Privacy Policy
Last updated: 27 July 2026
This describes what AeroRide collects, why, and what you can do about it. It describes the app as it actually behaves today — every item below corresponds to something real in the database or a real call to a named third party. If we add something, this page changes with it.
AeroRide is operated from Türkiye. If you are in Türkiye, KVKK (Law No. 6698) applies to you; if you are in the EU or UK, the GDPR does. Both give you the rights listed under "Your rights" below, and we apply them to everyone regardless of where they ride.
What we collect
Your account. Email address, a password stored only as a bcrypt hash, your interface language, and the dates the account was created and verified. If you sign in with Google or Apple we store the identifier they give us and the email address on that account. We never receive your Google or Apple password.
Your profile. Whatever you choose to fill in: username, name, country, city, home spot, sport, rider level, a short bio, and a photo. All of it is optional except the username, and you control who can see it.
Your sessions. This is the point of the app. When you record a session we store the GPS track — a series of positions with time, speed, heading, altitude and the accuracy of each fix — plus where it started and ended and which spot it was at.
Your jumps. For each jump: airtime, height, distance, take-off and landing speed, landing impact, and where it happened.
Motion sensor data. Accelerometer and gyroscope readings are processed on your phone to detect jumps and are normally discarded. Raw readings are stored only when you switch on jump diagnostics yourself, which exists so measurement problems can be investigated.
Your device. Platform, model, OS version, app version, and — if you allow notifications — a push token. Used to deliver notifications and to work out whether a bug affects one kind of phone or all of them.
Emergency contacts. If you add them: a name, a phone number, and the relationship you choose. These are somebody else's personal data, which is why they are only ever visible to you and are never used for anything except showing them to you when you open the safety panel. Please only add people who are happy for you to.
Consents and settings. Which permissions you have granted, your privacy choices, and your notification preferences.
Emails we send you. The address, which message it was, and whether it was delivered — so that "did my reset link arrive?" is a question we can answer.
What we do not collect
We do not collect contacts, photos beyond the one you upload, your calendar, your microphone, your browsing, or any advertising identifier. There is no advertising in AeroRide and no third-party advertising or tracking SDK in the app. We do not sell or rent your data to anyone, and we do not share it for anyone else's marketing.
There is currently no analytics or crash-reporting service running. The app contains code for both, and neither is switched on in the build you are using. If that changes, this section changes first.
Who else sees your data
Only these, and only what each needs:
- SMTP2GO — delivers our email. Receives your address and the content of
the message (a verification or reset link).
- Open-Meteo — supplies the wind forecast. Receives the coordinates of a
spot. It never receives your identity or your track.
- Google Firebase Cloud Messaging — delivers push notifications, if you
turn them on. Receives a push token, not your session data.
Our servers are in Austria, inside the EU, and are operated by us. Your data is not transferred outside the EU except through the three services above.
How long we keep it
Your data stays until you delete it. Sessions and jumps are yours and we do not expire them.
When you ask us to delete your account, we schedule it and tell you the date. You can cancel any time before it runs. When it runs, everything tied to you is removed — sessions, tracks, jumps, profile, emergency contacts, the lot — across every table that references you. Verification and reset tokens expire on their own within hours and are stored only as hashes.
Your rights
You have the right to see your data, to correct it, to take it elsewhere, to restrict or object to what we do with it, and to have it deleted.
Two of these are buttons in the app rather than an email you have to write:
- Export. Sen (You) → Hesap (Account) → Veri dışa aktarma iste (Request
data export). You get a portable file of everything.
- Deletion. Sen → Hesap → Hesabı sil (Delete account). Scheduled,
cancellable, then complete.
For anything else, or to complain about how we have handled your data, write to destek@aerori.de. If you are in Türkiye you may also complain to the KVKK authority; in the EU, to your local supervisory authority.
Children
AeroRide is not intended for children under 16. We do not knowingly collect data from them. If you believe a child has an account, write to us and we will remove it.
Security
Passwords are stored as bcrypt hashes and never in plain text. Verification and reset tokens are stored only as SHA-256 hashes, so possession of our database does not let anyone reset your password. Traffic between the app and our servers is encrypted with TLS.
No system is perfect. If you find a security problem, please tell us at destek@aerori.de before telling anyone else, and we will fix it and credit you if you would like.
Changes
If we change this policy we will update the date at the top, and for anything that affects what we collect or who receives it, we will tell you in the app before it takes effect.