✈️
Altitude

Privacy Policy

Last updated: 20 July 2026

Altitude is a social flight-companion app. You scan your boarding pass, join a private chat with other passengers on that same flight, and build a travel passport of where you've been. This policy explains exactly what we collect, why, who else sees it, and how to get rid of it.

The short version. We collect your email, the flight details from your boarding pass, and what you write in the app. We never store your raw booking reference or your legal name — they're hashed on our server and the original is discarded. We don't sell data, we don't run ad networks, and we have no analytics or tracking SDKs. You can delete your account, and everything tied to it, from inside the app.

1. Who we are

Altitude is operated by the developer of the Altitude iOS app. For any privacy question, or to exercise the rights described below, contact [email protected].

2. What we collect

Account

Boarding passes

When you scan a boarding pass, the barcode is sent to our server, parsed, and immediately reduced. What we keep:

We do not store your raw booking reference or your raw name. They exist only in memory on our server for the moment it takes to hash them.

Travel history

Things you write

Notifications

If you allow notifications, our push provider assigns your device an identifier and links it to your Altitude user ID so we can tell you when your cabin opens. Push providers typically derive an approximate location from your IP address; we never request or store precise location, and the app does not use location services.

What we do not collect

No precise location. No advertising identifier. No contacts. No health, financial or browsing data. No analytics or crash-reporting SDK is present in the app. We do not track you across other apps or websites.

3. Other people's boarding passes (Party Scan)

Altitude lets you scan a travel companion's boarding pass to invite them. When you do, we store the same reduced data described above — hashes and seat — under a temporary invite code, so that when your companion installs Altitude they land straight in the right cabin.

That invite expires after 72 hours, and unclaimed invites are deleted automatically. Nothing about your companion is shown to anyone, and no account exists for them, until they install the app and redeem the code themselves. Only scan a companion's pass with their agreement.

4. How we use it

We do not sell personal data, and we do not use it for advertising or profiling.

5. Who else processes your data

ServiceWhat it receivesWhy
SupabaseYour account and all app dataDatabase, authentication, realtime chat
RailwayAPI requests, including boarding-pass barcodes in transitHosts our API server
AeroDataBox (via RapidAPI)Airline, flight number, dateAircraft type, gate and delay information
SerpAPIYour flight-search terms (route, dates, budget)Returns Google Flights results
Self-hosted AI modelYour concierge and Memory Excavator messagesPowers the AI chat. Runs on our own server; your messages are not sent to a commercial AI provider and are not used to train anyone's model.
OneSignalDevice push token, your user IDDelivers push notifications (only if you allow them)
Google (ML Kit, Fonts)Barcode scanning runs on-device; fonts are fetched from Google's CDN, which sees your IPScanning and typography

Other passengers on your flight see your display name, your vibe status, your seat, and whatever you write in the cabin. Nothing else from your profile is shared with them.

6. Keeping it, and deleting it

We keep your data while your account exists.

You can delete your account at any time from inside the app — Profile → Delete account. This permanently removes your profile, flights, badges, travel history, memory entries, invites and blocks. It cannot be undone.

One exception: messages you sent in a cabin remain visible to the other passengers who were on that flight, but are detached from you and no longer show your name. This is so a conversation doesn't become unreadable for everyone else when one person leaves. If you need those removed as well, email us.

7. Security

No system is perfect, and we won't pretend otherwise. If you find a security problem, please tell us at [email protected].

8. Your rights

If you're in the EU/EEA or UK, the GDPR gives you the right to access, correct, export, restrict or erase your personal data, and to object to processing. Our lawful basis is performance of a contract (running the app you asked for) and, for notifications, your consent — which you can withdraw in iOS Settings at any time.

Most of this you can do yourself in the app: edit your name, delete individual memory entries, or delete your whole account. For anything else, email [email protected] and we'll respond within 30 days. You also have the right to complain to your local data protection authority.

9. Children

Altitude is not intended for anyone under 16. We don't knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.

10. Changes

If we change this policy materially, we'll update the date above and notify you in the app before the change takes effect.