.
1.2 CrewSync account (email + password)
Sign-in to your CrewSync account uses your personal email and a password created by you, directly in the app. Authentication is processed by Firebase Authentication (a Google Cloud service dedicated solely to validating the login), with traffic protected by Cloudflare. The password is stored encrypted by the authentication provider, never in plain text, and CrewSync has no direct access to it.
Sign-in is used to:
- Securely store your flight rosters in the cloud.
- Sync data across devices (iPhone, iPad, Apple Watch and Android).
- Enable the CrewSync ID, a public key used to share your roster with friends or family upon explicit authorization.
You may, at any time, sign out or permanently delete your account — on iOS, in Settings → Preferences → Danger zone; on Android, in Settings → Advanced options. Deletion removes all your cloud data as well as your account record on the authentication server.
1.3 Optional official integrations (CrewLink/IADP — GOL, IADP — ABX Air, iFlight Crew — LATAM)
For crew members of certain airlines, CrewSync offers optional authentication through the airline's own official SSO portal — CrewLink (GOL) or iFlight Crew (LATAM). These features are entirely optional and may be used only by those who wish to, within the app, to view the official crew list for the flight, import their own roster directly from the source, and see any notices.
How access works:
- The login screen is loaded in an embedded browser (WebView) pointing to the airline's official domain (Microsoft Entra/Azure AD, Google Workspace or Keycloak, depending on the company). Your credentials are entered directly on the airline's portal, not on a CrewSync screen.
- CrewSync does not read, store or transmit your login or password. The app only receives, from the portal itself, a session token/cookie.
- The session token is stored locally on the device (Keychain on iOS; the app's secure storage on Android). It is never sent to CrewSync servers.
- Data returned by the integration is displayed on screen and, to improve the offline experience, stored only locally, cached on the device.
- You can end the session at any time in the app's settings. On sign-out, the token and local cache are erased.
If you do not use these integrations, no login or session data is collected. All other CrewSync features remain fully available.
1.4 Garmin watches app (Connect IQ)
CrewSync offers a free, optional app for Garmin watches (the Connect IQ platform) that shows your roster on your wrist. It was designed with the same privacy stance as the rest of the app.
How pairing and data work:
- The watch does not sign in. Pairing uses a one-time 6-character code: the watch generates the code and you confirm it in the phone app (where you're already signed in). After that, the watch stores only a device token (a random identifier) — no password, e-mail or personal data.
- With that token, the watch fetches your roster from our server (Cloudflare Worker,
crewsync-api.hotcomin.workers.dev). This is the same roster data already covered by this policy — no new data is collected. - To enrich the flight screen, the watch queries flight status (gate/time) and destination airport weather through our server, which relays from providers such as OpenWeather and public flight-status sources. Only the airport IATA code and flight data are sent — no personal data.
- Syncing the roster to the watch is a Premium feature (subscription made in the phone app).
- You can unlink the watch at any time (removing the watch app or undoing the pairing), which invalidates the token.
- The watch app uses only the Connect IQ Communications (network) permission; it does not access location, health sensors or contacts.
1.5 Aircraft position (radar and aircraft track)
When you use the aircraft track on the Home screen or the aircraft lookup by registration, the app sends the CrewSync server only the aircraft registration and the reference airport. The server fetches the position from public, collaborative ADS-B networks (such as adsb.lol, data under the ODbL 1.0 license) and, when those networks do not cover the region, from the official Flightradar24 API. The flight route comes from public aviation databases. In every case the server sends the sources only the aircraft registration, never the crew member’s personal data.
Aircraft positions are public data, broadcast by the aircraft themselves. These lookups contain no personal data and are not associated with your profile.
1.6 Your profile photo in the crew list
When you look up the crew for a flight, the app shows the list provided by your airline (each crew member's name, staff number, base and seniority). For colleagues who also use CrewSync, their profile photo appears in place of the circle with the role initials.
How it works: the app sends CrewSync's server the staff numbers already present in the airline's list and receives back only the photos of those who are CrewSync users and left this feature enabled. Matching is done by staff number within your own airline — the same staff number at different airlines belongs to different people, and the server never responds with data from another airline. The response contains only the photo, the account identifier and the nickname chosen in the community; name, base and seniority are not returned by the server, because the app already received them from the airline itself.
This feature is enabled by default. You can turn it off at any time in Settings → Privacy (on Android) or Settings → Preferences → Privacy (on iPhone), under “My photo in the crew list”. Once off, your photo immediately stops appearing to colleagues, and you keep seeing the photo of those who left the feature on. The legal basis is your consent, revocable through that same switch; the alternative is the circle with the role initials, as it always was.
The photo is only visible to crew members rostered on the same flight as you, at the same airline, who also use CrewSync. It is not published on any open page, is not indexed by search engines and is not used for advertising. Even so, it is worth knowing: anyone who sees the photo on screen can capture it, as in any app. If you would rather not take that risk, turn the feature off or remove the photo from your profile.
2. Use of Data
Data is used only to:
- Organize and display flight rosters.
- Calculate duty periods and rest periods.
- Operate the Connections feature (crew and visitors).
- Show your profile photo to colleagues rostered on the same flight, when that feature is enabled (item 1.6).
- Generate anonymous, aggregated community statistics.
- Display aircraft position (aircraft track and lookup by registration), from public ADS-B data.
- Locally calculate salary and per diem estimates. Salary calculation data is processed entirely on the device and is not sent to CrewSync servers.
CrewSync does not sell, rent or share personal data with third parties for advertising purposes.
3. Community Statistics
When you sign in, the operational data of your roster (aggregated totals of hours flown, number of legs, destinations, etc.) is sent to the global community statistics. All signed-in users contribute; viewing rankings and averages is exclusive to premium subscribers. The statistics are fully anonymous, based on aggregated data, and make individual identification impossible. You may delete your cloud data or sign out at any time.
4. Sharing and Disclosure
CrewSync does not sell, rent, share or disclose your personal data to third parties for advertising purposes. The app uses cloud infrastructure services (Firebase Authentication for authentication; Cloudflare D1 + R2 for roster and photo backups; Cloudflare Workers for network protection) — these providers process data on our behalf, under confidentiality agreements and in compliance with applicable data protection law (including Brazil's LGPD).
5. Your Choices and Controls
- Review and edit your profile information in Settings → Edit profile.
- Delete specific rosters or your entire cloud backup.
- Sign out while keeping local data.
- Permanently delete your account, removing your cloud data and ending the authentication record.
- Enable or not the optional official integrations (CrewLink/iFlight) and end that session at any time.
- Enable or disable showing your profile photo in the crew list, in Settings → Privacy (Android) or Settings → Preferences → Privacy (iPhone) — item 1.6.
6. Data Security
CrewSync follows a zero-trust security approach:
- Does not collect or store passwords for corporate systems — authentication happens on the airline's own official portal, inside a secure embedded browser.
- Does not access airlines' internal systems without the crew member's explicit consent.
- Stores session tokens only on the device, never on our own servers.
- Uses secure storage and trusted cloud services with encryption in transit (TLS 1.2+) and at rest.
- App integrity verification (Play Integrity on Android and App Attest on iOS): the device sends an anonymous cryptographic attestation proving the request comes from the official app, without identifying the user or the device.
7. User Rights
In line with applicable data protection law (including Brazil's LGPD), you have the right to access your data, correct or update information, delete stored data, and permanently delete your account. All these options are available directly in the app — on iOS, under Settings → Preferences → Danger zone; on Android, under Settings → Advanced options.
8. Data Retention and Deletion
Data is kept only while the account is active or until you request deletion. Old backups on Cloudflare are automatically purged 30 days after account deletion.
Deleting your account permanently and irreversibly removes the personal data and schedule associated with it; it cannot be recovered afterward. The user is solely responsible for the decision to delete the account and should make copies beforehand if they wish to preserve their data.
9. App Store Compliance
CrewSync follows the Apple App Store and Google Play guidelines, including minimal and transparent data collection declared in the privacy manifests (Apple App Privacy and Google Data Safety). The app does not use advertising identifiers and does not track you outside CrewSync, and it offers sign-out and account deletion within the app.
10. Changes to this Policy
This Policy may be updated at any time without prior notice; the version published on this page always prevails. Relevant changes may be communicated within the app.