CatchFlights
Privacy Policy
Effective September 8, 2026
CatchFlights ("CatchFlights", "we", "us") is a plane-spotting app that turns real aircraft flying near you into a personal collection, logbook, and progression journey. This policy explains what information the app and its backend process, why, and what choices you have. It covers the CatchFlights iOS and Android apps and the backend services they talk to.
Data controller
Max Nowack
Schillerstr. 1
37120 Bovenden
Germany
Email: [email protected]
No account unless you ask for one
CatchFlights creates no account and requires no sign-up. Out of the box, the radar, catching aircraft, your collection, logbook, XP, levels, and achievements all work without any account, and everything you catch stays on your device.
Joining the Community is a deliberate, separate choice you make on the Community screen. Only then do we create an account for you, and even then it never involves an email address, phone number, name, or password: it is identified by a randomly generated key stored on your device plus a generated display name such as "SwiftAlbatross4821". Joining also puts you on the global leaderboard, which is what the confirmation dialog tells you before you agree. You can leave again at any time, which deletes the account and everything stored with it.
Information we process
Location
While the app is open, it uses your device's foreground location to find airborne aircraft near you, calculate their distance and catch eligibility, and save where a catch happened in your logbook. Your coordinates are sent to the CatchFlights backend for as long as the radar is connected, so it can stream nearby aircraft back to you. CatchFlights never requests background location access.
Your exact coordinates are held in memory only for the duration of that connection and are never written to our database. To query our upstream aircraft data source, the backend first snaps your position onto a shared grid cell of roughly one kilometre and queries using that cell's centre — so the upstream provider receives a coarsened area, never your precise position.
The catch coordinates saved in your logbook stay on your device (and, on iOS with iCloud sync enabled, in your own private iCloud database). They are never sent to the CatchFlights backend.
Compass and motion
If you enable compass-rotated radar, the app reads your device's heading and motion sensors to rotate the radar display. This is processed on your device only and never transmitted. You can switch it off and keep a fixed, north-up radar.
Community account and mirrored progress (only if you join)
If, and only if, you join the Community, we process: the account key (we store only an irreversible hash of it, never the key itself); the generated username; an identifier for your app database; and timestamps such as when the account was created and last seen.
From that point on, the app mirrors your progress to that account so XP and levels can be computed and verified server-side, and so your collection survives a reinstall. This covers your catches (aircraft identifier, registration, type, callsign, departure and arrival airport, the time of the catch, and your device's UTC offset), together with derived facts such as discoveries, achievements, completed sets, and perk activity. Progress you made before joining is included, so your existing collection carries over. Catch coordinates are never included. If you never join, none of this leaves your device.
Global leaderboard
Joining the Community puts your username, level, total XP, and catch count on the global leaderboard, where they are visible to other players. This is stated in the dialog you confirm when joining. You can switch the leaderboard off again at any time in the app while keeping your account.
Friends (off by default)
Friends require a Community account and are added only through an invite link you choose to create and share. We process the invite code, who created it, and the resulting friend relationships. Opening a shared invite link on the web also briefly shows the inviter's username and level so messaging apps can display a preview.
Once a friend request has been confirmed by both sides, friends can open each other's logbook: the registration, aircraft type, and time of each catch, plus the rarity the app derives from them. Nothing else about a catch is shared — in particular no catch locations, no aircraft identifier, no callsign, and no flight route. Only confirmed friends can see this; it is never public and never part of the global leaderboard. Ending a friendship ends that access immediately for both sides.
Push notifications (off by default)
Daily streak reminders are scheduled entirely on your device and transmit nothing. Separately, if you have a Community account and enable friend-request alerts, the app registers a push token for your device with us and with Expo's push notification service, so we can notify you when someone sends or accepts a friend request. Notifications are never used for advertising.
Aircraft photos
When an aircraft screen shows a photo, your device requests it directly from Planespotters.net or Wikimedia Commons using an aircraft identifier or aircraft type name. These requests contain no location and nothing that identifies you, but as with any web request, those services can see your IP address.
Reporting incorrect data
If you report that a catch's aircraft, route, or airline data looks wrong, the app sends a generated device identifier, the aircraft's identifier and flight details, the category of the issue, and any comment you write, so we can correct our catalog.
Cloud sync (iOS)
On iOS, CatchFlights can sync your catch log — including catch coordinates, aircraft data, and a generated device identifier — through Apple's CloudKit, into the private iCloud database belonging to your own Apple ID. We have no access to that private database; it is governed by Apple's own privacy practices and your iCloud settings.
Technical data
Like any internet service, our backend processes the IP address of incoming requests. We use it only transiently for rate limiting and abuse prevention; we do not build profiles from it or store it alongside your account data.
Data stored only on your device
Your full catch log — including catch coordinates — plus your collection, logbook, and settings are stored locally on your device. Apart from the specific items listed above, this data is not transmitted to us.
Legal bases for processing (GDPR)
If you are in the European Economic Area or the UK, we rely on the following legal bases under Article 6(1) GDPR:
- Performance of a contract, Art. 6(1)(b) — providing the app's core functions you asked for, in particular the location-based radar that cannot work without sending your position to our servers.
- Consent, Art. 6(1)(a) — everything to do with the Community: creating your account, mirroring your progress, the global leaderboard, friends, and push notifications. You give this consent in the dialog shown when you join, and by enabling notifications. You can withdraw it at any time by leaving the Community or switching the feature off, with no effect on the lawfulness of processing carried out beforehand.
- Legitimate interests, Art. 6(1)(f) — keeping the service secure and available (rate limiting, abuse and fraud prevention, catch verification) and correcting our aircraft catalog from user reports. Our interest is in operating a functioning, non-manipulated service; we balance this against your interests by using pseudonymous identifiers and only transient IP processing.
Providing location access is not a legal obligation, but the radar cannot work without it. You are free to decline it; the rest of the app remains usable.
What we don't do
- No advertising, and no advertising SDK is included in the app.
- No analytics, attribution, or tracking SDKs, and no cross-app or cross-site tracking.
- No sale or sharing of personal information for advertising purposes.
- No email address, phone number, real name, or password is ever collected.
- No account at all unless you explicitly join the Community.
- No access to your photo library, contacts, microphone, or camera.
- No automated decision-making or profiling that produces legal or similarly significant effects.
Recipients and third-party services
The app and backend rely on the following external services:
- adsb.lol — supplies worldwide aircraft data to our servers. No user location or user data is sent with those fixed global requests, and your device never contacts it.
- Planespotters.net — receives an aircraft identifier directly from your device to look up a registration photo.
- Wikimedia Commons — receives an aircraft type name directly from your device to look up a generic photo.
- Apple CloudKit — used only for iCloud sync on iOS, storing your catch log in your own private iCloud database.
- Expo Push Notification Service — used only if you enable friend-request alerts, to deliver push notifications to your device.
- Hetzner Online GmbH, Gunzenhausen, Germany — operates the servers on which the CatchFlights backend and its database run, as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Our servers are located in the EU.
We do not otherwise disclose your data, except where we are legally required to do so.
International transfers
The CatchFlights backend and its database are hosted in the European Union. Some of the services above are operated outside the European Economic Area, in particular Apple (CloudKit) and Expo (push notifications) in the United States. Where data is transferred outside the EEA, that transfer is based on the European Commission's Standard Contractual Clauses, an adequacy decision, or another mechanism permitted under Chapter V GDPR. For the aircraft data and photo services, only the technical, non-identifying lookups described above are involved.
Data retention
Data stored only on your device remains there until you delete the app or clear its data. If you joined the Community, account data and mirrored progress are retained for as long as the account exists, so your collection and level survive reinstalling the app; leaving the Community deletes them immediately, and we also delete them on request (see "Your rights"). Exact radar coordinates are never stored at all. IP addresses are processed only transiently for rate limiting and are not retained in a form linked to your account. Catalog correction reports are kept as long as needed to fix the underlying data.
Data security
We use appropriate technical and organizational measures to protect the data we process, including encrypted transport (HTTPS/WSS) to our backend and storing your account key only as an irreversible hash. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children's privacy
CatchFlights is not directed at children, and we do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact us so we can delete it.
Your rights
If you are in the European Economic Area or the UK, you have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw that consent at any time.
Most of these you can exercise directly in the app, without contacting us: Profile → Community → Leave Community deletes your account and everything mirrored with it, permanently and immediately. You can also turn the global leaderboard off, remove friends, disable notifications, change your username, and revoke location access in your device settings. For access to or a copy of your data, or anything else you cannot do in the app, email us at [email protected] — because accounts are pseudonymous, please include your in-app username so we can identify the right account. We respond within one month.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany. You may also complain to the authority where you live or work.
Changes to this policy
We may update this policy as the app changes. We will update the effective date above when we do, and, for material changes, make reasonable efforts to bring them to your attention in the app.
Contact us
Questions about this policy or your data can be sent to [email protected].