Version 1.0 · Effective 21 July 2026
Companion to the Terms of Service, which incorporate this policy. Guiding rule throughout: this policy mirrors the product's transparency screen and consent architecture exactly — it promises nothing the product doesn't do, and does nothing the policy doesn't say.
Pilot Exponent is a private reflection tool. Your observations are yours. We don't sell your data, we don't run advertising or third-party analytics, and no employer or organisation can see anything about you unless you personally, explicitly consent to contribute anonymous counts to an aggregate fleet report — and even then, never your entries, notes, dates, or identity. You can delete any observation, or your whole account and all its data, at any time, in the app. If any of this ever changes, this policy and the in-app "What your airline sees" page change first — and the change will be to your benefit or it won't happen.
Pilot Exponent (the "operator", "we") is the data controller for personal information processed through the Pilot Exponent service at www.pilotexponent.com (the "Service"). Contact: contact@pilotexponent.com.
Everything below is either provided by you or generated to run the Service. We collect nothing else — in particular, no GPS or flight-track data, no rostering or duty records, no airline operational data, no biometrics, and no third-party advertising or analytics identifiers.
Account information. Email address and a password (stored only as a bcrypt hash — we cannot read it).
Profile information (optional except where marked in-app). Name, year you started flying, total-hours band, flying frequency, operation type(s), aircraft category(ies), display preferences, and whether email nudges are enabled.
Your Content. The observations you write: title, date, phase of flight, event type, operational demands, environmental conditions, interventions, your risk assessment, and free-text notes; plus your Toolkit items (defences/techniques and their history) and in-app notifications derived from your own entries.
Waitlist information. If you join the waitlist: your email address, used to send your invitation and then handled under this policy.
Technical information. A session cookie (essential, first-party, used to keep you signed in) and a CSRF token (security). Standard server logs (IP address, request time, user agent) retained briefly for security and operations. We run no third-party analytics or tracking on the authenticated application — measurement is first-party only, as standing product policy.
Error reports. If the application errors, technical details of the
error are sent to our error-monitoring processor (Sentry) so we can fix
it. This integration is configured not to send personal data
(send_default_pii is off); error events carry technical context, not
your content.
| Purpose | What's used | Legal basis (GDPR terms) |
|---|---|---|
| Providing the Service — your journal, analytics, Toolkit | Account, profile, Your Content | Performance of a contract |
| Sign-in, security, abuse prevention | Account, technical info, logs | Contract; legitimate interests (security) |
| Transactional email — password resets, waitlist invitations | Email address | Contract; legitimate interests |
| Optional reflection nudge emails | Email address, minimal activity signal (e.g. time since last entry) | Consent — the in-app "email nudges" setting; off means off, and there's a cooldown even when on |
| Fixing defects | Error reports (no personal content) | Legitimate interests |
| Aggregate organisational reporting | Counts derived from Your Content — only ever with your consent | Explicit consent (see §5) — individual, informed, specific, revocable |
We do not use Your Content for advertising, for profiling unrelated to the Service's own displayed features, or to train third-party AI models. We do not make automated decisions about you that have legal or similarly significant effects.
This is the policy's core, and it restates the in-app "What your airline sees" page exactly:
| Who | Sees |
|---|---|
| You | Everything of yours — every observation, your risk profile, your Toolkit. |
| Any organisation (employer, sponsor) | By default: nothing. With your explicit consent: one aggregate fleet report — counts of pilots only, protected by anonymity floors (no figure below 5 contributing pilots; no report below 15 participants). Never your entries, notes, dates, identity, or whether you personally participate. |
| Us (the operator) | Operational access limited to running, securing, and supporting the Service. We do not browse Your Content; access is limited to what operating the Service requires. |
We do not sell personal information, and we do not share it for cross-context behavioural advertising (in CCPA/CPRA terms: no "sale" and no "sharing").
If your organisation runs Pilot Exponent, contributing to its aggregate report is governed by four properties, enforced in the product:
Free-text notes, dates, and individual observations are never transmitted to any organisation in any form — not de-identified, not aggregated, not at all.
We use a small number of service providers, bound by their own data processing terms, strictly to run the Service:
| Processor | Role | What reaches them |
|---|---|---|
| Render | Application hosting and database | The Service's data, encrypted in transit (TLS); storage in Singapore |
| Resend | Transactional email delivery | Recipient email address and message content for the specific email being sent |
| Sentry | Error monitoring | Technical error details; configured not to send personal data |
| GitHub | Encrypted-transport backup storage (private repository) | Daily database backup copies, retained 7 days then deleted |
No other third party receives personal information in the ordinary course. We will keep this list current — if it changes, this policy changes.
International transfers. The Service is operated from Australia, and your information is stored and processed in Singapore by our hosting provider (see the table above), and in the regions of the other processors listed. This means your information is processed outside Australia and outside your own country if you are elsewhere. Before disclosing personal information overseas we take steps intended to ensure it is handled consistently with this policy and applicable law, including through our contractual arrangements with those providers. If our hosting region changes, this policy changes with it.
We protect your information, but we cannot promise it is beyond legal process. If we receive a demand for user data (subpoena, court order, or similar), we will — unless legally prohibited — notify you before complying and challenge demands that are overbroad or improper where reasonably possible. We do not volunteer user data to authorities or employers.
Two further things, stated plainly: your entries are your own records, and like any personal document they could be sought from you in legal proceedings — no app can change that, and unlike formal reporting channels (ASAP/ASRS), a private reflective tool carries no statutory protection. And because the Service is server-side, your observations do not reside on your device: a lost, seized, or employer-managed tablet holds a signed-in session at most, not your journal — sign out on shared or company hardware, and prefer a personal device for the Service.
In the app, today, no request needed: view everything you've entered; edit or delete individual observations; change your email; enable/disable nudge emails; give or withdraw organisational consent (when applicable); delete your entire account and its data.
By request to contact@pilotexponent.com: a copy of your data in a portable format (self-serve export is on the product roadmap; until then we fulfil export requests manually); correction of account details you cannot edit yourself; and any right available to you under applicable law — including, depending on your jurisdiction: access, rectification, erasure, restriction, portability, objection (GDPR/UK GDPR); the rights in the Australian Privacy Principles; or CCPA/CPRA rights to know, delete, correct, and non-discrimination. We respond within the timeframe the applicable law sets.
You may also complain to your data-protection authority (e.g. the OAIC in Australia, the ICO in the UK, or your EU supervisory authority). We'd appreciate the chance to resolve it first.
Passwords are stored as bcrypt hashes; traffic is encrypted in transit (TLS); access to production systems is restricted; error monitoring is configured to exclude personal data; the authenticated application carries no third-party trackers. No internet service can promise perfect security — if a breach materially affects your personal information, we will notify you and any authority we are legally required to notify, promptly and plainly.
The Service is for adults (18+ under the Terms). We do not knowingly collect information from children; if we learn we have, we will delete it.
If we change this policy materially, we will give notice in the Service or by email before the change takes effect, and update the in-app transparency page in the same release. Changes are never retroactive, and we hold to the standing commitment: a change will be to your benefit or it won't happen.
Pilot Exponent · contact@pilotexponent.com
Pilot Exponent · Privacy Policy · Version 1.0 · Effective 21 July 2026.