← Underwing

Privacy Policy

Last updated: 26 Sep 2026 · Version 2.1

Note: this English text is a translation provided for convenience. The legally binding version is the Spanish text (Política de Privacidad); in case of any conflict, the Spanish version prevails.

This Policy explains who processes your personal data when you use Underwing (the web app at app.underwing.io and its iOS/iPadOS mobile apps), what data we process, for what purpose and legal basis, whom we share it with, how long we keep it and how you can exercise your rights. We comply with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

1. Data controller

THE FLYING FRIENDS SOLUTIONS LLC (trading as «Underwing»; "we", "us" or the "Controller"), a Limited Liability Company formed under the laws of the State of New Mexico (United States of America).

Although the company is registered in the USA, its principal place of business is in Spain (EU). The processing is therefore fully subject to the GDPR and to Spanish law, and the competent supervisory authority is the Spanish Data Protection Agency (AEPD), without prejudice to the supervisory authority of your place of residence in the EEA.

2. Scope and applicable law

This Policy applies to the processing of data of users and visitors of the Underwing service in the European Economic Area (EEA) and, generally, to any user whose data we process. Processing is governed by the GDPR, the LOPDGDD and other applicable EU and Spanish law.

3. Data we process, purpose and legal basis

DataPurposeLegal basis (GDPR)
Email (account and waiting list)Create and manage your account; service communicationsPerformance of a contract (art. 6.1.b) / consent for the waiting list (art. 6.1.a)
Account identifier and login credentials (incl. Google/Apple sign-in)Authentication and account securityPerformance of a contract (art. 6.1.b)
Pilot profile: name, licence no. and type, ratings and validity, home base, aircraft, recency rulesPersonalise briefings, recency and risk analysisPerformance of a contract (art. 6.1.b)
Medical class and certificate expiry — health data (art. 9)Expiry and recency remindersExplicit consent (art. 9.2.a), separate checkbox in the profile. Optional and revocable
Synced logbook (flights, hours, simulators, examiner signatures)Cloud logbook and experience analysisPerformance of a contract (art. 6.1.b)
Personal minima and preferencesCross-device configurationPerformance of a contract (art. 6.1.b)
Handwritten signature and signed-briefing recordsAuditable evidence of flight preparationContract / legitimate interest in traceability (art. 6.1.f)
Failed-import extracts (only if you agree to send them)Support new logbook formatsConsent (art. 6.1.a)
Documents and queries uploaded to the AI copilotAnswer using your manuals and the briefing contextContract / consent (art. 6.1.a/b)
Billing data (if you subscribe to a paid plan)Manage the subscription and meet tax obligationsContract (art. 6.1.b) / legal obligation (art. 6.1.c)
Technical data (user-agent, approximate country, device identifiers)Security, abuse prevention and diagnosticsLegitimate interest (art. 6.1.f)
Usage metrics (events: login, briefing generated/signed, logbook saved/imported)Measure service usage and improve itLegitimate interest (art. 6.1.f); you may object
Email for marketing communications (news, offers)Direct marketing, only if you acceptConsent (art. 6.1.a), revocable; unsubscribe in every message

On your own device (localStorage/IndexedDB) we also store, without sending it to our servers unless you enable syncing: drafts, preferences and a cache of aeronautical data.

3.1. Health data (medical certificate)

The class and expiry of your aviation medical certificate is health-related data (special category, art. 9 GDPR). We process it only if you enter it voluntarily, on the basis of your explicit consent, requested via a separate checkbox in the profile. You may withdraw it at any time by clearing the field or unticking the checkbox, without affecting the rest of the service or the lawfulness of prior processing. We do not use it for any other purpose or disclose it to third parties for purposes other than those described.

4. Source of the data

Data comes from you (registration, profile, logbook, copilot queries) and from the identity providers you choose to log in (Google or Apple), which give us your verified email address. We do not buy or enrich your data with external sources.

5. AI copilot (Underwing)

If you use the copilot, we send to Anthropic PBC (provider of the Claude model) your question and the context of the current briefing, together with any documents you upload for consultation. We do not send your email or your signature. Anthropic acts as a processor and, under its commercial (API) terms, does not use this data to train its models. We do not carry out automated decision-making with legal or similarly significant effects on you: the copilot is a support tool and the operational decision always rests with the pilot.

6. Recipients and processors

We do not sell your data. To provide the service we use providers acting as processors under a contract compliant with art. 28 GDPR:

ProviderFunctionProcessing location
SupabaseDatabase, authentication and storageEU (eu-west-1, Ireland)
CloudflareWeb hosting, CDN, functions and object storage (R2)Global network (with DPA and art. 46 safeguards)
Fly.ioBackend infrastructure for aeronautical APIsEU / global (by region)
Anthropic PBCAI copilot (Claude model)USA
SentryTechnical error monitoring (receives technical browser data and an internal account identifier; never your email, name or IP, which is discarded)EU
Brevo (Sendinblue SAS)Account emails (sign-up confirmation, password reset) and, with your consent, marketing communicationsEU (France)
Stripe Payments Europe, Ltd.Payment processing (only if you subscribe to a paid plan)EU (Ireland) / USA
Google / AppleIdentity providers for "Sign in with Google/Apple" (only if you choose that option)Per their policies

The official aeronautical and weather data sources and map providers we use do not receive identifying personal data: only airport codes, routes and query parameters. We may disclose data to authorities or third parties where required by law.

7. International transfers

As a rule, your account data is hosted in the European Union (Supabase in Ireland; Sentry and Brevo in the EU). Some providers may process data outside the EEA, in particular in the United States (Anthropic for the copilot; Cloudflare as a global network; and, where applicable, Stripe). The Controller itself is a US entity. These transfers are covered by the European Commission's Standard Contractual Clauses (SCCs) or other adequate safeguards under art. 46 GDPR and, where the provider is certified, by the EU-U.S. Data Privacy Framework. You may request information about the applicable safeguards at support@underwing.io.

8. Retention periods

9. Cookies and local storage

Underwing does not use advertising or third-party tracking cookies. We use only technical storage essential for the service to work: session cookies/tokens to keep you signed in, and browser local storage (localStorage/IndexedDB) to save your preferences, drafts and a cache of aeronautical data on your device. As strictly necessary storage, it does not require prior consent. You can clear it from your browser or device settings.

10. Your rights

You may exercise the rights of access, rectification, erasure ("right to be forgotten"), objection, restriction of processing, portability and to withdraw consent at any time (without retroactive effect). To do so:

We will respond within the legal deadline (one month, extendable). If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) or the supervisory authority of your EEA country of residence.

11. Minors

The service is aimed at pilots and adults. We do not knowingly process data of children under 16. If we detect that we have collected a minor's data without a proper legal basis, we will delete it.

12. Security

We apply technical and organisational measures appropriate to the risk: encryption in transit (HTTPS), per-user isolation (Row-Level Security), keys and secrets server-side only, private storage of signatures and PDFs, access control and audit logs with restricted modification. In the event of a personal-data breach posing a high risk to your rights, we will notify you in accordance with arts. 33 and 34 GDPR.

13. Changes to this Policy

We will publish new versions with their date and number. If the change is substantial, we will notify you by an appropriate means (e.g., in the app or by email) and, where applicable, ask for your consent again.

14. Contact

For any question regarding this Policy or the processing of your data: support@underwing.io.