Legal
Privacy Policy
Last updated: August 13, 2026
This Privacy Policy explains how Tally Aero, Inc. (“TallyAero,” “we,” “us”), a Delaware corporation at 3723 Greenville Ave, Ste 44161, Dallas, TX 75206, USA, collects, uses, shares, and protects your information across the TallyAero websites and applications (the “Service”). It covers residents of the United States (including California) and the European Economic Area and United Kingdom.
1. Information we collect
An account is required to use the TallyAero app. There is no anonymous mode.
Account and identity
You sign in with Apple, Google, or an email address. We request your name and email address as part of that sign-in. Your pilot profile can also hold your phone number (if you turn on SMS), date of birth, FAA certificate numbers, CFI and AGI/IGI numbers, FAA Tracking Number, passport expiry and issuing country, SIDA or ramp badge identifiers, employer and employment type, and military branch, rank, status and MOS.
Logbook content
Flights, aircraft, endorsements, simulator and ground sessions, free-text remarks on any record, safety and incident report narratives, entries transcribed from paper logbooks, and a signature you draw yourself. Flight records include departure and destination airports with dates, which taken together describe where you have flown and when.
Photos and documents
With your permission the app uses your camera and photo library. Documents you add to the Document Wallet, such as certificates, medicals, passports and insurance, are stored as complete images, not only as text read from them. Scanned logbook pages are stored in cloud storage, including an automatic sweep at app start that uploads pages not yet backed up. Photographs of aircraft maintenance records are stored the same way.
Information about other people
If you request an instructor signature, we store and transmit that instructor's name, email address and certificate number, the signature they draw, the message you write to them, and their reply. This information is also placed into the email we send them.
Purchases
Purchases are made through Apple's App Store or Google Play. The signed receipt or purchase token is sent to our server so we can verify it and record what you are entitled to. No payment card number ever reaches us.
Biometric unlock
If you turn on Face ID or fingerprint unlock, your device tells the app only whether the check passed or failed. No fingerprint or face data ever leaves your device's operating system, and we never receive it.
Local network
The app can connect to an ADS-B receiver on the same local network as your device, which is why your phone may ask for local network permission. This is a direct connection to that receiver.
2. Health and medical information
Some of what the app stores is health information about you. We are setting it out separately because it is treated as a special category of data under GDPR Article 9 and as sensitive personal information under California law.
- Your medical certificate class, issue date and expiry, and the name and designation of the Aviation Medical Examiner who issued it.
- Your BasicMed checklist and physical examination dates.
- Photographs of medical documents, including FAA medical certificates, BasicMed CMEC forms, eye examinations and EKG records.
- A Statement of Demonstrated Ability record. This identifies a disability category by its nature (colour vision, monocular vision, hearing, or limb) together with any limitations you type in.
- A Special Issuance record, which includes free text where you may describe a diagnosed medical condition.
You provide this information to track your own currency and eligibility to fly. We use it for that purpose and no other. We do not use it for advertising, we do not sell it, and we do not disclose it to insurers, employers or your flight school unless you take an action that shares it. Where GDPR applies we rely on your explicit consent, which you can withdraw by deleting these records or your account. You can leave every field in this section empty and still use the app.
3. Device identifiers and app integrity
The app creates or collects five identifiers. Two of them exist before you sign in.
- Firebase Installations ID and push token. When the app first launches it registers with Google for push messaging. This happens before you sign in, and whether or not you allow notifications.
- Device registry entry. The app generates a persistent identifier for each installation and records it, with your device name, against your account each time you sign in. It is stored in a second place on the device deliberately, so that clearing your browser or site data does not reset it. It is not user-resettable. Deleting your account removes it from our side.
- Device fingerprint. A one-way hash calculated from your user agent, language, screen size, colour depth and time zone, used to recognise the same device.
- App integrity attestation. Google reCAPTCHA Enterprise and Firebase App Check run at every launch, and keep checking while the app runs, to confirm requests come from a genuine copy of the app rather than an automated tool. This sends device and browser signals to Google.
4. Usage analytics and crash reports
Usage analytics, on by default
We record which screens you open and roughly 75 named events describing what you do in the app. Some carry detail such as the certificate level you are working toward, an incident event type, a knowledge-test score, or which aircraft a record belongs to. This is our own system running on our own servers. It is on by default. You can turn it off in Settings, and nothing about the app stops working when you do. We do not use it for advertising and it is not shared with an advertising network.
Crash and error reports
When the app hits an error it sends us the error message, the technical stack trace, the screen you were on, your browser or device user agent, and the app version, so we can fix it. If you are signed in, your email address is recorded on that report so we can tell whether one person is hitting a problem repeatedly. The analytics setting in Settings does not switch crash reporting off. Crash reports age out on their own retention schedule. If you have a question about one, contact [email protected].
5. How we use your information
- Provide, operate, secure and improve the Service;
- Sign you in, and confirm requests come from a real copy of the app;
- Calculate currency, generate reports, and run the features you use;
- Read values from documents you upload, so you do not have to type them (paid accounts);
- Send an instructor a signature request when you ask us to;
- Contact you about your account, verification and service changes;
- Verify purchases and record what you are entitled to; and
- Comply with law and enforce our Terms.
6. Legal bases (EEA/UK)
Where GDPR applies we rely on: performance of a contract (to provide the Service you asked for); legitimate interests (to keep the Service secure and working, and to understand how it is used); explicit consent (for the health information in section 2); and legal obligation.
7. How we share information
We share personal information only with the processors below, and only to run the Service. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
| Processor | Purpose | Data | Location |
|---|---|---|---|
| Google Firebase / Google Cloud | Identity and sign-in, database, file storage, functions, hosting, crash and error logs | Account, logbook and uploaded data; device identifiers; IP address | USA |
| Apple | In-app purchases on iOS (App Store) | Purchase receipt and transaction identifiers. Apple handles payment; we never see card details. | USA |
| Google Play | In-app purchases on Android | Purchase token and transaction identifiers. Google handles payment; we never see card details. | USA |
| Google reCAPTCHA Enterprise / Firebase App Check | Verifying that requests come from a genuine copy of the app | Device and browser signals, gathered at every launch and re-checked while the app runs | USA |
| Twilio SendGrid | Account and transactional email, including delivery and bounce events | Name, email address, delivery status keyed to the recipient address | USA |
| Twilio | SMS verification and notifications | Phone number, message content | USA |
| Amazon Web Services | Text extraction (Textract) from document images you upload, on paid accounts | The document image and the values read from it | USA |
| Cloudflare | Content delivery and bot protection | IP address, request metadata | USA / global edge |
We may also disclose information to comply with law or valid legal process, to protect rights and safety, or in connection with a merger, acquisition or asset sale (with notice where required).
8. Third-party data sources
The Service retrieves aeronautical and reference data from public and third-party sources to show it to you, including the FAA (registry, airmen, NOTAMs, charts, NASR, TFRs), NOAA and aviationweather.gov, Open-Meteo, airplanes.live (ADS-B), OpenStreetMap/Nominatim, and RainViewer. Requesting that data may share basic request information, such as an approximate location or your IP address, with those sources. It is used to give you the feature you asked for.
9. Storage, sync and security
Your logbook is held on your device so it works offline, and is also stored on our servers on Google Firebase and Google Cloud, encrypted in transit and at rest.
Cloud storage and sync are part of the Service, not an optional extra. An account is required, sync is on by default, and several kinds of record (your profile, documents, aircraft, endorsements and simulator entries) are written to the server regardless of the sync setting. If you belong to an organisation, sync stays on. If you do not want a record stored on our servers, do not enter it.
No method of transmission or storage is perfectly secure, but we use administrative, technical and organisational safeguards appropriate to the data.
10. Data retention and deletion
We keep personal information while your account is active, or as long as we need it to provide the Service, then delete or de-identify it, except where we must keep it to comply with law, resolve a dispute or enforce an agreement. Some specifics worth stating plainly:
- Documents you upload are kept as complete images until you delete them or your account.
- Text read from a document is cached for 30 days so the same page is not processed twice.
- Values read from documents are also written to our server logs. Deleting a record from the database does not remove it from those logs, which age out on their own retention schedule.
- Data held on your device stays there until you clear it or delete your account.
You can delete your account at any time from Settings, then Data & Backup, then Delete Account. See deleting your account for what is removed, what may remain, and why you should export first. If you have a question about deletion, contact [email protected].
11. Your privacy rights, United States (including California)
Depending on your state, you may have the following rights, which you can exercise by contacting [email protected]. We will verify your request and respond as required by law; you may use an authorized agent.
Know / Access. Learn what personal information we collect, use, and disclose.
Delete. Request deletion of your personal information, subject to legal exceptions.
Correct. Request correction of inaccurate personal information.
Limit use of sensitive information. Ask us to limit use of sensitive personal information, including the health data described in section 2.
Opt out of “sale”/“sharing”. We do not sell your personal information or share it for cross-context behavioral advertising.
Non-discrimination. We will not discriminate against you for exercising your rights.
Because we do not sell or share personal information as those terms are defined under the CCPA/CPRA, no “Do Not Sell or Share My Personal Information” action is necessary, but you may still contact us with any request.
12. Your privacy rights, EEA and UK (GDPR)
If you are in the EEA or UK you have the following rights, exercisable via [email protected]:
Access & portability. Get a copy of your data in a portable format.
Rectification. Correct inaccurate or incomplete data.
Erasure. Have your data deleted (“right to be forgotten”), subject to exceptions.
Restriction & objection. Restrict or object to certain processing.
Withdraw consent. Withdraw consent at any time where processing is based on it, including for health data.
Lodge a complaint. Complain to your local data-protection authority (or the UK ICO).
13. Cookies and website analytics
The TallyAero website uses Google Analytics to measure how the site is used. The app does not: it uses the first-party analytics described in section 4, and no Google Analytics. Essential cookies and local storage are used to operate both.
You can control cookies through your browser and can install Google's own opt-out extension. We honor recognized opt-out signals where legally required.
14. International data transfers
We are based in the United States and our processors are primarily in the United States. If you use the Service from outside the U.S., your information will be transferred to and processed in the U.S. Where required for EEA/UK transfers we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum.
15. Children's privacy
The Service is not directed to children under 13 and we do not knowingly collect their personal information. Student-pilot users must be at least 16. If you believe a child under 13 has given us information, contact [email protected] and we will delete it.
16. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified (for example by email or in the Service) and reflected in the “Last updated” date above.
17. Contact us
For privacy questions or to exercise your rights, contact [email protected], or write to Tally Aero, Inc., 3723 Greenville Ave, Ste 44161, Dallas, TX 75206, USA. You can manage your email and notification preferences in the app under Settings.