Privacy policy
This policy explains what personal data FlightFrame collects through the iOS app, your FlightFrame frames, the FlightFrame service behind them and this website, why we collect it, who else handles it, and the choices you have.
Last updated 3 October 2026
Who we are
FlightFrame is provided by Miradouro LLC (“we”, “us”). Miradouro LLC is the controller of your personal data under the EU General Data Protection Regulation (GDPR).
For anything about your data, write to support@flightframe.io.
In short
- Everything in the app needs an account. You sign in with Apple or Google, or with an email address and password if FlightFrame set up your account for you. There is no guest, preview or demo mode.
- There is no advertising, no tracking across other apps or websites, and no third-party analytics in the app or on this website. When the app crashes or runs into a problem, it sends a diagnostic report to our own server so we can fix it. We don’t sell your data.
- The app doesn’t track where you are. You tell us where each frame hangs, and we keep that point rounded to about a kilometre. The app uses the camera only to scan your frame’s setup code, and Bluetooth only to find and set up your frame.
- Your Wi-Fi password goes from your iPhone to your frame over an encrypted Bluetooth connection. It never reaches our servers.
- You can delete your account and its data in the app at any time.
What we collect and why
Your account
When you sign in, Apple or Google confirms who you are and shares an account identifier and your email address with us. With Sign in with Apple, the app asks only for your email address, which can be a private relay address if you choose to hide yours. With Google, Google also shares your name and a link to your profile picture; our sign-in provider stores these with your account, but the app doesn’t use them. Your FlightFrame account has its own random ID.
If FlightFrame set up your account for you, for example an account for Apple’s app review, you sign in with the email address and password we gave you instead. We keep that email address; our sign-in provider keeps only a one-way hash of the password, never the password itself.
We use this to create and secure your account, to link your frames, artwork and purchases to it, and to contact you about your account when we need to. The app keeps your sign-in session in your iPhone’s Keychain, on that device only.
Your profile photo, if you add one
You choose a photo with the iOS photo picker, so the app never has access to your photo library. Before uploading, the app resizes the photo to a 512 × 512 pixel JPEG and discards its metadata, such as where it was taken. It is stored privately, and only your account can read it. You can replace it at any time; to remove it without deleting your account, email us.
Your frames
- Device details. Each frame’s network hardware (MAC) address, its screen orientation and a secret credential it uses to reach us. We store only a one-way hash of the credential, never the credential itself.
- The area it watches. A point (latitude and longitude), a radius and an airport. We set them from your order when we prepare your frame. In the app you can change the point, the radius and, with Plus, the airport. We store the point rounded to two decimal places, about a kilometre. When you search for a place for your frame, Apple Maps receives what you type, and when the app shows a place name for your frame, Apple Maps receives the frame’s rounded point. Because a frame usually watches the sky above its home, we treat the point as personal data. When a frame leaves your account, we delete its point and reset its name, so the frame’s next owner never sees them.
- Your settings. The frame’s name, which flights it collects (overhead, arrivals, departures or all), any aircraft filter, the artwork style, whether collection is on, whether larp mode is on, and which artwork it is holding.
- Check-ins. When the frame checks in, it reports its battery voltage, Wi-Fi signal strength, firmware version and model. We keep the latest report with the time of the check-in and the artwork last offered to it.
We use these to show artwork on your frames, to let you manage them in the app and to help when something goes wrong.
Setting up a frame
- Camera. Used only to scan the setup QR code on your frame. The app reads the code and doesn’t keep or upload any image.
- Bluetooth. Used to find FlightFrame frames nearby that are ready for setup, and to talk to your frame during setup. The app pays attention only to FlightFrame frames and doesn’t store what it finds.
- Wi-Fi. Your frame scans for nearby networks and the app shows you the list. The network name and password you choose go only to your frame, over a Bluetooth connection encrypted with Espressif’s Security 2 scheme and unlocked with the code on your frame. They are never sent to our servers, and the app doesn’t save or log them. Your frame keeps them so it can connect to your network.
- Linking. The code on your frame’s screen is a one-time code. The app sends it to our server to link the frame to your account.
Crash and diagnostics reports
When the app crashes, stops responding, uses too much processing power or writes too much to storage, iOS gives it a diagnostic report, and the app also notes some problems of its own. The app sends these to our server with the app version and build, the iOS version and your iPhone model, linked to your account ID so we can match a report to a problem you tell us about. Reports contain technical details, such as where in the app the problem happened. They don’t include your name, email address, photos or location, and we don’t record your IP address with them. We keep them for 30 days, and accept at most 100 a day from an account.
Your Hangar
Artwork made from flights near your frames is linked to your account. We keep your favourites, the artwork you remove (so you can undo it), artwork hidden when your Hangar is over its limit, which artwork each frame should show, and a record of the artwork made for your account, which counts towards your monthly allowance. Artwork images are stored privately, and the app loads them through links that expire after a few minutes.
Aircraft you fly
With Plus, you can follow an aircraft you fly. We keep its registration, any callsign you add, the aircraft details we look up in a public registry (its Mode S address, type, manufacturer and country of registration) and when you confirmed that you fly it. The registry also returns the registered owner; we discard that and never store it. As you type a registration, the app looks it up to show you the aircraft, so a partly typed registration can be sent too.
While you follow an aircraft, we record its latest position and its flight track (position, altitude, speed and heading) from public flight-tracking data, so the app can follow its flights. On the aircraft’s map the app uses Apple Maps, and when the aircraft is on the ground it asks Apple for the nearest place name using the aircraft’s last position. Aircraft that their owners have asked us not to follow are blocked.
FlightFrame Plus
Apple sells Plus and takes the payment; we never see your payment details. When you subscribe, the app tags the purchase with your FlightFrame account ID and sends Apple’s signed transaction to our server, which checks it with Apple. We store the transaction identifiers, the product, the App Store environment, the transaction, expiry and any revocation dates, and whether the subscription is active. Apple also notifies our server when a subscription renews, lapses, is refunded or is revoked. We use this to give you Plus and to keep it in step with Apple.
Flight data and artwork
Artwork is made from public data about aircraft, not from data about you. Our servers collect aircraft positions for the areas where frames are watching, look up facts about the aircraft and its route, and create a print.
- Positions. We ask adsb.lol for the aircraft in a wide area: a shared region, about four degrees across, that includes the area your frame watches. We never send your frame’s own coordinates. As a fallback, the OpenSky Network is asked for the same wide regions.
- Aircraft and route facts. We look these up by the aircraft’s address, callsign or registration in Virtual Radar Server’s standing data and in ADSBdb.
- Artwork. We ask OpenAI to generate the image, and then to check the finished image. It receives the facts about the flight, such as the airline, aircraft type, flight number, registration and route. When a flight has no known route, it also receives your frame’s airport and the name of the area around it. It never receives your name, email or account, or the point where your frame hangs.
Public aircraft registries can include the name of an aircraft’s registered owner. We never print a private individual’s name on artwork. Looked-up facts are cached for up to about a day, and our records of individual flights are deleted after 29 days.
Aircraft positions: adsb.lol, available under the Open Database License (ODbL). Aircraft and route data: Virtual Radar Server standing data (CC0).
This website
Reserving a frame
- Next-batch list. When no batch is open you can ask to hear about the next one. We keep your name and email, the frame size and finish, the version of the terms you accepted, your reference, when you joined, and whether your confirmation email was sent, with a copy of it.
- Reservation. The same details, plus the batch, the price and reservation fee you agreed to, the fee’s status, Stripe’s identifiers for the checkout, payment and charge, when you paid and any amount refunded. You enter your card, delivery address and phone number on Stripe’s checkout page. Stripe keeps the card so that the balance can be charged later; we receive Stripe’s identifiers for you and for that card, never the card number, and we keep your delivery address and phone number to deliver your frame.
- Balance and order. When your batch is confirmed we record the order for your balance: its price, the fee credited, the delivery date, your personal order link and whether our emails were sent. The balance is charged to your saved card, or you pay it on Stripe’s checkout page. We receive the payment result and Stripe’s identifiers for it, not your card details.
- Updates. Emails about FlightFrame and your frame, such as a follow-up after you join or a reminder while a balance is waiting to be paid. Every update has an unsubscribe link. If you unsubscribe, we keep your address on an unsubscribed list so you stay unsubscribed.
- Abuse protection. To limit repeated sign-ups, we turn your IP address into a keyed one-way hash and count requests against it. These counters are deleted after 48 hours.
We use these to manage your reservation, send your confirmation and updates about your frame (never marketing), handle refunds and keep records of payments.
Browsing
Signing in to the feature-request board uses essential cookies to secure the Google sign-in flow and keep you signed in for up to one hour. These cookies are not used for advertising or tracking. The website also uses your browser’s session storage to remember the frame size you chose while you reserve, and to smooth one page transition; session storage is cleared when you close the tab. Like any website host, Vercel processes your IP address and request details to deliver the pages. Stripe’s checkout page is run by Stripe under its own privacy policy.
Feature requests and voting
You can read feature requests without signing in. To post or vote, you sign in with Google. We link your requests and votes to your FlightFrame account to prevent duplicate votes and limit abuse. Request titles, descriptions, status, submission times and total vote counts are public. Your name, email address and account identifier are not shown on the board. Please keep personal details out of requests.
We use a keyed hash of your IP address for rate limits. Expired rate-limit records are cleaned up during later requests. You can remove your upvote on the board. Deleting your FlightFrame account also removes its feature requests and votes. For help removing a request, contact support@flightframe.io.
Legal bases
- Contract (GDPR article 6(1)(b)): your account, frames, Hangar, aircraft, FlightFrame Plus, and your reservation, deposit or order.
- Legitimate interests (article 6(1)(f)): keeping FlightFrame secure and reliable, preventing abuse, and using frame check-ins and crash and diagnostics reports to diagnose problems and support you. You can object to this at any time.
- Consent (article 6(1)(a)): updates about your frame after you reserve, which you agree to when you reserve. You can withdraw consent at any time with the unsubscribe link in any update, or by emailing us.
- Legal obligation (article 6(1)(c)): keeping records of payments that accounting and tax law require.
Who handles your data
We use these services to run FlightFrame. We don’t sell personal data or share it with advertisers or data brokers.
- Supabase
- Our database, sign-in, file storage and server functions, hosted in the EU (West EU, Paris).
- Apple
- Sign in with Apple, App Store purchases and subscription checks, and Apple Maps for the aircraft map, for place searches and for the place names the app shows.
- Sign in with Google.
- Vercel
- Hosts this website.
- Stripe
- Takes reservation fees and balances on the website, stores the card you save for the balance, and collects your delivery address and phone number.
- Resend
- Sends reservation, order and update emails.
- OpenAI
- Generates and checks artwork from flight details and, when a flight has no known route, your frame’s airport and the name of the area around it.
- adsb.lol, OpenSky Network, Virtual Radar Server, ADSBdb
- Flight data sources. They receive wide regions, aircraft identifiers and registrations, not your personal data.
We may also disclose data where the law requires it, or to protect the rights and safety of our users and the service.
Transfers outside the EU
Our database and file storage are in the EU. Some of the services above, such as Apple, Google, Vercel, Stripe and Resend, are based in the United States or may process data there. When personal data leaves the European Economic Area, we rely on a safeguard the GDPR recognises: a European Commission adequacy decision, such as the EU–US Data Privacy Framework, or the Commission’s standard contractual clauses.
How long we keep it
- Account, frames and settings
- Until you delete your account or unlink a frame. See below for what stays with a frame.
- Frame location
- Until you change it, or the frame leaves your account because you unlink it or delete your account.
- Crash and diagnostics reports
- 30 days, or until you delete your account.
- Profile photo
- Until you replace it or delete your account.
- Hangar artwork
- Artwork that isn’t a favourite or on a frame is deleted 29 days after its flight was last seen. Artwork hidden because your Hangar is over its limit is deleted after 30 days hidden without Plus.
- Flight observations
- 29 days.
- Aircraft you follow
- Until you remove the aircraft or delete your account. Flight tracks are deleted after 14 days.
- Larp mode
- Aircraft seen on the radar map are kept for one day, and cleared when you turn larp mode off.
- Frame check-ins
- Only the latest report is kept.
- Plus records
- Until you delete your account.
- Reservations and orders
- While your reservation is open, or until you ask us to delete it. Payment and order records are kept for as long as accounting and tax law requires. An unsubscribed address is kept only to keep it unsubscribed.
- Hashed IP counters
- 48 hours.
Deleting your account
In the app, open Account and tap Delete account. If you signed in with Apple, you’ll be asked to confirm with Apple first.
This permanently deletes your sign-in account, profile photo, frame links, saved artwork choices, Hangar favourites, your records of removed and hidden artwork, the aircraft you follow, your Plus records, your artwork allowance records and your crash and diagnostics reports.
Your frames are unlinked, their location is deleted and their name is reset. The frame itself, its device record and its other settings stay with the frame so it can be set up again, and no new artwork is made for it until then. Artwork made from flights isn’t about you, so it isn’t deleted straight away; it is removed on the schedule above.
Deleting your account doesn’t cancel FlightFrame Plus. Apple bills Plus, so cancel it in your Apple Account settings. How to cancel.
Your rights
Under the GDPR you can ask us to:
- give you a copy of your personal data (access);
- correct data that is wrong (rectification);
- delete your data (erasure);
- limit how we use it (restriction);
- send the data you gave us to you or another service in a machine-readable format (portability);
- stop using it where we rely on legitimate interests (objection);
- and you can withdraw consent at any time.
Email support@flightframe.io. We’ll reply within one month, and may ask you to confirm it’s you before we act. You also have the right to complain to a data protection supervisory authority, in particular in the EU country where you live, work or think your rights were infringed.
Children
FlightFrame is not directed at children, and we don’t knowingly collect personal data from them. If you think a child has given us personal data, email us and we’ll delete it.
Security
- Data travels encrypted between the app, your frames, this website and our servers.
- Database rules restrict each account to its own data, and photos and artwork are stored privately.
- Frame credentials are stored only as one-way hashes, and your sign-in session stays in your iPhone’s Keychain.
- Wi-Fi setup happens over an encrypted Bluetooth connection that needs the code on your frame.
Changes
We’ll update this policy when FlightFrame changes. The date at the top shows the latest version. If a change significantly affects how we use your data, we’ll tell you in the app or by email before it takes effect.
Contact
Miradouro LLC, for FlightFrame: support@flightframe.io.