Privacy Policy
Last updated: 9 September 2026
the individual operator of SkyStudy, established in Romania and identified on the Legal Notice page (“we”, “us”, or “our”) operates the SkyStudy ATPL platform. This Privacy Policy explains how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data, in the sense of Article 4(7) GDPR, is the individual operator of SkyStudy, established in Romania and identified on the Legal Notice page. SkyStudy is a brand name, not a legal person, so the controller is the trader operating it.
The controller's full identification and establishment details are on our Legal Notice page. For any data protection matter, contact: to2000bv@gmail.com.
We have not appointed a Data Protection Officer. Article 37 GDPR requires one only where processing is carried out by a public authority, where the core activity is large-scale regular and systematic monitoring, or where the core activity is large-scale processing of special-category data, and none of those applies here. You can raise any data protection matter at the address above.
2. Data We Collect
2.1 Account Data
- Email address: for authentication and communications
- Display name: for your profile
- Password: handled by our authentication provider (Supabase Auth) and stored only as a secure hash; we never see or store it in plain text
- Profile information: licence type, target exam date, and the subjects on your study track
- Sign-in with Google (optional): if you choose Google sign-in (when enabled), we receive your email address, name, and profile picture URL from Google
- Communication preferences: your email reminder and unsubscribe choices
- Marketing email opt-in (optional): if you submit your email to receive study tips or a free download, we store your email address together with the date, time, and IP address of your consent and how you reached us. You can unsubscribe at any time; once you have unsubscribed, re-submitting the form will not silently put you back on the list
- Support correspondence: messages you send us about billing, access, or content issues
When you create an account we also record the date, time, and version of the Terms of Service you accepted, together with your confirmation that you are at least 16 years old.
2.2 Study Data
- Question answers: your responses to practice and exam questions, with timing and correctness
- Study sessions: mode, duration, subject, and score
- Learning-progress model: a per-topic estimate of your knowledge and weak areas, used by the adaptive engine (see Section 2.5)
- Spaced-repetition data: review scheduling state for questions you study
- Personal notes, bookmarks, flags, and collections: items you save, tag, or organise
- Gamification data: XP, level, streaks, and achievements
- Analytics data: computed accuracy, streaks, and study time (derived from the above)
- Offline study data: downloaded question packs, pending offline answers, and offline sync metadata stored on your device
2.3 Community Content (when you use it)
- Explanations, comments, and replies you post on questions
- Votes, reports, and exam sightings you submit
- Public-page comments you post on public pages (visible to other visitors)
- Community forum threads and replies you post, which are public: readable by anyone without an account and indexable by search engines. Forum posts show your community display name, never your real name.
- Public community profile (display name, optional bio) if you opt in to make it public
- Feedback you submit about the product
Staff replies in community areas may be drafted with AI assistance and are labelled accordingly. When we prepare such a reply, the text of your public comment may be processed with AI tools; nothing beyond the public content and display name already visible on your comment is shared.
2.4 Payment Data
- Stripe Customer ID: links your account to Stripe for billing
- Subscription status and plan: stored for access control
- Payment details: handled entirely by Stripe; we never store card numbers
- Billing event records: a log of Stripe webhook events, kept for reconciliation and fraud prevention
The ATPL subscription plans are not switched on yet, so no subscription billing data is created. Payment data is created when you buy a feature that is sold separately, such as the ICAO English Pro course. Card details are entered on Stripe's own checkout and are never seen or stored by us. Where you agree at checkout to give up the 14-day withdrawal right, the wording you agreed to and the time you agreed to it are stored with your purchase record, because we have to be able to show what you consented to.
2.5 Adaptive Learning Profile (automated processing)
When the adaptive study engine is enabled, every answer you give in practice and exam mode feeds a model that estimates your ability per learning objective (a per-topic mastery rating with a confidence value), classifies each topic (for example “learning”, “weak”, “proficient”, “mastered”), and predicts your accuracy. This is automated profiling of your learning performance. We use it only to personalise your study, to show your weak areas, and to choose which questions to serve you next so you learn faster. It has no legal or similarly significant effect on you, it never determines pricing or access, and there is no automated decision-making about you in the sense of Article 22 GDPR. You can object to this profiling (see Section 6.6); if you do, we serve questions without adaptive personalisation.
2.6 Technical Data
- IP address: used transiently as a key for rate limiting and abuse prevention, and not otherwise stored in our database in normal use. Exceptions: if you opt in to marketing emails we record the IP address at the moment of consent as part of the consent record (proof of consent), and IP ranges may be recorded in an abuse blocklist if an administrator blocks them. Offline question downloads also retain the account, IP address, time and question count for content-abuse investigation for the life of the account; this log has no separate scheduled expiry
- Device/browser info: for compatibility, debugging, and, if you enable push notifications, to deliver them
- Usage analytics: aggregate public-site measurement, Vercel page and performance metrics, optional third-party analytics and product usage events. These optional measurements are off until you accept analytics in the cookie controls. They are described separately in Sections 2.7, 2.17 and 8 because they do not collect the same data.
- Error telemetry: if you accept analytics in the cookie banner, our error-monitoring service (Sentry, EU region) is loaded in your browser and receives redacted runtime errors, a sample of page-performance traces and a session-health signal. IP address, email, headers, cookies, and request bodies are stripped from each event before it is sent. If you decline, or have not answered, the optional browser Sentry script is never loaded. Separately, your browser may send Content Security Policy violation reports to our own security endpoint without analytics consent. These reports describe the blocked resource, document and source-file URL and violated security rule; query strings and fragments are removed before server logging and reporting to Sentry. We process these reports and server errors to protect and operate the Service on the basis of our legitimate interests
- Anti-abuse checks: Cloudflare Turnstile verification during registration; your IP and a challenge token are processed by Cloudflare for bot detection
- Content marking: question text we deliver to you carries a short marker derived from your account identifier by a one-way hash. It is invisible on screen, it changes nothing you read, and it exists so that if our question bank is copied and republished elsewhere we can tell which account the copy came from. It is not used to profile you, it is never shared with advertisers or any other third party, and it is not a cross-site identifier: it appears only inside our own content, delivered to you. Bulk downloads for offline study are additionally logged (account, time, number of questions, IP) for the same purpose
We do not collect or store your timezone, and we do not use advertising or cross-site tracking cookies.
2.7 Product Usage Events (signed-in users)
When you are signed in, we record a small, fixed set of product milestones so we can see where the app is failing people. For example: that you opened the setup wizard, which step you reached, that you started a practice session, and that you answered your first question. Each record contains only your account identifier, an event name taken from a fixed internal list, a few short technical values such as a step number or a question count, and a timestamp.
Optional events sent by your browser require analytics consent. Separately, our servers record service events when processing actions such as completing onboarding, submitting an answer, starting a study session or changing an exam date, and when sending or handling requested reminders and job alerts. Those server records continue independently of the cookie choice, under the legitimate-interest basis for operating and improving these workflows. You can object as described in Section 6.6.
- Purpose: to find and fix the points where the product loses people, and to check whether a change actually improved things
- Legal basis: analytics consent (Art. 6(1)(a) GDPR) for optional browser events; legitimate interest (Art. 6(1)(f) GDPR) for service events recorded by our servers as described below
- Retention: 24 months, after which the records are deleted automatically. They are also erased immediately if you delete your account
- What is never recorded here: your IP address, your browser's user-agent string, your location, and any free text you have typed. Device information, if recorded at all, is limited to a broad category such as mobile, tablet, or desktop
- Where it stays: in our own database only. Supabase processes these records for us. They are not sold, used for advertising, or linked to your activity on other websites
These records are included in your data export (Section 6.1), and you can object to this processing at any time under Section 6.6.
2.8 Study Reminder Emails
There are two of these, and you can only ever be in scope for one of them at a time. Both carry a link straight to a practice question, both are covered by the same settings switch, and both stop the moment you turn that switch off. We send them because you signed up to study for an exam with a deadline, and a short nudge is the only way to reach you once you have stopped opening the app.
The study reminder, if you have answered at least one practice question and then go a few days without studying. It offers to pick up where you left off.
The first-session nudge, if you registered one to three days ago, finished setting your account up, and have not answered a practice question yet. It offers you your first session. You get this at most once, ever: if you do not act on it, we do not send it again, and there is no second or third attempt.
- Who gets which: the study reminder goes only to accounts that have answered a question and have not studied for one to three days. The first-session nudge goes only to accounts that have never answered a practice question. Nobody receives both for the same state, and an account that has had either one is not sent the nudge again
- Legal basis: our legitimate interest in helping learners who chose our service keep going with it (Art. 6(1)(f) GDPR). We assessed each of them against your interests before switching it on, and the limits below are the result
- How often: the first-session nudge is one email in the lifetime of the account. The study reminder is at most one email per break in your studying, so if you stop and do not come back, you get one email and nothing more. Across both, never more than four in any 30 days, and never more than one in a day
- How to stop it: a switch in your settings turns both of these off on their own and leaves everything else alone, and every email carries a one-click unsubscribe that stops all optional email. Both take effect immediately
- What it never does: neither one profiles you, scores you, or reads anything you have written. Whether you get the study reminder is decided by two dates and whether you have ever answered a practice question. Whether you get the first-session nudge is decided by your registration date, whether you finished setting your account up, whether you have ever answered a practice question, and whether we have already sent you either of these emails
You can object to this processing at any time under Section 6.6, and turning the setting off is the fastest way to exercise that.
2.9 Employer Job Submissions (no account needed)
If you propose a pilot vacancy through our posting form, we collect the details you type in: the company name and website, your name, your work email address, and the vacancy itself. You do not need an account, so this is the only thing we hold about you.
- Why we need the email address: we send a confirmation link to it, and a submission that is never confirmed is never reviewed. We then use the same address to tell you what we decided and to ask you about the vacancy if we need to
- Network address: we store a keyed hash of the address the submission came from, never the address itself. It exists only to spot a flood from one origin, and it cannot be turned back into an address without a key we hold separately
- Automated checks: before a person reads it, the submission goes through fixed rules (does the contact domain match the company, is the apply link on a plausible host, does this duplicate a live listing) and an automated content screen that looks for known recruitment-scam patterns in the advert text you wrote. The text you wrote, and nothing else about you, is sent to Anthropic's Claude API for that screen; your name, your email address and the network hash are not
- No automated decision: those checks only flag a submission for a person. They never publish it, never refuse it, and never rank it. A person makes every decision, and Art. 22 GDPR is therefore not engaged
- Legal basis: our legitimate interest in running a moderated job board and in keeping fraudulent vacancies away from pilots (Art. 6(1)(f) GDPR)
- How long: the network hash is erased after 90 days and the whole submission after 12 months, both automatically. You can ask us to erase yours sooner at any time
A published listing shows the vacancy and the operator. It does not show your name, your email address, or anything else about you.
2.10 Your Pilot Job Profile, Saved Jobs and Applications
If you use the pilot jobs board while signed in, you can fill in a career profile so the board can tell you which vacancies you already meet. This is entirely optional. The board works without it, and nothing is created until you fill something in.
- What it holds: flying hours (total, pilot in command, multi-engine, turbine, instrument), the licences you hold, your type ratings, your ICAO English level, your languages, the countries or blocs where you have the right to work, whether you will relocate, and which regions interest you
- What it does NOT hold: your date of birth. We do not collect your age and we never apply an age criterion to you. Where an operator states one, we show it attributed to them and exclude it from the match entirely (see Section 2.9 and our Terms, section 6.3)
- Medical certificates: the job profile does not collect or store your medical class or expiry. Vacancy pages may show an employer's stated medical requirement, but the job matcher does not decide whether you meet it. Check the requirement yourself before applying
- Saved jobs and your application tracker: the vacancies you save, and the applications you choose to record with their status and your own notes
- Where the match is calculated: in your own browser, not on our server. The public vacancy pages are cached and served the same to everybody; your profile is fetched by your browser and compared there. Nobody else can see your match, and the operator is never told you looked
- Who can see it: These four records are protected by row-level security with owner-only policies. A SkyStudy staff account querying them through an ordinary session sees zero rows, by design. Privileged backend and database access can bypass these policies for necessary operations and support
- Legal basis: performance of the contract you have with us for the Service (Art. 6(1)(b) GDPR). You asked for the feature by filling it in
- No automated decision: the match is a count of requirements you meet, shown to you. It decides nothing, is never sent to an operator, and never affects anything else about your account. Art. 22 GDPR is not engaged
- How long: for as long as your account exists. All four records are erased with your account in the same request
2.11 Pilot Job Alert Emails (opt-in)
You can ask us to email you when new vacancies match a search you saved. This is off until you switch it on, and there are two independent ways to switch it off again.
- What we process: the search you saved, your email address, and when we last wrote to you about it, so we only ever send what is new since the last email
- Legal basis: your consent (Art. 6(1)(a) GDPR). You give it by creating an alert, and you can withdraw it at any time without giving a reason and without affecting anything else
- Two-tier opt-out: every alert email carries a one-click link that stops that one saved search without a login, and your settings page carries a single switch that stops all pilot job email at once. Turning off all optional email in your account settings also stops them. Any one of the three is enough
- We do not send an empty alert: if nothing new matches, no email goes out
- How long: until you delete the alert or your account. Alerts are erased with your account in the same request
2.12 Reports About a Job Listing (no account needed)
Every vacancy page has a “Report this listing” control. Anyone can use it, including people who have never used SkyStudy, because the EU Digital Services Act requires that route to be open to everyone.
- What we collect: the listing you are reporting, the category you picked, what you wrote, and a keyed hash of the network address it came from. Nothing else
- Your email address is optional: we ask for it only so we can tell you what we decided or ask you one question. Leaving it blank does not make the report count for less. We accept anonymous reports. Providing an email lets us acknowledge receipt, request clarification and communicate the outcome
- We never tell the advertiser who reported them. Not their name, not their address, not the wording that would identify them
- No automated takedown: a report flags a listing for a person. It cannot hide or remove anything by itself. A person reads every one and decides
- Legal basis: our legal obligation under the Digital Services Act to operate a notice-and-action mechanism (Art. 6(1)(c) GDPR), and our legitimate interest in keeping fraudulent vacancies away from pilots (Art. 6(1)(f) GDPR)
- How long: the network hash is erased after 90 days and the whole report after 12 months, automatically
2.13 Saved CVs and Expiry Reminders (Pilot CV Pro)
The Pilot CV Maker is free and works entirely in your browser: unless you use Pilot CV Pro on a signed-in account and choose to save a version, nothing you type into it ever reaches us. If you do save a version, we store the text of that CV on your account so it is there on your other devices. Pilot CV Pro is free while SkyStudy is in beta, so this applies to any signed-in account and not only to one that has paid.
- What we store: the CV text you saved, and the name you gave that version. Your photo stays on your device. It is excluded from cloud-save requests and removed from server storage payloads. It does not sync to another device. Avoid putting health information into free-text fields or version names, which are included in cloud saves
- Who can read it: you. The table is restricted to its owner at the database level, and there is no staff-facing screen that shows anyone else's CV
- Expiry reminders are off until you switch them on: having Pilot CV Pro does not subscribe you to anything. When they are on, we email you if an ICAO English validity or type rating in your saved CV moves inside its warning window, and again if it lapses
- Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR). Expiry reminders are a listed feature of Pilot CV Pro, which is what makes this different from the study reminder in Section 2.8
- How often: at most one email per change in what is expiring, and never more than one in seven days. Sitting inside a warning window does not produce a second email
- How to stop it: the switch in the CV builder turns reminders off on their own, and every email carries a one-click unsubscribe that stops all optional email. Both take effect immediately
- What it never does: we do not check any of these dates against a licensing authority, we cannot confirm that any of them are correct, and we never share them with an airline, a recruiter or anyone else. Everything we hold is what you typed in
- How long: until you delete the version or your account. Deleting a saved version does not delete the record that you applied somewhere with it; that record simply stops naming a CV
2.14 Practice Interview Answers and Transcripts
Two paid features run a practice interview and record what you said: the mock interview inside ICAO English Pro, and the Interview Room (its technical oral and its airline interview). Both keep a written transcript of the session on your account, so this section says plainly what is stored, where it goes, and for how long. The ICAO English Pro mock interview also asks you to read one fixed sentence out loud before it starts, and stores that reading under exactly the same rules as everything else here.
- What we store: for every question in the session, the question the examiner asked and your answer in full, in your own words, with the time you answered it. We also store the written feedback report produced at the end, which quotes parts of your answers back to you as the evidence for what it says
- Why this section exists separately: an interview answer is not like an answer to an exam question. It is you describing your own career, the times something went wrong for you, the operators you have flown for, and why you left them. We hold it because you asked for feedback on it, and it deserves to be described rather than folded into “study data”
- We never receive or store audio of you: if you speak your answer rather than typing it, the speech-to-text is done by the speech recognition your browser already provides, and it is your browser, not SkyStudy, that reads the microphone. No audio of you is sent to us or stored by us, we could not produce a recording of you if we were asked for one, and what reaches us is the text your browser produced, which you can see and correct on screen before you submit it. One thing we should be straight about, because it is not ours to control: most browsers do that recognition on their maker's servers rather than on your device, so the audio can leave your device and go to your browser's maker, under that maker's own privacy terms rather than ours. It does not pass through us and we never see it. If you would rather no audio left your device at all, type your answer instead: typing is always available and is graded identically. It avoids microphone processing, but your submitted text still reaches SkyStudy and the feedback provider described below. An earlier version of this policy said the audio was never sent to anyone else, which overstated what a browser guarantees
- What we measure about how you sounded: in the ICAO English Pro mock interview only, and only when you speak rather than type, your browser also measures the sound of your answer while you give it: how long you spoke for, where your pauses fell and how long they were, how quickly the syllables came, how much your pitch moved, and how much background noise your microphone picked up. All of that happens on your device and none of it involves keeping any audio: your browser reads the microphone, reduces each fraction of a second to a handful of numbers, and throws the sound away. What is stored is about a dozen numbers describing the whole answer. They are averages and counts, they cannot be turned back into sound, they are not a voiceprint, and they cannot be used to recognise you or to tell you apart from anybody else. We measure them because fluency and pronunciation are two of the six things an ICAO language rating is scored on and neither of them is visible in the text, and because a noisy recording has to be detectable: where it is too noisy to judge we say nothing about your pronunciation rather than guess at it. They are kept, exported and deleted on exactly the same rules as the rest of this section
- The sentence you read before the mock interview starts: in ICAO English Pro only. Before the interview begins you are shown one fixed sentence and asked to read it aloud. We store what your browser turned it into and how much of it came out right. It is not scored as English and no part of your level comes from it: because we already know what the sentence says, it is the only way to measure how accurately your microphone and your browser are turning your speech into text at all. If they turn it into text badly, your answers would be judged on words you did not say, so we tell you and give your session back instead of rating you. As with everything else here, no audio of that reading is kept by us or sent to us, and the point above about where your browser does its recognition applies to it too
- Where the text goes: to us, and, at the end of the session only, to Anthropic's Claude API to write the feedback report (see Section 4). Your name and your email address are not sent with it. Nothing is sent to any airline, recruiter, training organisation or examiner, ever
- Who can read it: you, always. There is no staff-facing screen that shows anyone else's interview, and no report or export of one is produced for anybody but you. Beyond that the honest answer differs by feature, so it is set out rather than summarised. For the Interview Room, its two tables are restricted to their owner by database policies for ordinary authenticated sessions. For the ICAO English Pro mock interview, the same now holds: ordinary SkyStudy administrator sessions cannot read your session, your answers or your reading of the fixed sentence. Until 14 August 2026 those three tables did permit a system administrator to read them, and an earlier version of this section wrongly said they did not. The administrator policy has been removed. Privileged backend services and database operators can still access these records when necessary for operations or support; row-level policies do not restrict that privileged access
- Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR). The practice interview and its feedback are what you bought
- Retention: 12 months, then your answers and the report quoting them are deleted automatically by a scheduled job. What is kept after that is the bare record that a session happened: its dates, and which of our written questions it used, so your remaining allowance stays correct and so a later interview does not ask you the same questions again. That record contains none of your words
- Getting a copy, and getting rid of it sooner: your transcripts are included in the data export in Section 6.1, so you can keep your own copy before the 12 months run out. Account deletion removes these database records as part of the account-purge process; separate storage and provider cleanup is described in Section 7
The report is written feedback on one practice session. It is not a mark, not an assessment, and it does not predict how any real interview or selection process will go. Nothing about it is shared with anyone.
2.15 How You Found Us (signup attribution)
If you accept analytics and then create an account, we store, once, the campaign tags that were on the link you first arrived through. These are the utm_source, utm_medium, utm_campaign, utm_content and utm_term values that a link carries in its own web address, plus the page on our site you first landed on and the address of the site that linked you. The landing page can be recorded even without campaign tags. A later tagged visit may replace an earlier untagged attribution before signup. We keep it so we can tell which of the places we post actually brings people here, instead of guessing from view counts.
We also store, in the same record, which of our own pages you were on when you set off to create the account, if you got here from one of our free tools rather than straight from a link. It is one word from a fixed list we wrote ourselves, such as aptitude_results or cv_finished, and never anything you typed. It travels in the web address of our own link and, when you sign up with Google, in the address Google returns you to. Nothing is stored on your device to carry it. We keep it so we can see which of the free tools actually leads people to an account, which is the one thing view counts cannot tell us.
- Purpose: to know which channels bring learners to the Service, and which of our own free tools lead to an account, so we stop spending effort on the ones that do not
- Legal basis: your analytics consent (Art. 6(1)(a) GDPR)
- First touch only: one record per account, written when the account is created and never updated afterwards
- What is never recorded here: your IP address, your browser's user-agent string, your location, and any free text you have typed. There is no cookie or identifier here that could follow you to another website
- How long: while your account exists. It is erased with your account, in the same request
- Where it stays: in our own database only. Supabase processes it for us; it is not sold or used for advertising
This record is included in your data export (Section 6.1). You can withdraw analytics consent at any time in the cookie controls. Your browser then stops attaching attribution to new requests and removes its stored copy. This does not undo an authentication request already submitted or delete an existing account record; contact us to exercise the rights described in Section 6.
2.16 Your Pilot Aptitude Scores (when signed in)
The pilot aptitude exercises work without an account, and a score you earn while signed out stays in your own browser. When you are signed in, each completed run is also saved to your account, so your history and your best per exercise follow you to every device you sign in on. If your browser already holds runs from before you signed in, they are carried into your account once, the first time you play or open your progress page while signed in.
- What is saved: for each completed run, the exercise, the level (easy, medium or hard), the raw score, how many items were correct out of how many, the average time per item, the 0 to 100 value shown on your progress page, and when you played. No free text and nothing about your device
- Purpose: to show you your own history, your best per skill and your progress over time on any device, and to tell you where a score stands (see below)
- Legal basis: performance of the contract with you, Art. 6(1)(b) GDPR. Saving is the feature
- Who can read it: Aptitude runs are restricted to their owner by database policies for ordinary authenticated sessions. Privileged backend and database access remains available for necessary operations and support
- How long: while your account exists. Erased with your account in the same request, and you can delete them yourself at any time with the Clear my progress control on your aptitude progress page, which removes them from your browser and from your account together
- Getting a copy: they are included in your data export (Section 6.1)
Where a score stands. After a run we may tell you how your score compares with every completed run of the same exercise at the same level, for example that it beat 64% of 1,203 runs. That figure comes from a separate count of runs per exercise, level and 5-point score band, which is updated for every completed run whether or not the person was signed in. That count holds no identifier of any kind: not an account, not a network address, not a browser identifier. It is a tally of results, not a record of people, and it cannot be linked back to you. We show no comparison until an exercise has at least 30 recorded runs at that level. The comparison is with runs, not with people, and it does not predict how you would do in any airline or flight-school selection. It is not a profiling decision about you and has no legal or similar effect; it is a number you can look at.
2.17 Anonymous Usage Counters (no account, no identifier, nothing on your device)
The largest measurement on this site is also the emptiest one, and it is worth setting out in full rather than hiding behind the word analytics. We keep one table of counters. A row in it has exactly four values and can hold nothing else:
- Which kind of thing happened: a bucket name taken from a closed list of 55 names that is written into our source code and enforced again by the database, so a name that is not on the list is rejected rather than stored
- Which one it was: a short key, such as an exercise slug or a page path. It is not a free-text field. The server accepts it only if it is lowercase, at most 120 characters, and shaped like a slug or a path, with no spaces and no query string, so nothing you have typed anywhere can reach it
- Which day: the calendar date in UTC, and no finer
- How many: a whole number, incremented by one
What a row cannot contain, because the table has no column for it: your account identifier, your IP address, your browser's user-agent string, a session identifier, a cookie value, a time more precise than the day, or any free text. The table's own key is the bucket, the key and the day together.
These counters write nothing to your device. Where a counter is fired by your browser it sends us a bucket name and a key, and our own server supplies the day. One counter, visit_channel, first reduces two values your browser already hands to the page it is loading, the referring address and the campaign tags on the address you arrived at, down to a single word out of eleven fixed words such as direct, google or social. Only that one word is sent, and no counter row holds either original value.
Browser-initiated counters, including visit_channel, run only after analytics consent. We do not treat the absence of a cookie as sufficient reason to bypass that choice. Server-generated counts of completed account creation are separate and are described below. This subsection is about the counter rows only. The referring address and the campaign tags are kept in three other places, each described where it belongs: Section 2.15 above, which stores them once on your account row if you create an account; the Cookie Policy, which describes skystudy-attribution, a note of the campaign tags, the page you landed on and the origin of the site that linked you, kept in your browser only while you have accepted analytics; and Vercel, whose own documentation for the page counts in Section 4 lists Referrer and filtered query parameters among the values that may be stored with a data point.
Why there is no legal basis listed for this in Section 3. A basis under Article 6 GDPR is needed to process personal data. A row here identifies nobody, directly or indirectly, so it is not personal data and no basis applies. For the same reason, and we would rather say it than let you assume otherwise, there is no export and no erasure path for these counters: a request for your rows cannot be answered, because the concept of your rows does not exist in a table with no identifier in it. Nothing here is included in the data export under Section 6.1, and nothing here is deleted when you delete your account, because there is nothing in it that was ever about you.
One of the 55 names, signup_completed, stands for an account having been created. Its key is the door that account came through, and it can only ever be one of three fixed words: email, google or oauth. Nothing about the person reaches the row, not your account identifier, not your email address and not your name. It is a tally like every other counter in this section, so it can say how many accounts were created on a given day and never which ones or whose.
Two of the 55 names, experiment_exposed and experiment_converted, are reserved for measuring a future comparison between two versions of a page. Neither is written today: no such comparison is running. The code that would decide which version to show you does so on our server, by hashing six values together: the name of the comparison, the calendar day in UTC, the list of versions being compared, your IP address, your browser's user-agent string and your Accept-Language header. The result is one version number. It is recomputed for each request, and neither the hash nor the version number is written to your device, stored in a counter row, or recorded in any table of ours.
Recomputing rather than storing does not by itself settle the legal question, and this policy will not pretend it does. Three of those six inputs, your IP address, your user-agent string and your Accept-Language header, reach us from your own equipment: the browser sends all three with the request, and the other three are ours. Paragraph 55 of the European Data Protection Board's Guidelines 2/2023 on the technical scope of Article 5(3) treats reading an IP address as inside the same rule that governs cookies unless it can be shown that the address did not come from the terminal equipment. That is why nothing here is switched on. Before any comparison runs, this section will say which of the six inputs it uses, on what legal footing, and whether it sits behind the choice in the cookie banner.
3. Legal Basis for Processing
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Account creation and authentication | Contract performance (6.1.b) |
| Study progress tracking and adaptive personalisation | Contract performance (6.1.b) |
| Subscription billing | Contract performance (6.1.b) |
| Security, abuse prevention, and fraud detection | Legitimate interest (6.1.f) |
| Marking delivered question text so a copied bank can be traced (Section 2.6) | Legitimate interest (6.1.f) |
| Our own anonymous usage counters (Section 2.17) | The stored aggregates are not personal data, so no Article 6 basis is claimed for them. Browser collection still waits for your optional analytics choice. |
| Optional analytics involving personal data, including Vercel measurements and third-party analytics (Section 8) | Consent (6.1.a) |
| Product usage events for signed-in users (Section 2.7) | Consent for optional browser events; legitimate interest for server-recorded service events |
| How you found us, signup attribution (Section 2.15) | Consent (Art. 6(1)(a) GDPR) |
| Study reminder emails to your account (Section 2.8) | Legitimate interest (Art. 6(1)(f) GDPR) |
| Employer job submissions and their moderation (Section 2.9) | Legitimate interest (Art. 6(1)(f) GDPR) |
| Saved CVs and expiry reminders, Pilot CV Pro (Section 2.13) | Contract performance (6.1.b) |
| Pilot job profile, saved jobs and application tracker (Section 2.10) | Contract performance (6.1.b) |
| Practice interview answers, transcripts and feedback reports (Section 2.14) | Contract performance (6.1.b) |
| Pilot job alert emails (Section 2.11) | Consent (Art. 6(1)(a) GDPR) |
| Reports about a job listing, and acting on them (Section 2.12) | Legal obligation 6(1)(c) (EU Digital Services Act), legitimate interest 6(1)(f) |
| Invoice retention | Legal obligation (6.1.c), EU tax law |
4. Data Sharing (Processors)
We share data only with the providers below, and only for the purpose named beside each one. We do not sell your personal data, and we do not share it with advertisers or marketing platforms.
What stands behind each of these arrangements, stated plainly. Where a provider publishes data protection terms as part of the account terms we accepted, those terms apply. We have not negotiated a separate, individually signed data processing agreement with any provider on this list. Two of the calls below are made to public endpoints with no account at all, and therefore under no agreement of any kind: the read-aloud text-to-speech call to Microsoft, and the password-safety lookup. Both say so in their own entry. An earlier version of this policy stated that every provider here was covered by a data processing agreement; that was not accurate, and this paragraph replaces it.
- Supabase (database, authentication, file storage): hosted in the EU region we selected at setup
- Vercel (application hosting and edge network): processes requests and may route through US edge locations under appropriate safeguards. Vercel also provides aggregated page counts and performance measurements for us (Vercel Web Analytics and Speed Insights), but these browser measurements load only after you accept analytics. Neither sets a cookie and neither stores anything on your device. For Web Analytics, Vercel's own privacy documentation says that end users are identified by a hash created from the incoming request and that the lifespan of a visitor session is automatically discarded after 24 hours. For Speed Insights, its documentation lists no visitor identifier. Web Analytics is an identifier, even though it is not an advertising or cross-site identifier.
- Upstash (rate limiting): receives only rate-limit keys (user ID and/or IP); configured in an EU region
- Cloudflare (Turnstile anti-abuse): processes IP and challenge data during registration
- Resend (transactional email, when configured): receives your email address and message content to deliver account and system emails; processed on Resend's infrastructure (US)
- Sentry (error monitoring): receives redacted diagnostic events with personal data stripped, from our servers always, and from your browser only if you accepted analytics in the cookie banner; configured in the EU (Frankfurt) region
- Stripe (payment processing, when paid plans are enabled): PCI DSS Level 1; US-based
- Plausible Analytics (EU-hosted): optional, cookieless site analytics. Our browser adapter sends pageviews and custom events to Plausible's Events API only after analytics consent. It does not load Plausible's remote script and omits page query strings, fragments and referrer addresses
- Microsoft (text-to-speech), used without an account and under no agreement: when you use the read-aloud feature, the text of the question being read is sent to Microsoft's Edge Read Aloud text-to-speech service to turn it into audio. Your identity, your answers and your account data are not sent with it. We reach that service the way a browser does, with no account, no API key and no agreement between us and Microsoft, so there is no data processing agreement and no Standard Contractual Clauses behind this transfer, and we would rather say so than imply a contract we do not hold. Read-aloud is optional and nothing is sent unless you use it.
- Have I Been Pwned (api.pwnedpasswords.com), password safety, used without an account and under no agreement: when you choose or change a password, our server takes a one-way SHA-1 digest of it and sends only the first five characters of that digest to this public lookup, which replies with every known breached-password ending that starts with those five characters so that the comparison happens on our side. The service therefore never receives your password, the rest of the digest, your name, your email or anything else identifying you, and it exists so that you cannot choose a password that already appears in a public breach corpus. Legal basis: our legitimate interest in account security (Art. 6(1)(f) GDPR). The service is operated by Superlative Enterprises Pty Ltd in Australia and, like the read-aloud call above, is used without an account, so no data processing agreement stands behind it.
- Anthropic (AI feedback, where offered): if you use an AI coaching feature, the text you type into it is processed by Anthropic's Claude API to generate feedback. Where the feature is spoken rather than typed (the practice interviews in Section 2.14), the same applies to the text your own browser produced from your speech: the text is sent, never the audio. Your name and email are not sent with it.
Only if you use an optional feature: if you sign in with Google, Google LLC (US) processes your sign-in. If community explanation videos are enabled and you view one, YouTube (Google LLC, US) or Vimeo (US) receives your browser request to load the embed. These features are off by default.
Live weather pages fetch public data from NOAA / aviationweather.gov using airport codes only; no personal data is sent to that source.
Airport maps
Airport maps embed OpenStreetMap. When your browser loads the map, it contacts OpenStreetMap services and sends network information such as your IP address and browser headers, together with the airport coordinates in the map request. This is separate from optional analytics and provides the map you request. OpenStreetMap controls its own service logs and any storage used inside its embedded page. See the OpenStreetMap Foundation Privacy Policy.
5. Data Retention
- Account and study data: retained while your account is active
- Product usage events (Section 2.7): 24 months, then deleted automatically by a scheduled job
- Anonymous usage counters (Section 2.17): kept indefinitely, and that is a decision rather than an oversight. A row is already the total for one whole day and it identifies nobody, so ageing it out would destroy the long-run trend the counters exist to show and would make no one any safer
- How you found us (Section 2.15): one record per account, kept while your account is active and erased with it in the same request
- Data-export files: when you request a copy of your data (Section 6.1), the file we generate is held in our storage so you can download it. The download link expires after 7 days. Scheduled cleanup targets file deletion after 30 days, and account deletion requests earlier cleanup. Failed storage cleanup may require a retry (Section 7)
- Email and job queue: the internal queue we use to send email and run background work keeps a record of each job, which for an email includes the recipient address. Successful jobs have the address removed as soon as they finish; every finished record, successful or failed, is deleted automatically 30 days after it last ran, and account deletion requests removal of records for your address; failed cleanup may require a retry
- Employer job submissions (Section 2.9): the hashed network address is erased after 90 days and the whole submission after 12 months, both by a scheduled job. That applies whether we published the vacancy or declined it; a published listing is a separate record and stays up until it closes or is taken down
- Reports about a job listing (Section 2.12): the hashed network address is erased after 90 days and the whole report after 12 months, by the same scheduled job that clears employer submissions. Where we acted on a report, the record that we removed a listing and why is kept on the listing itself, without anything identifying whoever told us
- Pilot job profile, saved jobs, application tracker and job alerts (Sections 2.10 and 2.11): kept while your account is active, and erased with your account in the same request. You can also delete any of them yourself at any time
- Practice interview answers, transcripts and feedback reports (Section 2.14): 12 months, then deleted automatically by a scheduled job, in both the ICAO English Pro mock interview and the Interview Room. The bare session record (its dates, and which of our written questions it used) is kept while your account is active so your remaining allowance stays correct; it contains none of your words. Everything is erased with your account in the same request
- Pilot aptitude scores saved to your account (Section 2.16): kept while your account is active, erased with your account in the same request, and deletable by you at any time from your aptitude progress page. The aggregate count of runs per exercise, level and score band that comparisons are drawn from holds no identifier and is not personal data, so it is kept
- Support correspondence: retained as needed to resolve your request and for audit/compliance records
- Offline local data: kept on your device until you clear it, clear browser storage, or the browser removes it
- Payment records: Stripe retains invoice records for the periods required by the tax and accounting rules applicable to those records; billing event logs we keep for reconciliation and fraud prevention do not contain a direct account identifier
- After account deletion: successful primary database deletion is permanent; separate storage and provider cleanup may take longer (Section 7). Content you posted inside a shared discussion (a reply on another user's comment, or forum threads and replies) may stay visible with your authorship anonymized, so conversations others took part in remain intact (see Sections 6.3 and 7)
6. Your Rights (GDPR)
Where the GDPR applies, you have the following rights, subject to its conditions and exceptions:
6.1 Right to Access & Portability (Art. 15 & 20)
You can request a copy of your personal data in a machine-readable format (JSON) using the data export feature in your account settings. The export covers your profile and the sign-in record we hold for your account, study history and answers, daily study statistics, study plans, your learning-progress model, spaced-repetition data, notes, flags, bookmarks, collections, gamification data including leaderboard entries, your community contributions and votes, reports, sightings, feedback, in-app notifications, subscription, entitlement and withdrawal records, your pilot job profile, saved jobs, applications and job alerts, ICAO English course progress and placements, your practice interview transcripts (Section 2.14), your saved pilot aptitude scores (Section 2.16), your saved CVs (Section 2.13), your marketing-email subscription record, and any note an administrator recorded about your account. If you need any data that is not included in the automated export, contact us at to2000bv@gmail.com and we will provide it.
6.2 Right to Rectification (Art. 16)
You can update your profile information at any time from your account settings.
6.3 Right to Erasure (Art. 17)
You can request account deletion from your account settings. Successful deletion of your account and primary database records is permanent and cannot be undone. Export your data first if you want a copy (Section 6.1). Subscription cancellation, payment-provider cleanup, stored export files and email-list cleanup may require separate steps or retries. Section 7 explains these limits.
6.4 Right to Restrict Processing (Art. 18)
You can request that we restrict processing of your data while a complaint is being investigated.
6.5 Right to Data Portability (Art. 20)
Covered by the export feature described in Section 6.1.
6.6 Right to Object (Art. 21)
You can object to processing based on legitimate interests, including the adaptive learning profiling described in Section 2.5. We will stop that processing unless we demonstrate compelling legitimate grounds; for adaptive profiling we simply serve questions without personalisation.
7. What Happens When You Delete Your Account
The account-purge process removes the following primary database records. Successful deletion is irreversible:
- your profile, answers, study sessions, learning-progress model, spaced-repetition data, notes, bookmarks, flags, collections, gamification data, and achievements;
- your community explanations, comments, votes, reports, exam sightings, public-page comments, public profile, and feedback;
- your forum votes and watched-thread subscriptions;
- your practice interview sessions, every answer you gave in them, and every feedback report written from them;
- the internal account records used to queue email, subject to any separate cleanup retry;
- your local subscription record. Cancellation and deletion at Stripe are separate operations and failed payment-provider cleanup is queued for retry.
One exception: content you posted inside a shared discussion may remain visible so the conversation stays intact, but it is unlinked from your account and shown as written by a former member rather than by you. This applies to a reply you left on another user's comment and to forum threads and replies you authored; forum content is anonymized rather than deleted, because a thread can contain other people's replies that would otherwise be lost. Administrative audit-log entries are kept with your identity removed, as required for security and accountability. Stripe invoice records are retained by Stripe under its own compliance policies.
The deletion process also requests removal from our marketing list and deletion of stored data-export files. Failures in these separate steps can delay completion. Export files normally expire after 30 days through scheduled cleanup; this is not a guarantee that every copy is erased immediately or that a failed cleanup job has already succeeded. Contact us if you need confirmation of completion. If you subscribed to study emails without creating an account, use the unsubscribe link in any email instead.
8. Cookies & Analytics
Essential cookies and on-device storage support login, security and the functions you request, including offline study. Preference values remember settings such as your chosen theme. The Cookie Policy lists these technologies and how to remove them.
Optional browser analytics is off until you accept it. This includes browser-initiated first-party counters, campaign attribution, browser product events, Vercel Web Analytics and Speed Insights, Plausible when configured, and Sentry browser error monitoring. These services collect different information: Sections 2.7, 2.15, 2.17 and 4 explain the distinctions, including Vercel's request-derived visitor identifier. Server-side service records, security logs and counts generated while processing account actions continue as described in those sections.
Use Cookie settings in the public footer or account Settings to reject optional analytics or change your choice. Withdrawing stops new browser measurements and removes the stored attribution copy; the page may reload to end a previously loaded script. Your choice is kept for up to 180 days. Acceptance of the Terms does not grant analytics consent.
9. Security
We protect your data through:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest (Supabase)
- Encrypted offline question storage on supported browsers
- Row-Level Security (RLS) on database tables
- Rate limiting on API endpoints
- Secure password hashing (via Supabase Auth)
- Stripe handles all payment data (PCI DSS Level 1)
Owner-only database policies restrict ordinary signed-in accounts. They do not prevent privileged backend services or database operators from accessing data for necessary operations, security or support. These access paths are distinct from ordinary staff accounts and are not a promise that no person could ever access a record.
10. Children's Privacy
SkyStudy is not intended for users under 16 years of age. We do not knowingly collect data from children under 16. If we learn that we have collected such data, we will delete it promptly.
11. International Transfers
Your data is primarily processed within the EU. Some providers operate in or route through countries outside it, including Stripe, Resend (email), Cloudflare (anti-abuse), Vercel's edge network, Microsoft (text-to-speech for read-aloud audio), Anthropic (AI feedback, where offered), the password-safety lookup in Section 4, and Google, YouTube or Vimeo if you use those optional features.
A provider's privacy policy alone is not a legal transfer safeguard. Where a restricted international transfer occurs, the applicable mechanism must be established for that provider and service, such as an applicable adequacy decision or contractual safeguards with any required supplementary measures. We cannot confirm a single mechanism covering all the services listed here. Contact us for the provider-specific information available. The read-aloud request carries question text and the password-safety lookup carries the five-character hash prefix described in Section 4.
12. Changes to This Policy
We will notify you of material changes via email or in-app notice at least 30 days before they take effect.
13. Contact & Complaints
Data protection questions: to2000bv@gmail.com
You have the right to lodge a complaint with your local data protection authority (for example, ANSPDCP in Romania, or any EU Member State supervisory authority).
EASA Study-Aid Disclaimer
SkyStudy is an independent study aid not affiliated with EASA, any national aviation authority, or any approved training organisation. See our Terms of Service for full details. Do not use SkyStudy for flight operations, dispatch, navigation, legal decisions, medical decisions, or any safety-critical purpose.