Privacy Policy

Last updated: 12 July 2026

PlaneEcho (“PlaneEcho”, “we”, “us”) provides a personalized aviation tracking service. This policy explains what personal data we collect, why, and your rights over it. It applies to the PlaneEcho web app and any iOS/Android wrapper of it.

1. Who we are

The data controller is Riley Coleman, operating PlaneEcho as a sole trader based in the United Kingdom. For any privacy question or request, contact rileyq12@gmail.com.

2. Data we collect

  • Account data — your email address and authentication identifiers, handled by our auth provider (Supabase).
  • Home location — the home coordinates and watch radius you set during onboarding. This defines the default area we monitor for you.
  • Live location (“Follow me”) — if enabled, the app periodically reads your device’s live GPS position (roughly every 30 seconds while the app is open) so alerts can follow you instead of your fixed home point. This is on by default — you can turn it off at any time in Settings, after which we use your home point only. Live position is overwritten on each update; we do not keep a location history/trail from this feature.
  • Usage & preference data — your alert rules, watchlist, filters, settings, and the implicit signals you generate (which alerts you tap, dismiss, or rate). These train the personalization model that decides what to surface.
  • Sighting history — records of aircraft observed in your configured area, derived from public ADS-B feeds, associated with your account.
  • Photos you upload — stored privately and associated with your account. If your device embeds GPS coordinates in a photo’s metadata (EXIF), we store those coordinates too, since they may be more precise than your home or live location. Please don’t upload photos of identifiable people without their consent.
  • Push subscriptions & device identifiers — the browser/device push endpoint and keys (web push), or the device token (iOS/Android app push), needed to deliver notifications you opt into.
  • Billing data — if you subscribe, payment is processed by Stripe. We store a Stripe customer reference and subscription status; we never see or store your card number.
  • Diagnostics — if error monitoring is enabled, technical error/crash data (which may include a pseudonymous internal account ID, but not your email or content) to keep the service working.

3. Aircraft data

Aircraft positions come from public ADS-B data sources (e.g. OpenSky, adsb.lol, ADSBexchange). This is information broadcast publicly by aircraft transponders and is not personal data about you. When fetching this data we send only a bounding box of coordinates to these sources — never your account identity.

4. How we use your data

  • To operate the service: monitor your area, score aircraft, and send alerts you opt into.
  • To personalize what we surface, using your explicit and implicit feedback.
  • To process subscriptions and prevent abuse.
  • To diagnose and fix problems, and improve the product.

Our legal bases (UK GDPR Art. 6) are: performance of our contract with you (running the service you signed up for); your consent, which you can withdraw at any time (live location, push notifications); and our legitimate interests in securing the service and diagnosing faults, balanced against your rights.

5. Sharing & processors

We do not sell your personal data. We share it only with processors that help run the service:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting.
  • Stripe — payment processing (subscribers only).
  • Upstash (QStash) — queues background alert-processing jobs; receives your internal account ID and aircraft data already fetched for your area, not your email or billing details.
  • Push services — your browser/OS push provider (or Apple/Google push services for the app), to deliver notifications.
  • Groq, via the Vercel AI Gateway — if you enable AI-written alert copy/digests, aircraft and flight facts (type, operator, route, altitude, why it was flagged) are sent to generate the text. We do not send your email, location, or billing data to this processor.
  • Sentry — if error monitoring is enabled, receives crash/error diagnostics to help us fix bugs.

Some of these processors may transfer data outside the UK/EEA in the course of providing their service; where they do, they rely on their own approved safeguards (such as Standard Contractual Clauses). Contact us if you’d like details on a specific processor’s transfer mechanism.

6. Retention

We keep account data while your account is active. Flight-history “track” detail is deleted after 60 days; behavioral event logs (taps/dismissals used for personalization) are deleted after 180 days. Other sighting and alert records are retained to power your history and may be trimmed over time. To delete your account and the personal data associated with it, contact rileyq12@gmail.com (subject to any legal retention obligations, e.g. billing records) — we’re working on in-app self-service deletion.

7. Your rights

Under UK GDPR, you have the right to: access the personal data we hold about you; correct inaccurate data; request erasure; restrict or object to processing; receive your data in a portable format; and withdraw consent at any time where we rely on consent (this does not affect processing already carried out). You can turn off live location or push notifications at any time in Settings or your browser/OS. To exercise any of these rights, contact rileyq12@gmail.com. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk) if you think we’ve mishandled your data.

8. Children

PlaneEcho is not directed at children under 13 (or the minimum age in your jurisdiction).

9. Changes

We may update this policy; we will revise the date above and, for material changes, notify you in-app.

See also our Terms of Service.