Privacy Policy
The short version. FlyHedral is a small, independent aviation software project. We collect what the apps need to work, and nothing to sell.
We do not sell your data. We do not share it with advertisers. We do not use it to train AI models. If you ask us to delete your account, we delete it.
Two things worth knowing up front: flight instructors using FlyHedral CFI enter records about their students, and some content you submit is sent to an AI provider — Google (Gemini) or Anthropic (Claude) — to produce logbook entries, summaries, and checklists. Both are explained below.
1. Who we are
FlyHedral is operated by Russell Spurlock, an individual sole proprietor based in the United States. "FlyHedral," "we," "us," and "our" refer to that operator.
This policy covers the FlyHedral account service at account.flyhedral.com, the website at flyhedral.com, and all FlyHedral apps: Study, Weather, Charts, Checklists, CFI, and Career.
2. What we collect
Account information
When you create a FlyHedral account we store your email address, your name (if you provide one), a cryptographic hash of your password (never the password itself), and which apps your plan entitles you to use. If you reset your password we generate a single-use, time-limited token.
Data you put into the apps
Each app stores the content you create in it. Depending on which apps you use, that can include:
- CFI — student records, lesson notes, flight and ground times, logbook entries, endorsements and training progress, aircraft tail numbers, scheduling and booking requests, and calendar feeds you connect.
- Study — flashcard decks, quiz answers, and study progress.
- Weather — routes, airports, and flight plans you look up or save.
- Charts — charts and airports you view or save.
- Checklists — the checklists you create or import.
- Career — job searches, saved postings, and the qualifications you record to compare against them.
Records instructors keep about students
If you are a flight student: your instructor may keep records about your training in FlyHedral CFI — your name, contact details, lesson history, progress toward certificate requirements, and instructor notes.
Your instructor decides what to record and how long to keep it. We store it on their behalf and do not use it for any purpose of our own. If you want to see, correct, or remove what is held about you, ask your instructor first — they control it. You can also contact us and we will help.
Technical information
Our hosting providers record standard server logs (IP address, browser type, timestamps, and which pages or endpoints were requested) for security and reliability. If you enable push notifications, we store the notification subscription your browser issues. We do not use advertising trackers, third-party analytics pixels, or cross-site cookies.
Payment information
FlyHedral does not currently take payments. If and when paid plans launch, card details will be handled entirely by a PCI-compliant payment processor and we will never see or store your card number. This policy will be updated before that happens.
3. Google user data
Some FlyHedral features can connect to your Google account. This is always optional — the apps work without it, and nothing connects unless you explicitly authorize it on Google's own consent screen.
What we request, and why
| Google data | Why we ask for it |
|---|---|
| Google Calendar — read | To see when you are already busy, so your public booking page only offers students times you are genuinely free. |
| Google Calendar — write | To put confirmed lessons on your calendar automatically, and to update or remove them if a lesson is rescheduled or cancelled. |
We read only the timing and identity of events needed to determine availability and to keep lessons we created in sync. We create, update, and delete only events that FlyHedral itself created.
Limited Use
FlyHedral's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Specifically, we do not:
- transfer or sell Google user data to third parties, brokers, or advertisers;
- use Google user data for advertising of any kind;
- use Google user data to train, fine-tune, or improve any AI or machine-learning model;
- allow humans to read Google user data, except with your explicit consent, to resolve a specific support issue you have raised, for security purposes, or where required by law.
Disconnecting
You can disconnect Google at any time in the app's settings, or revoke access directly at myaccount.google.com/permissions. When you disconnect, we delete the stored access and refresh tokens. Lessons already written to your calendar remain yours and stay there unless you remove them.
4. AI processing
Several FlyHedral features use AI to turn what you submit into something structured — for example, converting free-text lesson notes into a logbook entry, summarizing a debrief, reading landing counts out of your notes, or extracting a checklist from a document you upload.
We use one or more of the following providers, and which one handles a given request may change as we tune quality and cost:
- Google — Gemini
- Anthropic — Claude
When you use one of those features, the content involved is sent to whichever provider is serving that feature. That content can include student names and lesson details you have written, or the text and images in a document you upload. It is sent only when you invoke the feature — not in the background, and not for everything you type.
We do not use your content to train our own models, and we do not permit any AI provider to train on it. If you would rather not use AI features, do not use them; every app works without them, and in FlyHedral CFI you can supply your own Google AI key so that processing runs under your own Google account and terms.
Google Calendar data is never sent to an AI provider. If you connect a calendar, that data is used only to work out when you are free and to keep FlyHedral's own lesson events in sync. It is not passed to Gemini, to Claude, or to any other model — see the Limited Use commitments above.
5. How we use your information
- To operate the apps and give you the features you asked for.
- To authenticate you and keep your account secure.
- To send transactional email — password resets, invitations, booking confirmations, and reminders you turned on.
- To diagnose faults, prevent abuse, and keep the service reliable.
- To comply with the law.
We do not use your information for advertising, profiling, or resale, and we do not send marketing email to addresses collected through the apps.
6. Who we share it with
We share data only with the service providers required to run FlyHedral, each processing it only on our instructions:
| Provider | What it handles |
|---|---|
| Neon | Database hosting — where your app data is stored |
| Vercel | Website and front-end app hosting |
| Railway | Back-end application hosting |
| Google (Gemini) | AI processing of content you submit to AI features |
| Anthropic (Claude) | AI processing of content you submit to AI features |
| Google (Calendar) | Calendar read/write, only if you connect it |
| Resend | Sending transactional email |
We may also disclose information if legally compelled, or where necessary to protect the safety, rights, or property of users or the public. If FlyHedral is ever sold or transferred, your data may transfer with it — you would be notified before that took effect, and this policy would continue to apply until replaced.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
7. Security
- All traffic runs over HTTPS.
- Passwords are stored only as salted cryptographic hashes.
- Particularly sensitive stored values — your own AI API keys, calendar feed URLs, and OAuth tokens — are encrypted at rest with symmetric encryption, separately from the database's own encryption.
- Sign-in is centralized through the FlyHedral account service; individual apps receive short-lived tokens rather than your credentials.
No system is perfectly secure. If we ever discover a breach affecting your personal information, we will notify affected users promptly and as required by applicable law.
8. Retention and deletion
We keep your data for as long as your account is active. You can delete your data at any time:
- Individual records — delete them in the app.
- A Google connection — disconnect it in settings; tokens are deleted immediately.
- Your whole account — email privacy@flyhedral.com and we will delete your account and its data within 30 days, then confirm.
Server logs and backups roll off on their own within 90 days. Records an instructor keeps about a student belong to that instructor's account; deleting a student's own login does not by itself erase the instructor's training records, which they may be required to retain.
9. Your rights
Wherever you live, you may ask us to: tell you what we hold about you, correct it, delete it, or give you a copy in a portable format. You may also object to or restrict certain processing. Email privacy@flyhedral.com and we will respond within 30 days. We will not discriminate against you for exercising any of these rights.
Data is stored and processed in the United States. If you are in the EEA or UK, using FlyHedral means your data is transferred there.
10. Children
FlyHedral accounts are not intended for children under 13, and we do not knowingly collect their personal information. Flight training legitimately involves minors — a student can solo at 16 — so an instructor may hold records about a student aged 13 to 17. Those records are entered and controlled by the instructor, who is responsible for having the appropriate permission. If you believe a child under 13 has given us information directly, email us and we will delete it.
11. Changes to this policy
If we change this policy we will update the date at the top. For material changes — a new category of data, a new provider, or a new purpose — we will notify account holders by email before the change takes effect.
12. Contact
Privacy questions, data requests, and account deletion:
privacy@flyhedral.com
We aim to answer within a few days, and always within 30.