1. About This Privacy Policy
This Privacy Policy explains how Crew Sphere collects, uses, stores, shares, and protects information when people use the Crew Sphere mobile application, create a Crew Sphere account, manage rosters, use Sphere or Nearby, create or accept connections, create external roster-sharing links, open Crew Sphere-associated webpages, contact support, or otherwise interact with the service.
This policy applies to crew users, family or friend users, and visitors of related Crew Sphere webpages where relevant. Third-party services used by Crew Sphere have their own privacy practices, and this policy does not replace those third-party notices.
2. Who We Are
Crew Sphere is operated by:
These operator details should stay aligned with Crew Sphere's app-store listings, legal pages, and support communications. If a production deployment uses updated operator details, the configured values should be refreshed here.
3. Information We Collect
Depending on how you use Crew Sphere, we may collect or process the categories of information described below.
Account and profile information
This may include your first name, last name, display name, email address, authentication identifiers, profile photo, user role or account type, timezone, onboarding state, app preferences, account creation date, and account status.
Authentication information
Crew Sphere uses Firebase Authentication for core sign-in flows. Authentication may involve an email address, password-based sign-in, authentication tokens, or provider-specific sign-in credentials required to create a session. Passwords are handled through the configured authentication system and are not displayed to Crew Sphere administrators in plaintext.
If you use Google Sign-In or Sign in with Apple, Crew Sphere may receive identifiers and profile details made available by those providers, such as your name, email address, and authentication assertions. Crew Sphere does not receive your Apple or Google account password.
Crew profile information
Crew users may provide an airline selection, home-base airport, roster preferences, sharing preferences, and timezone. Crew Sphere does not require airline portal usernames, airline portal passwords, or airline employee credentials in order to use the app. Crew Sphere does not intentionally require employee or staff numbers in the current product flow.
Family or friend profile information
Family or friend users may provide a display name, email address, profile photo, timezone, invitation or connection details, and privacy-related connection settings. Family or friend accounts only receive schedule information that a crew user has chosen to share.
4. Information You Provide
You may voluntarily provide information when you create an account, edit your profile, add roster entries, select an airline, set a home base, choose a manual city, configure Nearby, connect with people in your Sphere, accept or decline connection requests, configure relationship and sharing settings, create external share links, name share links, contact support, or make privacy-related requests.
5. Roster and Schedule Information
Crew Sphere allows users to enter schedule information manually. Depending on the duty type, this can include flight dates, flight number, origin airport, destination airport, report time, scheduled departure, scheduled arrival, return timing, days off, standby, leave, training, notes, and other duty types.
Derived roster information
Crew Sphere also derives additional status information from roster inputs through application logic, including home or away state, likely layover continuity, current destination, upcoming return, availability, unavailability, unknown status, and overlapping free days with accepted connections. These derived states help power Home, Roster, Nearby, Overlap, connection sharing, and external share pages.
Missing or unknown schedule information
Crew Sphere does not intentionally treat missing schedule information as confirmation that a user is free, off duty, or available. Where roster continuity is unclear, Crew Sphere may show an unknown or limited status instead of guessing.
6. Location and Nearby Information
Nearby is designed around city-level presence, not precise public tracking. Crew Sphere may use approximate device location when you grant permission, a city you manually select, or a city inferred from reliable roster context where available.
Why location is used
- To determine whether accepted Sphere connections appear to be in the same city
- To populate the Nearby experience
- To support availability context
- To help users identify opportunities to meet trusted connections
What Nearby is not designed to share
Crew Sphere is not intended to expose exact GPS coordinates, street addresses, neighborhoods, hotels, room numbers, live movement, exact distance, or location history through Nearby.
Optional location access
Location access is optional. Users can choose a manual city instead, or turn Nearby off entirely. Users can also revoke device location permission through their operating-system settings.
Background location
Crew Sphere does not currently use continuous background location tracking for Nearby.
Location freshness
Crew Sphere may retain a city-level presence update timestamp or expiry marker so the service can determine whether a location remains current enough for Nearby. The feature is intended to refresh or expire over time rather than build a permanent location history.
7. Connections and Sphere Information
Crew Sphere processes network and relationship information such as connection requests, accepted connections, pending connections, blocked relationships, relationship labels, sharing permissions, and invite links or QR-based connection flows. This information is used to operate Sphere, sharing controls, Nearby, and overlap calculations.
Crew Sphere does not provide a public directory of all users. Connections and discovery are intended to stay private and limited to accepted or otherwise eligible relationships. Relationship labels, if used, are based on user choice and should not be treated as inferred relationship facts.
Blocking can limit or prevent connection interactions, sharing visibility, Nearby visibility, and access to connection-based schedule features where appropriate.
8. External Schedule Sharing
Crew Sphere allows users to generate private web links so trusted recipients can view a limited, privacy-filtered schedule without necessarily creating a Crew Sphere account or signing in to the mobile app.
Users control what an external link can expose. Depending on the link settings, this may include a display name, profile photo, home or away state, day off status, leave, standby, destination, return day, or approximate return timing. Different links can use different sharing permissions.
Anyone who possesses an active external schedule link may be able to view the information allowed by that link. Users should only share active links with people they trust. Recipients should not redistribute those links without permission.
When someone opens an external share page, Crew Sphere may process technical information such as request time, share-link access time, browser or device characteristics, server-side security logs, and IP-address-related logging used for security or rate limiting where recorded by the hosting stack. Crew Sphere does not assume it knows the real-world identity of every unauthenticated share-page visitor.
9. Device and Technical Information
Crew Sphere may automatically process device and technical information needed to operate and secure the app, including device type, operating system, app version, device language, timezone, request timestamps, authentication-session identifiers, Firebase installation or registration identifiers, and push-notification tokens.
Crew Sphere may also process server-side request metadata, including IP-address-related information recorded through normal hosting, security, or rate-limiting infrastructure.
10. Notifications
Crew Sphere uses Firebase Cloud Messaging and related device registration tokens to deliver push notifications. These notifications may include connection requests, connection acceptance, schedule reminders, duty-related reminders, share-related notices, and account or security events where those features are enabled.
Push-notification tokens are technical identifiers used to deliver notifications; they are not the notification content itself. Users can manage push-notification permissions through device settings and Crew Sphere preferences where supported.
11. Analytics and Diagnostics
Crew Sphere does not currently enable separate product analytics or crash-diagnostics tooling in this build. If Crew Sphere later enables analytics or crash reporting in a production release, this Privacy Policy should be updated before or when that processing goes live.
Even where technical logging is used for operations or security, Crew Sphere should avoid intentionally sending sensitive roster entries, exact locations, share-link tokens, passwords, or full private URLs into analytics or diagnostic tooling.
12. How We Use Your Information
We use personal information to provide and improve Crew Sphere, including to:
- Create and manage accounts, profiles, sessions, and onboarding state
- Store, display, and organize rosters and roster-derived states
- Calculate availability, overlap, and home or away context
- Operate Sphere, Nearby, privacy controls, and external share links
- Deliver notifications and account-related service messages
- Authenticate users, prevent abuse, protect private links, and enforce blocking
- Respond to support, security, legal, and privacy requests
- Maintain the internal administrative and support dashboard with data-minimization controls
Crew Sphere aims to use personal information only for appropriate, disclosed, and compatible purposes, unless additional consent or another lawful basis is required.
13. Grounds for Processing
Depending on where you live and the applicable law, Crew Sphere may process personal data based on user consent, the performance of a contract or requested service, legitimate interests, compliance with legal obligations, the protection of legal rights or security, or other lawful grounds available under the law that applies.
Where a feature depends on optional consent or permission, such as approximate device location for Nearby, you can withdraw that permission later. Withdrawal does not automatically invalidate processing that was lawful before withdrawal.
14. How Information Is Shared
Crew Sphere does not sell personal information to advertisers. Crew Sphere may share information in the following ways:
- With accepted connections, but only within the permissions the user has chosen
- With recipients of active external roster-share links, limited to the fields allowed by that link
- With service providers that help operate Crew Sphere
- With legal authorities or other parties where required by law or necessary to protect rights and safety
- With parties involved in a business transaction, subject to applicable protections
Not every connection sees the same information. Sharing settings can vary by connection and by external share link.
15. Third-Party Service Providers
Crew Sphere currently relies on a limited set of third-party or platform providers, including:
- Google / Firebase for Firebase Authentication and Firebase Cloud Messaging
- Apple for Sign in with Apple and Apple platform push-delivery pathways where applicable
- Hosting and infrastructure providers that run Crew Sphere's web and API infrastructure
- Database and storage services used to store application data and profile assets
If Crew Sphere later activates public flight-status enrichment or similar external provider integrations, the policy should be updated before describing those live data flows in more detail.
Third-party providers process information according to their own privacy terms and their service relationship with Crew Sphere.
16. International and Cross-Border Processing
Crew Sphere may use service providers or infrastructure located in countries different from your own. As a result, personal information may be processed or stored internationally. Where applicable, Crew Sphere should use appropriate legal or contractual safeguards for cross-border processing.
17. Data Retention
Crew Sphere retains information only for as long as reasonably necessary to provide the service, maintain accounts, secure the platform, resolve disputes, investigate abuse, comply with legal obligations, and enforce agreements.
- Account information: generally retained while your account remains active, subject to legal and operational needs
- Roster data: retained while you keep it in the service unless you delete it, your account is deleted, or a retention process removes it
- Nearby presence: intended to refresh or expire over time rather than function as permanent location history
- Share-link metadata: may remain for audit, security, or operational reasons even after a link is revoked or expires
- Security and server logs: may be retained for a limited period consistent with operational and legal needs
18. Security
Crew Sphere uses reasonable technical and organizational measures designed to protect personal information. Depending on the feature, these can include HTTPS or TLS transport security, authentication controls, server-side authorization, rate limiting, secure token generation, privacy filtering on shared views, restricted admin access, and revocable external links.
No system can guarantee complete security. External share links should be treated like private credentials, because anyone with an active link can access the information allowed by that link until it expires or is revoked.
Authorized personnel may access limited account or system information where reasonably necessary for support, security, abuse prevention, legal compliance, or platform administration.
19. Your Privacy Choices
You may have choices to:
- Edit your profile or remove a profile photo
- Change connection-by-connection sharing permissions
- Enable or disable Nearby
- Choose a manual city instead of using approximate device location
- Remove or block connections
- Revoke external share links
- Disable notifications through the app or device settings
- Delete roster entries
- Request account deletion
20. Your Data Protection Rights
Depending on where you live and applicable law, you may have rights to access your personal information, correct inaccurate data, request deletion, restrict processing, object to certain processing, withdraw consent where consent applies, request portability where applicable, and lodge a complaint with an appropriate regulator.
Crew Sphere may need to verify your identity before completing some privacy requests and will try not to request more information than is reasonably necessary for that verification.
21. Account Deletion
If your build of Crew Sphere provides an in-app deletion control, you can use that flow to request deletion. If your build does not yet expose a self-service deletion flow, you can request deletion using the privacy contact listed below.
Account deletion may include profile removal or anonymization, roster deletion, connection removal, Nearby disablement, share-link invalidation, external shared-page inaccessibility, and session revocation, subject to legitimate retention requirements.
Deleted information may remain temporarily in encrypted backups or security logs before those systems are automatically overwritten or cleaned up according to operational practice.
22. Data Export
Crew Sphere does not currently advertise a self-service in-app export tool in this build. Where applicable law gives you a right to request a copy of your information, you can make that request through the privacy contact listed in this policy.
23. Children
Crew Sphere is not intended for children under the minimum age applicable in the user's jurisdiction.
Crew Sphere is intended primarily for adult crew users and trusted adult family or friend connections. Crew Sphere does not knowingly seek to collect children's data without an appropriate legal basis where required.
24. Cookies and Web Technologies
The mobile app does not use browser cookies in the same way a website does, but Crew Sphere webpages may use essential session, security, CSRF, or technical storage mechanisms where needed for the page to function.
Private roster-share pages are intended to avoid nonessential tracking, and the public privacy-policy page is designed to work without nonessential analytics cookies.
26. Derived and Automated Information
Crew Sphere automatically derives statuses such as home, away, layover, available, unavailable, and likely overlap from roster inputs. These outputs are designed to help users organize and share schedule context.
Crew Sphere does not use this logic to make employment, credit, insurance, government-eligibility, or similarly high-impact decisions.
27. Business Transfers
If Crew Sphere is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, personal information may be transferred as part of that process, subject to applicable law and appropriate safeguards.
28. Legal Requests and Safety
Crew Sphere may disclose information where reasonably necessary to comply with law, respond to valid legal process, protect rights, investigate fraud or abuse, or protect users, Crew Sphere, or the public where legally permitted or required.
Crew Sphere does not assume every government request is automatically valid. Requests should be reviewed and handled according to applicable law.
29. Changes to This Privacy Policy
Crew Sphere may update this Privacy Policy as the service changes. For material changes, Crew Sphere may notify users through the app, by email, through a prominent notice, or by updating this page, depending on what is appropriate.
Where applicable law requires fresh consent for a materially different use of personal information, Crew Sphere should request that consent rather than relying only on a posted update.
30. Contact Us
Privacy questions or requests can be directed to:
31. Jurisdiction-Specific Rights
Additional rights and obligations may apply depending on where you live and where Crew Sphere is offered. This includes privacy principles around transparency, purpose limitation, data minimization, security, and access, correction, deletion, objection, restriction, portability, or complaint rights where the law provides them.
If Crew Sphere is offered in the UAE, European Economic Area, United Kingdom, California, or other regions with specific privacy laws, the legal basis, scope, and exercise of rights may vary. This Privacy Policy is intended to support those principles without claiming that every right applies identically in every jurisdiction.