Privacy Policy
Effective 24 July 2026
This Privacy Policy explains how FlightBrief, operated by Alexma ("we", "us", "our"), collects, uses and shares personal data when you use the Service. FlightBrief is a professional tool for pilots and is not intended for children. For the nature and limitations of the Service, see our Terms of Service.
1. Data we collect
- Account data — your email address and authentication details.
- Profile data — your airline/operator, fleet, display name, unit preference, plan and (where applicable) subscription/license status.
- Flight-preparation data — Operational Flight Plan (OFP) images you upload and the values extracted from them (e.g. registration, route, weights, fuel, times), the briefings generated, aircraft profiles and limits, personal weather preferences, and any local knowledge or notes you submit.
- Usage data — briefing counts and basic technical logs needed to run and secure the Service.
- Acceptance records — the fact, time and version of the Terms/Privacy acknowledgement you accepted at sign-up.
2. How we use data
- To provide the Service — parse OFPs, retrieve weather/NOTAM data, generate advisory briefings and passenger cards, and enforce plan limits.
- To operate global fact caches (e.g. country/aircraft facts) that reduce processing and cost.
- To secure the Service, prevent abuse, provide support and comply with legal obligations.
3. Third-party data processors
We rely on the following categories of processors to deliver the Service. Only the data needed for each function is shared:
- Hosting & database (Supabase, Vercel) — store your account, profile and briefing data and serve the application.
- Artificial intelligence (Anthropic) — OFP images and passenger/briefing text you submit are processed to read the OFP and to generate the advisory analysis and passenger prose. This data is processed via Anthropic's API and is not used by Anthropic to train its models.
- Aeronautical data (SkyLink and public aviation-weather sources) — we send airport/route identifiers to retrieve METAR/TAF/SIGMET/NOTAM, ADS-B and aircraft-performance information. These providers deliver third-party data we do not control (see Terms §3).
- Email (Resend) — to send transactional messages and to relay "request your airline" enquiries.
- Payments (Stripe) — where paid subscriptions are enabled, to process billing. We do not store full card details.
4. Legal bases (GDPR)
Where the GDPR applies, we process personal data to perform our contract with you (providing the Service), for our legitimate interests (securing and improving the Service), to comply with legal obligations, and on the basis of your consent where required (e.g. the sign-up acknowledgement).
5. International transfers
Our primary database is hosted in the EU. Some processors (for example AI, hosting-edge and payment providers) may process data outside the EU/EEA, including in the United States. Where such transfers occur, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
6. Retention
We keep personal data for as long as your account is active and as needed to provide the Service, then delete or anonymise it within a reasonable period, unless a longer period is required by law. You can request deletion of your account and associated data at any time.
7. Sharing of briefings and passenger cards
Briefings are private to your account and your fleet as applicable. Passenger companion cards are shared only when you choose to share them; by design they expose only passenger-safe information and never operational hazard data (such as cautions, NOTAMs, limits or alternate/fuel detail). A public share link is accessible to anyone who has the link.
8. Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, and may object to or restrict certain processing. To exercise these rights, contact hello@alexma.app. You may also lodge a complaint with your local data-protection authority (in Denmark, Datatilsynet).
9. Security
We use access controls, row-level database security and encryption in transit to protect data. No system is perfectly secure; you are responsible for keeping your credentials confidential.
10. Cookies
We use strictly necessary cookies to keep you signed in and to operate the Service. We do not use the Service for third-party advertising.
11. Changes
We may update this Policy from time to time; material changes will be notified by reasonable means and the effective date above will be updated.
12. Contact
Data controller: Alexma. Contact: hello@alexma.app.