CatchFlights

Privacy Policy

Effective September 8, 2026

CatchFlights ("CatchFlights", "we", "us") is a plane-spotting app that turns real aircraft flying near you into a personal collection, logbook, and progression journey. This policy explains what information the app and its backend process, why, and what choices you have. It covers the CatchFlights iOS and Android apps and the backend services they talk to.

Data controller

Max Nowack
Schillerstr. 1
37120 Bovenden
Germany
Email: [email protected]

No account unless you ask for one

CatchFlights creates no account and requires no sign-up. Out of the box, the radar, catching aircraft, your collection, logbook, XP, levels, and achievements all work without any account, and everything you catch stays on your device.

Joining the Community is a deliberate, separate choice you make on the Community screen. Only then do we create an account for you, and even then it never involves an email address, phone number, name, or password: it is identified by a randomly generated key stored on your device plus a generated display name such as "SwiftAlbatross4821". Joining also puts you on the global leaderboard, which is what the confirmation dialog tells you before you agree. You can leave again at any time, which deletes the account and everything stored with it.

Information we process

Location

While the app is open, it uses your device's foreground location to find airborne aircraft near you, calculate their distance and catch eligibility, and save where a catch happened in your logbook. Your coordinates are sent to the CatchFlights backend for as long as the radar is connected, so it can stream nearby aircraft back to you. CatchFlights never requests background location access.

Your exact coordinates are held in memory only for the duration of that connection and are never written to our database. To query our upstream aircraft data source, the backend first snaps your position onto a shared grid cell of roughly one kilometre and queries using that cell's centre — so the upstream provider receives a coarsened area, never your precise position.

The catch coordinates saved in your logbook stay on your device (and, on iOS with iCloud sync enabled, in your own private iCloud database). They are never sent to the CatchFlights backend.

Compass and motion

If you enable compass-rotated radar, the app reads your device's heading and motion sensors to rotate the radar display. This is processed on your device only and never transmitted. You can switch it off and keep a fixed, north-up radar.

Community account and mirrored progress (only if you join)

If, and only if, you join the Community, we process: the account key (we store only an irreversible hash of it, never the key itself); the generated username; an identifier for your app database; and timestamps such as when the account was created and last seen.

From that point on, the app mirrors your progress to that account so XP and levels can be computed and verified server-side, and so your collection survives a reinstall. This covers your catches (aircraft identifier, registration, type, callsign, departure and arrival airport, the time of the catch, and your device's UTC offset), together with derived facts such as discoveries, achievements, completed sets, and perk activity. Progress you made before joining is included, so your existing collection carries over. Catch coordinates are never included. If you never join, none of this leaves your device.

Global leaderboard

Joining the Community puts your username, level, total XP, and catch count on the global leaderboard, where they are visible to other players. This is stated in the dialog you confirm when joining. You can switch the leaderboard off again at any time in the app while keeping your account.

Friends (off by default)

Friends require a Community account and are added only through an invite link you choose to create and share. We process the invite code, who created it, and the resulting friend relationships. Opening a shared invite link on the web also briefly shows the inviter's username and level so messaging apps can display a preview.

Once a friend request has been confirmed by both sides, friends can open each other's logbook: the registration, aircraft type, and time of each catch, plus the rarity the app derives from them. Nothing else about a catch is shared — in particular no catch locations, no aircraft identifier, no callsign, and no flight route. Only confirmed friends can see this; it is never public and never part of the global leaderboard. Ending a friendship ends that access immediately for both sides.

Push notifications (off by default)

Daily streak reminders are scheduled entirely on your device and transmit nothing. Separately, if you have a Community account and enable friend-request alerts, the app registers a push token for your device with us and with Expo's push notification service, so we can notify you when someone sends or accepts a friend request. Notifications are never used for advertising.

Aircraft photos

When an aircraft screen shows a photo, your device requests it directly from Planespotters.net or Wikimedia Commons using an aircraft identifier or aircraft type name. These requests contain no location and nothing that identifies you, but as with any web request, those services can see your IP address.

Reporting incorrect data

If you report that a catch's aircraft, route, or airline data looks wrong, the app sends a generated device identifier, the aircraft's identifier and flight details, the category of the issue, and any comment you write, so we can correct our catalog.

Cloud sync (iOS)

On iOS, CatchFlights can sync your catch log — including catch coordinates, aircraft data, and a generated device identifier — through Apple's CloudKit, into the private iCloud database belonging to your own Apple ID. We have no access to that private database; it is governed by Apple's own privacy practices and your iCloud settings.

Technical data

Like any internet service, our backend processes the IP address of incoming requests. We use it only transiently for rate limiting and abuse prevention; we do not build profiles from it or store it alongside your account data.

Data stored only on your device

Your full catch log — including catch coordinates — plus your collection, logbook, and settings are stored locally on your device. Apart from the specific items listed above, this data is not transmitted to us.

Legal bases for processing (GDPR)

If you are in the European Economic Area or the UK, we rely on the following legal bases under Article 6(1) GDPR:

Providing location access is not a legal obligation, but the radar cannot work without it. You are free to decline it; the rest of the app remains usable.

What we don't do

Recipients and third-party services

The app and backend rely on the following external services:

We do not otherwise disclose your data, except where we are legally required to do so.

International transfers

The CatchFlights backend and its database are hosted in the European Union. Some of the services above are operated outside the European Economic Area, in particular Apple (CloudKit) and Expo (push notifications) in the United States. Where data is transferred outside the EEA, that transfer is based on the European Commission's Standard Contractual Clauses, an adequacy decision, or another mechanism permitted under Chapter V GDPR. For the aircraft data and photo services, only the technical, non-identifying lookups described above are involved.

Data retention

Data stored only on your device remains there until you delete the app or clear its data. If you joined the Community, account data and mirrored progress are retained for as long as the account exists, so your collection and level survive reinstalling the app; leaving the Community deletes them immediately, and we also delete them on request (see "Your rights"). Exact radar coordinates are never stored at all. IP addresses are processed only transiently for rate limiting and are not retained in a form linked to your account. Catalog correction reports are kept as long as needed to fix the underlying data.

Data security

We use appropriate technical and organizational measures to protect the data we process, including encrypted transport (HTTPS/WSS) to our backend and storing your account key only as an irreversible hash. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children's privacy

CatchFlights is not directed at children, and we do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact us so we can delete it.

Your rights

If you are in the European Economic Area or the UK, you have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw that consent at any time.

Most of these you can exercise directly in the app, without contacting us: Profile → Community → Leave Community deletes your account and everything mirrored with it, permanently and immediately. You can also turn the global leaderboard off, remove friends, disable notifications, change your username, and revoke location access in your device settings. For access to or a copy of your data, or anything else you cannot do in the app, email us at [email protected] — because accounts are pseudonymous, please include your in-app username so we can identify the right account. We respond within one month.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany. You may also complain to the authority where you live or work.

Changes to this policy

We may update this policy as the app changes. We will update the effective date above when we do, and, for material changes, make reasonable efforts to bring them to your attention in the app.

Contact us

Questions about this policy or your data can be sent to [email protected].