Privacy Policy
Last updated: 2026-09-22
1. Overview
CrewSync ("the Service") helps cabin crew and shift workers manage their schedules and share them with family and friends — only as much as the owner decides. This policy explains what we collect, why, and how it is protected. Contact: hello@crewsync.link
2. What we collect
- Account: email, display name, public handle, worker type (crew/shift/viewer), home base, time-reference city, airline (optional), language
- Profile photo: stored only if you upload one (emoji and badges are not stored as files).
- Social sign-in: when you use Google, Kakao or Apple we receive your email and basic profile from them.
- Schedule data: roster photos/PDFs you upload (processed only for analysis), the resulting entries (flights, shifts, days off, personal events), recurring activities and custom entry types
- Seat notes: note text and handwriting strokes you save in-flight, with the related flight number and date
- Sharing settings: Safe Link configuration (circle class, period, quiet mode), care notes, friendships and nicknames, groups, block list, invite and QR records
- Usage records: the days and platform you opened the app, roster-parse outcomes (airline, duration, size — never the photo itself), feature counters
- Payment data: we never receive or store your full card number, CVC or card password — the payment instrument is handled entirely by the payment provider (Lemon Squeezy · App Store · Google Play) on their own screen. What the provider passes to us and we keep is: the order and subscription identifiers, product name and billing interval, amount, currency, tax and the exchange rate applied, the time of purchase / renewal / refund, the name and email you entered at checkout, the card brand and last four digits (web purchases), and the store country (in-app purchases). We keep the provider's original record alongside it as evidence for refunds and disputes.
- What we do NOT collect: no GPS or real-time location, no microphone or audio, no contacts. Status is computed purely from your schedule data.
3. Why we process it
- Providing the Service: identifying your account and signing you in, turning rosters into schedules, showing the calendar, home, widgets and watch, computing time zones
- Sharing: showing your schedule to the people you choose, at the level (Circle Class) you choose — Safe Link, OFF Sync, friends and groups
- Payments: processing Premium subscriptions, Sync Miles and gifts, checking subscription status, refunds and statutory record-keeping
- Safety and abuse prevention: enforcing usage limits, handling blocks and reports, stopping token brute-forcing and other abnormal access
- Improving the Service: aggregate usage analytics to see where features fail (we do not profile individuals for marketing)
- Support: answering your emails and keeping a record of them
We will ask for separate consent before using data for any other purpose.
4. AI processing
Roster photos and PDFs are sent to Anthropic's Claude API to convert them into schedule entries. Photos are used only for that conversion and are not stored on our servers.
Live flight status is not handled by Claude — it is looked up through AeroDataBox (via RapidAPI). Only the flight number and departure date are sent; nothing that identifies you.
5. Processors and international transfers
We use the processors below to run the Service. They process data outside Korea, mostly in the United States.
- Supabase (US) — database, authentication and file storage (account, schedule, notes, profile photo) · kept while your account exists
- Vercel (US) — web hosting (access logs)
- Anthropic (US) — AI analysis of roster photos/PDFs · discarded right after conversion, never stored
- AeroDataBox / RapidAPI (US) — live flight status (flight number and departure date)
- PostHog (US) — product analytics (user identifier, screens visited, feature events). Uses cookies and browser storage.
- Lemon Squeezy (US) — web checkout (email and order details at purchase)
- Apple · Google · RevenueCat (US) — in-app purchases and subscription status
- Google · Kakao (US · Korea) — social sign-in
- Google AdSense/AdMob (US) — when ads are shown, they may use cookies or advertising identifiers
When and how: data is transferred over encrypted connections (TLS) at the moment you use the related feature. Refusing transfers: the Service cannot run without these providers, so you can refuse by deleting your account (Account tab). If you only object to one feature (AI analysis, live status, payments, ads), simply do not use it — that data is then never transferred.
Ad and analytics scripts are never loaded on Safe Link viewer pages, invite links, or the sign-in screen — the token in those URLs is itself the permission to read.
6. Sharing with third parties
Your data is visible only to people you explicitly invite through a Sync, Safe Link or QR, and only at the circle level you chose. We never sell personal data, and disclose it to authorities only when legally required and only to the minimum extent.
7. Cookies and similar storage
We use essential storage to keep you signed in, plus cookies and browser storage for product analytics (PostHog) and advertising (Google). Blocking essential storage will sign you out. We do not use session replay (screen recording).
How to refuse: block or clear cookies in your browser settings. Ad personalisation can be turned off at adssettings.google.com.
8. App permissions
The mobile app requests the permissions below. None of them is mandatory.
- Camera (optional) — only to scan a friend's QR code. Nothing is saved or sent.
- Photos (optional) — to upload a roster photo or pick a profile picture. Only the photo you choose is processed.
- Notifications (optional · Apple Watch only) — requested only when you set a reminder on a seat note in the watch app. The reminder is scheduled and shown on the watch itself; nothing is sent to our servers and no push token is created. The iPhone and Android apps do not request notification permission.
- Never requested — location, microphone, contacts. Status comes from your schedule, not GPS.
You can revoke a permission in your device settings at any time; only that feature stops working.
9. Payments and refunds
Premium subscriptions, Sync Miles and gifts are charged by Lemon Squeezy on the web and by the App Store or Google Play in the app; RevenueCat is used to check whether a subscription is still active. We never handle the payment instrument itself (card number, CVC) — we only receive the record the provider sends us after the payment is complete.
- When: only when a purchase, renewal, cancellation or refund actually happens, via the notification (webhook) the provider sends.
- Why: granting and revoking subscription access, making sure one payment is not credited twice, handling refunds and disputes, tax filing and statutory bookkeeping.
- How long: the periods Korean e-commerce law requires — 5 years for contract and withdrawal records, 5 years for payment and delivery records, 3 years for consumer complaints and disputes. During those periods payment records survive account deletion, because the law requires it; only the billing record remains — schedules, notes and friendships are deleted with the account.
- Refunds: who refunds you depends on where you paid — see the Refund & Cancellation Policy.
10. Retention & deletion
Data is kept while your account exists. You can permanently erase your account and all data (schedules, friends, Safe Links, notes, profile photo, …) at any time via Account → Delete my account. Deletion is immediate and irreversible. Payment and transaction records are kept separately for the period Korean e-commerce law requires (5 years for contracts and payments, 3 years for consumer complaints) and then destroyed in a non-recoverable way.
11. Security measures
- Access control: row-level security in the database means you can only read and write your own data; shared data is gated server-side by the circle you chose.
- Encryption: all traffic is encrypted with TLS; passwords are stored only as hashes.
- Sharing tokens: Safe Link and QR tokens are unguessable random values; QR tokens expire in 5 minutes and work once. No third-party scripts run on pages that carry a token.
- Data minimisation: roster photos are not stored after conversion; location and microphone are never collected.
- Operational: service keys live only on the server, never in app or web code; the number of people with access is kept minimal.
12. Your rights and how to exercise them
You may request access, correction or erasure of your data, restriction of processing, or withdrawal of consent — in-app (Account tab) or by contacting hello@crewsync.link. We respond without undue delay and within 10 days. Where GDPR or similar laws apply, you also have the rights to portability and to object.
Complaints: in Korea you may contact the Personal Information Infringement Report Center (KISA, privacy.kisa.or.kr, 118), the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972), or the police cybercrime unit (ecrm.police.go.kr, 182).
13. Privacy officer
We appoint a privacy officer under Article 31 of the Korean Personal Information Protection Act. Questions, complaints and remedies about personal data — and the access, correction, erasure and restriction requests in the previous section — are all received at the address below and answered without undue delay.
- Privacy officer — name / title: Insuk Kang (Representative)
- Where to file access, correction or erasure requests — the in-app Account tab (handled immediately) or hello@crewsync.link
- Contact — hello@crewsync.link · privacy enquiries are handled by email
Company name, representative, address, business registration number and e-commerce registration number are published in the Operator section of the Terms of Service.
14. Children
The Service is not directed to children under 14, and you confirm you are 14 or older when signing up.
15. Changes
Updates are posted here at least 7 days before they take effect (30 days for changes that reduce your rights); material changes are announced in the Service. Effective: 2026-09-22