Privacy policy
What this site stores about you, why it stores it, and what you can do about it. It describes what the software actually does today, not what a template says it might do.
Last updated Aug 6, 2026
Anything in square brackets is a placeholder. It has to be filled in with the operator's real details before this site goes live.
Who is responsible
The controller for the personal data described here is WAVETOL FUSION LIMITED, Coliemore House, Coliemore Road, Dalkey, Co. Dublin, Ireland. Data protection enquiries: privacy@pirepaero.com.
There is no appointed data protection officer; enquiries go to the address above.
What is stored, and why
- Your email address
- Required in order to have an account. Signing in is done with a link sent to your email, so there is no password and none is stored. If you sign in with Google instead, Google tells us your email address and an account identifier, and nothing else.
- Your handle and display name
- Shown publicly beside everything you contribute. The handle is created with the account from the part of your email before the @, and you can change it — and your display name — on your account page. The handle at most once every 30 days, because it is a public URL and every change breaks the links to it. Neither has to be your real name.
- What you contribute
- Facts, confirmations, corrections, comments, forum posts and photos, each with your handle and a date. This is public by design — peer review does not work anonymously — and it stays visible as part of the record.
- Your reputation score
- A number derived from your contributions and how they were received. It appears on your public profile and it decides what you can publish without review.
- The audit log
- Every change writes one row: who did it, what changed, when, plus a hash of the IP address and of the browser user-agent behind the request. The IP itself is never stored. The hash is salted with a server secret and truncated, and exists to investigate abuse and reconstruct what happened — not to profile you or locate you.
- Rate limiting
- Your IP address is used in memory to count requests over a short window. It is not written to the database.
- Photos you upload
- Stored with your account as the uploader. All embedded metadata — EXIF, IPTC, XMP, including GPS coordinates — is stripped during processing and never reaches storage.
- Experience reports about schools and airlines
- Deliberately pseudonymous. Your user identifier is never written in clear; it is encrypted, alongside a one-way hash that lets you find and delete your own reports. The next section explains it.
- Content reports
- If you report content, the report, your email address and the outcome are stored with a ticket reference, so you can follow the case and appeal the decision.
- Notifications
- Email addresses queued for outgoing notifications about your own content — a confirmation on your fact, a moderation decision.
- Private messages
- Nobody at PirepAero reads your private messages. There is no admin screen that lists or searches them, and no query in the software that returns a conversation to anyone who is not in it. The only way a message reaches a moderator is if you report it: at that moment the message and the ten before it are copied into the report, and moderation happens on that copy — there is no link back to the conversation. Messages are deleted with your account, you can delete your own at any time, and everything older than 24 months is deleted automatically. Notification emails never quote what was written; they say only that someone messaged you.
Pseudonymous experience reports
Reports about flight schools and airlines are the one place where authorship is hidden, because a named report about your own school is a report nobody writes.
The protection is technical, not a promise. The stored row holds an AES-256-GCM ciphertext of your user identifier plus a one-way HMAC of it. The key lives only in the server environment, and without it the site cannot even accept a submission — storing the identifier “temporarily in clear” is exactly the leak this design exists to prevent.
Revealing who wrote a report requires an administrator account, is refused to every other role including moderators and stewards, requires a written reason, and writes its own entry in the audit log. In practice that is for a legal order or a credible threat, not curiosity.
Cookies and local storage
- Session cookie
- Set when you sign in, httpOnly, and the only thing keeping you signed in. Sessions live server-side; the cookie holds a random token and nothing about you.
- NEXT_LOCALE
- Remembers which of the three languages you last used, so a link without a language prefix takes you to the right one.
- Content report token
- Set only if you open a link to a content report you filed. It takes the secret out of the URL so it stops appearing in your history and in referrer headers. httpOnly.
- Theme preference
- Light or dark, kept in your browser's local storage. Not a cookie, and never sent to the server.
- Training progress
- Which briefings you marked as studied, kept in your browser's local storage only. It never leaves your device and it is not tied to your account.
There is no analytics, no advertising, no tracking pixel and no third-party script that follows you between sites. Nothing here asks for consent because nothing here is used for anything other than making the site work.
Who else sees it
Hosting and database: Hetzner Online GmbH (Gunzenhausen, Germany), on servers in Helsinki, Finland — European Union, with data stored in the European Union.
Email delivery: Resend, Inc. (sending, from the European Union region) and Cloudflare, Inc. (routing of incoming mail), used for sign-in links and notifications.
Google, and only if you choose to log in with a Google account.
Nothing is sold, rented or shared for advertising, and nothing is transferred outside the European Economic Area other than through the providers named above and their own safeguards.
How long it is kept
Account data is kept for as long as the account exists.
Contributions are kept indefinitely as part of the aerodrome record. The history is append-only: values are superseded, never overwritten.
The audit log is append-only by database trigger — nothing in the application can edit or delete a row, administrators included. That is a deliberate integrity property, and it means audit entries outlive the account they refer to.
Content reports are kept with their decision for as long as the transparency record requires.
Operational logs are pruned on a schedule (`db:prune-logs`). The audit log is the exception that needs explaining: entries that record a moderation decision — content reports and their outcome, DSA notices and appeals, contribution and dispute decisions, role and account changes — are kept for 60 months, because they are the evidence behind a decision that can be challenged and the source of the transparency figures. Every other audit entry is pruned after 24 months.
Notification records are deleted 90 days after the email is sent. Expired sessions and expired sign-in tokens are deleted as soon as they expire.
Private messages are deleted after 24 months, by a separate job.
Your rights
Under the GDPR you can ask for access to your data, correction, erasure, restriction of processing and portability, and you can object to processing. You can also complain to a supervisory authority — the one in the country where you live, or the Data Protection Commission (Ireland), which supervises the controller.
Most of it is self-service, on your account page: you can export everything we hold about you as a JSON file (Article 15 and 20), change your display name and handle, delete your own experience reports from the page that lists them, and delete the account itself.
Deleting the account anonymises it rather than dropping the row. Your email address, name, display name, handle, picture and role are cleared, any stewardship ends, and your sessions and linked Google account are deleted outright — access stops the same second, not at the next sign-in. A suspended account can still delete itself; the right to erasure is not a reward for good behaviour.
Erasure has a real limit, and it is better said plainly than buried. What goes is everything that identifies you. What stays is what you contributed: other pilots' confirmations point at it, the verification state of a field is computed from it, and the history is append-only by design. Deletion cuts the link between you and those contributions. It cannot make the facts never have existed.
For anything the account page does not cover — a correction, a restriction, an objection — write to privacy@pirepaero.com.
Age
Accounts are for people aged 13 and over. If you believe a younger child has created one, write to privacy@pirepaero.com and it will be removed.
Changes
If this policy changes in a way that matters, the date at the top changes with it and account holders are told by email.
Contact
Privacy questions and rights requests: privacy@pirepaero.com. You can export your data and delete your account yourself, from your account settings. Operator details are on the imprint page.