Pilot Exponent ← Back

Privacy Policy

Pilot Exponent — how your information is handled

Version 1.6 · Effective 15 August 2026


The plain-language summary

Pilot Exponent is a private reflection tool. Your observations are yours. We don't sell your data, we don't run advertising or third-party analytics, and no employer or organisation can see anything about you unless you personally, explicitly consent to contribute anonymous counts to an aggregate fleet report — and even then, never your entries, notes, dates, or identity. You can delete any observation or your whole account in the app. Account deletion is subject only to the limited backup and transaction record retention described in §8.


1. Who is responsible for your information

Scott Nyholm trading as Pilot Exponent — a sole trader registered in Australia — is the "operator" ("we") and the data controller for personal information processed through the Pilot Exponent service at www.pilotexponent.com (the "Service"). Contact: contact@pilotexponent.com.

2. What we collect

We collect the categories below where you provide them or where they are needed to operate, secure, and bill for the Service. In particular, we collect no GPS or flight-track data, no rostering or duty records, no airline operational data, no biometrics, and no third-party advertising or analytics identifiers.

Account information. Email address and a password (stored only as a bcrypt hash — we cannot read it).

Agreement information. The version of the Terms and Privacy Policy you accepted and the date and time of acceptance.

Profile information (optional except where marked in-app). Name, year you started flying, total-hours band, flying frequency, operation type(s), aircraft category(ies), display preferences, and whether email nudges are enabled.

Your Content. The observations you write: title, date, phase of flight, event type, operational demands, environmental conditions, interventions, your risk assessment, and free-text notes; plus your Toolkit items (defences/techniques and their history) and in-app notifications derived from your own entries. Any factors or reflections you record are voluntary and intended solely to support your own self-awareness.

Billing information. When you start a subscription, Stripe processes your payment method, billing address, and transaction. We receive and store limited identifiers and subscription information, including your Stripe customer ID, subscription status, trial end, and billing-period dates. We do not receive or store your complete card number or card security code.

Technical information. A session cookie (essential, first-party, used to keep you signed in) and a CSRF token (security). Standard server logs (IP address, request time, user agent) retained briefly for security and operations. We run no third-party analytics or tracking on the authenticated application — measurement is first-party only, as standing product policy.

Error reports. If the application errors, technical details are sent to Sentry so we can diagnose the problem. Sentry is configured to minimise personal information and not intentionally send observation content, but an error report may include technical identifiers or context associated with the request that failed.

3. What we use it for, and on what basis

Purpose What's used Legal basis (GDPR terms)
Providing the Service — your journal, analytics, Toolkit Account, profile, Your Content Performance of a contract
Sign-in, security, abuse prevention Account, technical info, logs Contract; legitimate interests (security)
Transactional email — password resets and service notices Email address Contract; legitimate interests
Optional reflection nudge emails Email address, minimal activity signal (e.g. time since last entry) Consent — the in-app "email nudges" setting; off means off, and there's a cooldown even when on
Starting and managing subscriptions, payments, cancellations, and refunds Account and billing information Performance of a contract; compliance with legal obligations
Determining and administering applicable taxes Billing address, transaction, and tax information Legal obligations; legitimate interests in administering sales
Fixing defects Technical error reports configured to minimise personal information Legitimate interests
Aggregate organisational reporting Counts derived from Your Content — only ever with your consent Explicit consent (see §5) — individual, informed, specific, revocable
Understanding whether the Service works — how many pilots are active, how records develop, which features are used Counts across accounts, computed in our own systems; never identifying an individual, never sold, never shared Legitimate interests (see §5)

We do not use Your Content for advertising, for profiling unrelated to the Service's own displayed features, or to train third-party AI models. We do not make automated decisions about you that have legal or similarly significant effects.

4. Who can see what — the three tiers

This is the policy's core, and it restates the in-app "What your airline sees" page exactly:

Who Sees
You Everything of yours — every observation, your risk profile, your Toolkit.
Any organisation (employer, sponsor) By default: nothing. With your explicit consent: one aggregate fleet report — counts of pilots only, protected by anonymity floors (no figure below 5 contributing pilots; no report below 15 participants). Never your entries, notes, dates, identity, or whether you personally participate.
Us (the operator) Aggregate counts across accounts, which is how we tell whether the Service is working, and the access that running, securing and supporting it involves. Not your entries: there is no administrative view of another pilot's observations, profile or Toolkit (§5).

We do not sell personal information, and we do not share it for cross-context behavioural advertising (in CCPA/CPRA terms: no "sale" and no "sharing").

When you send us something to get help

If you contact support and choose to include a screenshot, a copied passage, an observation, or a description of what you were doing, you are handing us that material so we can answer you. Sending it is your decision, and our using it to resolve your request is not a disclosure of your data to anyone.

The boundaries on it are the same as everywhere else in this policy:

If you would rather not send a screenshot of your own entries, say so — we will work from your description instead. Answering may be slower, and that is a fair trade for you to make.

5. Aggregation

Aggregate means counts across pilots. It never means your entries, and never anything that identifies you.

We may, with your consent and agreement, contribute information derived from your records to an aggregate comparison — whether an organisation-level report or a comparison with other pilots. That consent is explicit, specific and revocable; the form is counts only, subject to the anonymity floors below; and it never includes your entries, notes or dates, never identifies you, and never identifies another pilot to you. Absent that consent nothing is contributed to anyone, and you form no part of any comparison.

Separately, we count across accounts to run the Service — active pilots, how records develop, which features are used — computed in our own systems with no third-party analytics involved, never sold, never shared, never identifying an individual. Developing, maintaining and monitoring the Service involves, or may involve, access to the systems those records are held on; it does not extend to viewing your entries or your personal fields, and the Service provides no administrative view of them.

Organisational aggregation — the consent model

If your organisation runs Pilot Exponent, contributing to its aggregate report is governed by four properties, enforced in the product:

Free-text notes, dates, and individual observations are never transmitted to any organisation in any form — not de-identified, not aggregated, not at all.

6. Processors — who touches the data on our behalf

We use a small number of service providers, bound by their own data processing terms, strictly to run the Service:

Processor Role What reaches them
Render Application hosting and database The Service's data, encrypted in transit (TLS); storage in Singapore
Resend Transactional email delivery Recipient email address and message content for the specific email being sent
Stripe Checkout, subscription billing, payment processing, billing-address and tax administration Email address, billing address, payment method and transaction details, and subscription information
Sentry Error monitoring Technical error and request context, configured to minimise personal information and not intentionally send observation content
GitHub Encrypted backup storage (private repository) Encrypted daily database backup copies, retained 7 days then deleted

Apart from these providers, we disclose personal information only when you direct us to, when required by law, or when reasonably necessary to protect the Service, its users, or another person. We do not sell personal information. We will keep this list current — if it changes, this policy changes.

International transfers. The Service is operated from Australia, and your information is stored and processed in Singapore by our hosting provider (see the table above), and in the regions of the other processors listed. This means your information is processed outside Australia and outside your own country if you are elsewhere. Before disclosing personal information overseas we take steps intended to ensure it is handled consistently with this policy and applicable law, including through our contractual arrangements with those providers. If our hosting region changes, this policy changes with it.

7. Legal process — stated honestly

We protect your information, but we cannot promise it is beyond legal process. If we receive a demand for user data (subpoena, court order, or similar), we will — unless legally prohibited — notify you before complying and challenge demands that are overbroad or improper where reasonably possible. We do not volunteer user data to authorities or employers.

Two further things, stated plainly: your entries are your own records, and like any personal document they could be sought from you in legal proceedings — no app can change that, and unlike formal reporting channels (ASAP/ASRS), a private reflective tool carries no statutory protection. And the Service is server-side, so your journal lives on our servers rather than on your tablet — with one exception you should know about. When you log with no usable connection, or begin an entry and are interrupted before saving it, that single draft is held on your own device (in the browser's local database) so it is not lost. It is removed from the device as soon as it reaches our servers, and it is the only observation content ever stored there.

That is a deliberate trade: without it, an entry made in an aircraft with no signal, or interrupted halfway, would simply disappear. It does mean a lost, seized or employer-managed device may hold an unsent draft as well as a signed-in session. Sign out on shared or company hardware, prefer a personal device for the Service, and sync when you can.

8. Retention

9. Your rights and controls

In the app, today, no request needed: view everything you've entered; edit or delete individual observations; change your email; enable/disable nudge emails; give or withdraw organisational consent (when applicable); delete your entire account and its operational data, subject to §8.

From your Operational Profile: a self-serve PDF of the profile currently shown, with your name included by default and a choice to leave it out. The PDF does not include observation titles, notes or observation cards.

By request to contact@pilotexponent.com: a copy of your underlying data in a portable format (self-serve raw-data export is on the product roadmap; until then we fulfil export requests manually); correction of account details you cannot edit yourself; and any right available to you under applicable law — including, depending on your jurisdiction: access, rectification, erasure, restriction, portability, objection (GDPR/UK GDPR); the rights in the Australian Privacy Principles; or CCPA/CPRA rights to know, delete, correct, and non-discrimination. We respond within the timeframe the applicable law sets.

If you are unhappy with how we have handled your information

There is a stated process, and it does not require a lawyer.

  1. Tell us. Write to contact@pilotexponent.com with what happened and what you would like done. Put "Privacy" in the subject so it is not read as an ordinary support request.
  2. We acknowledge within 5 business days and give you a substantive response within 30 days. If a complaint will take longer than that, we tell you why and when to expect an answer, rather than letting it run.
  3. If our answer does not resolve it, we will say so plainly and, where a good-faith discussion might still settle it, offer 30 days of that — the same step the Terms of Service set out for other disputes.
  4. You can escalate at any point, including immediately. Nothing here is a precondition, a waiver, or a substitute for your statutory rights.

Your regulator is the OAIC in Australia, the ICO in the United Kingdom, your supervisory authority in the EU, or your state Attorney-General in the United States. You may go to them without coming to us first, and using this process does not extend or shorten any deadline the law gives you.

10. Security

Passwords are stored as bcrypt hashes; traffic is encrypted in transit (TLS); access to production systems is restricted; error monitoring is configured to minimise personal information; the authenticated application carries no third-party trackers. No internet service can promise perfect security. If a personal-information breach occurs, we will investigate it and notify affected people and relevant authorities where required by applicable law.

11. Children

The Service is for adults (18+ under the Terms). We do not knowingly collect information from children; if we learn we have, we will delete it.

12. Changes to this policy

If we materially change this policy, we will update its version and effective date and give reasonable advance notice in the Service or by email where appropriate. We will seek consent where required by law. Changes do not apply retroactively.

13. Contact

Scott Nyholm trading as Pilot Exponent · ABN 45 616 594 351 · contact@pilotexponent.com


Pilot Exponent · Privacy Policy · Version 1.6 · Effective 15 August 2026.