Crewops — Privacy Policy

What stays on your device

Crewops works without an account. There is no sign-up, no password of ours, and no profile held anywhere but on your phone. The following is written to the app's private storage on your device and nowhere else:

We cannot read any of it. It is not backed up to a server of ours, because there is no server of ours. If your phone is included in an Apple device backup, that backup belongs to Apple and to you.

One option changes where some of this sits, and only if you switch it on yourself: iCloud sync puts an encrypted copy of part of it in your own iCloud account so your second device can read it. It is off unless you turn it on, and your sleep entries, fatigue self-ratings and IMSAFE answers are never included.

Your calendar and notifications

Two optional conveniences use parts of your phone outside the app, and each asks for its own permission only when you switch it on:

What leaves your device

Only these, and only for the purpose named:

There is no analytics SDK, no advertising, no tracking identifier and no crash reporter that sends us your data. We do not sell personal data and we have nothing to sell.

Your airline's crew portal

One of the ways to import a roster is to sign in to the crew portal your airline operates. If you use it, the username and password you enter are sent to your airline's own system so it can return your roster. They are never sent to us and we never see them.

If you leave the automatic refresh on, they are sent to that same portal again each time you open the app, at most once every six hours, so the app can notice a republished roster. Turning the refresh off in Me → Roster sync stops that, and manual import keeps working. Those credentials are stored in the iOS Keychain on your device, protected by your device passcode and marked so that they are not copied into device backups or to another phone. You can remove them at any time from Me → Roster sync (Turkish build: Ben → Roster senkronu).

Two things you should know before using it. First, many airline crew portals are reachable only over an unencrypted connection, because that is how the airline operates them; where that is the case, the connection between your phone and your employer's server is no more protected than opening the same portal in a browser. Second, what happens to your data inside your airline's system is governed by your airline's own policies and your employment relationship, not by this policy.

Health information

Sleep entries, fatigue self-ratings, IMSAFE answers and the estimated cosmic radiation dose are health-related information about you. They are created by you, stored only on your device, never transmitted to us, and never shared with your employer, your regulator or anyone else by this app.

Each health module is switched off until you turn it on, and each one states what it reads and what it keeps before you enable it. Turning a module off stops it being used; deleting your data removes it.

Crewops is not a medical device. Its fatigue indicator, sleep readings, circadian plan and dose estimate are planning aids, not diagnoses, and the app never states that anyone is fit or unfit to fly.

Purchases

Crewops Pro is an auto-renewable subscription sold through the App Store. Apple processes the payment; we never receive your payment card details. RevenueCat, Inc. processes the resulting subscription state on our behalf under its own privacy policy so that Pro can be restored on a device you sign into with the same Apple Account.

iCloud sync

Crewops can keep your devices in step through your own iCloud account. It is off when you install the app and stays off until you turn it on in Me → iCloud sync, where the app tells you what travels before you agree. You can turn it off again at any time, which also deletes that device's copy.

What is copied to your iCloud:

What is never copied, whatever your settings:

How it is protected. Each device writes a single file into a private area of the app's iCloud container, and the file is encrypted by the app before it is written, with AES-256-GCM. The key is generated on your device and kept in your iCloud Keychain, which Apple encrypts end-to-end. We never hold the key and never hold the file. Apple stores the encrypted file but cannot read its contents.

How long it lasts, and how to remove it. The copy belongs to your iCloud account, not to the app, so deleting Crewops from your device does not delete it — that is what lets your data come back on a new phone. To remove it, either turn iCloud sync off in the app, which deletes that device's copy, or delete the app's iCloud data from Settings → your name → iCloud → Manage Account Storage. The copy counts against your iCloud storage. Deleting it removes it from every device signed into that account.

If iCloud Keychain is switched off on a device, that device cannot hold the key and Crewops will not start syncing there rather than write anything unencrypted. If you lose access to your iCloud Keychain, the encrypted copy cannot be decrypted by anyone, including us; your own JSON export is the safeguard against that.

Crewmates (formerly Crew Circle)

Crewmates lets you share your roster with colleagues you choose, and see the rosters they share with you. It is off until you tap Share my roster in Me → Crewmates. It uses Apple's iCloud sharing (CloudKit): your shared roster is stored in your own iCloud account and read through Apple by the people who join your circle. You send the invitation link yourself, through WhatsApp, Messages or any app you choose; anyone who opens that link in Crewops while signed in to iCloud can join, read-only, so send it only to people you trust. You see everyone who has joined and can remove anyone, and stopping sharing turns the link off. We run no server for this and cannot read it.

What the people you invite see: your first name as you entered it in the app, your role and home base, and your duties from 7 days ago to about 2 months ahead — the day, type, report and release times, stations, flight numbers and sector times. Your name as it appears on your Apple Account is shown to them by Apple as part of the invitation.

What is never shared: the names of the other crew on your duties, your fatigue, sleep and IMSAFE entries or any other health information, your notes, documents, logbook confirmations and tail numbers. The roster is written as one of CloudKit's encrypted fields.

Stopping. In Me → Crewmates → Manage people you can remove anyone, or stop sharing altogether, which removes their access. Pressing and holding a colleague's name removes their roster from your phone. Delete everything in Data & privacy also deletes your shared roster from iCloud and ends the sharing. What someone already saw on their screen is not recalled.

Legal basis and international transfers

Almost everything Crewops does with your data happens on your own device, under your control, and we are not a recipient of it. Where the GDPR and the KVKK ask us to name a basis, these are the ones that apply:

Where the data goes. We are established in Türkiye, so if you are in the EU/EEA or the UK your subscription state reaches a country outside it. RevenueCat, Inc. is established in the United States. There is no European Commission adequacy decision for Türkiye, and the EU–US Data Privacy Framework covers only certified recipients, so these transfers rest on the Standard Contractual Clauses in our agreement with RevenueCat and on your explicit consent to use a paid subscription from a developer based in Türkiye, which you give by subscribing. The data transferred is an app-generated identifier and the purchase information the App Store returns — never your roster, your logbook, your documents or your health entries. If you are in Türkiye, the same transfer to the United States rests on your explicit consent under KVKK Art. 9.

We use one processor and no others: RevenueCat, Inc., for subscription state. Apple is an independent controller for the purchase itself.

How long data is kept, and how to delete it

Everything Crewops holds about you stays on your device, or with iCloud sync on in your own iCloud account, until you remove it. We keep nothing, so there is nothing for us to delete on our side.

Your rights

Under the Turkish Personal Data Protection Law (KVKK) and the EU General Data Protection Regulation (GDPR), you have the right to access, correct, delete and port your personal data, to object to its processing, to ask us to restrict it, and to withdraw a consent you have given at any time. For Crewops those rights are exercised directly on your device: the data is in your hands, the export gives you a portable copy, and the delete function erases it. Where you believe we hold something about you — for example a support email you sent us — write to us and we will tell you what we have and delete it on request. You may also complain to your national data protection authority.

Crewops is a professional tool intended for adults working as airline crew. It is not directed at children and we do not knowingly process children's data.

Contact

Questions about this policy, or about what the app does with anything: hello@hawkmason.com.

If we change this policy we will update the date at the top of this page, and where the change is significant we will say so in the app.