Skip to main content

Privacy Policy

Last updated: July 26, 2026

Introduction

This Privacy Policy explains how KLL Studios LLC ("Aviate," "we," "our," or "us") collects, uses, shares, retains, and deletes information when you use the Aviate Android app, Wear OS companion, website, public profile pages, waitlists, and support services.

Data controller

KLL Studios LLC
9412 Civic Way, Apt 210
Prospect, KY 40059, United States
[email protected]

Children's privacy

Aviate is designed and marketed for users age 16 and older. People age 13 through 15 may use Aviate with permission from a parent or guardian, but Aviate is not directed to that age group. We do not knowingly collect personal information from anyone under 13. Contact us if you believe a child under 13 has provided information so we can investigate and delete it.

Information we collect

Account and authentication data

  • Email address, username, display name, securely hashed password, account dates, preferences, and subscription status.
  • Google account identifier, name, and email when you choose Google Sign-In. Google does not give us your Google password.
  • Passkeys and authentication security records, such as public-key credential data, session or refresh tokens, IP address, device/app information, and security events.
  • Google Play purchase and entitlement data, including product, transaction, and purchase-token information used to verify Pro access. We do not receive your full payment-card number.

Travel and feature data

  • Boarding-pass fields, passenger details contained in a pass, flight numbers, dates, airports, seats, confirmation details, and loyalty identifiers you choose to store.
  • Manually added or imported flights, routes, trip groupings, shared-flight links, and travel statistics.
  • When you connect an airline account: your name, loyalty number, elite status, miles or points balance and qualifying metrics, expiring-balance information, and available trip details such as confirmation code, route, dates, flight number, cabin, and seat. The feature also handles the temporary authentication material described under Airline Connections below.
  • Group names, descriptions, membership, invitations, and flights shared with a group.
  • Public-profile username/display name and the flight counts, airports, airlines, aircraft, and route-map legs you choose to publish.
  • Precise location when you choose parking capture, indoor-map positioning/walking directions, or a ride-service pickup. Parking coordinates and photos, trip documents, and checklists are stored locally where the feature says they remain on-device.

Device, diagnostics, and communications

  • A stable device identifier generated by the operating system, a Firebase installation identifier, and a push token when you enable notifications. Aviate links the server-side notification registration to your account so Firebase Cloud Messaging can deliver flight and service notifications to the selected device. Prerelease 6 uses Android's notification permission as the user control; prerelease 7 and later also records the disclosure version and server timestamp associated with your choice.
  • Crash traces, app version, device model, operating-system details, and related diagnostic identifiers. Prerelease 6 may send this information under its existing Firebase Crashlytics configuration. Prerelease 7 and later starts Crashlytics collection off and sends it only after you opt in to optional crash diagnostics.
  • Website and API security logs such as IP address, user agent, request time, route, response status, and abuse-prevention events.
  • Email address, delivery/confirmation events, consent record, signup source, and abuse-prevention data when you join a waitlist or receive a transactional email. Depending on the message, Aviate uses Resend or Amazon Simple Email Service (Amazon SES), and the waitlist uses Cloudflare Turnstile to prevent automated abuse.

Feedback, forms, and reports

  • In-app form and survey answers. A response is associated with your account internally so Aviate can enforce one response per account and delete the response with your account. Your Aviate account username and email are not automatically included in the reviewer view or CSV. Reviewers can see identifying information you choose to type into an answer. Participation is optional.
  • Bug-report title and description. If you separately choose to attach them, a report may also include screenshots, recent console logs, or recent network diagnostics. Review the preview before sending; do not include passwords, payment details, or unrelated personal information.
  • User-safety reports include the reporter's account ID, reported user/profile/group ID and type, a protected snapshot used for moderation, selected reason, optional details, status, timestamps, and the reviewing administrator's decision, action, and note. The reported user is not shown the reporter's identity through this feature.

Feature-specific processing

Boarding-pass screen capture

If you start the current-screen boarding-pass scanner, Aviate first shows its own disclosure and then Android's system capture prompt. Aviate captures a single current-screen frame, processes the image locally to find a barcode, and deletes the temporary image. The source screenshot is not uploaded. Only the decoded barcode content is sent to Aviate to add or look up the pass. Screens protected by Android's secure-display controls cannot be captured.

Location, walking routes, and ride pickup

Parking location is captured only after you choose it and is kept with the local parking record. If you opt in to showing your position on an indoor airport map, Aviate accesses precise location while that map is open and sends the coordinates needed for a walking route to the third-party OpenStreetMap Valhalla routing endpoint. If you choose a ride provider that requires a pickup location, Aviate obtains location once and puts the coordinates in the external ride link sent to that provider, such as Lyft. Aviate shows a purpose-and-recipient disclosure before either transfer. These features remain usable without background location access, and the map remains available without sharing your position.

Device calendar

If you enable calendar access, Aviate lists writable calendars on your device and adds, updates, or removes only the flight events you select. Calendar contents are handled through the device calendar provider and are not uploaded to Aviate's servers.

Airline Connections

Airline Connections is an optional Pro feature, made available to accounts that have the applicable feature flag, for viewing loyalty balances and importing trip history. You sign in on the airline's own website in an in-app browser. Aviate does not receive or store the password you enter on that website.

  • Delta: The app obtains short-lived OAuth access tokens from the signed-in airline session and sends them over HTTPS to Aviate's servers. Aviate uses the tokens to request the loyalty profile, balance, and trip data you selected the feature to retrieve. The access tokens are processed for that request and are not stored in the airline-connections database.
  • Flying Blue: The app reads the selected profile, dashboard, and loyalty-card responses made available to the signed-in WebView session and sends those responses over HTTPS to Aviate's servers for normalization. Aviate does not receive your Flying Blue password.
  • Aviate stores the normalized name, loyalty number, status, balance, qualifying metrics, and trip details with your Aviate account. The app may also keep a local cache for up to seven days.
  • Disconnecting through Aviate deletes that airline's normalized connection record from Aviate's servers and removes its Aviate app cache. It does not delete your airline loyalty account or necessarily sign you out of the airline website session.

Aviate is not affiliated with or endorsed by Delta, Air France, KLM, Flying Blue, or another airline or loyalty program. Airline data can be delayed, incomplete, or inaccurate; verify it with the airline. The airline's own terms and privacy practices apply.

LiveATC in-app browser

LiveATC access is an optional Pro feature. When you open it, Aviate loads and reformats pages and audio-player content supplied by the independent LiveATC.net service inside an in-app browser. LiveATC and the advertising or measurement providers used by its pages may receive your IP address, browser or device information, cookies or similar identifiers, the airport and feed pages requested, and interaction data. Those parties process this information under their own terms and privacy practices, including for service operation, analytics, content customization, and advertising. Aviate does not send your Aviate username or email to LiveATC through this feature.

LiveATC availability and legality vary by airport and region. Its feeds are for entertainment and training, not operational decisions. LiveATC is not affiliated with Aviate, and using its content remains subject to LiveATC's terms and privacy policy.

Samsung Wallet

Where the feature is available for an eligible boarding pass, selecting Add to Samsung Wallet asks Aviate's server to decrypt the existing pass for that request and construct a wallet card containing the passenger and barcode information plus relevant confirmation, flight, airport, date, seat, cabin, baggage, boarding, and status fields. Aviate signs the card payload, encrypts it for Samsung, and sends you to Samsung Wallet to complete the user-initiated transfer. Samsung's terms and privacy practices apply.

If the encrypted signed payload is too large for the direct Samsung link, Aviate stores that encrypted payload under an opaque card/reference pair so Samsung can retrieve and refresh it. The current maximum retrieval lifetime is one year. Entries that are linked to an Aviate account or pass can be removed with that data. Some legacy encrypted entries were created without an account or pass link and cannot be matched to an account-deletion request; they become unavailable at their recorded expiry and a periodic cleanup worker removes expired rows from storage. A card already saved in Samsung Wallet is controlled through Samsung Wallet and is not removed by deleting your Aviate account.

Groups

Group flight data is encrypted in transit and at rest. Aviate's servers facilitate member access and key distribution, so this feature is not described as end-to-end encryption. Group members can see data shared with their group.

Public profiles and user-generated content

Public profiles, chosen statistics, aircraft lists, and route-map data can be viewed without signing in. Do not publish content you do not want public. Signed-in users can report users, profiles, and groups and can block other users. Blocking suppresses covered interactions and content. Aviate administrators can review reports, remove content, disable a profile, or suspend user-generated-content participation as described in the Terms of Service.

How we use information

We use information to provide and secure accounts; import, store, and display travel features; deliver notifications; verify purchases; operate public sharing and groups; answer support requests; enforce limits; prevent abuse; moderate user-generated content; diagnose crashes under the version-specific controls described above; send requested emails; comply with law; and improve reliability. We do not sell personal information. Aviate does not operate its own advertising program or use Aviate account data for behavioral advertising. Embedded LiveATC content may contact LiveATC's advertising and measurement providers as described above.

Storage and service providers

  • Aviate-operated servers: Core account, flight, group, form, report, and moderation data is processed on Aviate's servers. Report attachments and other eligible objects are stored in Aviate-operated Garage object storage on our servers. This is first-party storage operated by Aviate, not Amazon Web Services.
  • Google Sign-In: Provides optional account authentication.
  • Google Play Billing: Processes purchases and returns verification and entitlement data.
  • Google Play Integrity: Provides app/device integrity verdicts used for authentication security and abuse prevention.
  • Firebase Cloud Messaging: Delivers notifications when enabled and processes a Firebase installation identifier.
  • Firebase Crashlytics: Processes crash and diagnostic data sent by prerelease 6 under its existing configuration, and processes it in prerelease 7 and later only when the user enables optional diagnostics.
  • Samsung Wallet: Receives the encrypted, signed boarding-pass card payload when you explicitly choose Add to Samsung Wallet. Samsung acts under its own terms and privacy practices for a card saved in its service.
  • Resend: Sends account, support, and some waitlist-related email and processes delivery metadata.
  • Amazon Simple Email Service (Amazon SES): Sends iOS waitlist verification messages and processes the waitlist address and delivery metadata. Amazon SES is an email provider; Aviate does not use Amazon S3 for Garage object storage.
  • Cloudflare Turnstile: Processes a waitlist challenge token, requester IP address, and related abuse-prevention signals to distinguish people from automated traffic.
  • LiveATC.net and its page providers: Supply the optional in-app airport feed browser and audio player. When opened, the controlled WebView can transmit the browser, page, cookie, interaction, advertising, and measurement data described under LiveATC in-app browser.
  • Travel, map, weather, airport, and airline providers: Receive the minimum route, airport, flight, map-tile, or airline-data request needed for the feature you choose. This includes precise start coordinates sent to OpenStreetMap Valhalla after indoor-map opt-in, pickup coordinates included in a ride-provider link after separate confirmation, and the airline authentication/data requests described under Airline Connections for Delta and Air France-KLM/Flying Blue. Their own terms apply to their services.

We may disclose information to a service provider acting for us, to comply with a valid legal request, to protect users and the service, or as part of a business transfer subject to appropriate protections. We do not automatically include a form submitter's Aviate account username or email in the admin reviewer view or CSV; reviewers can see identifying information the submitter types into an answer.

Android permissions and user controls

Aviate requests permissions in context when a feature needs them, including notifications, camera, calendar, and location. You may deny or revoke a permission in Android settings. Current-screen capture always uses Android's MediaProjection consent dialog. Notifications can be disabled in Aviate settings or Android settings. Prerelease 7 and later also provides an in-app, default-off control for optional crash diagnostics; prerelease 6 uses its existing Crashlytics configuration. Denying an optional permission disables only the related feature where practical.

Retention and deletion

  • Account and travel data: Kept while your account is active, then deleted from live systems within 30 days after a verified deletion request, except data we must retain for legal, fraud-prevention, or security reasons.
  • Connected-airline data: The normalized server record is kept until you disconnect that airline or delete your Aviate account. The Aviate app's local cache is removed when you disconnect through the feature and otherwise ages out after seven days or is erased when you clear app storage.
  • Samsung Wallet link payloads: Direct links expire after the short link-generation window. Oversized encrypted payloads become unavailable for Samsung retrieval no later than one year after creation, and a periodic cleanup worker deletes expired rows from storage. Linked entries can be removed with their account or pass; ownerless legacy entries cannot be matched to a deletion request before their recorded expiry. Cards already saved in Samsung Wallet must be removed through Samsung Wallet.
  • Form responses: Kept until the form or response is deleted or your account is deleted. The account link is used internally for one-response enforcement and deletion, not shown to form reviewers.
  • Bug reports: Kept while the report is open and afterward as account-linked support history. Optional screenshots and diagnostic attachments are deleted when the report closes. The report record, text, and any remaining attachments are deleted when the associated account is deleted.
  • User-safety reports and moderation records: Kept while needed to review, resolve, document, and prevent UGC abuse. Records linked by the database to a deleted reporter or reported account are deleted with that account; a report about a removed group may remain as moderation history while the reporter's account remains active.
  • Public profiles and groups: Your public profile is removed or de-published when you disable it, moderation removes it, or your account is deleted. Your memberships and invitations are removed when applicable. A group and content shared with its other active members may remain, and ownership may transfer instead of deleting the group. Cached public pages may take a short time to refresh.
  • Push identifiers: Aviate's server-side device registration is removed when you disable it, sign out where the app removes it, the provider marks it invalid, or your account is deleted. Firebase controls provider-side identifier retention under its terms and retention practices.
  • Crash diagnostics: In prerelease 7 and later, unsent reports are deleted when you decline or withdraw crash-reporting consent. Firebase controls provider-side retention of reports already sent by prerelease 6 or while consent was enabled in prerelease 7 and later under its terms and retention practices.
  • Waitlist records: Kept until the waitlist purpose ends or you withdraw, then deleted within 30 days unless a legal record is required.
  • Security and request logs: Normally retained for 30 days; records tied to an active security investigation may be retained until the investigation and any required legal period end.
  • Disaster-recovery copies: If a deleted record remains temporarily in a restricted disaster-recovery copy, it is not returned to ordinary use and remains only until that copy ages out under the applicable operational schedule. This statement does not imply that a backup copy exists for every record.

Closing a Google Play subscription and deleting an Aviate account are separate actions. See Account deletion for both steps.

You may also request deletion of selected account-linked data without deleting your account. Use the relevant in-app deletion control or follow the verified email process on the Account deletion page. This selected-data process does not change the separate form-response retention rule above.

Security

We use transport encryption, service access controls, hashed passwords, application-level encryption for sensitive group fields, and platform-protected credential storage where supported. No system is perfectly secure. Keep your device and account credentials protected and report suspected compromise to [email protected].

Your choices and rights

Depending on your location, you may request access, correction, export, restriction, objection, or deletion; withdraw optional consent; disable a public profile; leave groups; block users; and complain to a data-protection authority. Use in-app controls where available or contact [email protected]. We may need to verify your identity.

International processing

Aviate is operated from the United States. Providers such as Google, Resend, Amazon SES, and Cloudflare may process data in other locations under their applicable safeguards. By using the service, you understand that information may be processed outside your country.

Health information disclaimer

Jet-lag and sleep-timing features provide general educational travel information only. Aviate is not a medical device and does not diagnose, treat, cure, or prevent disease; consult a qualified professional.

Changes and contact

We may update this policy as features or laws change. We will update the date above and provide additional notice when required. Questions or privacy requests: [email protected].