Crewops — Privacy Policy
Last updated: 29 September 2026
Crewops is a personal planning tool for airline crew, published by Hawk & Mason Studios (“Hawk & Mason”, “we”, “us”). It has no account and no server of ours. Your roster, your logbook, your documents and everything you record about your own sleep and fatigue are stored on your device and are not sent to us.
Hawk & Mason Studios is a trading name of Hakan Aydın, an independent developer based in Türkiye. Contact: hello@hawkmason.com.
What stays on your device
Crewops works without an account. There is no sign-up, no password of ours, and no profile held anywhere but on your phone. The following is written to the app's private storage on your device and nowhere else:
- Your profile — the first name, crew code, home base and rule set you enter during setup.
- Your roster — duties, flights, report and release times, and the raw text of the roster the import was read from.
- Your logbook — the sectors you confirm, and the flight-and-duty record for cabin crew.
- Your documents — licence, medical, passport and visa records, their expiry dates, and any scan or photo you attach.
- What you record about yourself — sleep entries, fatigue self-ratings, IMSAFE answers and notes.
- The colleagues on your roster — when a roster PDF names the crew on each sector, those names are read and kept with the duty, together with anything you write about a colleague or an airport yourself. That is personal data about other people, held on your device only: it is never sent to us, never sent anywhere else, and it goes when you delete your data.
- Calculated results — duty limits, rest, the fatigue indicator, the estimated radiation dose and the coaching cards built from all of the above.
We cannot read any of it. It is not backed up to a server of ours, because there is no server of ours. If your phone is included in an Apple device backup, that backup belongs to Apple and to you.
One option changes where some of this sits, and only if you switch it on yourself: iCloud sync puts an encrypted copy of part of it in your own iCloud account so your second device can read it. It is off unless you turn it on, and your sleep entries, fatigue self-ratings and IMSAFE answers are never included.
Your calendar and notifications
Two optional conveniences use parts of your phone outside the app, and each asks for its own permission only when you switch it on:
- Calendar mirroring — writes your duties into a calendar you choose on the device, so they appear next to everything else in your Calendar app. It only ever writes the events it created and removes them when you switch it off. The calendar belongs to your device and to whichever account backs that calendar; nothing about it is sent to us.
- Report reminders and roster-change notices — scheduled on the device itself as local notifications. There is no push server: nothing about your roster leaves the phone to make a notification appear.
What leaves your device
Only these, and only for the purpose named:
- Weather — when you open a duty briefing, the app asks a public aviation weather service for the METAR and TAF of an airport. The request carries an airport code and nothing about you.
- Space weather — the app reads NOAA's public space-weather scales. The request carries nothing about you.
- Purchase state — if you subscribe, RevenueCat, Inc. processes your subscription status on our behalf so the app knows whether Crewops Pro is active and can restore it. RevenueCat receives an app-generated identifier and the purchase information the App Store returns. It does not receive your roster, your logbook, your documents or your health entries.
- Your airline's crew portal — only when you choose that import method. See the next section.
- A calendar link you paste — if your crew system publishes your roster as a calendar link and you paste it into the app, the app downloads the calendar from that address when you refresh. The request goes only to the address you gave and carries nothing else about you; the link stays on your device.
- Your own iCloud account — only if you switch iCloud sync on. See the section below for exactly what goes and what does not.
- Anything you export yourself — a CSV logbook or a JSON copy of your data goes wherever you send it, through your own share sheet.
- App updates — when it opens, the app asks updates.hawkmason.com, our own server, whether a newer version of its code is available. The request carries the app's runtime version and platform, nothing about you; updates are signed and the app refuses anything we did not sign.
- A roster file you choose to send us — when the app cannot read your airline's roster format yet, it offers to email the file to us. The email opens in your own mail app with the file attached — plus your portal's sign-in address if you choose to type it, never a password — and nothing is sent until you press Send. We use the file only to teach the app that format, keep it no longer than that takes, and then delete it; it may contain your name, crew code and colleagues' names, so remove anything you prefer not to share before sending.
There is no analytics SDK, no advertising, no tracking identifier and no crash reporter that sends us your data. We do not sell personal data and we have nothing to sell.
Your airline's crew portal
One of the ways to import a roster is to sign in to the crew portal your airline operates. If you use it, the username and password you enter are sent to your airline's own system so it can return your roster. They are never sent to us and we never see them.
If you leave the automatic refresh on, they are sent to that same portal again each time you open the app, at most once every six hours, so the app can notice a republished roster. Turning the refresh off in Me → Roster sync stops that, and manual import keeps working. Those credentials are stored in the iOS Keychain on your device, protected by your device passcode and marked so that they are not copied into device backups or to another phone. You can remove them at any time from Me → Roster sync (Turkish build: Ben → Roster senkronu).
Two things you should know before using it. First, many airline crew portals are reachable only over an unencrypted connection, because that is how the airline operates them; where that is the case, the connection between your phone and your employer's server is no more protected than opening the same portal in a browser. Second, what happens to your data inside your airline's system is governed by your airline's own policies and your employment relationship, not by this policy.
Health information
Sleep entries, fatigue self-ratings, IMSAFE answers and the estimated cosmic radiation dose are health-related information about you. They are created by you, stored only on your device, never transmitted to us, and never shared with your employer, your regulator or anyone else by this app.
Each health module is switched off until you turn it on, and each one states what it reads and what it keeps before you enable it. Turning a module off stops it being used; deleting your data removes it.
Crewops is not a medical device. Its fatigue indicator, sleep readings, circadian plan and dose estimate are planning aids, not diagnoses, and the app never states that anyone is fit or unfit to fly.
Purchases
Crewops Pro is an auto-renewable subscription sold through the App Store. Apple processes the payment; we never receive your payment card details. RevenueCat, Inc. processes the resulting subscription state on our behalf under its own privacy policy so that Pro can be restored on a device you sign into with the same Apple Account.
iCloud sync
Crewops can keep your devices in step through your own iCloud account. It is off when you install the app and stays off until you turn it on in Me → iCloud sync, where the app tells you what travels before you agree. You can turn it off again at any time, which also deletes that device's copy.
What is copied to your iCloud:
- Your roster — duties, flights, report and release times, and the crew named on each sector.
- Your logbook confirmations and the times you attested a duty as flown.
- Your document records — kind, title, number, issuer, issue and expiry dates, countries and notes.
- Your crew notes, airport notes and the notes you write on a duty.
- Your profile and display settings — name, crew code, home base, rule set, language, theme.
What is never copied, whatever your settings:
- Your sleep entries, fatigue self-ratings and IMSAFE answers. These are health data, and Apple does not permit personal health information to be stored in iCloud. They stay on the device that recorded them. If you want them on another phone, the JSON export is the way.
- Document scans and photographs. The record travels; the image does not.
- Your crew-portal password. It is held in your device Keychain, bound to that device, and you enter it once on the new phone.
- Per-device settings such as the portal address, the last sync time and cached weather.
How it is protected. Each device writes a single file into a private area of the app's iCloud container, and the file is encrypted by the app before it is written, with AES-256-GCM. The key is generated on your device and kept in your iCloud Keychain, which Apple encrypts end-to-end. We never hold the key and never hold the file. Apple stores the encrypted file but cannot read its contents.
How long it lasts, and how to remove it. The copy belongs to your iCloud account, not to the app, so deleting Crewops from your device does not delete it — that is what lets your data come back on a new phone. To remove it, either turn iCloud sync off in the app, which deletes that device's copy, or delete the app's iCloud data from Settings → your name → iCloud → Manage Account Storage. The copy counts against your iCloud storage. Deleting it removes it from every device signed into that account.
If iCloud Keychain is switched off on a device, that device cannot hold the key and Crewops will not start syncing there rather than write anything unencrypted. If you lose access to your iCloud Keychain, the encrypted copy cannot be decrypted by anyone, including us; your own JSON export is the safeguard against that.
Crewmates (formerly Crew Circle)
Crewmates lets you share your roster with colleagues you choose, and see the rosters they share with you. It is off until you tap Share my roster in Me → Crewmates. It uses Apple's iCloud sharing (CloudKit): your shared roster is stored in your own iCloud account and read through Apple by the people who join your circle. You send the invitation link yourself, through WhatsApp, Messages or any app you choose; anyone who opens that link in Crewops while signed in to iCloud can join, read-only, so send it only to people you trust. You see everyone who has joined and can remove anyone, and stopping sharing turns the link off. We run no server for this and cannot read it.
What the people you invite see: your first name as you entered it in the app, your role and home base, and your duties from 7 days ago to about 2 months ahead — the day, type, report and release times, stations, flight numbers and sector times. Your name as it appears on your Apple Account is shown to them by Apple as part of the invitation.
What is never shared: the names of the other crew on your duties, your fatigue, sleep and IMSAFE entries or any other health information, your notes, documents, logbook confirmations and tail numbers. The roster is written as one of CloudKit's encrypted fields.
Stopping. In Me → Crewmates → Manage people you can remove anyone, or stop sharing altogether, which removes their access. Pressing and holding a colleague's name removes their roster from your phone. Delete everything in Data & privacy also deletes your shared roster from iCloud and ends the sharing. What someone already saw on their screen is not recalled.
Legal basis and international transfers
Almost everything Crewops does with your data happens on your own device, under your control, and we are not a recipient of it. Where the GDPR and the KVKK ask us to name a basis, these are the ones that apply:
- Performance of our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) — processing your subscription state so Crewops Pro works and can be restored.
- Your consent (GDPR Art. 6(1)(a), and Art. 9(2)(a) for health data; KVKK Art. 6(2)) — each health module, and the crew-portal sign-in. Each is off until you switch it on, and you may withdraw at any time by switching it off or deleting your data. Withdrawing does not affect what was done before you withdrew.
- Our legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)) — the public weather and space-weather lookups, which carry an airport code and nothing about you.
Where the data goes. We are established in Türkiye, so if you are in the EU/EEA or the UK your subscription state reaches a country outside it. RevenueCat, Inc. is established in the United States. There is no European Commission adequacy decision for Türkiye, and the EU–US Data Privacy Framework covers only certified recipients, so these transfers rest on the Standard Contractual Clauses in our agreement with RevenueCat and on your explicit consent to use a paid subscription from a developer based in Türkiye, which you give by subscribing. The data transferred is an app-generated identifier and the purchase information the App Store returns — never your roster, your logbook, your documents or your health entries. If you are in Türkiye, the same transfer to the United States rests on your explicit consent under KVKK Art. 9.
We use one processor and no others: RevenueCat, Inc., for subscription state. Apple is an independent controller for the purchase itself.
How long data is kept, and how to delete it
Everything Crewops holds about you stays on your device, or with iCloud sync on in your own iCloud account, until you remove it. We keep nothing, so there is nothing for us to delete on our side.
- Delete everything in the app — Me → Data & privacy → Delete everything (Turkish build: Ben → Veri ve gizlilik → Her şeyi sil) wipes the roster, logbook, documents and attachments, health entries, saved portal credentials and scheduled reminders, and your roster shared through Crewmates, and returns the app to its first-launch state.
- Export first if you want a copy — the same screen writes a full JSON copy of your data, and the logbook exports as CSV.
- Delete the app — removing Crewops from your device deletes its storage with it. If you turned iCloud sync on, the encrypted copy in your iCloud account is not deleted with the app; remove it as described under iCloud sync.
- Subscription — deleting your data does not cancel a subscription. Cancel it in your Apple Account settings.
Your rights
Under the Turkish Personal Data Protection Law (KVKK) and the EU General Data Protection Regulation (GDPR), you have the right to access, correct, delete and port your personal data, to object to its processing, to ask us to restrict it, and to withdraw a consent you have given at any time. For Crewops those rights are exercised directly on your device: the data is in your hands, the export gives you a portable copy, and the delete function erases it. Where you believe we hold something about you — for example a support email you sent us — write to us and we will tell you what we have and delete it on request. You may also complain to your national data protection authority.
Crewops is a professional tool intended for adults working as airline crew. It is not directed at children and we do not knowingly process children's data.
Contact
Questions about this policy, or about what the app does with anything: hello@hawkmason.com.
If we change this policy we will update the date at the top of this page, and where the change is significant we will say so in the app.