The short version
This site sets no cookies at all. There is no analytics, no advertising, no tracking pixel and no third-party script anywhere on it. Nothing you do here is profiled, and nothing about you is sold or shared for marketing.
What we hold is what you gave us: an email address if you have an account, and whatever you have written here.
1. Who is responsible
Soaring Spirit GmbH, registered in the Canton of Bern, Switzerland, under CHE-271.410.648, registered office Oberdorfstrasse 36A, 3053 Münchenbuchsee, is the controller of the data described here. Reach us through the contact form.
2. Visiting the site
Pages are delivered through Cloudflare, which sees the request and your IP address as part of getting the page to you, and keeps its own logs of that.
Our own server does not keep an access log. It records errors, and it records an IP address in one case only: when a request is refused for hitting a rate limit, so that abuse can be recognised. Those records live in the server's system log and are kept for as long as that log is retained.
3. If you have an account
We store:
- Your email address — it is how you sign in and the only thing an account requires.
- Your username — chosen by you. It is the only name attached to anything you write here; we do not ask for, and do not hold, your real name.
- When you accepted the terms, and which revision.
- Sign-in codes, which are valid for ten minutes and replaced by the next one.
- Sessions — a token, the IP address the session was started from, and an expiry. Sessions last fourteen days and are deleted automatically once they expire.
- Passkeys, if you register one: public key material and an identifier. A passkey never leaves your device and we could not use one to identify you elsewhere.
- When the account was created and when it was last used.
- Which of the internal documents you have been granted you have opened, and when — contributors only, together with a fingerprint of the version you were shown. One time and one fingerprint for each document, and not a history: both are overwritten every time you open that document, so they cannot say how often, in what order or for how long you read anything. They are there so that a document edited since you read it can be marked as such — for you, in your own list, and for whoever made the edit — and they are deleted when your access to that document is.
We use it to let you sign in, to send you the emails the account needs — a sign-in code, a confirmation of a change you asked for — and to know who wrote what. The legal basis is the agreement between us; keeping the account secure is our legitimate interest, and so is keeping the site up.
4. If you write to us
The contact form asks for a name, an email address, an optional subject and your message. All four are stored and sent on to us by email, so that a message cannot be lost by a mail server having a bad day.
Your IP address is not stored with the message.
We keep a message for as long as it takes to deal with it and for as long as it is useful to remember the exchange. Ask and we will delete it.
5. What you write here
Posts, comments, proposed edits, test reports and uploaded files are stored with your account against them, and shown to the people that part of the site is meant to show them to. Uploaded files are held in object storage in the EU.
Some of it is deliberately private: a draft is visible to nobody but its author, and a test report is its author's own account of a flight, which nobody else can edit.
6. Your browser
Instead of a cookie, signing in puts a session token in your browser's local storage, and a copy of your own profile in session storage so that every page does not have to ask for it again. Both are readable only by this site, are not sent anywhere else, and are cleared when you sign out. Neither is used to track you.
7. Who else handles it
- Cloudflare delivers the site and stores uploaded files. File storage is pinned to the EU.
- Proton Mail (Switzerland) sends the email this site sends.
- The server itself is a dedicated machine hosted in Germany.
Nobody else receives your data, and it is not sold, rented or shared for anyone's marketing.
8. How it is protected
Everything is served over HTTPS. There is no password on this site to steal: signing in is a one-time code sent to your inbox, or a passkey whose private half never leaves your device.
The database is backed up nightly. Every backup is checked to be readable and copied off the machine to storage in the EU, so a failed disk cannot take the only copy with it.
None of this is a guarantee against every possible failure, and we would tell you if something happened to your data.
9. How long it is kept
Account data is kept while the account exists. Closing your account does not delete what you wrote — it removes your personal details and detaches your name from it, so that discussions other people took part in stay readable. Sessions expire and are deleted. Sign-in codes are replaced by the next one.
10. What you can ask for
You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to what we are doing with it. Ask through the contact form and we will answer.
If you are in Switzerland you may complain to the Federal Data Protection and Information Commissioner; in the EU or the UK, to your own supervisory authority.
11. Changes
This notice will change as the site does. The revision is at the top of the page.