Privacy Policy
Last updated 2 September 2026
The short version
We hold your professional details so we can write your applications, and an application-specific password so we can send them from your own email account. We use that password to send mail and for nothing else. We do not read your mailbox. You can disconnect in one click, which deletes it.
1. What we collect
Things you give us
- Your name, email address and phone number.
- Your city and state, which we turn into a map position so we can measure distance to employers.
- Your professional details: role, certificates, flight hours, medical class, availability, and the short description you write about yourself.
- Your resume, as a PDF.
- An application-specific password for your email account.
Things we generate
- Which employers we matched you to, what we sent, and when.
- Whether an employer opened your resume link.
- Replies you tell us about, and the outcome you select.
- Technical logs of send attempts, including any error your email provider returned.
Payment
Payments are handled by Stripe. We never see or store your card details. We store the customer and subscription identifiers Stripe gives us so we know whether your subscription is active.
2. Your email credential, specifically
This is the most sensitive thing you give us, so here is exactly how it is handled.
- It is encrypted before storage using a managed key held by Google Cloud Key Management Service. We do not hold the encryption key ourselves in a form that can be extracted from our code.
- It is decrypted only inside the process that sends your mail, only at the moment of sending, and it exists in memory only for that connection.
- It is never written to a log, an error report or a diagnostic trace. Our logging strips anything that looks like a credential before writing.
- It is never returned to your browser. Even signed in as you, our own web app cannot read it back.
- We connect over the sending channel only. We do not connect to your mailbox to read, list, download or search messages.
We recognize that this kind of credential is not technically limited to sending. The limit is one we impose on ourselves in our own software, and we state it here so you can hold us to it. If we ever needed to read your mail, for example to detect replies automatically, we would ask you first and you would have to turn it on.
Disconnecting from your account settings deletes the stored credential and halts sending immediately. You can also revoke the password in your Google or Apple account at any time, which stops us instantly and without needing us.
3. Why we hold each thing
- Your details and resume: to write and send your applications. Your description is included in the message word for word.
- Your location: to find employers near you and to say how far you are from them.
- Your credential: to send from your account.
- Send and reply records: to show you what happened, to avoid contacting the same employer twice, and to honor sending limits.
- Payment identifiers: to know whether your subscription is active.
4. Who else sees it
We do not sell your information and we do not share it for advertising.
Employers receive what you would expect an application to contain: your name, email address, phone number if you provided one, your description, your qualifications and a link to your resume. That is the point of the service.
Service providers that process data on our behalf: Google Cloud and Firebase (hosting, authentication, file storage, encryption), Supabase (database), Stripe (payment), Mapbox (turning your city into a map position), and an email verification service used to check employer addresses. Each holds only what it needs.
Legal: we may disclose information if we are legally required to.
5. Employer information
We hold business contact information for aviation employers, gathered from public government registries and from what those businesses publish on their own websites. This is business contact data, not personal data about a private individual, and we use it only to deliver applications from our users.
Every message we send includes a one-click opt-out. An opt-out is honored across the entire service immediately and permanently, and re-collecting the same address later does not undo it. Employers can also write to privacy@aviseek.com to be removed or to ask what we hold.
6. How long we keep things
- Your profile and resume: until you delete your account.
- Your email credential: until you disconnect, or your account is deleted.
- Application records: until you delete your account.
- Send logs: up to 24 months, for troubleshooting and abuse investigation.
- Opt-out records: kept indefinitely, because forgetting one would let us contact someone who asked us not to.
- Payment records: as long as tax and accounting rules require.
7. Your choices
- See and change your details at any time in the app.
- Pause sending without cancelling.
- Disconnect your email in one click.
- Ask us for a copy of what we hold about you.
- Delete your account, which deletes your profile, resume, credential and application history.
Write to privacy@aviseek.com for access or deletion requests. We will respond within 30 days.
8. Security
Data is encrypted in transit. Your email credential is additionally encrypted at rest with a managed key. Access to employer contact details and stored credentials is restricted to our server processes; the database enforces this directly rather than relying on our application code to remember.
No system is perfect. If a breach affects your information we will tell you.
9. Children
AviSeek is not for anyone under 18 and we do not knowingly collect their information.
10. Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect.
11. Contact
Privacy questions: privacy@aviseek.com