CrewCalc
Privacy policy
How the CrewCalc app and service handle your information.
The CrewSuite Family
This policy covers CrewCalc (web, iOS, and Android) and CrewBook (iOS and the current Android version). Sections that name CrewCalc apply to CrewCalc. CrewBook's iOS and Android behavior is described separately because the two versions do not yet have the same cloud features.
CrewBook on iOS
- Your logbook, military record, medical and certificate records, aircraft and people directories, attachments, and settings are stored in CrewBook's app storage on your device.
- Files you choose to import, including LogTen and ForeFlight exports, military JSON, and IFRR PDFs, are read and parsed on the device. IFRR image recognition uses Apple's on-device Vision framework.
- If CrewCalc is installed on the same Apple device, the apps can exchange flight (OOOI) records through Apple's private App Group container. This App Group exchange stays on that device.
- At launch, CrewBook writes backup files in its local Documents folder. When iCloud Drive is available for CrewBook, it also automatically copies the plaintext full JSON backup to CrewBook's iCloud Drive folder. Original attachment files are stored locally and are also mirrored to that iCloud Drive folder on a best-effort basis. These iCloud Drive files are not wrapped in CrewBook's CrewSuite encryption envelope and are handled under your Apple/iCloud settings.
- Reports, exports, and manual backup files are shared only when you choose a destination or use the system share sheet. A copy saved to a cloud-backed Files location may be uploaded by that storage provider.
- CrewSuite Cloud is optional. You can create or sign in to the same CrewSuite account used by CrewCalc. Account requests send the username, salt and key-derivation settings, a password-derived authentication verifier, and an optional GEMS number to the CrewSuite server. The password itself is not stored or sent.
- While signed in, CrewBook encrypts its full JSON backup on the device with AES-GCM and a password-derived key, then uploads the encrypted envelope to CrewSuite Cloud. Launch-time upload is automatic and best-effort. The server stores ciphertext plus operational metadata such as the blob name, version, size, modification time, request time, and network address; it cannot decrypt the backup without the password-derived key. Attachment file bytes are not included in this encrypted backup.
- CrewSuite Cloud is backup and restore, not live record-by-record sync. Restoring a backup requires confirmation and replaces the local CrewBook records covered by that backup.
CrewBook on Android
- The current Android version is local-only. It stores its Room database in the app's private storage, does not request Internet permission, and does not offer CrewSuite account creation, sign-in, cloud backup, or server sync.
- Android does not use Apple's App Group OOOI exchange. The current version receives data through a CrewBook backup restore or supported LogTen and ForeFlight file imports.
- CrewBook Android lets you manually store FAA medical certificate records, including examination date, certificate class, whether an ECG was included, and an optional examiner note. This feature is for recordkeeping only: CrewBook is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Consult a qualified healthcare professional for medical advice, diagnosis, or treatment.
- The app does not use Health Connect, body sensors, health permissions, or a health SDK. FAA medical data is stored and processed only in CrewBook's private on-device database and is not transmitted to CrewSuite or collected by the developer.
- Restoring a compatible iOS or Android CrewBook backup imports its FAA medical rows and medical-owned attachment metadata. Android backup JSON includes those medical rows and metadata so they can be restored on iOS or Android. Attachment metadata can include the related record identifier, filename, label, and creation date; the attachment file bytes are not included in or restored from the JSON backup.
- Imports are read on the device through Android's system document picker. CrewBook reads only the file you select.
- Reports and exports are created only when you choose a destination through Android's system file picker. Available plaintext files include logbook, experience, FAA/IACRA-summary, and military PDFs; LogTen-compatible tab-separated data; military JSON; and a CrewBook JSON backup. Depending on the export, these files may include your pilot name, flight dates, routes, aircraft, crew names, remarks, totals, military records and notes, certificates, FAA medical records, settings, and supported attachment metadata. Attachment file bytes are not included in the Android backup.
- If you choose a cloud storage provider as the destination, that provider may upload the exported file; CrewBook does not upload it to CrewSuite. Exported files remain at the destination after you close or uninstall CrewBook and must be deleted there when you no longer want them.
- Android OS-managed cloud backup and device-transfer backup are disabled for CrewBook. To move or preserve Android data, create a CrewBook backup and keep it in a location you control.
- FAA medical records and other local data remain until you delete them in CrewBook, replace the database through a confirmed restore, clear the app's storage, or uninstall CrewBook. Uninstalling removes the private local database. Reports, tab-separated exports, military JSON, and backup files you exported remain wherever you saved them and must be deleted separately.
CrewBook Analytics & Advertising
CrewBook on iOS and Android does not include analytics, advertising, or cross-app tracking SDKs, and CrewSuite does not sell CrewBook data. Network activity on iOS is limited to the optional account and encrypted CrewSuite backup behavior described above, plus Apple's handling of iCloud Drive.
What CrewCalc Handles
- Financial data you enter or import, including paychecks, pay rates, tax figures, annual statements, and deduction assumptions.
- Military pay and retirement data, including LES-derived values, service dates, points, grade, and retirement assumptions.
- Trip, fatigue, OOOI, accrual, retirement, Snapshot/bid-pack, and seniority information you choose to enter, import, or sync.
- Documents, PDFs, photos, screenshots, or pasted text that you explicitly choose to import or analyze.
CrewCalc Encrypted Sync
- CrewCalc stores your username and encrypted blobs for settings, ledger, annual records, military records, bidding/Snapshot state, retirement facts, trip data, accrual records, OOOI records, and seniority preferences.
- Your password is not stored. It derives separate authentication and encryption keys in the browser or app.
- User vault data is encrypted before upload. The server stores encrypted blobs that it cannot decrypt without the password-derived encryption key.
- If you lose your password, CrewCalc cannot recover or decrypt your saved encrypted data.
CrewCalc Plaintext Exceptions
CrewCalc's encrypted vault does not make every processing path zero-knowledge. Optional server OCR, server image conversion, Snapshot/bid-pack parsing uploads, and any files or screenshots you separately send for support can expose plaintext content for that specific action.
CrewSuite Account Administration
- For CrewCalc accounts and optional CrewBook iOS accounts, admins can see account usernames, an account-linked GEMS number when one was supplied, blob app/name, blob sizes, versions, and modified times.
- Admins may delete or download encrypted blobs for support, account, or maintenance purposes.
- Admins cannot read encrypted CrewCalc data or encrypted CrewBook backups without the user's password-derived encryption key.
CrewCalc Documents & Uploads
- Text-backed PDFs, pasted text, and supported images are parsed locally where the platform supports it.
- Image-only PDFs may ask for explicit server OCR consent. If you approve, that document is uploaded in plaintext for OCR processing for that upload.
- Snapshot and bid-pack PDFs are uploaded to the CrewCalc server for parsing into Snapshot datasets.
- Raw bid-pack PDFs are not stored inside the encrypted user vault unless a future attachment workflow is added.
- HEIC/image conversion may use local conversion where available; any server conversion is limited to the selected file and should be treated as plaintext processing for that action.
CrewCalc Local App Data
- iOS and Android store app data locally on the device. Mobile sync, where enabled, uses the same encrypted vault model as the web app.
- File and photo access happens only when you pick a file, image, or document to import.
- CrewCalc does not use advertising SDKs and does not sell user data.
- CrewCalc does not intentionally collect analytics, web history, contacts, messages, or device advertising identifiers.
Seniority & Reference Data
- Seniority and Snapshot datasets may be maintained as shared reference data for app features.
- CrewCalc stores personal seniority preferences inside encrypted settings. If you provide a GEMS number to create, claim, or find a shared CrewSuite account, the server receives it and may retain its association with that account.
- Raw GEMS numbers are not intended to be published in public seniority reference datasets.
Retention & Deletion
- Local app data remains until you delete it in the app or uninstall the app. Uninstalling does not remove files you exported, iCloud Drive files, or an optional CrewSuite server backup.
- On CrewBook iOS, Sign Out removes the stored account credentials from that device and keeps the local logbook. It does not delete the shared CrewSuite account or its server backup.
- The current CrewBook iOS version does not provide account deletion inside CrewBook. To delete a shared CrewSuite account and its stored CrewCalc and CrewBook encrypted blobs, contact admin@farhorizongroup.com. Account deletion affects every CrewSuite product using that account.
- Account deletion does not remove local, exported, or iCloud Drive copies. Delete those copies separately through the app, Files, iCloud Drive, or the storage provider where you saved them.
- CrewBook Android currently has no account or server copy to delete. Uninstalling removes its private app data; exported reports and data files remain at the destination you selected.
- Limited operational and security logs may be retained after account deletion when reasonably necessary to protect the service, investigate abuse, or meet legal obligations.
Contact
For privacy or security questions, contact admin@farhorizongroup.com.