Back to home

Legal

Privacy Policy

(Pilot Mobile Application)

Last updated: August 14, 2026 · Effective: August 14, 2026

This Privacy Policy (the "Policy") explains what information we collect, why we collect it, and how you can review, manage, export and delete your data. It follows Japan's Act on the Protection of Personal Information (APPI), the EU General Data Protection Regulation (GDPR), the UK GDPR, the California CCPA/CPRA, and other applicable data protection laws.

Service Provider (Data Controller)

The Service "HUD SONiC" (the "Service"; available at www.hud-sonic.com, the Apple App Store and Google Play) is provided and operated by Aeromuse, Inc. (address: 6F Aoyama Marutake Building, 3-1-36 Minami-Aoyama, Minato-ku, Tokyo, Japan). We are the controller of your personal data. Contact, EU Representative and supervisory-authority details are in Section 15.

About the Service: The Service provides: recording, management, aggregation and export of flight records (logbook); browsing and searching of job postings (including links out to airlines' own job pages); a pilot-facing display of the match rate between your qualifications/experience and job requirements; and viewing of airline public pages.

1. Information We Collect

1.1 Personal Data

We collect only the personal data reasonably necessary to provide the Service:

  • Account and authentication data: email address, authentication identifier (Firebase UID), and the authentication method used (Google / Apple / email / phone number).
  • Basic profile data: name, date of birth, nationality, current airline, current position, and current aircraft type.
  • Qualification and certificate data: licenses, type/class ratings, instrument ratings, aviation English (ELP), and the aviation medical certificate (class and expiry only; we do NOT collect diagnoses, medical history or details of your health) (including issuing authority, certificate number and expiry).
  • Work-authorization data: the type of right to work (citizenship / permanent residence / freedom of movement / work visa, etc.), the covered country/region, and validity. We do NOT use nationality itself for acceptance/rejection; it is used only to determine eligibility to work under the applicable laws of each country and each operator's criteria.
  • Flight record (logbook) data: flight date, aircraft type, aircraft registration, departure/arrival airports, times, breakdown of flight hours, take-offs/landings, remarks (free text), etc. Remarks and certain fields may contain third-party personal data (e.g. instructors or students) — please keep such entries to the minimum necessary.
  • Aggregated data: total flight time, PIC/SIC time, night/instrument/multi-engine/jet/ turbine time, total landings, last flight date, and per-aircraft aggregates.
  • Enquiry data: the content and records of your support enquiries.

1.2 Log and Device Data

When you use the Service, or in the event of an error, we collect log data such as IP address; device type, name and OS version; app configuration; and date, time and usage details.

1.3 Push Notifications and Device Permissions

We may send account- or app-related notifications, which you can turn off in your device settings. We may request access to certain device features (e.g. file access) to enable features; you can change these in your device settings.

1.4 Match-Rate Display

The Service compares your qualifications and experience against job requirements and displays a match rate to you only. This is informational, to help you consider job opportunities; it does not determine hiring outcomes and is not automatically shared with airlines or other third parties (see Section 11).

2. Purposes and Legal Bases

We process personal data for the following purposes, each on the corresponding legal basis. The legal bases (GDPR) described in this Section apply to users in the EU / EEA / the United Kingdom. For users in other regions, we handle personal data in accordance with applicable local laws, within the scope of the purposes described in this Policy.

PurposeLegal basis (GDPR)
Account creation and authenticationPerformance of a contract (Art. 6(1)(b))
Providing the logbook function (record, aggregate, import/export)Performance of a contract (Art. 6(1)(b))
Managing qualifications and expiry (incl. medical class and expiry)Performance of a contract (Art. 6(1)(b))
Browsing/searching jobs and the pilot-facing match-rate displayPerformance of a contract (Art. 6(1)(b))
Determining eligibility to workPerformance of a contract (Art. 6(1)(b))
Service improvement, quality, fraud prevention, securityLegitimate interests (Art. 6(1)(f))
Usage analytics (Firebase Analytics)Consent (Art. 6(1)(a))
Responding to enquiriesContract / legitimate interests
Legal complianceLegal obligation (Art. 6(1)(c))

3. How We Share Information

We do NOT:

  • provide raw flight record data to any third party, including airlines;
  • automatically share your job browsing/search history or match rate with airlines; or
  • provide your contact details (email, phone number) to third parties without your consent.

We allow the following processors to handle personal data as necessary to operate the Service. We enter into data processing agreements (DPAs) with them.

ProcessorRole
Google (Firebase Authentication)User authentication
Google (Firebase Analytics / Crashlytics)Usage and crash analytics (based on consent, etc.)
Google Cloud (Cloud SQL / Cloud Storage)Application and database infrastructure, and storage of files you upload (ISO 27001 / SOC 2)
Mapbox, Inc.Map display in the app
Resend, Inc.Email delivery (notifications and support)
Slack Technologies, LLCInternal notification of support enquiries

We may also disclose data to public authorities where required by law, and to successors in a merger or business transfer. An up-to-date list of sub-processors is available at www.hud-sonic.com/subprocessors.

We do not sell personal information, and we do not share it for cross-context behavioral advertising (including as those terms are defined under the CCPA/CPRA).

4. Anonymized and Aggregated Data

We may use anonymized and aggregated data that does not identify any individual for statistics shown on airline public pages, for service improvement and analysis, and for future market analysis. These are aggregate values not linked to any individual pilot, and we prevent re-identification (for example, by not displaying figures where a group is too small — a k-anonymity threshold of generally fewer than 5 records). Fully anonymized information is no longer personal data.

5. Sharing with Airlines (When You Apply or Accept Scouting)

If you apply to a job or accept scouting from an airline, we share the information you actively provide through that action (profile such as name, current position and aircraft type; aggregated flight hours; licenses and qualifications; application content) only with the specific airline you apply to or accept.

  • Recipient: the airline you applied to or whose scouting you accepted.
  • Data shared: profile, aggregated flight time/experience, qualifications, application content (which may be grouped/abstracted). Raw flight record data is not shared.
  • Purpose: recruitment assessment by that airline.
  • Legal basis: performance of a contract (Art. 6(1)(b)); applying/accepting is an essential use of the job-matching service.

The receiving airline acts as an independent controller and handles your data under its own responsibility (you may also exercise access/deletion rights with that airline). The treatment of data already shared after you withdraw an application depends on the airline's policy.

6. Analytics (Firebase Analytics), SDKs and Consent

We may use Firebase Analytics (usage analytics) and Crashlytics (crash analytics) to improve the Service and address defects. These access device identifiers and similar information.

We use Google's consent tool, the User Messaging Platform (UMP), to determine your region and, for users in the EU / EEA / United Kingdom and similar regions, to display a consent screen on first launch. In these regions we enable these analytics (Firebase Analytics and Crashlytics) only if you consent (disabled by default). You can change or withdraw consent at any time in settings, and the Service remains fully usable if you decline. In other regions these analytics are enabled by default, and you can opt out at any time in settings. We use IP address and similar signals to determine your region.

For users in Japan, details of information transmitted externally (its content, recipients and purposes) are separately disclosed in an "External Transmission Policy" under the Telecommunications Business Act.

7. International Data Transfers

We generally set our cloud storage regions to within the EU or Japan (Japan benefits from an EU adequacy decision). Where data is transferred outside the EEA through our processors (e.g. Google, Mapbox, Slack), we rely on Standard Contractual Clauses (SCCs), adequacy decisions, or other appropriate safeguards permitted under the GDPR.

8. Data Security

We implement appropriate technical and organizational measures commensurate with the risk (encryption of stored data, encryption in transit (TLS), access controls) to keep personal data secure. In particular, for relatively sensitive information such as work-authorization and aviation medical certificate data, we apply stricter safeguards, including role-based access restrictions and masking where not needed.

9. Data Retention and Deletion

We retain personal data for as long as necessary to achieve each purpose, or as required by law. Our category approach is:

CategoryRetention approach
Account and basic dataFor the life of the account.
Flight records (raw and aggregated)For the life of the account (kept as your record).
Qualification and work-authorization dataFor the life of the account.
Aviation medical certificate dataMinimum necessary to manage validity.
Log and analytics dataAs necessary for the purpose; subject to consent/opt-out.
Enquiry dataA reasonable period after resolution.

You can delete your data at any time in the Service settings. Upon a deletion request, data is promptly removed from active systems. After a period during which recovery from backups may be technically possible (e.g., 14 days), it is permanently deleted from all systems and backups and cannot be restored.

10. Your Rights

Subject to applicable law, you have the rights of access, rectification, erasure ('right to be forgotten'), restriction of processing, data portability, objection (in particular to processing based on legitimate interests and to direct marketing), and withdrawal of consent (withdrawal takes effect prospectively). The Service also lets you view, edit, export your data and delete your account. To exercise your rights, contact us using the details in Section 15.

You have the right to lodge a complaint with a data protection supervisory authority in your place of residence, work, or where an alleged infringement occurred (see Section 15).

California residents have additional rights under the CCPA/CPRA (see Section 14).

11. Automated Decision-Making and Profiling

We do not carry out automated decision-making that produces legal or similarly significant effects (GDPR Art. 22) in the Service. The match-rate display is informational to you only and does not determine hiring outcomes.

12. Children's Data

The Service is intended for professional pilots and adults and is not directed to children.

13. Changes to this Policy

We may update this Policy to reflect changes in law or in the Service. For material changes, we will provide advance notice within the Service or by email.

14. Additional Disclosures for California Residents (CCPA/CPRA)

This section provides additional disclosures under the California Consumer Privacy Act (CCPA), as amended by the CPRA, and applies to California residents. If it conflicts with other provisions of this Policy, this section controls for California residents.

(1) Categories of personal information collected (past 12 months): identifiers (name, email, phone number, account identifiers); professional or employment-related information (airline, position, licenses and ratings, flight records); characteristics of protected classifications (nationality, date of birth); internet or other electronic network activity (in-app usage, browsing, searching); geolocation-related information (e.g., airports in flight records); inferences (match rate against job requirements); and sensitive personal information (aviation medical certificate class [health information]; nationality [which may reveal racial or ethnic origin]).

(2) Retention period: we retain each category of personal information described in (1) (including sensitive personal information) on the following basis. See Section 9 of this Policy for details, including our deletion process and treatment of backups.

  • Identifiers / professional or employment-related information (including flight records and geolocation-related information) / characteristics of protected classifications: retained for the life of the account and deleted upon account deletion.
  • Inferences (match rate): retained for the life of the account, and deleted together with the underlying data used to calculate it or upon account deletion.
  • Sensitive personal information: aviation medical certificate class and expiry are retained for the minimum period necessary to manage the expiry of your qualification. Nationality is retained for the life of the account, to the extent necessary to determine eligibility to work.
  • Internet or other electronic network activity: retained as necessary to achieve the purpose (analytics data is subject to your consent/opt-out status).

(3) Sources: we collect personal information from you and your device, as well as from the authentication provider you choose (Google / Apple), which supplies information necessary for authentication (e.g., email address, authentication identifier). Aggregated data such as total flight time, and inferences such as the match rate, are generated by us based on the information we collect.

(4) Business purposes: we use the personal information we collect, by category, for the following business purposes (see Section 2 for details).

  • Identifiers: account creation and authentication, sending notifications, and responding to enquiries.
  • Professional/employment-related information: providing the logbook function (record, aggregate, import/export), managing qualifications and expiry, the pilot-facing match-rate display, and disclosure to airlines when you apply or accept scouting (see Section 5).
  • Characteristics of protected classifications: date of birth is used for identity verification and account management; nationality is used to determine eligibility to work (see (7)).
  • Internet or other electronic network activity: service improvement, quality assurance, fraud prevention and security, and consent-based usage analytics (see Section 6).
  • Geolocation-related information: providing the logbook function (recording, aggregating and exporting flight records).
  • Inferences (match rate): the pilot-facing match-rate display.
  • Sensitive personal information: the purposes described in (7).

(5) Categories of recipients: as described in Section 3, we disclose to service providers (processors) as necessary for business purposes.

(6) Sale/Sharing: we do not "sell" or "share" (for cross-context behavioral advertising) personal information as defined under the CCPA/CPRA. Accordingly, no processing is subject to a sale/share opt-out.

(7) Use of sensitive personal information: we use sensitive personal information only for the following specific purposes. Aviation medical certificate class and expiry are used to manage the validity/expiry of your qualifications and for the pilot-facing match-rate display against job requirements. Nationality is used to determine eligibility to work under the applicable laws of each country and each operator's criteria. These uses are limited to what is necessary to provide the Service, and we do not use sensitive personal information to infer characteristics about you.

(8) California residents' rights: to know, to delete, to correct, to opt out of sale/sharing (not applicable, as we do not sell or share), to limit the use and disclosure of sensitive personal information, and not to be discriminated against for exercising these rights.

(9) How to exercise: submit a request via the contact in Section 15 (support@aero-muse.com) or via in-app functions. We verify identity before responding; authorized-agent requests are accepted subject to verification.

(10) Opt-out preference signals (GPC): we honor Global Privacy Control and similar signals to the extent applicable.

(11) Non-discrimination: we will not discriminate against you for exercising these rights.

15. Contact, Representative and Supervisory Authorities

  • Business Operator (Personal Information Handling Business Operator under APPI): Aeromuse, Inc. (Representative: Masahiro Nojiri; Address: 6F Aoyama Marutake Building, 3-1-36 Minami-Aoyama, Minato-ku, Tokyo, Japan)
  • Contact / Data Protection Officer (DPO): support@aero-muse.com
  • EU Representative (GDPR Art. 27): Prighter GmbH, Schellinggasse 3, 1010 Vienna, Austria.
  • UK Representative (UK GDPR): Prighter Ltd, United Kingdom.
  • Contacting our representative: Users in the EU/EEA and the United Kingdom may submit privacy-related enquiries and data subject requests to our representative (Prighter) via the dedicated portal: https://app.prighter.com/portal/17408205363.
  • Supervisory authorities: EU — your national data protection authority; UK — the ICO; Japan — the Personal Information Protection Commission.
© 2026 Aeromuse, Inc.PrivacyTermsContact