# NextCaptain Privacy Policy Effective date: 2026-07-21 ## 1. Controller and contact NextCaptain is operated by **Cankan Ahmet Günaydın**, located at **Fatih Mah. Sanayi Cad. Armis 1 Sitesi No: 12/7 Gaziemir/İzmir, Türkiye**. The operator is the data controller for the account and training data described in this policy. Privacy and support contact: **support@nextcaptain.app** ## 2. Scope and data categories This policy applies to the NextCaptain iOS application, its API, account services, training progress, leaderboard, organization features, and community functions. We process the following categories when you use the relevant feature: - Account data: email address, nickname, account status, language, time zone, verification state, and consent records. - Optional profile data: first/last name, aviation role, training goal, country or region, experience level, avatar URL, and bio. - Security data: salted password hash, hashed session/token values, encrypted MFA secret, recovery-code hashes, device/platform description, keyed IP hash, request identifier, login failures, and allowlisted audit events. - Training data: quiz progress, answers, scores, points, achievements, wrong and flagged questions, downloaded-pack state, and saved tests. - Digital Logbook data: manually entered or user-confirmed flight dates, routes, airport codes, aircraft and duty details, flight times, operating role, take-offs/landings, procedure fields, verification status, private remarks, personal airports, roster rows, recognized logbook text, import review decisions, user-supplied track/procedure points, and crew names entered by the user. Camera photos, PDFs, and videos are processed on the device and the source media is not uploaded by the current release. Recognized text and confidence information may be synchronized to create a private import review before row-by-row confirmation. No flight is added to the Digital Logbook until the user reviews and confirms the applicable rows. - Personal document validity data: the user may optionally save a document name, category, issuing framework, validity method, issue/last-renewal date, printed expiry date, and a user-confirmed expected-expiry calculation record for medical certificates, pilot licences/certificates, ratings, passports, or another named personal document. These fields are encrypted at rest and synchronized to the verified account. A date of birth entered into the optional EASA/FAA medical calculator is used transiently on the device and is not saved, synchronized, logged, or included in calculation provenance. Selected document images are re-encoded without source metadata, stored only in that account's protected device container, excluded from backup, and never uploaded or processed with OCR. Local renewal notifications use generic lock- screen text and are enabled only after the user opts in on that device. - Smart Detect location data: approximate coordinates, rounded on the device and supplied only after the user taps Use My Location, together with the selected airline/base and time window. The coordinates are encrypted in a short-lived detection session and are not used to build a location history. - Weather Briefing location data: after the user selects Use location, an approximate device position is compared on the device with the bundled supported-airport catalog. Only the selected ICAO weather-station code is sent to the weather service. Weather Briefing does not retain coordinates; it stores only the user's location preference and cached station observation. Automatic refresh uses location only while permission is already granted and never opens the system prompt without a new Use location action. The configured base airport is used when location is unavailable. - Organization data: memberships, roles, invitations, and organization-scoped training information. - Community data: topics, comments, likes, reports, blocks, and moderation actions. Content is visible according to the feature's stated audience. - Account lifecycle data: export requests, deletion request/deadline, and the minimum audit evidence needed to complete or troubleshoot those operations. We do not intentionally collect passport or government ID numbers, pilot licence numbers, document images, dates of birth used by the validity calculator, clinical health records, precise location, address-book contacts, advertising identifiers, or payment-card data. Optional document metadata and confirmed dates are collected only when entered by the user as described above. The current release contains no advertising or cross-app tracking SDK. ## 3. Collection method, purposes, and legal bases Data is collected directly from forms and actions in the app, automatically from authentication/security requests, or from an authorized organization invitation. We process it to: - create and secure accounts, synchronize progress, and provide requested training/community functions; - send verification, password-reset, deletion, security, and requested reminder messages; - prevent abuse, enforce access rules, investigate incidents, moderate content, and maintain service integrity; - provide portable exports, execute deletion, answer support/privacy requests, and meet applicable legal obligations; - show leaderboard, marketing, reminders, or optional analytics only when the corresponding choice is enabled. Depending on applicable law, processing is based on performance of the service requested by the user, compliance with legal obligations, establishment or exercise of legal rights, legitimate interests in security and service integrity that do not override user rights, or consent where consent is legally required. Optional marketing, analytics, and leaderboard participation are off by default and can be withdrawn without losing core quiz access. ## 4. Recipients and international transfers Data is limited to personnel who need it for support, security, moderation, or service operation. Authorized organization administrators/instructors can see only organization-scoped membership and training information; they cannot see passwords, tokens, MFA secrets, private consent history, or unrelated organizations. The production infrastructure host and transactional-email provider process data on the operator's instructions. Public forum or leaderboard information is shared only when the user posts or opts in. Brief Live is retrieved and cached by the operator's API from an allowlist of public aviation publishers; the mobile device does not send account tokens or profile data to those publishers. The app may retain supplied headlines, publisher names, publication dates, links, and summaries in an account-independent local archive for up to seven days so recent briefings remain available between refreshes. When the user requests Smart Detect, the API may send the selected airport, airline, UTC time window, and rounded approximate coordinates to the contracted flight-data provider to return possible flights. Provider credentials remain on the server. Detection data expires after two minutes, and provider-derived data must not be retained beyond the provider's contractual storage limit. Where a provider processes data outside the user's country, the operator uses the transfer mechanism and safeguards required by applicable law and limits the data to the stated purpose. The current processor list and transfer information can be requested at support@nextcaptain.app. We do not sell personal data. ## 5. Retention and deletion - Active account/profile/training data: while the account remains active. - Synchronized Digital Logbook data: while the account remains active, until the user deletes an individual record, or until account deletion. - Protected source scans retained on the device: until the user disables scan retention, account deletion clears the device cache, app data is cleared, or the app is uninstalled. Disabling retention removes stored source scans after recognition; review thumbnails remain only for the active in-memory screen. - Access sessions: up to 30 days by default, or earlier when revoked. - Four-digit verification codes: up to 10 minutes by default; backup verification links: up to 24 hours; password-reset tokens: up to 30 minutes. - Invitations: up to 7 days; encrypted export payloads: up to 1 hour. - Security/audit events: 365 days by default unless a shorter or legally required period applies. - Deletion requests: a displayed 7-day grace period by default. - Encrypted operational backups: 14 days by default. Account deletion is available in Account centre. It revokes all sessions immediately. During the displayed grace period the user can reauthenticate and cancel. After the deadline, the retryable deletion worker removes account, identity, profile, preference, organization, quiz, Digital Logbook, export, and user-generated content records unless a specific legal obligation requires minimum retention. The requesting device also removes that account's local Digital Logbook cache after a deletion request succeeds. Restored backups must replay overdue deletion jobs before general access. ## 6. User rights and choices Users can update profile/preferences, change email/nickname/password, manage MFA and sessions, withdraw optional choices, export their data, edit/delete their community content, and request full account deletion in the app. Subject to applicable law, users may also request information about processing, access, correction, deletion, restriction, objection, portability, information about recipients, and review of material automated decisions. Requests can be sent to support@nextcaptain.app. We may verify identity before fulfilling a request and will respond within the legally applicable period. ## 7. Security Controls include TLS, salted memory-hard password hashing, token hashing and rotation, iOS Keychain storage, encryption of MFA/export secrets, least- privilege authorization, tenant isolation, rate limits, audit logging, integrity-checked backups, and retryable account deletion. No system can guarantee absolute security; suspected incidents should be reported promptly. ## 8. Children The service is an aviation training product and is not directed to children. Users who are below the minimum digital-consent age applicable in their country must not create an account without any legally required parental authorization. ## 9. Changes Material changes will receive a new policy version and, where required, an in-app notice or renewed acknowledgement. Mandatory rights are not reduced by this policy. --- # NextCaptain Gizlilik Politikası ve Aydınlatma Metni Yürürlük tarihi: 2026-07-21 ## 1. Veri sorumlusu ve iletişim NextCaptain, **Fatih Mah. Sanayi Cad. Armis 1 Sitesi No: 12/7 Gaziemir/İzmir, Türkiye** adresindeki **Cankan Ahmet Günaydın** tarafından işletilmektedir. İşletmeci, bu metinde açıklanan hesap ve eğitim verileri bakımından veri sorumlusudur. Gizlilik ve destek iletişimi: **support@nextcaptain.app** ## 2. Kapsam ve işlenen veri kategorileri Bu metin NextCaptain iOS uygulaması, API, hesap hizmetleri, eğitim ilerlemesi, liderlik tablosu, organizasyon ve topluluk özelliklerini kapsar. İlgili özellik kullanıldığında şu veriler işlenebilir: - Hesap: e-posta, kullanıcı adı, hesap durumu, dil, saat dilimi, doğrulama ve onay kayıtları. - İsteğe bağlı profil: ad/soyad, havacılık rolü, eğitim hedefi, ülke/bölge, deneyim seviyesi, avatar bağlantısı ve biyografi. - Güvenlik: tuzlanmış parola özeti, token/oturum özetleri, şifreli MFA anahtarı, kurtarma kodu özetleri, cihaz/platform tanımı, anahtarlı IP özeti, istek numarası, başarısız giriş ve izinli denetim kayıtları. - Eğitim: ilerleme, cevaplar, puanlar, başarımlar, yanlış/işaretli sorular, indirilen paketler ve kayıtlı testler. - Dijital Uçuş Defteri: kullanıcı tarafından girilen veya onaylanan uçuş tarihi, rota ve meydan kodları, uçak ve görev bilgileri, uçuş süreleri, pilot rolü, kalkış/inişler, usul alanları, doğrulama durumu, özel notlar, kişisel meydanlar roster satırları, tanınan logbook metni, içe aktarma inceleme kararları, kullanıcının sağladığı track/usul noktaları ve ekip isimleri. Kamera fotoğrafları, PDF ve videolar cihaz üzerinde işlenir ve mevcut sürüm kaynak medyayı sunucuya yüklemez. Tanınan metin ve güven bilgisi, satır onayından önce kullanıcıya özel bir içe aktarma incelemesi oluşturmak için eşitlenebilir. Kullanıcı ilgili satırları inceleyip onaylamadan Dijital Uçuş Defteri'ne hiçbir uçuş eklenmez. - Kişisel belge geçerlilik verileri: kullanıcı isteğe bağlı olarak belge adı, kategori, düzenleyen kurum veya mevzuat çerçevesi, geçerlilik yöntemi, düzenlenme/son yenileme tarihi, belgede basılı bitiş tarihi ve kullanıcı tarafından onaylanmış tahmini bitiş hesaplama kaydını sağlık sertifikaları, pilot lisansları/sertifikaları, yetkiler, pasaportlar veya adını kendisinin verdiği başka bir kişisel belge için kaydedebilir. Bu alanlar şifreli olarak saklanır ve doğrulanmış hesapla eşitlenir. İsteğe bağlı EASA/FAA sağlık hesaplayıcısına girilen doğum tarihi yalnızca cihazda geçici olarak kullanılır; kaydedilmez, eşitlenmez, loglara yazılmaz ve hesaplama kaynağına dahil edilmez. Seçilen belge resimleri kaynak meta verileri kaldırılarak yeniden kodlanır, yalnızca ilgili hesabın cihazdaki korumalı alanında tutulur, iOS yedeğine dahil edilmez, sunucuya yüklenmez ve OCR ile işlenmez. Yerel yenileme bildirimleri kilit ekranında genel ifadeler kullanır ve yalnızca kullanıcı o cihazda açıkça etkinleştirdikten sonra planlanır. - Organizasyon: üyelik, rol, davet ve organizasyonla sınırlı eğitim bilgileri. - Topluluk: başlık, yorum, beğeni, bildirim, engelleme ve moderasyon işlemleri. - Hesap yaşam döngüsü: dışa aktarma ve silme talepleri ile bu işlemlerin tamamlanması için gereken sınırlı denetim kayıtları. Pasaport veya resmî kimlik numarası, pilot lisans numarası, belge resimleri, geçerlilik hesaplayıcısında kullanılan doğum tarihi, klinik sağlık kaydı, kesin konum, rehber, reklam kimliği veya kart verisi bilerek toplanmaz. İsteğe bağlı belge meta verileri ve onaylanan tarihler yalnızca kullanıcı yukarıda açıklandığı şekilde girdiğinde toplanır. Mevcut sürüm reklam ve uygulamalar arası takip SDK'sı içermez. ## 3. Toplama yöntemi, amaçlar ve hukuki sebepler Veriler uygulamadaki form ve işlemlerden, kimlik doğrulama/güvenlik isteklerinden veya yetkili organizasyon davetinden elde edilir. Hesabın kurulması ve güvenliği, ilerleme senkronizasyonu, talep edilen eğitim/topluluk hizmetleri, zorunlu mesajlar, kötüye kullanımın önlenmesi, moderasyon, destek, veri aktarımı ve hesap silme amaçlarıyla işlenir. Uygulanabilir mevzuata göre hukuki sebepler; talep edilen hizmetin veya sözleşmenin kurulması ya da ifası, hukuki yükümlülük, bir hakkın tesisi veya korunması, kullanıcı haklarını zedelemeyen güvenlik ve hizmet bütünlüğü meşru menfaati ve gerektiği yerde açık rızadır. Pazarlama, isteğe bağlı analiz ve liderlik tablosu varsayılan olarak kapalıdır; temel quiz erişimi kaybedilmeden geri alınabilir. ## 4. Alıcılar ve yurt dışına aktarım Veriler yalnızca destek, güvenlik, moderasyon veya işletim için bilmesi gereken yetkililerle sınırlıdır. Organizasyon yetkilileri sadece kendi organizasyonuna ait üyelik ve eğitim bilgilerini görebilir; parola, token, MFA sırrı, özel onay geçmişi ve diğer organizasyonları göremez. Üretim altyapısı ve e-posta sağlayıcıları veri sorumlusunun talimatıyla veri işleyebilir. Forum/liderlik verisi sadece paylaşım veya katılım halinde gösterilir. Brief Live içerikleri veri sorumlusunun API'si tarafından izinli herkese açık havacılık yayıncılarından alınır ve önbelleğe alınır; mobil cihaz bu yayıncılara hesap belirteci veya profil verisi göndermez. Uygulama; yayıncı tarafından sağlanan başlık, yayıncı adı, yayın tarihi, bağlantı ve özetleri, güncel haberlerin yenilemeler arasında erişilebilir kalması için hesaptan bağımsız yerel bir arşivde en fazla yedi gün saklayabilir. Verinin ülke dışında işlenmesi halinde uygulanabilir mevzuatın gerektirdiği aktarım mekanizması ve güvenceler kullanılır. Güncel alıcı/veri işleyen bilgisi support@nextcaptain.app adresinden talep edilebilir. Kişisel veriler satılmaz. ## 5. Saklama ve silme Aktif hesap ve eğitim verileri hesap aktifken; senkronize Dijital Uçuş Defteri verileri kayıt tekil olarak veya hesap tamamen silinene kadar; oturumlar varsayılan olarak en fazla 30 gün; dört haneli doğrulama kodu varsayılan olarak 10 dakika, yedek doğrulama bağlantısı 24 saat; parola sıfırlama tokeni 30 dakika; davet 7 gün; şifreli dışa aktarma 1 saat; güvenlik/denetim kaydı varsayılan olarak 365 gün; şifreli yedekler varsayılan olarak 14 gün saklanır. Cihazda korumalı tutulan kaynak taramalar; kullanıcı tarama saklamayı kapatana, hesap silme cihaz önbelleğini temizleyene, uygulama verisi silinene veya uygulama kaldırılana kadar saklanabilir. Saklama kapalıysa tanıma tamamlandıktan sonra kaynak taramalar silinir. Hesap Merkezi'nden verilen silme talebi tüm oturumları hemen kapatır. Gösterilen varsayılan 7 günlük sürede talep geri alınabilir. Süre sonunda hesap, kimlik, profil, tercih, üyelik, quiz, Dijital Uçuş Defteri, dışa aktarma ve kullanıcı içeriği kayıtları; özel bir yasal saklama zorunluluğu yoksa yeniden denenebilir silme worker'ı tarafından silinir. Yedekten geri dönüşte gecikmiş silme işleri genel erişimden önce çalıştırılır. Silme talebi başarıyla alındığında talebi gönderen cihazdaki ilgili hesaba ait yerel Dijital Uçuş Defteri önbelleği de kaldırılır. ## 6. İlgili kişinin hakları ve tercihleri Kullanıcı profil ve tercihlerini düzenleyebilir, e-posta/kullanıcı adı/parola değiştirebilir, MFA ve oturumları yönetebilir, isteğe bağlı tercihleri geri alabilir, verisini indirebilir ve hesabını uygulama içinden silebilir. Uygulanabilir mevzuat kapsamında; kişisel verisinin işlenip işlenmediğini öğrenme, bilgi ve erişim talep etme, işleme amacını ve aktarılan kişileri öğrenme, düzeltme veya silme isteme, otomatik analiz sonucuna itiraz etme ve zararın giderilmesini talep etme hakları bulunabilir. Talepler support@nextcaptain.app adresine iletilebilir; yanıt öncesi kimlik doğrulaması istenebilir. ## 7. Güvenlik, çocuklar ve değişiklikler TLS, güçlü parola özetleme, token rotasyonu, iOS Keychain, şifreleme, en az yetki, tenant izolasyonu, hız sınırı, denetim kaydı ve doğrulanmış yedekler kullanılır. Mutlak güvenlik garanti edilemez. Hizmet çocuklara yönelik değildir; yerel dijital rıza yaşının altındakiler gerekli veli izni olmadan hesap açmamalıdır. Esaslı değişikliklerde yeni sürüm numarası ve gerektiğinde uygulama içi bildirim veya yeniden onay sunulur. Zorunlu haklar bu metinle sınırlanmaz.