Privacy Policy
Questions? Write to privacy@highlandsoftware.org.
TL;DR
- Your logbook is yours. We store it so you can see it on every device. We do not sell it, we do not sell you, and we do not train AI on it.
- We collect what you type in, plus what a server needs to work, like an IP address and an app version.
- Medical and ID records are sensitive. We use them only for the feature you put them in. We never ask for a Social Security number.
- Analytics are off until you say yes. No ad tracking, no retargeting, ever.
- A short list of providers keeps the lights on: a database, file storage, payments, email, and sign-in.
- Deactivate pauses your account. Delete erases it.
- You must be 16 or older to fly with us. Student pilots welcome.
1. Who we are and what this policy covers
Abeam is made by Highland Software, LLC, a Colorado limited liability company (“Highland Software”, “we”, “us”). This policy explains what personal information we collect, how we use it, who we share it with, and the choices you have.
It applies to the following, which we call the “Services”:
- The abeamflight.com website and the Abeam launch waitlist
- The Abeam web application
- The Abeam Pilot app for iPhone
The Services are for pilots, student pilots, and flight instructors in the United States who sign up for Abeam themselves. Highland Software decides how and why your personal information is processed. Features for flight schools and other organizations are not available today. We will update this policy before we launch them.
2. Information we collect
Most of what we hold, you typed in. The tables show what each kind of information is, what it looks like, and why Abeam needs it.
Information you give us
| What | What it looks like | Why we need it |
|---|---|---|
| Account and profile | Name, email address, phone number, date of birth, mailing address, emergency contact, an optional gender field, and a signature image if you draw one. If you sign in with Google, Apple, or Microsoft, that provider gives us your name and email address. If you set up a passkey, we store its public part, never the private key. | To create your account, sign you in, and fill in the records that ask for these details. |
| Pilot records | Pilot certificates and ratings, endorsements, flight reviews, currency data, training goals, and checkride progress. | To show your records and work out what is current and what expires. |
| Government identification | The type of ID (driver's license, passport, state ID, or military ID), the issuing country or state, the issue and expiration dates, a partly masked ID number, and any scan you choose to upload. Your citizenship status and TSA Flight Training Security Program (FTSP) status, if you record them. We do not ask for, and do not collect, full Social Security numbers. Please do not upload a document that shows one. | To keep the identification a pilot must show for training and TSA checks in one place. |
| Health-related aviation records | FAA medical certificate class, examination and expiration dates, special issuance status, any Statement of Demonstrated Ability (SODA) and its conditions, BasicMed course dates, and the driver's license details BasicMed relies on. If you live in Washington or Nevada, Section 16 also applies. | To show your medical status and work out when it expires. |
| Logbook and flight data | Flights, aircraft, routes, airports, times, remarks, and the attachments you add. If you enter another person, such as an instructor or a safety pilot, we store the details you enter about them, for example a name, email address, or certificate number. | It is your logbook. This is the product. |
| Documents | Files you upload, such as certificates, medical documents, identification, and aircraft records. | To store them and show them back to you. |
| Billing | On the web, Stripe collects your card and we receive the brand, the last four digits, and your subscription status. Through the App Store, Apple handles payment and we receive a transaction identifier and subscription status. | To run your subscription. We never see your full card number. |
| Waitlist, feedback, and support | The email address, name, and interests you give us on the waitlist, and the content of any message you send us. | To tell you when Abeam is ready, and to answer you. |
Information we collect automatically
| What | What it looks like | Why we need it |
|---|---|---|
| Device and technical data | IP address, browser and device type, operating system, app version, request times, and error reports. | To run the service, find errors, and stop abuse. |
| Push notification token | A device token from Apple, created when you turn on notifications in the Pilot app. | To deliver the notifications you asked for. |
| Security logs | Sign-in events, sign-in approvals from another device, and changes to sensitive profile fields. | To protect your account and investigate a problem. |
| Usage analytics | Which features you use and how you move through screens. Only if you turn analytics on. See Section 5. | To see where Abeam can improve. |
Information from other sources
Your sign-in provider (Google, Apple, or Microsoft) gives us your name and email address. Stripe and Apple tell us whether your subscription is active. Another Abeam user may enter your name or email address in their logbook or contacts.
3. How we use your information
We use personal information to:
- Create and secure your account, and sign you in
- Store, display, and organize your logbook, records, and documents
- Calculate currency, expiration dates, and checkride progress from the records you enter
- Send the reminders and notifications you turn on
- Let you share a record with a person you choose, such as sending an endorsement to an instructor for signature
- Process your subscription and send billing messages
- Answer your support requests and reply to your feedback
- Send product news, if you agreed to receive it
- Understand how Abeam is used, if you turned analytics on
- Find and fix errors, and keep the Services reliable
- Prevent abuse, fraud, and unauthorized access
- Meet our legal obligations
4. What we do not do
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- We do not currently show targeted advertising, and we do not retarget you on other sites.
- We do not currently make automated decisions about you that have legal or similarly significant effects.
- We do not currently use your personal information, your records, or your documents to train artificial intelligence models.
- We do not use your government identification, health-related aviation records, or documents for any purpose other than the features you use them in.
If a practice marked “currently” ever changes, we will update this policy and tell you before the change takes effect.
7. How long we keep information
We keep personal information while your account is active and for as long as we need it for the purposes in Section 3. After that we delete it or make it anonymous, except where we must keep it longer for a legal, tax, security, or accounting reason.
| What | How long |
|---|---|
| Files and documents you delete | Hidden at once. Our storage provider permanently deletes the hidden copy within 30 days. |
| Monitoring logs | About 30 days. |
| Backups | Rolling. Each backup is overwritten as new ones are taken, so a deleted record can remain in a backup until that backup expires. Backups are used only to recover from a failure. |
| Billing records | As long as tax and accounting law requires. |
| Deactivated accounts | Until you reactivate or request deletion (Section 10). |
Your aviation records are yours. FAA regulations place record-keeping duties on pilots and instructors, not on Abeam. For example, a pilot must be able to show the aeronautical experience used to meet a requirement (14 CFR 61.51), and a flight instructor must keep a record of certain endorsements for three years (14 CFR 61.189). We do not keep your records after you delete them on the basis of those rules. Before you delete a record or request account deletion, save or export any record you need to keep.
8. Your choices
- Profile and records. You can view and edit your profile, records, and documents in the app at any time.
- Analytics. Turn analytics on or off as described in Section 5.
- Notifications. Turn push notifications and reminder emails on or off in your account settings or in your device settings.
- Marketing email. Use the unsubscribe link in any marketing email, or contact us. See Section 14.
- Your account. Deactivate your account, or request deletion of your account and data. See Section 10.
9. Your privacy rights
Depending on where you live, state law may give you the right to:
- Confirm whether we process your personal information and access it
- Receive a copy of the personal information you gave us
- Correct inaccurate personal information
- Delete your personal information
- Opt out of the sale of personal information, targeted advertising, and certain profiling (we do none of these)
- Appeal a decision we make about your request
We honor these rights where applicable law gives them to you. You can see and correct most of your information in the app. You can download your logbook as a CSV file from the logbook screen. A full copy of every record we hold about you is available on request while we build a self-service export.
How to make a request. Email privacy@highlandsoftware.org from the address on your account, or use the deletion option in the app. We will confirm your identity before we act. For a request by email, that usually means a reply from your account email address, and for a sensitive request it may mean signing in to confirm. An authorized agent may make a request for you if they show that you gave them permission. We respond within 45 days. If we need more time, we will tell you why and when to expect an answer.
Appeals. If we decline a request, we will explain why. You can appeal by replying to our decision or by emailing privacy@highlandsoftware.org with “Appeal” in the subject line. We will answer your appeal in writing within 45 days. If we deny your appeal, you can contact your state attorney general.
We will not treat you differently for exercising your rights.
Residents of Washington and Nevada have additional rights over health-related information. See Section 16.
10. Deactivating or deleting your account
We offer two actions. They are different, and each is named for what it does.
| Deactivate account | Request account and data deletion | |
|---|---|---|
| Your access | Stops right away. | Stops right away. |
| Your data | Stays in place, marked deleted, so we can restore the account if you contact us. Nothing is erased. | Your account, profile, records, and uploaded documents are erased from our systems, and we instruct our service providers to do the same. Deleted data can remain in backups until those expire. |
| What we keep | Everything. | Only what the law requires, such as billing records. We tell you what that is. |
| Can it be undone? | Yes. Contact us to reactivate. | No. |
| How to start | Account settings on the web or in the Pilot app, or email us. | Account settings on the web or in the Pilot app, or email us. We confirm by email before we act, and again when it is done. |
Cancel any subscription before you request deletion. An App Store subscription must be cancelled in your Apple account settings. Requests go to privacy@highlandsoftware.org.
11. Security
We use measures designed to protect your information against unauthorized access, change, disclosure, or loss. They include:
- Encryption in transit with TLS for every connection to the Services
- Encryption at rest for uploaded files and documents
- Sign-in with passkeys or a trusted sign-in provider, with no passwords for us to store
- Access controls that limit who and what can reach your data
- Security logging of sign-in activity and changes to sensitive fields
No system is completely secure. If we learn of a breach that affects your personal information, we will notify you as the law requires.
12. Age requirements
You must be at least 16 years old to use the Services. We do not knowingly collect personal information from anyone under 16. If you believe a person under 16 has an account, contact us and we will delete it.
If you are 16 or 17, you can use Abeam to keep your own training records. We do not sell the personal information of any user, show targeted advertising, or profile users, and we do not keep the information of a user under 18 longer than we need to provide the Services.
13. Where we process information
Highland Software is based in the United States, and the Services are designed for people in the United States. Most of our providers process data in the United States. Some, as shown in Section 6, use a global network or process data in the European Union. If you use the Services from outside the United States, your information is transferred to and processed in the United States and in the locations shown above.
14. Messages from us
Service messages. We send email and push notifications about your account, security, billing, legal notices, and the reminders you turn on. These are part of the Services. Opting out of marketing email does not stop them.
Marketing email. If you join the waitlist or agree to product news, we may send occasional updates. Every marketing email identifies Highland Software, LLC at PO Box 470424, Aurora, CO 80047 and includes an unsubscribe link. We process an unsubscribe promptly.
15. Changes to this policy
When we make a material change, such as collecting a new kind of information, sharing it with a new kind of recipient, or using it for a new purpose, we will email you at your account address before the change takes effect. For a minor change, we update the effective date and the version number at the top of this page.
16. Consumer health data (Washington and Nevada)
This section is our Consumer Health Data Privacy Policy for people in Washington and Nevada, as the Washington My Health My Data Act and Nevada Senate Bill 370 require. It explains how we handle the health-related information you keep in Abeam. If it ever conflicts with the rest of this policy for that information, this section controls.
What we collect
Abeam is a logbook and records tool for pilots. The only health-related information we collect is what you enter about your FAA medical qualification so that Abeam can show it and calculate when it expires:
- The class of your FAA medical certificate (first, second, or third) and its examination and expiration dates
- Whether the certificate was a special issuance
- Whether you hold a Statement of Demonstrated Ability (SODA), and the conditions it lists
- BasicMed course completion and expiration dates, and the driver's license details BasicMed relies on
- Any remarks you add to a medical record
- Any medical certificate or BasicMed document you choose to upload
We do not collect diagnoses, medications, test results, or any other health information. We do not collect precise location data, and we do not use geofencing.
Where it comes from
Only from you. You type it into your Abeam records or upload a document. We do not obtain health-related information from any other source.
Why we collect it and how we use it
- To store and display your medical records to you
- To calculate your medical currency and expiration dates, and show them on your dashboard and checkride progress
- To send you an expiration reminder, if you turn reminders on
- To keep the records available on your devices when you are offline
These uses are necessary to provide the features you asked for when you entered the information. We do not use it for advertising, for analytics, for profiling, or for any other purpose.
How we share it
We do not sell consumer health data, and we do not share it for advertising. We share it only with:
- Service providers that store or transmit data for us and may use it only to provide their service: our database and sign-in provider (Supabase), our server host (DigitalOcean), our file storage provider (Backblaze B2), and, for reminder emails you turn on, our email provider (Resend).
- People you choose, when you send a record to someone yourself.
- Authorities, when the law requires it.
We have no affiliates, and we share consumer health data with no other third party.
Your rights
- Confirm whether we collect, share, or sell your consumer health data, and access it
- Receive a list of the third parties with whom we have shared it
- Withdraw your consent to our collection and sharing of it
- Have it deleted, including from our service providers and, as they expire, from backups
- Appeal a decision we make about your request
You can view, edit, and delete each medical record and document yourself in the app at any time. Deleting a record in the app removes it from our active systems. Uploaded documents are permanently deleted from storage within 30 days.
To make a request, email privacy@highlandsoftware.org from your account email address, or use the account deletion option in the app. We verify your identity before we act on a request, usually by a reply from your account address or by asking you to sign in. We respond within 45 days. If we need up to 45 more days, we will tell you why.
To appeal, reply to our decision or email privacy@highlandsoftware.org with “Appeal” in the subject line. We answer appeals in writing within 45 days. If we deny your appeal, you can contact the Washington Attorney General or the Nevada Attorney General.
We will not treat you differently for exercising these rights.
17. Contact us
Questions, requests, and appeals go to:
Highland Software, LLCPO Box 470424, Aurora, CO 80047
Email: privacy@highlandsoftware.org