01Who is responsible
MeshLog is provided by the Norwegian sole proprietorship below, which is the data controller for the personal data processed in the service:
Questions about privacy, or requests to use your rights, can be sent to hei@faem.no.
02What we store, and why
- Your account
- Name and e-mail address, and your password stored only as a salted hash. If you sign in with Vipps: the name, e-mail address and phone number Vipps shares with us, plus the technical tokens from the sign-in.
Why: To create your account, let you sign in and keep your logbook separate from everyone else's.
Legal basis: Contract (GDPR art. 6(1)(b)).
- Your logbook
- Everything you log: flights with dates, times, airports, aircraft, roles, landings and remarks; your aircraft list; totals carried forward from earlier logbooks; licence number, the name on your licence and your settings.
Why: This is the service: keeping your EASA FCL.050 logbook, calculating totals, recency and limits, and printing or exporting it.
Legal basis: Contract (GDPR art. 6(1)(b)).
- People you fly with
- Names and initials of crew members, instructors and examiners you add, and any e-mail, phone number or notes you choose to add.
Why: A pilot logbook must show, among other things, the name of the pilot-in-command. These entries are only visible to you.
Legal basis: Our legitimate interest in providing a complete logbook (GDPR art. 6(1)(f)). Only add what you need.
- Signatures
- When an instructor, examiner or PIC endorses a flight on your screen: their drawn signature, name, licence number, role and the time of signing.
Why: To record the endorsement on the logbook entry and detect if the entry is changed afterwards.
Legal basis: Contract with you, and our legitimate interest in reliable endorsements (GDPR art. 6(1)(b) and (f)).
- Certificates and medical
- Licences, ratings, training and medical certificates you record, with numbers and dates. A medical certificate can reveal information about your health (that you hold a medical of a certain class, and until when).
Why: To show you what is valid and remind you before something expires.
Legal basis: Contract (GDPR art. 6(1)(b)). For medical certificates, your explicit consent by entering them (GDPR art. 9(2)(a)); withdraw it by deleting the entry.
- Images you ask us to read
- Roster screenshots and ACARS photos you upload for automatic reading. The live ACARS camera scan runs entirely on your device, and those images never leave it.
Why: To read the flights in the image and fill in the form for you. We do not keep the images; only the flights you save are stored.
Legal basis: Contract (GDPR art. 6(1)(b)).
- Public map link
- Only if you turn on map sharing: anyone with the link can see your name (or the name on your licence), the airports and routes you have flown and your total distance.
Why: So that you can share your map. Turning sharing off, or making a new link, stops the old link from working.
Legal basis: Your consent (GDPR art. 6(1)(a)).
- Sign-in and security data
- For each signed-in session: IP address, browser/device type and when the session expires (30 days without use). Our servers may also keep short-lived technical logs of requests.
Why: To keep you signed in, protect your account and troubleshoot errors.
Legal basis: Our legitimate interest in running a secure service (GDPR art. 6(1)(f)).
If the service is invite-only, we also store the e-mail addresses or phone numbers on the invite list.
03Who else is involved
We never sell your data or share it for advertising. We use these providers:
- Hetzner Online GmbH (Germany) hosts our servers and database in data centres in the EU. Hetzner is our data processor.
- Anthropic, PBC (USA) reads roster screenshots and ACARS photos, but only when you choose to upload one for automatic reading. Anthropic is our data processor. Under its commercial terms the images are not used to train AI models. The transfer to the USA is covered by the EU Commission's Standard Contractual Clauses in Anthropic's data processing terms.
- Vipps MobilePay AS (Norway) handles the sign-in if you choose Vipps. Vipps is an independent controller for that, under its own privacy policy.
If you add a photo link to an aircraft, your browser loads the picture from that website, which can see your IP address. The operator of the service can see the list of accounts (name, e-mail or phone, and the number of flights) in order to run the service. We do not look at the contents of your logbook unless you ask us to help, or we have to for security or legal reasons.
04Cookies and storage on your device
We only use what the app needs in order to work, so we don't ask for cookie consent:
- A session cookie that keeps you signed in (up to 30 days).
- A language cookie that remembers your choice of language (1 year).
- When the app is installed or used offline: copies of pages you have opened, your most recent flights, aircraft and people (so you can edit them offline), and changes you make without a connection until they have been sent to the server. The OCR engine for the ACARS scanner is also downloaded once. Your data is deleted from the device when you sign out.
There are no analytics, advertising or third-party tracking scripts.
05How long we keep data
- Your account and logbook: for as long as you have an account.
- When you delete your account, your account and entire logbook are deleted from the database straight away. Any backup copies are deleted automatically within 30 days.
- Sessions: until you sign out, or 30 days without use.
- Images for automatic reading: not stored by us.
06Your rights
You have the right to access, correct and delete your personal data, to get it in a portable format, to object to or restrict processing based on legitimate interest, and to withdraw consent at any time. Most of this you can do yourself in the app:
- See and correct: everything you have logged is visible and editable in the app.
- Export: Export / Print gives you your whole logbook as a file.
- Delete: Settings → Delete account removes your account and logbook permanently.
For anything else, e-mail hei@faem.no. We answer within one month.
If you believe we process your data unlawfully, you can complain to the Norwegian Data Protection Authority (Datatilsynet), datatilsynet.no.
07Security
All traffic is encrypted (HTTPS). Passwords are only stored as salted hashes. Each user's data is kept separate, and access to the servers is restricted to the operator.
08Changes
If we change this policy in a way that matters, we will tell you in the app before the change takes effect. The date at the top shows when it was last updated.