Privacy Policy
Last updated: August 23, 2026
1. Data Controller
The data controller under the GDPR for data processed in connection with the "SectorLog" app and this website is:
Stefan Ischkum
Mannswörther Straße 63/1/5
2320 Schwechat, Austria
Email: developer@smahoma.com
2. The short version
- Your logbook — flights, duties, signatures, aircraft — lives in a local database on your device. It is not uploaded.
- No account is needed for logging, FTL calculation, imports, exports or backups. An account exists for two purposes: fetching your roster and relaying crew chat messages.
- Crew chat is optional and end-to-end encrypted on your device. Our server relays sealed envelopes it cannot open and deletes them once delivered.
- This website sets no cookies and runs no analytics, trackers or ads. Neither does the app.
3. What the app processes on your device
Flights, duty periods, home-base history, currency dates, signatures and photos you attach, weather stations you follow, and rule packs. All of it stays in the app's local database and in backups you create yourself. Backups are encrypted on the device with a recovery code that only you hold; we cannot open them.
If you turn on calendar export, the app writes your duties into a calendar of its own ("SectorLog") on your device; from there your calendar provider treats them like any other entry. Widgets, Siri shortcuts and the Live Activity read a small snapshot of your upcoming duties that stays on the device.
4. What the server processes — only if you create an account
If you connect a roster account, our server (hosted in the EU) processes:
- Account data: your email address, an Argon2 hash of your app password, and short-lived session tokens.
- Crew portal credentials: your crew ID, and your portal password, encrypted with a public key. Decrypting it needs a separate private key, kept apart from the public one; it is used solely to fetch your roster from your airline's crew portal — which is also what lets us notify you when your roster changes. The password is never stored readable.
- Roster data: duties, flights and crew assignments of your roster, so the app can sync them. Sync responses are scoped to your own crew ID.
- Push token: if you allow notifications, the device token Apple or Google issues for this installation, with your language and platform (section 6).
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) — this processing exists only to provide the roster sync you requested.
5. Crew chat
Crew chat is off until you turn it on. Messages are encrypted end-to-end on your device with the Double Ratchet protocol (vodozemac, the open-source Olm implementation used by Matrix). Keys are created on your device and exchanged in person by QR code; they never reach our server.
- What the server sees: a sealed envelope (ciphertext), the recipient's mailbox — the public identity key of their device, not a name — and the account that posted it. The server has no key to open envelopes and keeps no list of who talks to whom beyond the envelopes currently in transit.
- How long: an envelope is deleted as soon as the recipient confirms receipt, and in any case after 7 days (hard cap 14), fetched or not. There is no archive; a conversation exists only on the two devices.
- Who may fetch: posting requires your app account (rate limit against abuse); fetching is authorised by a signature of your device key, not by the account — so the server cannot map mailboxes to accounts.
- Your controls: you can turn chat off entirely or block individual contacts; a blocked contact's envelopes are discarded on your device.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) — the relay exists only for the chat you switched on.
6. Notifications and Live Activity
If you allow notifications, the app registers a device push token with our server, together with your language and platform. When a roster sync finds a change, the server sends you a short notification whose text names that change — a cancelled sector, for instance, with its flight number, date and route. On iOS that text travels through Apple's Push Notification service, on Android through Google's Firebase Cloud Messaging; on those systems there is no other way to reach your device. The token is deleted when you turn notifications off, and in any case once Apple or Google reports it invalid. Legal basis: Art. 6(1)(b) GDPR.
If you use the Live Activity for the current duty, the app registers a push token for that one activity with our server, together with the duty's identifier and whether you have checked in. After a roster sync, the server sends the activity its new state — the end of duty and the check-in flag, no names, no text — through Apple's Push Notification service, the same path every iOS notification takes. The token is deleted when the activity ends or the app asks the server to forget it, and in any case once Apple reports it invalid. Legal basis: Art. 6(1)(b) GDPR.
7. What we do not do
- No analytics, tracking or advertising SDKs, in the app or on this site.
- No sale or sharing of data with third parties.
- No processing outside the EU for the roster and chat services — with one exception we cannot avoid: notifications and Live Activity updates pass through Apple's or Google's push service (section 6), as every notification on those systems does.
8. Retention and deletion
Unlinking your crew portal in the app deletes your encrypted portal credentials from the server immediately. To delete your account and its synced roster data entirely, email developer@smahoma.com — deletion is confirmed within 30 days. Chat envelopes, push tokens and Live Activity tokens are deleted as described in sections 5 and 6. Local data you delete yourself by deleting the app or its entries.
9. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection under Art. 15–21 GDPR, and the right to lodge a complaint with a supervisory authority. The fastest way to exercise them: developer@smahoma.com.
10. This website
Serving this site produces standard server logs (IP address, time, requested page) kept briefly for operation and security (Art. 6(1)(f) GDPR). No cookies, no embedded third-party content.