Privacy notice
Effective: 2026-09-15
This notice explains which personal data the AeroBrief VFR flight weather briefing web application (the “service”) processes, for what purpose and on what legal basis, for how long, who can access it, and what rights you have.
The service is fully usable without signing in. A user account is only created by people who want to sync their settings and saved routes across devices.
1. Controller
- Controller: Tibor Zákány, private individual, operator of AeroBrief.
- Contact for privacy matters: privacy@aerobriefapp.com
- There is no obligation to appoint a data protection officer, so none has been appointed.
2. Using the service without an account
When you request a briefing, the route you entered (airfields, place names, coordinates, altitudes) and your planning settings are sent to our server, which fetches weather and airspace data and computes the result.
- Purpose: producing the requested briefing, map layers, station weather (METAR/TAF), SIGMETs and airspace information.
- Legal basis: the controller’s legitimate interest in providing the function you explicitly requested (Art. 6(1)(f) GDPR).
- Retention: a computed briefing stays in server memory for at most 30 minutes (so its details can be opened); place-name lookups (name → coordinates) are cached for at most 30 days without any link to a user.
- When you share a route, the route is placed in the link URL; only the people you send the link to can see it.
3. Server logs
To operate the service, troubleshoot errors and protect against abuse, the server keeps logs.
- Logged data: time of the request, IP address, requested URL, browser identifier (User-Agent), status code and response time, a random session identifier, the briefing route text and, when signed in, the internal account identifier (uid). E-mail addresses, passwords and authentication tokens are not logged.
- If you enter your own OpenAIP API key in Settings, it is part of the URL of airspace map tile requests and may therefore end up in the logs.
- Legal basis: legitimate interest in the secure and error-free operation of the service (Art. 6(1)(f) GDPR).
- Retention: 30 days, after which the logs are deleted automatically.
4. User account and sync
An account is optional. You can sign in with a Google account or with an e-mail address and password; authentication is handled by Google Firebase Authentication, and we never see or store your password.
- Data processed: e-mail address, display name (from your Google profile when signing in with Google), internal account identifier (uid), e-mail verification status, sign-in method, account creation and last-use time.
- Synced data: your app settings (without the Windy and OpenAIP API keys — these stay in your browser only) and your saved routes (name, route, departure and destination, timestamps; at most 100).
- Purpose: signing in, syncing settings and saved routes across your devices, verifying your e-mail address and resetting your password.
- Legal basis: providing the service you use with your account (Art. 6(1)(b) GDPR).
- Retention: until the account is deleted. “Delete account” in the account menu immediately deletes the settings and saved routes stored in the cloud and the account itself; the account identifier in the logs is kept for at most 30 days.
- We only send account-related system e-mails to your address (verification, password reset) — no newsletters or advertising.
5. Storage in your browser, cookies
The service uses no advertising or analytics cookies, no tracking code and no third-party analytics. Data needed for the app to work is kept in your browser’s local storage:
- localStorage: settings (language, thresholds, display), the API keys you entered (Windy, OpenAIP), saved routes and, when signed in, the account identifier and a local copy of the synced data.
- sessionStorage: a random session identifier that is deleted when the browser tab is closed.
- IndexedDB: when signed in, the Firebase Authentication sign-in state.
- These are strictly necessary for the functionality you request, so no separate consent is asked for. You can remove them at any time by clearing the site data in your browser.
6. Processors
We do not sell personal data or share it for advertising. The service uses the following processor:
- Google (Google Cloud EMEA Ltd., Google Ireland Ltd.): Firebase Hosting (serving the website), Cloud Run (server, region europe-west1, Belgium), Cloud Firestore (account data, region europe-west1, Belgium), Cloud Logging (logs) and Firebase Authentication (sign-in).
- Firebase Authentication and some Google infrastructure may also process data in the United States; such transfers rely on the EU–US Data Privacy Framework and the European Commission’s standard contractual clauses.
- When you sign in with Google, Google processes the data belonging to your Google account under its own privacy terms.
7. External data sources
The briefing and the map use public external data sources. These are independent providers acting under their own privacy policies.
- Directly from your browser (they receive your IP address and the map area displayed): OpenStreetMap (map tiles), OpenTopoMap, Esri (satellite imagery), NASA GIBS (cloud imagery, if enabled), RainViewer (radar, if enabled).
- Through our server (not your IP address, only route-related data): Open-Meteo (weather — coordinates), OpenStreetMap Nominatim (resolving the place names you enter), aviationweather.gov / NOAA (METAR, TAF, SIGMET — the area around the route), OpenAIP (airspace data — the area enclosing the route).
- Only if you enable them in Settings: Windy (weather forecast using your own Windy API key) and MET Norway (fallback weather source) — these receive coordinates.
8. Automated decision-making
The briefing assessment is produced automatically, but it is decision-support information, not a decision with legal effect on you, and no profiling takes place. The pilot always decides whether and how to fly.
9. Security
All connections are encrypted (HTTPS). Account data can only be accessed by the server with a verified sign-in token; there is no direct database access from the browser. Account data can only be written with a verified e-mail address.
10. Your rights
- Access: you can ask what data we process about you and receive a copy of it.
- Rectification and erasure: you can change your settings and saved routes in the app and delete your account at any time; other requests are handled by e-mail.
- Restriction and objection: you can request restriction of processing and object to processing based on legitimate interest.
- Data portability: you can request the data belonging to your account in a machine-readable format (JSON).
- We respond to requests without undue delay and within one month at the latest: privacy@aerobriefapp.com
- You can lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, Falk Miksa utca 9–11, 1055 Budapest, Hungary, www.naih.hu, ugyfelszolgalat@naih.hu) or the data protection supervisory authority of your place of residence, or turn to the courts.
11. Children
The service is not directed at people under 16; we do not knowingly process personal data from children.
12. Changes to this notice
We update this notice when the service changes; the current version, with its effective date, is always available on this page. The notice is available in Hungarian, English and German; in case of discrepancy the Hungarian version prevails.