Privacy Policy

Last updated: August 23, 2026

1. Data Controller

The data controller under the GDPR for data processed in connection with the "SectorLog" app and this website is:

Stefan Ischkum
Mannswörther Straße 63/1/5
2320 Schwechat, Austria
Email: developer@smahoma.com

2. The short version

3. What the app processes on your device

Flights, duty periods, home-base history, currency dates, signatures and photos you attach, weather stations you follow, and rule packs. All of it stays in the app's local database and in backups you create yourself. Backups are encrypted on the device with a recovery code that only you hold; we cannot open them.

If you turn on calendar export, the app writes your duties into a calendar of its own ("SectorLog") on your device; from there your calendar provider treats them like any other entry. Widgets, Siri shortcuts and the Live Activity read a small snapshot of your upcoming duties that stays on the device.

4. What the server processes — only if you create an account

If you connect a roster account, our server (hosted in the EU) processes:

Legal basis: performance of a contract (Art. 6(1)(b) GDPR) — this processing exists only to provide the roster sync you requested.

5. Crew chat

Crew chat is off until you turn it on. Messages are encrypted end-to-end on your device with the Double Ratchet protocol (vodozemac, the open-source Olm implementation used by Matrix). Keys are created on your device and exchanged in person by QR code; they never reach our server.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR) — the relay exists only for the chat you switched on.

6. Notifications and Live Activity

If you allow notifications, the app registers a device push token with our server, together with your language and platform. When a roster sync finds a change, the server sends you a short notification whose text names that change — a cancelled sector, for instance, with its flight number, date and route. On iOS that text travels through Apple's Push Notification service, on Android through Google's Firebase Cloud Messaging; on those systems there is no other way to reach your device. The token is deleted when you turn notifications off, and in any case once Apple or Google reports it invalid. Legal basis: Art. 6(1)(b) GDPR.

If you use the Live Activity for the current duty, the app registers a push token for that one activity with our server, together with the duty's identifier and whether you have checked in. After a roster sync, the server sends the activity its new state — the end of duty and the check-in flag, no names, no text — through Apple's Push Notification service, the same path every iOS notification takes. The token is deleted when the activity ends or the app asks the server to forget it, and in any case once Apple reports it invalid. Legal basis: Art. 6(1)(b) GDPR.

7. What we do not do

8. Retention and deletion

Unlinking your crew portal in the app deletes your encrypted portal credentials from the server immediately. To delete your account and its synced roster data entirely, email developer@smahoma.com — deletion is confirmed within 30 days. Chat envelopes, push tokens and Live Activity tokens are deleted as described in sections 5 and 6. Local data you delete yourself by deleting the app or its entries.

9. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection under Art. 15–21 GDPR, and the right to lodge a complaint with a supervisory authority. The fastest way to exercise them: developer@smahoma.com.

10. This website

Serving this site produces standard server logs (IP address, time, requested page) kept briefly for operation and security (Art. 6(1)(f) GDPR). No cookies, no embedded third-party content.