Skip to content
AirPassbook
The appPrivacyDelete my data

Privacy, without the fog.

AirPassbook is a private flight archive. This policy explains, in plain language, which data the website, apps, and AeroBox backend use—and why.

Last updated 24 August 2026
Advertising
None
Behavioral analytics
None
Sale of personal data
Never
ScopeControllerData and purposesRetentionService providersYour rightsSecurity

1. Scope

This notice covers the AirPassbook Android and iOS apps, this public website, the account-deletion page, and the AeroBox service at api.airpassbook.com. It does not control Apple, Google, OpenFreeMap, Resend, or infrastructure providers when they act under their own terms.

The public website contains no advertising or behavioral-analytics code. Its marketing and policy pages do not intentionally set advertising or analytics cookies. Like any hosted website, the hosting network receives ordinary request data such as an IP address, date and time, requested page, browser information, and security signals so it can deliver and protect the site.

2. Who is responsible

The data controller for AirPassbook is:

Muhammad Saad Bhattim.saad.bhatti@protonmail.com

No data-protection-officer contact has been supplied for this draft. Add one here before launch if the controller has designated or is required to designate a data-protection officer.

3. What AirPassbook uses and why

AirPassbook processes only the categories needed for the service, optional features you choose, account safety, legal duties, and reliable operation. The main GDPR legal bases are performance of the service contract, legitimate interests in security and reliability, consent where an optional permission requires it, and compliance with legal obligations.

DataPurpose and legal basis
Account and profile

First and last name, username, country, phone number, email, password hash, gender choice, profile photo or Airmoji, account status, roles, and timestamps. Used to create, secure, synchronize, and display your account (contract; account security).

Authentication and device trust

Hashed one-time codes, code-delivery records, session and trusted-device token hashes, device names, expiry and revocation times, and rate-limit fingerprints. Used for login, password reset, trusted devices, and abuse prevention (contract; legitimate interest in security).

Boarding passes and journey archive

Decoded IATA boarding-pass data, including passenger name, route, airports, airline, flight number/date, booking class, seat, check-in sequence, passenger status, PNR where present, import time, and a payload fingerprint. Used to validate ownership, prevent duplicates, build your archive, draw your atlas, and calculate private travel statistics (contract).

Camera and barcode scan

The scanner reads the barcode on your device. AirPassbook sends the decoded boarding-pass data—not a photo of your camera view—to AeroBox for validation and import. Android uses Google’s code-scanning component; iOS uses the system camera framework (contract; device permission where required).

Optional airport context

When you choose nearby-traveler features, the app sends a location sample with capture time and accuracy. AeroBox stores precise coordinates encrypted, derives an airport context, and may keep the selected journey/flight identity, destination, and traveler country for short-lived discovery (feature request; consent or contract, depending on local law).

Connect and chat

Visibility choice, invitations, participant and presence references, airport context, message metadata, encrypted text or shared-location content, delivery events, unsend receipts, and lifecycle timestamps. Used only to provide the chat and nearby features you initiate (contract).

Push notifications

An encrypted device token, token fingerprint, platform, last-seen time, and delivery metadata. Used to deliver optional, privacy-safe notifications through Firebase Cloud Messaging. Notification bodies are designed not to contain names, coordinates, PNRs, seats, barcode data, or schedules (feature request; device permission where required).

Coffee support

Store, product ID, price, currency, date, and an encrypted/fingerprinted store transaction reference. Used to record an optional consumable support purchase and prevent duplicate recording (contract; legal obligations where applicable). AirPassbook does not receive full card details.

Feedback

Optional rating, subject, message, account reference, and submission time. Used to respond to and improve the product (your request; legitimate interest in product support).

Operations and security

Request ID, route template, response status, duration, service health, and security counters. AeroBox is configured not to log request bodies, query strings, headers, client addresses, email addresses, names, passwords, codes, tokens, raw barcode payloads, or PNRs. Used to operate and defend the service (legitimate interest).

Deletion request

The submitted email is used to find the account and deliver a short-lived code. AeroBox stores the account-linked request ID, a hash of the code, expiry, remaining attempts, verification/schedule timestamps, and invalidation state; its delivery outbox holds the recipient and encrypted code until delivery or cancellation. Used only to verify control of the account email and complete the erasure request (legal obligation; legitimate interest in preventing unauthorized deletion).

AirPassbook does not use your data for advertising, behavioral profiling, or automated decisions that produce legal or similarly significant effects. It does not sell or rent personal data.

4. How long data stays

  • Account and decoded journey archive: until you delete the relevant content or account, subject to limited legal retention duties.
  • Raw active barcode payload: encrypted only until midnight after the final flight, calculated in that leg’s origin-airport time zone; then the payload and key version are destroyed while decoded archive data remains.
  • Airport presence: normally expires after 10 minutes without a heartbeat. Encrypted precise airport context normally expires after 15 minutes.
  • Presence-scoped chat: sessions last at most 12 hours and are normally purged 24 hours after closing. Shared-location content expires after 15 minutes.
  • AirPartner chat: remains available until either participant deletes the shared conversation; it is then scheduled for purge after the configured closed-retention window, currently 24 hours.
  • Login and password-reset codes: expire after 10 minutes. Refresh sessions and trusted-device records are configured for up to 30 days unless revoked earlier.
  • Push device token: until unregistered, invalidated, replaced, or the account is deleted.
  • Donation and legal records: only for the period required to document transactions, prevent fraud, resolve disputes, and meet applicable accounting or tax duties.
  • Website and infrastructure logs: according to the shortest operational and security period configured with the production hosting provider; the exact provider and period must be added before launch.

5. Who receives data

Data is shared only as needed to run the service, fulfill your request, or comply with law:

  • Production hosting, PostgreSQL, and Redis: Cloudflare. The final provider, region, contract, and retention settings must be confirmed before publication.
  • Resend: email delivery for login, password reset, and deletion verification. Email address and message content are processed for delivery. Resend DPA.
  • Google Firebase Cloud Messaging: optional push delivery; the device token and message payload pass through Firebase. Firebase privacy and security.
  • OpenFreeMap: map style and tile requests when you open the atlas; ordinary network metadata may be visible to the provider. OpenFreeMap privacy policy.
  • Apple App Store and Google Play: app distribution and optional coffee purchases. They process store-account and payment data under their own terms; AirPassbook receives limited transaction references and product/price details.
  • Authorities or advisers: only when legally required or necessary to establish, exercise, or defend legal claims.

Some providers may process data outside the EEA. Where GDPR applies, AirPassbook must ensure an appropriate transfer mechanism, such as an adequacy decision or approved contractual safeguards, and document that choice before production use.

6. Your choices and rights

Depending on where you live, you may have rights to information, access, correction, erasure, restriction, portability, objection, and withdrawal of consent. Withdrawing consent does not affect processing that was lawful before withdrawal.

To request account deletion, use the AirPassbook deletion page. For another privacy request, contact m.saad.bhatti@protonmail.com. AirPassbook may ask for limited extra information when reasonably needed to verify identity. Requests are handled without undue delay and ordinarily within one month; applicable law can allow a longer period for complex requests, with notice.

You can also complain to the data-protection authority responsible for your location or the controller. The European Commission provides an overview of individual GDPR rights, and the binding text is available on EUR-Lex.

7. Security and changes

AeroBox uses access controls, hashed credentials and one-time codes, short-lived access tokens, revocable refresh sessions, encrypted sensitive fields, restricted CORS origins, abuse controls, and structured logs designed to exclude sensitive request content. Chat encryption is server-side encryption at rest; it is not end-to-end encryption.

No system is risk-free. If this policy changes materially, the updated date and affected sections will be changed, and notice will be provided in the app when required. New purposes will not be silently folded into old consent.

AirPassbook

A private archive for the journeys that shaped you.

Privacy policyLegal notice / ImpressumRequest account deletion
Download on the App StoreGet it on Google Play

© 2026 AirPassbook. No ads. No behavioral analytics.