Privacy Policy
Last updated: 13 August 2026
the individual operator of SkyStudy, established in Romania and identified on the Legal Notice page (“we”, “us”, or “our”) operates the SkyStudy ATPL platform. This Privacy Policy explains how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data, in the sense of Article 4(7) GDPR, is the individual operator of SkyStudy, established in Romania and identified on the Legal Notice page. SkyStudy is a brand name, not a legal person, so the controller is the trader operating it.
The controller's full identification and establishment details are on our Legal Notice page. For any data protection matter, contact: to2000bv@gmail.com.
We have not appointed a Data Protection Officer. Article 37 GDPR requires one only where processing is carried out by a public authority, where the core activity is large-scale regular and systematic monitoring, or where the core activity is large-scale processing of special-category data, and none of those applies here. You can raise any data protection matter at the address above.
2. Data We Collect
2.1 Account Data
- Email address: for authentication and communications
- Display name: for your profile
- Password: handled by our authentication provider (Supabase Auth) and stored only as a secure hash; we never see or store it in plain text
- Profile information: licence type, target exam date, and the subjects on your study track
- Sign-in with Google (optional): if you choose Google sign-in (when enabled), we receive your email address, name, and profile picture URL from Google
- Communication preferences: your email reminder and unsubscribe choices
- Marketing email opt-in (optional): if you submit your email to receive study tips or a free download, we store your email address together with the date, time, and IP address of your consent and how you reached us. You can unsubscribe at any time; once you have unsubscribed, re-submitting the form will not silently put you back on the list
- Support correspondence: messages you send us about billing, access, or content issues
When you create an account we also record the date, time, and version of the Terms of Service you accepted, together with your confirmation that you are at least 16 years old.
2.2 Study Data
- Question answers: your responses to practice and exam questions, with timing and correctness
- Study sessions: mode, duration, subject, and score
- Learning-progress model: a per-topic estimate of your knowledge and weak areas, used by the adaptive engine (see Section 2.5)
- Spaced-repetition data: review scheduling state for questions you study
- Personal notes, bookmarks, flags, and collections: items you save, tag, or organise
- Gamification data: XP, level, streaks, and achievements
- Analytics data: computed accuracy, streaks, and study time (derived from the above)
- Offline study data: downloaded question packs, pending offline answers, and offline sync metadata stored on your device
2.3 Community Content (when you use it)
- Explanations, comments, and replies you post on questions
- Votes, reports, and exam sightings you submit
- Public-page comments you post on public pages (visible to other visitors)
- Community forum threads and replies you post, which are public: readable by anyone without an account and indexable by search engines. Forum posts show your community display name, never your real name.
- Public community profile (display name, optional bio) if you opt in to make it public
- Feedback you submit about the product
Staff replies in community areas may be drafted with AI assistance and are labelled accordingly. When we prepare such a reply, the text of your public comment may be processed with AI tools; nothing beyond the public content and display name already visible on your comment is shared.
2.4 Payment Data
- Stripe Customer ID: links your account to Stripe for billing
- Subscription status and plan: stored for access control
- Payment details: handled entirely by Stripe; we never store card numbers
- Billing event records: a log of Stripe webhook events, kept for reconciliation and fraud prevention
The ATPL subscription plans are not switched on yet, so no subscription billing data is created. Payment data is created when you buy a feature that is sold separately, such as the ICAO English Pro course. Card details are entered on Stripe's own checkout and are never seen or stored by us. Where you agree at checkout to give up the 14-day withdrawal right, the wording you agreed to and the time you agreed to it are stored with your purchase record, because we have to be able to show what you consented to.
2.5 Adaptive Learning Profile (automated processing)
When the adaptive study engine is enabled, every answer you give in practice and exam mode feeds a model that estimates your ability per learning objective (a per-topic mastery rating with a confidence value), classifies each topic (for example “learning”, “weak”, “proficient”, “mastered”), and predicts your accuracy. This is automated profiling of your learning performance. We use it only to personalise your study, to show your weak areas, and to choose which questions to serve you next so you learn faster. It has no legal or similarly significant effect on you, it never determines pricing or access, and there is no automated decision-making about you in the sense of Article 22 GDPR. You can object to this profiling (see Section 6.6); if you do, we serve questions without adaptive personalisation.
2.6 Technical Data
- IP address: used transiently as a key for rate limiting and abuse prevention, and not otherwise stored in our database in normal use. Two exceptions: if you opt in to marketing emails we record the IP address at the moment of consent as part of the consent record (proof of consent), and IP ranges may be recorded in an abuse blocklist if an administrator blocks them
- Device/browser info: for compatibility, debugging, and, if you enable push notifications, to deliver them
- Usage analytics: aggregate, cookieless usage measurement of the public site (see Section 8). No cross-site tracking. Product usage events inside your account are covered separately in Section 2.7
- Error telemetry: redacted runtime errors if error monitoring (Sentry) is configured in production. IP address, email, headers, cookies, and request bodies are stripped before any event is sent
- Anti-abuse checks: Cloudflare Turnstile verification during registration; your IP and a challenge token are processed by Cloudflare for bot detection
We do not collect or store your timezone, and we do not use advertising or cross-site tracking cookies.
2.7 Product Usage Events (signed-in users)
When you are signed in, we record a small, fixed set of product milestones so we can see where the app is failing people. For example: that you opened the setup wizard, which step you reached, that you started a practice session, and that you answered your first question. Each record contains only your account identifier, an event name taken from a fixed internal list, a few short technical values such as a step number or a question count, and a timestamp.
- Purpose: to find and fix the points where the product loses people, and to check whether a change actually improved things
- Legal basis: our legitimate interest in operating and improving the Service (Art. 6(1)(f) GDPR)
- Retention: 24 months, after which the records are deleted automatically. They are also erased immediately if you delete your account
- What is never recorded here: your IP address, your browser's user-agent string, your location, and any free text you have typed. Device information, if recorded at all, is limited to a broad category such as mobile, tablet, or desktop
- Where it stays: in our own database only. These records are never shared with a third party, never sold, never used for advertising, and never linked to your activity on any other website
These records are included in your data export (Section 6.1), and you can object to this processing at any time under Section 6.6.
2.8 Study Reminder Emails
If you have answered at least one practice question and then go a few days without studying, we may send you one email offering to pick up where you left off, with a link straight to your next question. We send it because you signed up to study for an exam with a deadline, and a short nudge is the only way to reach you once you have stopped opening the app.
- Who gets it: only accounts that have actually answered a question and have not studied for one to three days. If you have never answered a question, you are never sent this email
- Legal basis: our legitimate interest in helping learners who chose our service keep going with it (Art. 6(1)(f) GDPR). We assessed this against your interests before switching it on, and the limits below are the result
- How often: at most one email per break in your studying, so if you stop and do not come back, you get one email and nothing more. Never more than four in any 30 days, and never more than one in a day
- How to stop it: a switch in your settings turns study reminders off on their own and leaves everything else alone, and every email carries a one-click unsubscribe that stops all optional email. Both take effect immediately
- What it never does: it does not profile you, score you, or read anything you have written. Whether you get it is decided by two dates and whether you have ever answered a question
You can object to this processing at any time under Section 6.6, and turning the setting off is the fastest way to exercise that.
2.9 Employer Job Submissions (no account needed)
If you propose a pilot vacancy through our posting form, we collect the details you type in: the company name and website, your name, your work email address, and the vacancy itself. You do not need an account, so this is the only thing we hold about you.
- Why we need the email address: we send a confirmation link to it, and a submission that is never confirmed is never reviewed. We then use the same address to tell you what we decided and to ask you about the vacancy if we need to
- Network address: we store a keyed hash of the address the submission came from, never the address itself. It exists only to spot a flood from one origin, and it cannot be turned back into an address without a key we hold separately
- Automated checks: before a person reads it, the submission goes through fixed rules (does the contact domain match the company, is the apply link on a plausible host, does this duplicate a live listing) and an automated content screen that looks for known recruitment-scam patterns in the advert text you wrote. The text you wrote, and nothing else about you, is sent to Anthropic's Claude API for that screen; your name, your email address and the network hash are not
- No automated decision: those checks only flag a submission for a person. They never publish it, never refuse it, and never rank it. A person makes every decision, and Art. 22 GDPR is therefore not engaged
- Legal basis: our legitimate interest in running a moderated job board and in keeping fraudulent vacancies away from pilots (Art. 6(1)(f) GDPR)
- How long: the network hash is erased after 90 days and the whole submission after 12 months, both automatically. You can ask us to erase yours sooner at any time
A published listing shows the vacancy and the operator. It does not show your name, your email address, or anything else about you.
2.10 Your Pilot Job Profile, Saved Jobs and Applications
If you use the pilot jobs board while signed in, you can fill in a career profile so the board can tell you which vacancies you already meet. This is entirely optional. The board works without it, and nothing is created until you fill something in.
- What it holds: flying hours (total, pilot in command, multi-engine, turbine, instrument), the licences you hold, your type ratings, your medical class and its expiry date, your ICAO English level, your languages, the countries or blocs where you have the right to work, whether you will relocate, and which regions interest you
- What it does NOT hold: your date of birth. We do not collect your age and we never apply an age criterion to you. Where an operator states one, we show it attributed to them and exclude it from the match entirely (see Section 2.9 and our Terms, section 6.3)
- Your medical certificate: we store the CLASS and the expiry date only, because that is what a vacancy states as a requirement. We do not ask for and do not hold any medical finding, diagnosis, condition, or examiner's report, so we hold no health data within the meaning of Art. 9 GDPR
- Saved jobs and your application tracker: the vacancies you save, and the applications you choose to record with their status and your own notes
- Where the match is calculated: in your own browser, not on our server. The public vacancy pages are cached and served the same to everybody; your profile is fetched by your browser and compared there. Nobody else can see your match, and the operator is never told you looked
- Who can see it: only you. These four records are protected by row-level security with owner-only policies and no administrator read access at all. A SkyStudy staff account querying them through an ordinary session sees zero rows, by design
- Legal basis: performance of the contract you have with us for the Service (Art. 6(1)(b) GDPR). You asked for the feature by filling it in
- No automated decision: the match is a count of requirements you meet, shown to you. It decides nothing, is never sent to an operator, and never affects anything else about your account. Art. 22 GDPR is not engaged
- How long: for as long as your account exists. All four records are erased with your account in the same request
2.11 Pilot Job Alert Emails (opt-in)
You can ask us to email you when new vacancies match a search you saved. This is off until you switch it on, and there are two independent ways to switch it off again.
- What we process: the search you saved, your email address, and when we last wrote to you about it, so we only ever send what is new since the last email
- Legal basis: your consent (Art. 6(1)(a) GDPR). You give it by creating an alert, and you can withdraw it at any time without giving a reason and without affecting anything else
- Two-tier opt-out: every alert email carries a one-click link that stops that one saved search without a login, and your settings page carries a single switch that stops all pilot job email at once. Turning off all optional email in your account settings also stops them. Any one of the three is enough
- We do not send an empty alert: if nothing new matches, no email goes out
- How long: until you delete the alert or your account. Alerts are erased with your account in the same request
2.12 Reports About a Job Listing (no account needed)
Every vacancy page has a “Report this listing” control. Anyone can use it, including people who have never used SkyStudy, because the EU Digital Services Act requires that route to be open to everyone.
- What we collect: the listing you are reporting, the category you picked, what you wrote, and a keyed hash of the network address it came from. Nothing else
- Your email address is optional: we ask for it only so we can tell you what we decided or ask you one question. Leaving it blank does not make the report count for less. The law makes it optional except for an intellectual-property claim, and we would rather hear about a fake vacancy anonymously than not at all
- We never tell the advertiser who reported them. Not their name, not their address, not the wording that would identify them
- No automated takedown: a report flags a listing for a person. It cannot hide or remove anything by itself. A person reads every one and decides
- Legal basis: our legal obligation under the Digital Services Act to operate a notice-and-action mechanism (Art. 6(1)(c) GDPR), and our legitimate interest in keeping fraudulent vacancies away from pilots (Art. 6(1)(f) GDPR)
- How long: the network hash is erased after 90 days and the whole report after 12 months, automatically
2.13 Saved CVs and Expiry Reminders (Pilot CV Pro)
The Pilot CV Maker is free and works entirely in your browser: unless you buy Pilot CV Pro and choose to save a version, nothing you type into it ever reaches us. If you do buy it and save a version, we store the text of that CV on your account so it is there on your other devices.
- What we store: the CV text you saved, and the name you gave that version. Never your photo. If your CV has one, it is removed before the CV is stored and it stays on your own device
- Who can read it: you. The table is restricted to its owner at the database level, and there is no staff-facing screen that shows anyone else's CV
- Expiry reminders are off until you switch them on: buying the product does not subscribe you to anything. When they are on, we email you if a medical, ICAO English validity or type rating in your saved CV moves inside its warning window, and again if it lapses
- Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR). Expiry reminders are a listed feature of what you bought, which is what makes this different from the study reminder in Section 2.8
- How often: at most one email per change in what is expiring, and never more than one in seven days. Sitting inside a warning window does not produce a second email
- How to stop it: the switch in the CV builder turns reminders off on their own, and every email carries a one-click unsubscribe that stops all optional email. Both take effect immediately
- What it never does: we do not check any of these dates against a licensing authority, we cannot confirm that any of them are correct, and we never share them with an airline, a recruiter or anyone else. Everything we hold is what you typed in
- How long: until you delete the version or your account. Deleting a saved version does not delete the record that you applied somewhere with it; that record simply stops naming a CV
2.14 Practice Interview Answers and Transcripts
Two paid features run a practice interview and record what you said: the mock interview inside ICAO English Pro, and the Interview Room (its technical oral and its airline interview). Both keep a written transcript of the session on your account, so this section says plainly what is stored, where it goes, and for how long.
- What we store: for every question in the session, the question the examiner asked and your answer in full, in your own words, with the time you answered it. We also store the written feedback report produced at the end, which quotes parts of your answers back to you as the evidence for what it says
- Why this section exists separately: an interview answer is not like an answer to an exam question. It is you describing your own career, the times something went wrong for you, the operators you have flown for, and why you left them. We hold it because you asked for feedback on it, and it deserves to be described rather than folded into “study data”
- Your voice is never recorded or uploaded: if you speak your answer rather than typing it, the speech-to-text happens inside your own browser, using the speech recognition your browser already provides. No audio of you is sent to us, stored by us, or sent to anyone else, and we could not produce a recording of you if we were asked for one. What leaves your browser is the text your browser produced, which you can see and correct on screen before you submit it
- What we measure about how you sounded: in the ICAO English Pro mock interview only, and only when you speak rather than type, your browser also measures the sound of your answer while you give it: how long you spoke for, where your pauses fell and how long they were, how quickly the syllables came, how much your pitch moved, and how much background noise your microphone picked up. All of that happens on your device and none of it involves keeping any audio: your browser reads the microphone, reduces each fraction of a second to a handful of numbers, and throws the sound away. What is stored is about a dozen numbers describing the whole answer. They are averages and counts, they cannot be turned back into sound, they are not a voiceprint, and they cannot be used to recognise you or to tell you apart from anybody else. We measure them because fluency and pronunciation are two of the six things an ICAO language rating is scored on and neither of them is visible in the text, and because a noisy recording has to be detectable: where it is too noisy to judge we say nothing about your pronunciation rather than guess at it. They are kept, exported and deleted on exactly the same rules as the rest of this section
- Where the text goes: to us, and, at the end of the session only, to Anthropic's Claude API to write the feedback report (see Section 4). Your name and your email address are not sent with it. Nothing is sent to any airline, recruiter, training organisation or examiner, ever
- Who can read it: you. Both tables are restricted to their owner at the database level, with no administrator read access at all, and there is no staff-facing screen that shows anyone else's interview
- Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR). The practice interview and its feedback are what you bought
- Retention: 12 months, then your answers and the report quoting them are deleted automatically by a scheduled job. What is kept after that is the bare record that a session happened: its dates, and which of our written questions it used, so your remaining allowance stays correct and so a later interview does not ask you the same questions again. That record contains none of your words
- Getting a copy, and getting rid of it sooner: your transcripts are included in the data export in Section 6.1, so you can keep your own copy before the 12 months run out. Deleting your account deletes every transcript and report immediately, along with everything else
The report is written feedback on one practice session. It is not a mark, not an assessment, and it does not predict how any real interview or selection process will go. Nothing about it is shared with anyone.
2.15 How You Found Us (signup attribution)
When you create an account we store, once, the campaign tags that were on the link you first arrived through. These are the utm_source, utm_medium, utm_campaign, utm_content and utm_term values that a link carries in its own web address, plus the page on our site you first landed on and the address of the site that linked you. If you arrived without any of that, we store nothing at all. We keep it so we can tell which of the places we post actually brings people here, instead of guessing from view counts.
- Purpose: to know which channels bring learners to the Service, so we stop spending effort on the ones that do not
- Legal basis: our legitimate interest in understanding how people reach the Service (Art. 6(1)(f) GDPR)
- First touch only: one record per account, written when the account is created and never updated afterwards
- What is never recorded here: your IP address, your browser's user-agent string, your location, and any free text you have typed. There is no cookie or identifier here that could follow you to another website
- How long: while your account exists. It is erased with your account, in the same request
- Where it stays: in our own database only. It is never shared with a third party, never sold, and never used for advertising
This record is included in your data export (Section 6.1), and you can object to this processing at any time under Section 6.6.
3. Legal Basis for Processing
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Account creation and authentication | Contract performance (6.1.b) |
| Study progress tracking and adaptive personalisation | Contract performance (6.1.b) |
| Subscription billing | Contract performance (6.1.b) |
| Security, abuse prevention, and fraud detection | Legitimate interest (6.1.f) |
| Usage analytics (aggregate, cookieless) | Consent (6.1.a), where requested |
| Aggregated, cookieless page metrics (Vercel) | Legitimate interest (Art. 6(1)(f) GDPR) |
| Product usage events for signed-in users (Section 2.7) | Legitimate interest (Art. 6(1)(f) GDPR) |
| Study reminder emails to your account (Section 2.8) | Legitimate interest (Art. 6(1)(f) GDPR) |
| How you found us, signup attribution (Section 2.15) | Legitimate interest (Art. 6(1)(f) GDPR) |
| Employer job submissions and their moderation (Section 2.9) | Legitimate interest (Art. 6(1)(f) GDPR) |
| Saved CVs and expiry reminders, Pilot CV Pro (Section 2.13) | Contract performance (6.1.b) |
| Pilot job profile, saved jobs and application tracker (Section 2.10) | Contract performance (6.1.b) |
| Practice interview answers, transcripts and feedback reports (Section 2.14) | Contract performance (6.1.b) |
| Pilot job alert emails (Section 2.11) | Consent (Art. 6(1)(a) GDPR) |
| Reports about a job listing, and acting on them (Section 2.12) | Legal obligation 6(1)(c) (EU Digital Services Act), legitimate interest 6(1)(f) |
| Invoice retention | Legal obligation (6.1.c), EU tax law |
4. Data Sharing (Processors)
We share data only with the processors below, under data processing agreements. We do not sell your personal data, and we do not share it with advertisers or marketing platforms.
- Supabase (database, authentication, file storage): hosted in the EU region we selected at setup
- Vercel (application hosting and edge network): processes requests and may route through US edge locations under appropriate safeguards. Vercel also provides cookieless, aggregated page metrics for us (Vercel Web Analytics and Speed Insights). These run without cookies or cross-site identifiers and store nothing on your device; we rely on our legitimate interest in operating and improving the Service.
- Upstash (rate limiting): receives only rate-limit keys (user ID and/or IP); configured in an EU region
- Cloudflare (Turnstile anti-abuse): processes IP and challenge data during registration
- Resend (transactional email, when configured): receives your email address and message content to deliver account and system emails; processed on Resend's infrastructure (US)
- Sentry (error monitoring, when configured): receives redacted diagnostic events with personal data stripped; configured in the EU (Frankfurt) region
- Stripe (payment processing, when paid plans are enabled): PCI DSS Level 1; US-based
- Plausible Analytics (EU-hosted): optional, cookieless site analytics that loads only if you accept analytics in the cookie banner
- Microsoft (text-to-speech): when you use the read-aloud feature, the text of the question being read is sent to Microsoft's text-to-speech service to generate the audio. Your identity, answers, and account data are not sent with it.
- Anthropic (AI feedback, where offered): if you use an AI coaching feature, the text you type into it is processed by Anthropic's Claude API to generate feedback. Where the feature is spoken rather than typed (the practice interviews in Section 2.14), the same applies to the text your own browser produced from your speech: the text is sent, never the audio. Your name and email are not sent with it.
Only if you use an optional feature: if you sign in with Google, Google LLC (US) processes your sign-in. If community explanation videos are enabled and you view one, YouTube (Google LLC, US) or Vimeo (US) receives your browser request to load the embed. These features are off by default.
Live weather pages fetch public data from NOAA / aviationweather.gov using airport codes only; no personal data is sent to that source.
5. Data Retention
- Account and study data: retained while your account is active
- Product usage events (Section 2.7): 24 months, then deleted automatically by a scheduled job
- How you found us (Section 2.15): one record per account, kept while your account is active and erased with it in the same request
- Data-export files: when you request a copy of your data (Section 6.1), the file we generate is held in our storage so you can download it. The download link expires after 7 days and the file itself is deleted automatically after 30 days, or straight away if you delete your account before then
- Email and job queue: the internal queue we use to send email and run background work keeps a record of each job, which for an email includes the recipient address. Successful jobs have the address removed as soon as they finish; every finished record, successful or failed, is deleted automatically 30 days after it last ran, and the records for your address are deleted immediately if you delete your account
- Employer job submissions (Section 2.9): the hashed network address is erased after 90 days and the whole submission after 12 months, both by a scheduled job. That applies whether we published the vacancy or declined it; a published listing is a separate record and stays up until it closes or is taken down
- Reports about a job listing (Section 2.12): the hashed network address is erased after 90 days and the whole report after 12 months, by the same scheduled job that clears employer submissions. Where we acted on a report, the record that we removed a listing and why is kept on the listing itself, without anything identifying whoever told us
- Pilot job profile, saved jobs, application tracker and job alerts (Sections 2.10 and 2.11): kept while your account is active, and erased with your account in the same request. You can also delete any of them yourself at any time
- Practice interview answers, transcripts and feedback reports (Section 2.14): 12 months, then deleted automatically by a scheduled job, in both the ICAO English Pro mock interview and the Interview Room. The bare session record (its dates, and which of our written questions it used) is kept while your account is active so your remaining allowance stays correct; it contains none of your words. Everything is erased with your account in the same request
- Support correspondence: retained as needed to resolve your request and for audit/compliance records
- Offline local data: kept on your device until you clear it, clear browser storage, or the browser removes it
- Payment records: invoice records are retained by Stripe for 7 years per EU tax requirements; billing event logs we keep for reconciliation and fraud prevention do not contain a direct account identifier
- After account deletion: your personal data is permanently erased immediately, except that content you posted inside a shared discussion (a reply on another user's comment, or forum threads and replies) may stay visible with your authorship anonymized, so conversations others took part in remain intact (see Sections 6.3 and 7)
6. Your Rights (GDPR)
As an EU resident, you have the following rights:
6.1 Right to Access & Portability (Art. 15 & 20)
You can request a copy of your personal data in a machine-readable format (JSON) using the data export feature in your account settings. The export covers your profile, study history and answers, your learning-progress model, spaced-repetition data, notes, flags, bookmarks, collections, gamification data, your community contributions, reports, sightings, feedback, subscription metadata, and your practice interview transcripts (Section 2.14). If you need any data that is not included in the automated export, contact us at to2000bv@gmail.com and we will provide it.
6.2 Right to Rectification (Art. 16)
You can update your profile information at any time from your account settings.
6.3 Right to Erasure (Art. 17)
You can delete your account from your account settings. Deletion is immediate and permanent: there is no grace period and it cannot be undone. We recommend exporting your data (Section 6.1) first if you want to keep a copy. When you delete your account:
- any active subscription is cancelled and your Stripe customer record is removed;
- you are signed out; and
- your personal data is permanently erased straight away.
Some data is retained only where the law requires it (for example, Stripe keeps invoice records for tax purposes for up to 7 years on its own systems). See Section 7 for exactly what is deleted and what survives anonymised.
6.4 Right to Restrict Processing (Art. 18)
You can request that we restrict processing of your data while a complaint is being investigated.
6.5 Right to Data Portability (Art. 20)
Covered by the export feature described in Section 6.1.
6.6 Right to Object (Art. 21)
You can object to processing based on legitimate interests, including the adaptive learning profiling described in Section 2.5. We will stop that processing unless we demonstrate compelling legitimate grounds; for adaptive profiling we simply serve questions without personalisation.
7. What Happens When You Delete Your Account
Deletion is immediate and irreversible. The following is permanently deleted right away:
- your profile, answers, study sessions, learning-progress model, spaced-repetition data, notes, bookmarks, flags, collections, gamification data, and achievements;
- your community explanations, comments, votes, reports, exam sightings, public-page comments, public profile, and feedback;
- your forum votes and watched-thread subscriptions;
- your practice interview sessions, every answer you gave in them, and every feedback report written from them;
- any data-export file we still hold for you, and any record of your email address in our internal email queue;
- your local subscription record; your Stripe customer is deleted, which cancels any remaining subscriptions.
One exception: content you posted inside a shared discussion may remain visible so the conversation stays intact, but it is unlinked from your account and shown as written by a former member rather than by you. This applies to a reply you left on another user's comment and to forum threads and replies you authored; forum content is anonymized rather than deleted, because a thread can contain other people's replies that would otherwise be lost. Administrative audit-log entries are kept with your identity removed, as required for security and accountability. Stripe invoice records are retained by Stripe under its own compliance policies.
Deleting your account also removes your email address from our marketing list if it was on it. If you subscribed to study emails without creating an account, use the unsubscribe link in any email instead.
8. Cookies & Analytics
We use essential cookies and on-device storage for authentication, security, and account session management, plus a small set of preference values (such as theme and resume state) stored in your browser. These are strictly necessary or set only when you change a setting, and do not require consent under GDPR.
Where usage analytics are enabled, we use a cookieless, privacy-focused analytics service that measures aggregate usage only. It sets no cookies and does not track you across sites. Where we ask for your consent to analytics, you can decline, and you can change your choice later from the cookie banner or your in-app settings.
That third-party analytics service measures the public site only. Separately, and inside your account, we record the product usage events described in Section 2.7. Those are stored in our own database rather than sent to an analytics vendor, they set no cookies and use no cross-site identifier, and unlike the aggregate site measurement above they are linked to your account so we can see where a signed-in learner gets stuck. They run on legitimate interest, not consent, and you can object under Section 6.6.
Offline mode uses IndexedDB, service workers, and browser cache storage on your device. See our Cookie Policy for the full list of cookies and browser storage and how to clear it.
9. Security
We protect your data through:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest (Supabase)
- Encrypted offline question storage on supported browsers
- Row-Level Security (RLS) on database tables
- Rate limiting on API endpoints
- Secure password hashing (via Supabase Auth)
- Stripe handles all payment data (PCI DSS Level 1)
10. Children's Privacy
SkyStudy is not intended for users under 16 years of age. We do not knowingly collect data from children under 16. If we learn that we have collected such data, we will delete it promptly.
11. International Transfers
Your data is primarily processed within the EU. Some processors operate in or route through the United States, including Stripe, Resend (email), Cloudflare (anti-abuse), Vercel's edge network, Microsoft (text-to-speech for read-aloud audio), and Anthropic (AI interview coaching, where offered), and Google/YouTube/Vimeo if you use those optional features. Where data is transferred outside the EU, it is protected by EU Standard Contractual Clauses (SCCs) or an equivalent safeguard under each provider's data processing agreement.
12. Changes to This Policy
We will notify you of material changes via email or in-app notice at least 30 days before they take effect.
13. Contact & Complaints
Data protection questions: to2000bv@gmail.com
You have the right to lodge a complaint with your local data protection authority (for example, ANSPDCP in Romania, or any EU Member State supervisory authority).
EASA Study-Aid Disclaimer
SkyStudy is an independent study aid not affiliated with EASA, any national aviation authority, or any approved training organisation. See our Terms of Service for full details. Do not use SkyStudy for flight operations, dispatch, navigation, legal decisions, medical decisions, or any safety-critical purpose.