Privacy Policy
Our architectural guarantee: What happens in your cockpit stays on your device.
Effective Date: September 19, 2026 • Version 1.0
1. Core Privacy Philosophy
EF Bee was designed from the first line of code around a strict Privacy-by-Architecture model. We believe flight deck situational awareness should never come at the cost of your personal privacy, commercial tracking, or data harvesting.
2. Transparent Location Services Usage
In accordance with Apple App Store Review Guideline 5.1.1 (Data Collection and Storage) and Guideline 5.1.5 (Location Services):
- Data Accessed: With your permission, EF Bee requests access to your device's CoreLocation framework to read real-time GPS coordinates, barometric/GPS altitude, heading, ground speed, and horizontal/vertical accuracy metrics.
- Purpose: This data is utilized strictly in real-time to center the moving map, render the aircraft indicator, calculate flight instrument telemetry (PFD strip, range rings, waypoint distance), and display situational warnings.
- Strictly On-Device Processing: All location data is processed exclusively in volatile memory on your physical iOS device. It is NEVER transmitted over any network, uploaded to external servers, or logged to remote analytics platforms.
- No Background Location Snooping: EF Bee only utilizes location services while the application is active and visible on screen (or running in an active flight navigation session).
3. Zero Personal Data Collection
EF Bee collects zero personally identifiable information (PII). Specifically:
- No Accounts: You do not need to register, create a username, provide an email address, or log in via any identity provider.
- No Contact Information: We never request access to your contacts, address book, calendar, camera, or photo library.
- No Financial or Payment Data: Any future purchases or subscriptions are handled directly through Apple's native In-App Purchase and StoreKit infrastructure; EF Bee never sees or stores credit card numbers or billing details.
4. Zero Third-Party Trackers & Telemetry SDKs
Unlike typical mobile applications, EF Bee is built with zero third-party software development kits (SDKs).
- No Google Firebase, Google Analytics, or Crashlytics.
- No Meta / Facebook SDKs or tracking pixels.
- No advertising networks, attribution trackers, or behavioral profiling tools.
- No background crash reporting tools that send silent device logs or memory dumps to commercial third parties.
5. Local-Only Storage and Data Retention
All data generated during your flights belongs exclusively to you:
- Flight Plans & Routes: Waypoint strings and parsed route chips are stored locally in the application's sandboxed device storage.
- Kneeboards & Scratchpads: Pinned charts, CRAFT clearance clearances, and hand-written scratch notes reside solely in local app storage.
- Downloaded Charts & Offline Tiles: FAA sectional basemaps, d-TPP terminal procedure PDFs, and obstacle databases are downloaded directly to local device cache for offline cockpit reference.
- Data Deletion: Because all data resides in the sandboxed app directory on your device, deleting the EF Bee app instantly and irreversibly removes all stored records, charts, and scratchpad notes.
6. Network Connections & Outbound Requests
EF Bee initiates outbound network requests solely to fetch public-domain aeronautical data:
- FAA Aeronautical Data & Charts: Requests made to public FAA AIS / NASR servers, aeronav.faa.gov, or our lightweight read-only proxy (
efbee.bendrucker.dev) to synchronize 28-day AIRAC cycles, terminal procedure plates, and airport directories. - Aviation Weather: Requests made to official NOAA / aviationweather.gov endpoints for live METAR and TAF weather station reports.
- Privacy of Network Requests: Outbound requests use standard encrypted HTTPS connections and contain no unique user tracking tokens, device serial numbers, or advertising identifiers.
7. Regulatory Compliance (GDPR, CCPA, COPPA)
Because EF Bee does not collect, process, or sell any personal data, we automatically adhere to global privacy statutes including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Children's Online Privacy Protection Act (COPPA).
We do not sell personal information, and we do not engage in cross-site behavioral advertising.
8. Updates and Contact Information
We may update this Privacy Policy periodically to reflect new features or regulatory requirements. Any revisions will be published immediately at this URL.
If you have questions, comments, or independent security audit inquiries regarding our privacy architecture, please contact us: