Commute Magic — Privacy Policy
Last updated 2026-09-07.
Commute Magic (the "Service") estimates the probability that a commuting airline crewmember makes report time. This policy describes what the app and its server store, why, where it lives, and how to delete it. Using the Service is also subject to the Terms of Service.
What we collect
- Account: your email address and a password hash (argon2id — the password itself is never stored). If you sign in with Google instead, we store the Google account's stable identifier and its verified email address in place of a password.
- Subscription: if you buy Pro, the Google Play purchase token, the product and plan identifiers, and the subscription's state and expiry, so we can verify it with Google. Google Play handles payment; we never see your card number or billing address.
- Commute settings: the airports you commute between, your airline, your report times and duty roster, and your alert preferences.
- Roster corrections: flights you add, retime or remove on a route's schedule.
- Shared commute: when you confirm the flight — or the one-stop routing — you plan to take for a duty day, the app records it (one row per leg), together with the role and airline from your settings, so other crew on the same flight can be counted. A flight you only looked at while planning is never recorded. This is the one thing you store here that other people see, and only ever as a count — see "What other crew can see" below.
- Outcome answers: whether you made report and whether you boarded your first choice, when you choose to answer.
- App version: which version of the app each of your signed-in devices is running, so we can tell whether an update reached people. No device model, no operating system version, no identifier.
- Push token: a device token used only to deliver your own briefings to your own phone.
- Prediction and alert history: an append-only log of the predictions computed and the briefings sent for your account, keyed by an internal numeric id.
- Crash reports: if the app crashes, the error message, the screen you were on and the app version, so the fault can be fixed. No device identifiers. A crash that happens before you sign in is also reported, with no account attached to it and no identifier of any kind — it is stored against a placeholder meaning “nobody” and cannot be linked to you or to a later sign-up.
What we do not collect
- No location tracking. The app never reads your device location.
- No calendar, contacts, photos, or anything else on your device.
- No advertising identifiers, no analytics SDKs, no trackers.
- No employer credentials. The Service never signs in to any airline or crew-scheduling system.
- No sale or rental of your data, ever, to anyone. No advertising, no data brokers, no third-party analytics. The only outside company that handles any of it is the push-notification relay described below, and the only thing other users ever see is the anonymous count described in "What other crew can see".
What other crew can see
Commute Magic shows you how many other crewmembers are planning the same flight. That is the only feature in the Service where your data reaches another user, and it reaches them as a number, never as an identity.
For one flight on one day, another crewmember planning that same route and date is shown:
- how many people have that flight recorded, and how many of those are pilots and how many are flight attendants;
- a count per airline — for example "DL 1, UA 2";
- whether they themselves are one of the people in that count.
Your name, email address, account identifier, device, location and duty roster are never included. No message or contact of any kind passes between users: there is no way for anyone to reply to you, find you, or learn who you are through this feature.
Be aware of what a small count implies. On a thin route, "1 pilot · DL 1" may be enough for a colleague who knows the operation to guess who it is. That is the nature of the feature — a crew lounge tells them more — but it is why we publish exactly what is shared and nothing beyond it. You can remove your row for a day at any time by stepping the plan card off that flight, and deleting your account removes every one of them.
Where it lives and how it is protected
All data is stored on a server the Operator controls, reached only over HTTPS. Push notifications are delivered through Expo's push service, which sees your device token and the text of your briefing in transit and nothing else. Flight schedule and weather inputs come from public government data (BTS, FAA, NOAA) and licensed schedule providers, and contain nothing about you. Passwords are hashed, sessions expire, and a password change signs out every other device.
How long we keep it
Account data is kept while your account exists. Prediction and alert history is append-only and kept indefinitely for model evaluation, keyed by an internal number only. Crash reports are kept for 90 days.
Deleting your account
Full instructions, including how to ask us if you cannot get into the app, are on the account deletion page.
Settings → Account → Delete account erases your account immediately: email, password hash, settings, duty roster, roster corrections, shared-commute rows, outcome answers, devices and sessions. Already-computed prediction history remains in the append-only log, but with your account gone it carries no email, name or token — only an internal number no longer connected to anyone, and that number is never reused.
Children
The Service is for working airline crew and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes
When this policy changes, the "last updated" date above changes with it, and material changes will be announced in the app.
Contact
Questions or data requests: support@thepocketappcompany.com.