This policy is written under Israeli law, and in particular the Protection of Privacy Law, 5741-1981 (including Amendment 13, in force since 14 August 2025) and the regulations made under it. It is the notice required by section 11 of that Law.
Aviators is a flight-training and flight-logging app for student pilots, private pilots and flight instructors in Israel. This policy tells you exactly what the app collects, why we collect each item, who else can see it, how long we keep it, and how you get it back or get rid of it.
If anything here is unclear, write to us before you sign up. Our address is at the end.
1. Who is responsible for your data
Operator (the "database owner" under the Law): Omer Weiner.
Address: Hatayasim 9, Ness Ziona 7406209, Israel.
Contact for anything in this policy:support@aviators.org.il.
Privacy contact: the same address. Write "Privacy" in the subject line and we will route it accordingly.
We have not appointed a privacy protection officer (ממונה על הגנת הפרטיות). If the app grows to the point where the Law requires one, we will appoint one and name them here.
2. The short version
We collect what an aviation logbook and a training-progress tracker need, and nothing else.
We run no analytics, no advertising, no crash-reporting and no tracking of any kind. There is no Google Analytics, no Firebase, no Meta SDK, no advertising identifier, and no profiling of you.
We never sell, rent or trade your data, and we never share it for anyone else's marketing.
Your position is used on your phone to draw the map. It leaves your phone only when you record a track and save it — a saved recording is your own flight track, kept in your account so you can open it on any device, and deleted with your account. If you share a recording with a share code, whoever you give the code to sees the track and can keep their own copy — see section 4.5. Simply looking at a map tells no server anything: the map data is built into the app.
Your instructor sees your training data only after both of you approve the link, and either of you can end it.
You can delete your account and everything in it from inside the app, at any time, without asking us.
3. The legal basis we rely on
Israeli law recognises two lawful bases for processing personal data: your informed consent, and a specific authorisation in law. There is no "legitimate interest" basis in Israel, and we do not claim one.
Everything described in this policy is done on the basis of your consent, given as section 8 describes. Where we are required by another law to keep or produce information — for example a lawful order of a competent authority or court — that law is the basis, and we say so where it applies.
Consent is not permanent and not unlimited. If we ever want to use your data for a purpose that is not listed in this policy, we will ask you again, before that use starts.
4. What we collect, why, and for how long
Every item below is listed with the purpose it is collected for. We do not use any of it for a purpose that is not written next to it.
4.1 Account and identity
Email address. To create your account, sign you in, verify that the address is yours, let you reset your password, and send you service messages about your own account. Required — without it there is no account.
Password. Stored only as a cryptographic hash by our authentication provider. We never see or store your actual password. Required, unless you sign in with Apple (below).
Apple account identifier, if you choose "Sign in with Apple". Apple gives us a permanent identifier for you and the email address you choose to share — either your real address or an Apple private relay address. We do not receive your Apple password, and we cannot see anything else in your Apple account. Required only if you use that sign-in method.
First name and surname. To identify you to yourself, to your instructor, and to students who search for an instructor. Required.
Phone number. So that we can reach you about your account, and so that we can contact you to verify an instructor application before enabling an instructor account. Required. It is stored in a separate, locked table: no other user of the app can see your phone number, including your own instructor. Each phone number may be registered to one account only.
Account type (student, private pilot, or instructor). Determines what the app shows you and what permissions you have. Required.
Pilot licence number, if you have one. To identify you as a licence holder to an instructor you have linked with, and for your own records. Optional — a student pilot who has not yet been issued a licence can open an account and use the app without it.
Instructor qualifications and instructional scopes, for instructor accounts. So students can see what you are qualified to teach, and so we can verify an instructor claim before enabling the account. Required for instructor accounts.
Profile photo, if you choose to add one. Shown to you and to other users in the in-app directory. Optional.
4.2 Your flying and training records
Flight logbook entries: date and times, departure and destination aerodromes, aircraft type and registration, flight type, flight hours by category, landings, the role you flew in, the instructor or co-pilot you flew with, and your own notes. This is the core of the service.
Instructor grading and signatures: per-skill scores, written feedback, and the record of a requested or given instructor signature.
Your own self-assessments of a flight.
Syllabus progress, ground briefings, and theory exam records — subject, status, score, date, and any certificate or payment document you attach.
Aircraft class records and checkouts you record for yourself.
Routes, markers and map layouts you draw and choose to save; flight tracks you record and choose to save (the sampled positions, the start and finish times and the distance); and any of these you choose to share with another user through a share code.
Pre-flight risk flags the app raises for a planned flight date, based on weather and NOTAM conditions for that date.
In-app messages between you and an instructor or student, and the status of link requests between you.
Purpose: to provide the service — keeping your records, showing your progress, and letting a linked instructor supervise your training. Nothing in this category is used for any other purpose.
4.3 Documents you upload
Files you add to your document folder — for example a medical certificate, a licence, a rating certificate, an examination certificate or a receipt — together with the name you give the document and its issue and expiry dates.
Purpose: to store them for you and to remind you before one expires, if you asked for that reminder.
A medical certificate is health information. Under Israeli law health information is "data of special sensitivity", and we treat this whole folder as such. These files are stored in a private area that is not publicly reachable; access happens only through short-lived links issued to your own signed-in session. Uploading documents is entirely optional — the app works without them.
4.4 Technical data
Session data needed to keep you signed in, held in your phone's encrypted storage (the iOS Keychain or the Android Keystore).
A record of the devices signed in to your account — a random device identifier, a device label, and the time it was last active. Purpose: to cap how many devices can use one account at once and to let you see where you are signed in. We do not use it to locate you.
IP address, for abuse control only. When you use an action that is rate-limited — for example checking whether a phone number is free during registration — your IP address is used to enforce a short cooldown. It is held for the length of that cooldown, in minutes, and then cleared. We do not build a record of your IP history, and we do not use IP addresses to locate or profile you.
Authentication logs kept by our authentication provider (sign-in times, IP address, device type), for security and fraud investigation.
4.5 Location and phone sensors
This is the section pilots ask about, so we will be blunt about it.
Live position, while you fly, stays on your device. It draws your position and heading on the map. It is not sent to our servers, it is not sent to anyone else, and it is held only in the memory of the running app.
A recording you start yourself is the exception, and you should read this bullet carefully. If you press Record on the map, the app samples your position while recording. When you save that recording, the track it produced — the list of positions, the start and finish times, and the distance — is stored in your account on our servers, so you can open it on any device. This is precise location data about you, and Israeli law treats it as data of special sensitivity. It is stored only when you choose to save it, only you can see it, you can delete any recording from the Maps screen at any time, and every recording is deleted with your account. Sharing is the exception to everything above. If you send someone a share code for a recording, that code hands them the complete flight track — the sampled positions, the start and finish times, the distance and any notes you wrote. They can view it and save their own copy into their account. A copy they have saved is their record, and it is not deleted when you delete your account — just as we cannot delete any other user's records. The code itself expires after 3 days, but a copy already saved remains. Only share with someone you trust.
The maps are offline. The map data is built into the app, so displaying a map does not tell any server where you are looking or where you are.
Motion and compass sensors are read on the device for heading and barometric altitude. That data is also never transmitted.
You can refuse the location permission and revoke it at any time in your phone's settings. The map still works; it simply will not show your own position.
What we do store is where you flew, not where you are. Your logbook records the departure and destination aerodrome, date and times of every flight, and any routes, markers and map layouts you choose to save are stored on our servers. Under Israeli law location information is data of special sensitivity, and we hold it to the same standard as your medical documents: per-row access control, no use for any purpose except showing you your own records and showing your training to the instructor you approved, no sale, no profiling, and deletion with your account.
4.6 If you write to us
If you email us we keep your message and the address you sent it from, in order to answer you. You do not need an account to write to us.
5. Is providing your data required, and what happens if you refuse
Israeli law requires us to tell you this plainly.
No law obliges you to give us any of this data. You give it voluntarily, under a contract with us, so that we can provide the service.
However:
Email, password (or Apple sign-in), first name, surname, phone number and account type are required to hold an account. If you do not provide them, we cannot open an account and you cannot use the app. Nothing else follows from that refusal: we do not contact you, and we keep no record of you. If you begin a registration and never confirm your email address, the part-made account is deleted automatically after 48 hours (section 9). Checking during registration whether a phone number is already in use briefly records the network address the check came from, for a few minutes, so that the check cannot be abused.
Instructor qualification details are required for an instructor account. Without them we cannot verify the claim, and the account stays a regular account.
Everything else is optional, including your licence number. Refusing a profile photo, a licence number, a document upload, location access, or notifications costs you only the specific feature involved. It never affects the rest of the app, and it never affects your training records.
If you later withdraw your consent, the only way to give effect to that is to close the account, and closing it destroys your logbook, gradings and documents irreversibly. Export first.
Refusing marketing messages costs you nothing at all. It is not a condition of using the app and never will be.
6. Who else can see your data
We disclose your data only to the recipients below, only for the purposes stated, and to no one else.
6.1 Other users of the app
An instructor you are linked with sees your profile — including your email address, licence number and flight hours — your complete flight logbook, including flights you did not fly with them, your gradings, your self-assessments, your syllabus progress and your messages with them. They need your whole logbook because your training stage is calculated from your total hours by type. They do not see your phone number, your uploaded documents or your theory exam records. The link requires both of you to approve it, neither side can create it alone, and either side can end it. When it ends, that access ends.
Any signed-in user browsing the in-app directory sees only your first name, surname, account type and profile photo. They cannot see your email address, your phone number, your licence number, your documents, your logbook or your grades.
A pilot you record as a co-pilot or trainee on a flight is shown that flight entry, because it is a shared flight.
A user you send a share code to can open the map layout, route or recorded flight track that code refers to, until the code expires. Nothing else in your account is reachable with a code.
Anyone, without an account, can find out from the registration screen whether a given email address or phone number already belongs to an Aviators account — that is how the form can tell you a number is taken before you submit it. It reveals nothing else: no name, no profile, no other field, and it is rate-limited.
6.2 Service providers who process data for us
These companies process data on our instructions and are contractually restricted to doing so. This is the complete list.
Supabase Inc. — our database, authentication and file storage provider. It holds effectively all of the data described in section 4, on infrastructure operated by Amazon Web Services.
Cloudflare, Inc. — serves our website, including this policy page and the account-deletion page. It sees the IP address of anyone who opens those pages. It does not process any account data.
Apple Inc. — only if you use "Sign in with Apple". Apple performs the sign-in and tells us the identifier and the email address you chose to share.
Google LLC and Apple Inc. as app stores — they distribute the app and know that you installed it. That relationship is between you and them, under their own privacy policies, not ours.
6.3 Aviation data sources
The Aviation Weather Center of the United States National Oceanic and Atmospheric Administration (aviationweather.gov) supplies METAR and TAF weather reports. When your device requests a report directly, that server receives the aerodrome code requested and your device's network address. Some requests go through our own server instead, which caches reports for every user; on that path the weather service sees our server's address, not yours. Either way it receives no account data, no name and no identifier of any kind from us.
6.4 Links out to other sites
The app contains links to the Civil Aviation Authority of Israel, the Israel Meteorological Service and other aviation sites. Opening one takes you out of the app and onto that site, under its own privacy policy. We do not pass anything to them.
6.5 Legal disclosure
We will disclose data where we are required to by a lawful order of a competent Israeli authority or court. Where we are permitted to tell you that this has happened, we will.
6.6 What we never do
We never sell, rent or trade your data.
We never pass it to advertisers, data brokers, insurers, employers or aviation authorities on our own initiative.
We never use your training records to make decisions about you other than showing them to you and to the instructor you approved.
7. Where your data is stored, and transfers outside Israel
Your data is stored outside Israel. We say so plainly because you are entitled to know before you sign up.
Our database, authentication and file storage run on Supabase, on Amazon Web Services infrastructure in the ap-northeast-1 (Tokyo, Japan) region. Our website is delivered by Cloudflare through servers in many countries, including inside Israel.
Transfers out of Israel are governed by the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001. We rely on two grounds:
Your consent to the transfer, which you give when you accept this policy knowing where the data goes; and
Contractual undertakings by each provider to protect the data to a standard no lower than Israeli law requires, in the data processing agreement we have signed with them.
Our providers' support staff may access systems from other countries in order to operate and maintain them. We treat that access as a transfer and it is covered by the same agreements.
8. Consent — what you agree to, separately
Israeli privacy guidance asks that agreement be given for each purpose separately rather than bundled into a single act. We are honest about where we currently stand against that standard.
Service terms and this policy — today you accept both together when you create an account, through the notice on the registration screen. Both documents are linked there and on the sign-in screen, are readable in full before you sign up, and are published on our website. The version in force is the one numbered at the top of this document. We are working towards a separate, recorded acceptance of each document, and we will update this section when it is in place.
Location access — asked for by your phone, the first time you open a map. Refusable, revocable, and it affects only the map.
Notifications — asked for separately by your phone. You can switch them off per document or entirely.
Marketing messages — we do not send any. If that ever changes, it will be a separate choice, off by default, never a condition of using the app, and we will ask before sending anything.
If we change what we do with your data in a way that goes beyond this policy, we will ask you again rather than rely on the consent you gave today.
You may withdraw a consent at any time. Withdrawing consent to the service means closing your account, because the service cannot run without the data it is built on. We may keep a minimum of information where another law requires it, or to defend a legal claim, and we will tell you if that applies.
9. How long we keep things
Your account and everything in it: for as long as your account exists.
A registration that is never confirmed: deleted automatically after 48 hours.
After you delete your account: your profile, logbook, grading, documents, messages, uploaded files, phone number and session records are deleted. Backups held by our hosting provider are overwritten on that provider's backup cycle, which does not exceed 30 days; after that cycle completes no copy of your data remains in them.
Rate-limiting records: minutes, then cleared.
Authentication logs held by our authentication provider: kept for that provider's standard security-log period. We do not use them for anything except investigating a security or fraud incident.
Map layouts and tracks published with a share code: deleted automatically 3 days after publication.
Device records: until you sign that device out, or until it is displaced by a newer device under the per-account device limit.
Emails you send us: up to 24 months after we have answered you, in case you come back to us about the same matter.
Anything we are required by law to keep: for the period that law requires, and no longer.
10. Your rights
Under the Protection of Privacy Law you have the following rights, and we will honour them.
The right to inspect your data (זכות עיון). Most of it you can see in the app at any time. For anything else, write to us and we will provide it within 30 days.
The right to correct data that is incorrect, incomplete or out of date (זכות תיקון). Your profile, phone number, licence number and your records are editable in the app. If something you cannot edit is wrong, tell us and we will fix it or tell you why we disagree — and if we refuse, you may apply to a court.
Deletion. The Law gives a right to have data erased in defined circumstances. Beyond that, we let you delete your whole account and everything in it yourself, at any time and for any reason — see section 11.
The right to withdraw consent, as described in section 8.
The right to complain to the Privacy Protection Authority (הרשות להגנת הפרטיות) at the Ministry of Justice, and the right to go to court. Nothing in this policy or in our Terms of Use limits that right in any way.
To use any of these, write to support@aviators.org.il. We may need to confirm that you are the account holder before we act, in order to protect you from someone else making the request.
11. Deleting your account
You do not need our permission and you do not need to ask.
In the app: Profile → Settings → Delete account. It removes your profile, logbook, grading, documents, messages, uploaded files, phone number and sign-in credentials. This is immediate and cannot be undone.
If you no longer have the app installed: the instructions are at https://links.aviators.org.il/delete-account. That route is a request by email from your registered address; we verify that it comes from you, complete the deletion within 7 days, and confirm by email.
Export anything you want to keep before you delete — the app can export your logbook.
One thing does not disappear, and you should know why: a flight you flew with another pilot or an instructor is part of their logbook too. Their copy of that flight entry stays in their records, as their own flight record. Grading written by an instructor stays in the instructor's record of the flights they graded.
12. Keeping your data safe
We apply the security measures required by the Protection of Privacy (Data Security) Regulations, 5777-2017, at the level appropriate to a database holding data of special sensitivity. In general terms:
All traffic between the app and our servers is encrypted in transit. The app also restricts which certificate authority it will accept for its own backend, on both Android and iOS, as a further defence against an intercepted connection. It is an extra layer, not a guarantee.
Access to your rows is enforced by the database itself, per row, per user, through row-level security — not by the app asking nicely. Every table holding user data has row-level security enabled, and rows you do not own are not returned to you.
Documents and profile photos are stored in private buckets and reachable only through short-lived links issued to your own session.
Sign-in tokens are held in the iOS Keychain or the Android Keystore.
Sensitive actions are rate-limited on the server.
Access to the production database is restricted to the people who operate the service, and we keep the internal security procedure the Regulations require.
No system is perfectly secure. If a security incident occurs that the Regulations require us to report, we will report it to the Privacy Protection Authority immediately on discovery, and where the Authority so directs or where we judge it right, we will tell you directly.
13. Notifications and marketing
Service messages — a document nearing expiry, a signature request, a link request, an account or security notice. These come with the service. Reminders can be switched off per document or altogether.
Marketing messages: we do not send them. We do not send advertising by email, SMS, WhatsApp or push notification, and we do not give your details to anyone who does. If we ever start, it will be governed by section 30A of the Communications (Telecommunications and Broadcasting) Law, 5742-1982: we will ask for your active agreement first, every message will be marked as an advertisement, identify us, and carry a one-tap way to stop — and if you ask us to stop, we stop immediately and permanently.
14. Children
Aviators is for people training for or holding a pilot licence and is not directed at children. You must be at least 16 to hold an account. We do not ask for your date of birth, so we cannot check this — it is a condition of using the app and we rely on you. If we learn that we hold data about someone younger, we will delete it. If you believe we do, write to us.
15. Automated decision-making
We do not make automated decisions about you that have a legal or similarly significant effect, and we do not profile you. The app performs calculations and raises pre-flight risk flags for information only — every one of those is advisory, a human always decides, and none of it is reported to anyone.
We do not use your data to train any artificial intelligence or machine learning model, and we do not give it to anyone else for that purpose.
16. Changes to this policy
If we change this policy we will update the version number and the date at the top. For a change that affects what we collect, why, or who receives it, we will tell you inside the app before the change takes effect, and where the law requires it we will ask for your consent again rather than assume it.
17. Governing law
This policy is governed by the law of the State of Israel.
This policy is published in Hebrew and in English. In the event of any inconsistency between them, the Hebrew version prevails.