Overview
NiteOcean is a premium Digital Flight Deck developed and operated by Fly Away Today Ltd, a UK registered company. This policy explains how we handle information when you visit niteocean.com, create or use a NiteOcean account, use the Digital Logbook and account-support routes, manage subscriptions or contact us about the product.
Data Controller
Fly Away Today Ltd is the data controller for personal data processed through NiteOcean. For privacy questions or requests, contact us at [email protected].
Information We Collect
We collect information you choose to provide, such as your name, email address, authentication information processed by Supabase, account profile details, pilot profile information, saved aircraft or airport preferences, avatar uploads, support messages and other information you enter into NiteOcean. Supabase also provides a stable internal user identifier which NiteOcean uses to associate account services and protect account isolation.
Digital Logbook information may include manually entered flight records, imported or scanned logbook pages, aircraft type and registration, departure and arrival information, flight times, role, takeoffs, landings, remarks, endorsements, import jobs, draft rows and related aircraft or flight information supplied by you.
NiteOcean uses per-user local device storage for some logbook and account-related data. Authenticated users have a user-scoped local logbook store so one account's local records are not intentionally shown to another account on the same device. Cloud backup stores supported account data in Supabase for recovery and durability. Where multi-device synchronisation is available to your plan, including Captain multi-device synchronisation, NiteOcean may reconcile the current user's cloud logbook rows with that same user's scoped local store across devices.
Subscription status, purchase history relevant to entitlement, active store product identifiers and store-management links may be processed through Google Play, the Apple App Store and RevenueCat so NiteOcean can unlock and display the correct plan. NiteOcean uses your Supabase user ID as the RevenueCat App User ID. Google Play and the Apple App Store handle payment credentials and payment methods; NiteOcean does not receive full payment-card details.
If you enable Analytics in the app, NiteOcean may collect optional app usage and engagement analytics such as app opens, sessions, logical screen views and bounded feature or subscription events.
We may also receive basic technical information from hosting, security and backend services, such as IP address, browser or device type, pages or endpoints requested, timestamps, diagnostics needed to operate the service and similar operational metadata.
AI-Assisted Logbook Processing
If you use AI-assisted logbook import, uploaded logbook pages or files may be processed to extract structured flight information for your review. NiteOcean stores import files and draft extraction results in Supabase and may route extraction requests through NiteOcean backend services on Cloudflare to OpenAI for the implemented AI-assisted processing path.
Extracted entries are intended to help prepare draft logbook rows for user review before final confirmation. AI-assisted extraction can be incomplete or inaccurate, and NiteOcean does not guarantee that AI output is correct. You remain responsible for reviewing and confirming any imported logbook information before relying on it.
How We Use Information
We use information to provide and secure your account, operate the Digital Logbook, support cloud backup and eligible multi-device synchronisation, process logbook imports, display subscription entitlements, send account and security communications, respond to enquiries, understand feature usage where Analytics is enabled, improve reliability and meet legal or regulatory obligations.
Lawful Bases
Where UK data protection law applies, our lawful bases depend on the purpose of processing. Account creation, authentication and core NiteOcean service delivery are processed as necessary for performance of our contract with you. Digital Logbook, cloud backup and eligible multi-device synchronisation are processed as necessary to provide the NiteOcean services you use. Subscription entitlement and account-plan processing are processed as necessary to provide paid plan access.
We process security, fraud-prevention, abuse-prevention, service-integrity and necessary operational diagnostic information where necessary for our legitimate interests in protecting NiteOcean, users and the integrity and security of the service. We process information where necessary to comply with applicable legal, tax, accounting or regulatory obligations. Where NiteOcean relies on consent for an optional processing activity, you may withdraw that consent where applicable; choosing to use a feature does not automatically mean consent is the lawful basis for all related processing.
Cookies And Analytics
NiteOcean may use necessary local storage or similar device storage to keep account sessions, app preferences, per-user local logbook data and operational state.
If you enable Analytics in the app, NiteOcean uses Firebase / Google Analytics for product usage analytics. Analytics collection is disabled until you opt in. Measured data may include app opens, sessions, logical screen views and bounded feature or subscription events.
NiteOcean's custom analytics events do not include your email, name, account identifiers, precise location, aircraft registration or hex, Digital Logbook records or totals, Ask Captain prompts or responses, airport search terms or ICAOs, METAR/TAF/NOTAM contents, receipts, tokens or payment credentials.
Advertising ID collection is disabled, and ad personalization and ad user-data signals are disabled.
Sharing
We do not sell personal information. We share limited information with service providers who help us host, secure, operate, authenticate, process subscriptions, support logbook import features or communicate about NiteOcean, or where disclosure is required by law.
Relevant processors and services include Supabase for authentication, account data, database storage, private storage and Edge Functions; RevenueCat for subscription customer identity, purchase-status and entitlement processing; Google Play and the Apple App Store for store billing and subscription management; Firebase / Google Analytics for product usage measurement only when Analytics is enabled; Resend for transactional account emails; OpenAI for AI-assisted logbook extraction when that feature is used; and Cloudflare for public website hosting and NiteOcean backend or Worker processing. These providers receive only the information needed for the relevant service.
International Transfers
NiteOcean is operated from the UK, but the service providers listed above may process personal data outside the UK, including in the United States and other countries where they or their sub-processors operate. Where a transfer of UK personal data requires a safeguard, we rely on the provider's applicable data processing terms and transfer safeguards where available, such as Standard Contractual Clauses, the UK International Data Transfer Addendum, Data Privacy Framework participation or other lawful mechanisms made available by that provider.
Provider transfer mechanisms can change and may depend on the specific service, contracting entity and processing location. We keep this wording conservative and rely only on mechanisms made available by the relevant provider's current contractual or privacy documentation.
Retention
We keep account, logbook, import and operational records for as long as needed to provide the service, maintain account-backed recovery or synchronisation, support security, resolve disputes, comply with legal obligations or meet legitimate business requirements. We do not set a fixed retention period for every category because retention depends on the account state, feature used and operational need.
Local device data may remain on a device until it is cleared by the app, by account deletion cleanup, by the operating system or by the user. Cloud account data is handled through the account-deletion process described below, subject to the limited retention exceptions in this policy.
Account Deletion
You can request deletion of your NiteOcean account and associated account data from inside the app or at niteocean.com/account-deletion/. The in-app deletion flow removes the Supabase Auth user, account/profile data and associated NiteOcean user data tied to that account, including cloud logbook and import records, uploaded avatar files, uploaded logbook import files and account-backed usage records where applicable.
The deletion backend cleans the configured private storage prefixes for avatars and logbook imports, deletes the associated RevenueCat customer record where applicable for the Supabase UUID used as the RevenueCat App User ID, then deletes the Supabase Auth user so database cascade rules can remove user-owned rows. After an in-app deletion succeeds, NiteOcean also clears device-local NiteOcean user data on that device where practical.
We may retain limited records when reasonably required for security, fraud prevention, legal compliance, dispute handling, tax or accounting obligations, or to protect the integrity of the service. Deleting your NiteOcean account does not automatically cancel an active Google Play or App Store subscription; billing must be managed separately through the applicable store subscription settings. Store purchase history is controlled by the relevant app store, and a future store restore may make store purchase records available again through RevenueCat.
Your Rights
Depending on your location and the applicable lawful basis, you may have rights to request access, correction, deletion, restriction or portability of personal information, to object to certain processing, and to withdraw consent where processing relies on consent. These rights can depend on the circumstances and applicable legal exemptions. You can use the in-app Delete Account flow for account deletion, visit niteocean.com/account-deletion/, or contact us at [email protected] for privacy requests.
Complaints
You can contact Fly Away Today Ltd at [email protected] with privacy concerns. If you are in the UK, you also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint/.
Contact
For privacy questions or product enquiries, contact Fly Away Today Ltd at [email protected].