In short: Windshear has no user accounts and runs no server that stores your personal data. Your roster lives in your own iCloud. Windshear Pro is billed by Apple, and all our service keeps is an expiry date tied to your installation of the app. We don't use analytics or advertising, we don't track you, and we never sell your data.
Windshear (the "app") is an iPhone app for airline crew, developed by Windshear AS, a company registered in Norway ("we", "us"). This policy explains what data the app handles and why. By using Windshear you agree to this policy.
Data controller. Windshear AS (org. no. 938 008 329), Norway, is the data controller for the personal data described in this policy. You can reach us at [email protected].
Data stored in your iCloud
Your roster, including flights, duties, crew lists, notes, and your profile (name, base, employee number, and similar fields you enter), is stored in your personal iCloud account using Apple's CloudKit private database and iCloud key-value storage. This keeps your data in sync across your devices.
- This data is held in your iCloud, governed by Apple's Privacy Policy. We do not have access to it.
- We do not operate any database or account system that holds your roster.
- Roster PDFs are parsed entirely on your device; a copy of your most recent import is kept locally so you can re-open it.
Flight tracking
To show actual times and live aircraft positions, the app looks up flight data through our tracking service (a Cloudflare Worker that forwards requests to a flight-data provider, AeroDataBox). A lookup carries only what identifies the flight: a flight number and date, or an aircraft registration if you search by tail. Your name, your location and your roster are never part of it. Searching for an airport is answered from a database inside the app and never leaves your device.
- To prevent abuse, requests are signed with Apple's App Attest, which confirms they come from a genuine, unmodified copy of the app. Our service stores the resulting key identifier and public key for up to a year so it can check those signatures. The identifier belongs to the installation, not to you: it is not linked to your name, your Apple Account or your roster, and it is replaced if you reinstall the app.
- Responses are cached to reduce repeated lookups, for a few minutes while a flight is in progress and up to a week once it has landed and its times can no longer change. The cache is keyed on the flight, not on who asked for it.
- We keep no request history, so nothing on our side can be assembled into a record of where you have flown.
Purchases and subscriptions
Windshear Pro is an auto-renewing subscription sold through Apple. Apple takes the payment and holds the payment details. We never see your card, your Apple Account, your name or your address, and there is nothing to log in to.
When you subscribe, the app sends the receipt Apple signed for that purchase to our tracking service, which verifies Apple's signature and then unlocks the paid features for your installation. What it stores is small, and it expires on its own:
- the subscription's expiry date, which of the two products you bought, and the transaction identifier Apple issued for it;
- the App Attest key identifier of the installation the purchase came from, so the service knows which installation to unlock, plus the identifiers of any other installations that have unlocked the same subscription (at most 50, so that a refund can withdraw access from all of them);
- an opaque handle, derived from the transaction identifier by a one-way hash, which is what lets someone you share your roster with see live tracking of your flights in the Viewer app.
These records delete themselves automatically 30 days after the subscription expires. Apple notifies our service when a subscription renews, expires, lapses or is refunded, so access follows what you actually hold; if a purchase is refunded we also record that transaction identifier so the same receipt cannot be used to unlock the app again. None of this is linked to your name, your email or your Apple Account, and none of it is shared with anyone.
You can view, change or cancel the subscription at any time in Settings, [your name], Subscriptions on your iPhone. Cancelling stops the renewal; the paid features stay available until the period you have paid for ends.
Weather and airport data
When you view weather, the app fetches METAR and TAF reports directly from the Aviation Weather Center (aviationweather.gov), a service of the US National Weather Service, sending only the airport codes you are looking at. Because that request goes straight from your device rather than through us, that service sees your device's IP address, as any website you open does.
Airport ground diagrams come through our own service, which serves hand-drawn geometry where we have it and otherwise fetches the layout from OpenStreetMap. Only the airport code is sent. Diagrams built from that data are © OpenStreetMap contributors.
Sharing your roster
Sharing is entirely optional and off by default. If you choose to share, the app creates a private CloudKit invite link that lets the people you send it to view a window of your upcoming schedule. What they see is your roster for that window as it stands: every flight and every duty in it, including days off, standby, training, and any day your roster records as an absence, whatever your airline calls it. Each entry carries its flight number, airports, times and your crew role, and the roster carries your own name so they know whose schedule they are looking at. It does not include your crew lists, your notes, or tail numbers.
- An invite link is read-only and remains valid until you revoke it (Stop Sharing, or remove an individual person).
- Anyone who has the link can view the shared schedule until it is revoked, so only share it with people you trust.
- Treat a shared roster as the whole roster for that period. If there is something in it you would rather not show, remove that entry before you share, or do not share at all.
- People you share with can follow your schedule in Windshear itself or in the free companion app, Windshear Viewer. If you subscribe to Pro, the opaque handle described above travels with the shared roster, which is what lets them see your flight moving. It carries an expiry date and nothing else: not your identity, not your purchase, and nothing about them.
On-device storage
The app stores your settings and preferences locally on your device (using standard iOS storage) and schedules local notifications you enable, such as report reminders and duty-hour warnings. These stay on your device, as does the Live Activity the Lock Screen shows while you are flying, which is drawn from data the app already holds.
What we do not do
- No user accounts, logins, or passwords.
- No analytics, usage-tracking or advertising SDKs in the app, and no third-party trackers.
- No sale or sharing of personal data for marketing.
- No collection of your location. The app never asks for location permission, and the aircraft you see on the map is the flight's position reported by the flight-data provider, not yours.
- No crash-reporting SDK. If you have chosen to share diagnostics with Apple, Apple may show us anonymised, aggregated crash and usage statistics in App Store Connect, which we cannot trace to an individual.
Service logs
Our tracking service records one row per request so we can tell whether it is working and how much provider quota is left: the endpoint that was called, the status code, whether the answer came from cache, and the quota figures. These rows carry no key identifier, no flight number and nothing about you. As with any website, Cloudflare handles the underlying connection, including your IP address, in the ordinary course of delivering the request, under its own privacy policy.
Third-party services
Windshear relies on a small number of services to function:
- Apple iCloud / CloudKit stores and syncs your roster (your own iCloud account), and Apple sells and bills the subscription. See Apple's Privacy Policy.
- Cloudflare hosts our tracking service and this website. See Cloudflare's Privacy Policy.
- AeroDataBox provides the flight data returned through our service for the flight number, date or registration you look up.
- Aviation Weather Center (US National Weather Service) provides METAR and TAF reports, fetched by the app directly.
- OpenStreetMap contributors provide the airport ground geometry we do not draw ourselves.
Our service runs on Cloudflare's global network, and the flight data provider is outside the EU/EEA, so a request may be handled outside Norway and the EEA. What those requests contain is a flight number, a registration or an airport code, never your identity. Where personal data is transferred, it is covered by the standard contractual clauses these providers publish.
Legal basis for processing
If you are in the EU/EEA, we rely on these bases under the GDPR:
- Performance of a contract for the small set of subscription records described above, which is what unlocks and maintains the service you paid for.
- Legitimate interest in keeping the service available and not paying for abuse of it, which is what App Attest verification, caching and the request counts in our service logs are for.
- Your consent, which you give by turning a feature on, for optional roster sharing. You withdraw it by stopping the share.
Your roster itself is processed inside your own iCloud by Apple, on your instructions rather than ours.
Data retention and deletion
Because your roster lives in your iCloud, you control it. You can clear your flights and duties from within the app's Settings, stop sharing at any time, or delete the app. Removing the app and its iCloud data deletes your roster from Apple's storage on Apple's schedule. On our service, everything expires by itself:
- Cached flight-lookup responses: a few minutes to a week, and keyed on the flight rather than on you.
- App Attest key records: up to one year, and reset if you reinstall the app.
- Subscription records: until 30 days after the subscription expires.
- A refunded transaction identifier is kept so the refunded receipt cannot be reused.
Your rights
If you are in the EU/EEA, the General Data Protection Regulation (GDPR) gives you rights over your personal data. Because your roster lives in your own iCloud and we keep no account or server-side copy of it, you already control most of your data directly, from within the app and from your Apple account. Where we act as data controller, you have the right to:
- Access the personal data we hold about you and receive a copy of it.
- Have inaccurate data corrected, or incomplete data completed.
- Have your data erased (the "right to be forgotten").
- Restrict or object to how your data is processed.
- Receive your data in a portable, machine-readable format.
To exercise any of these, email [email protected]. Because the subscription records hold no name or email, we will ask you for the transaction identifier from your App Store receipt so we can find the right record, and deleting it will end paid access on every device using that subscription. You also have the right to lodge a complaint with your local data protection authority; in Norway this is Datatilsynet.
Children
Windshear is intended for working airline crew and is not directed at children.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected here with a new "last updated" date.
- 22 September 2026: added the section on Windshear Pro subscriptions, named the weather and airport data sources the app talks to, set out the legal bases, retention periods and service logs, and made plain that a shared roster is the whole roster for the window shared.
Contact
Questions about privacy? Email [email protected].