Privacy Policy
Looking at the sky should not mean being tracked for advertising. Here is what A PLANE! needs to work.
Effective October 2, 2026
Who is responsible
A PLANE! is developed and operated by Michael Gorini, the controller of personal data processed to provide this app. For privacy questions and requests, email michael.gorini@icloud.com.
Location and saved places
With your permission, the app uses your location to show nearby aircraft and help you aim towards them. The coordinates of the area you monitor and its radius are sent to the backend to request aircraft data. You can also choose a place manually.
When you save a watch location, the backend stores its name, precise coordinates, radius, altitude and aircraft filters, lead time, notification hours and time zone, enabled state and record timestamps. These settings are associated with your app account so the service can predict passages while the app is closed. The app does not need continuous background device-location updates to monitor a saved place.
Accounts and notifications
The app creates an anonymous account through Supabase, with an account identifier and authentication session. Optional Sign in with Apple connects an Apple identity and any email Apple supplies, which may be a private relay address. A PLANE! does not receive your Apple password.
If you enable notifications, the backend stores your Apple push notification token, account association, language, delivery environment and registration timestamps. It also processes aircraft observations, passage predictions and alert delivery state associated with your saved places. Notification content can appear on your lock screen according to your iPhone settings.
Camera and device settings
The camera aiming view processes the camera feed and orientation on your iPhone. The app does not upload camera images or video to its backend. Display preferences are saved locally. Authentication information is handled by the app’s authentication library and Apple device storage.
Services that receive information
- Supabase: authentication, saved watch locations, aircraft requests and notification processing. The primary project database is in Frankfurt, Germany. Other service infrastructure and subprocessors may operate elsewhere.
- Apple: optional sign-in, push delivery, system permissions, place search and geocoding. Place queries and coordinates used for search are processed by Apple’s map services.
- ADSB.lol: aircraft data. Our backend sends a geographic search area to the provider; it does not attach your account identifier or notification token.
- CARTO / OpenStreetMap: the app’s map background. Loading maps contacts map servers, which receive ordinary network request information and the requested map area.
- Cloudflare Pages: hosts this website and may process IP addresses, requested URLs, browser information and security signals to deliver and protect it.
Provider information: Supabase, Apple, ADSB.lol, CARTO and Cloudflare. International processing is subject to the safeguards applicable to the relevant provider and service.
Why we process it
We use this information to provide the features you request, authenticate accounts, calculate aircraft passages, deliver alerts, respond to support requests and protect the service from abuse. The app has no advertising or third-party analytics SDKs, and we do not sell your personal data or use it for cross-app advertising tracking.
Where European data-protection law applies, providing requested app features is based on performance of the service agreement; optional device access depends on your permission; proportionate security and abuse prevention are based on legitimate interests; legal compliance may require certain records.
Retention and deletion
Saved places and account-linked device registrations remain until you delete them or delete your account. Alert and operational records may remain while needed for delivery, deduplication, troubleshooting and service security. Infrastructure logs and backups follow the relevant provider’s retention settings and may not disappear immediately when live records are deleted.
Use Settings → Account → Delete account in the app to delete your backend account and its associated saved places and device records. Deleting the app alone does not delete backend data. You can delete individual watch places, disable alerts and revoke location, camera or notification access in iOS Settings. After deletion, using the app again may create a new anonymous account.
Your choices and rights
Contact us to request access, correction, deletion or an export of your personal data. Depending on applicable law, you may also request restriction, object to processing, withdraw consent or complain to a data-protection authority, including the Italian Garante. We may need information to verify that a request concerns your account; do not email your authentication session or push token.
Network connections use HTTPS and backend access is restricted by authentication and database policies. No service can promise absolute security. The app is intended for a general audience and does not knowingly collect children’s data for profiling or advertising.
This website and policy updates
This site has no analytics, advertising, cookies, contact forms or third-party scripts. Fonts and the illustrative map are served locally. Following an external link takes you to a service governed by its own policy. Emails you send are used to handle your request.
We update this page when the app’s data handling changes and revise the effective date. Material changes will be communicated when required.