App Privacy Policy

Last updated: 15.07.2026

Looking for how this website handles your data? See the Website Privacy Policy.

1. Introduction

This privacy policy explains how the ezSTBY mobile app handles your data. We respect your privacy and are committed to protecting your personal data. This policy applies only to the ezSTBY application itself, not to this website.

2. The Data We Collect

ezSTBY is designed with privacy at its core. Your data stays on your device. We do not collect, transmit, or store your personal flight information, credentials, or rostering data on any third-party servers controlled by us.

When the app syncs with airline servers, it does so directly from your device. All information retrieved is stored locally on your device for the sole purpose of providing the app's functionality (like the 3-day overview and notifications).

3. Device Permissions

To provide its core functionality, the ezSTBY app may request the following permissions on your device:

  • Notifications: Required to alert you about duty changes, understaffed flights, or paranoia mode alerts.
  • Background Processing (Sync): Required to fetch updates from the airline server while the app is not actively open on your screen.
  • Vibrate: Used to play custom vibration patterns for notification alerts.
  • Calendar (Read & Write): Used to optionally add or update duty events in your device's calendar. All calendar data remains entirely on your device and is never transmitted to any server.
  • Camera: Required to scan QR codes when importing a settings backup. The camera is only activated when you explicitly initiate a QR code scan.

4. Third-Party Services

The application communicates directly with your airline's infrastructure (e.g. Intranet and CrewDoc) to fetch flight data. The privacy policy of the airline applies to the data held on their servers.

5. No Analytics, No Crash Reporting

ezSTBY contains no analytics, no crash reporting, and no third-party SDKs that "phone home." No usage data about how you use the app is collected or transmitted anywhere.

6. Local Credential Storage

Your airline login credentials are stored locally on your device using encrypted secure storage (AES-backed, e.g. Android's EncryptedSharedPreferences). They are never transmitted anywhere except directly to your airline's own Intranet and CrewDoc systems in order to log you in.

7. Backup & Restore / QR Export

ezSTBY lets you export your settings and credentials as a backup, either as a file or a QR code, so you can restore them later or transfer them to another device. This export is protected with strong encryption (AES-256-GCM, with a key derived via PBKDF2 using 100,000 iterations). Please note that once you export and share this backup (for example, by sending the file or showing the QR code to someone), it has left the app's own secure storage, and its safety from that point on depends on how carefully you handle it.

8. Contact Details

If you have any questions about this privacy policy or our privacy practices, please contact us at:
Email: ezstby@mp94.de