# NextCaptain Privacy Policy

Effective date: 2026-07-21

## 1. Controller and contact

NextCaptain is operated by **Cankan Ahmet Günaydın**, located at
**Fatih Mah. Sanayi Cad. Armis 1 Sitesi No: 12/7 Gaziemir/İzmir, Türkiye**. The operator is the
data controller for the account and training data described in this policy.

Privacy and support contact: **support@nextcaptain.app**

## 2. Scope and data categories

This policy applies to the NextCaptain iOS application, its API,
account services, training progress, leaderboard, organization features, and
community functions.

We process the following categories when you use the relevant feature:

- Account data: email address, nickname, account status, language, time zone,
  verification state, and consent records.
- Optional profile data: first/last name, aviation role, training goal,
  country or region, experience level, avatar URL, and bio.
- Security data: salted password hash, hashed session/token values, encrypted
  MFA secret, recovery-code hashes, device/platform description, keyed IP hash,
  request identifier, login failures, and allowlisted audit events.
- Training data: quiz progress, answers, scores, points, achievements, wrong and
  flagged questions, downloaded-pack state, and saved tests.
- Digital Logbook data: manually entered or user-confirmed flight dates, routes,
  airport codes, aircraft and duty details, flight times, operating role,
  take-offs/landings, procedure fields, verification status, private remarks,
  personal airports, roster rows, recognized logbook text, import review
  decisions, user-supplied track/procedure points, and crew names entered by the
  user. Camera photos, PDFs, and videos are processed on the device and the
  source media is not uploaded by the current release. Recognized text and
  confidence information may be synchronized to create a private import review
  before row-by-row confirmation. No flight is added to the Digital Logbook
  until the user reviews and confirms the applicable rows.
- Personal document validity data: the user may optionally save a document
  name, category, issuing framework, validity method, issue/last-renewal date,
  printed expiry date, and a user-confirmed expected-expiry calculation record
  for medical certificates, pilot licences/certificates, ratings, passports, or
  another named personal document. These fields are encrypted at rest and
  synchronized to the verified account. A date of birth entered into the
  optional EASA/FAA medical calculator is used transiently on the device and is
  not saved, synchronized, logged, or included in calculation provenance.
  Selected document images are re-encoded without source metadata, stored only
  in that account's protected device container, excluded from backup, and never
  uploaded or processed with OCR. Local renewal notifications use generic lock-
  screen text and are enabled only after the user opts in on that device.
- Smart Detect location data: approximate coordinates, rounded on the device
  and supplied only after the user taps Use My Location, together with the
  selected airline/base and time window. The coordinates are encrypted in a
  short-lived detection session and are not used to build a location history.
- Weather Briefing location data: after the user selects Use location, an
  approximate device position is compared on the device with the bundled
  supported-airport catalog. Only the selected ICAO weather-station code is
  sent to the weather service. Weather Briefing does not retain coordinates;
  it stores only the user's location preference and cached station observation.
  Automatic refresh uses location only while permission is already granted and
  never opens the system prompt without a new Use location action. The
  configured base airport is used when location is unavailable.
- Organization data: memberships, roles, invitations, and organization-scoped
  training information.
- Community data: topics, comments, likes, reports, blocks, and moderation
  actions. Content is visible according to the feature's stated audience.
- Account lifecycle data: export requests, deletion request/deadline, and the
  minimum audit evidence needed to complete or troubleshoot those operations.

We do not intentionally collect passport or government ID numbers, pilot
licence numbers, document images, dates of birth used by the validity
calculator, clinical health records, precise location, address-book contacts,
advertising identifiers, or payment-card data. Optional document metadata and
confirmed dates are collected only when entered by the user as described above.
The current release contains no advertising or cross-app tracking SDK.

## 3. Collection method, purposes, and legal bases

Data is collected directly from forms and actions in the app, automatically
from authentication/security requests, or from an authorized organization
invitation. We process it to:

- create and secure accounts, synchronize progress, and provide requested
  training/community functions;
- send verification, password-reset, deletion, security, and requested reminder
  messages;
- prevent abuse, enforce access rules, investigate incidents, moderate content,
  and maintain service integrity;
- provide portable exports, execute deletion, answer support/privacy requests,
  and meet applicable legal obligations;
- show leaderboard, marketing, reminders, or optional analytics only when the
  corresponding choice is enabled.

Depending on applicable law, processing is based on performance of the service
requested by the user, compliance with legal obligations, establishment or
exercise of legal rights, legitimate interests in security and service
integrity that do not override user rights, or consent where consent is legally
required. Optional marketing, analytics, and leaderboard participation are off
by default and can be withdrawn without losing core quiz access.

## 4. Recipients and international transfers

Data is limited to personnel who need it for support, security, moderation, or
service operation. Authorized organization administrators/instructors can see
only organization-scoped membership and training information; they cannot see
passwords, tokens, MFA secrets, private consent history, or unrelated
organizations.

The production infrastructure host and transactional-email provider process
data on the operator's instructions. Public forum or leaderboard information is
shared only when the user posts or opts in. Brief Live is retrieved and cached
by the operator's API from an allowlist of public aviation publishers; the
mobile device does not send account tokens or profile data to those publishers.
The app may retain supplied headlines, publisher names, publication dates,
links, and summaries in an account-independent local archive for up to seven
days so recent briefings remain available between refreshes.

When the user requests Smart Detect, the API may send the selected airport,
airline, UTC time window, and rounded approximate coordinates to the contracted
flight-data provider to return possible flights. Provider credentials remain on
the server. Detection data expires after two minutes, and provider-derived data
must not be retained beyond the provider's contractual storage limit.

Where a provider processes data outside the user's country, the operator uses
the transfer mechanism and safeguards required by applicable law and limits the
data to the stated purpose. The current processor list and transfer information
can be requested at support@nextcaptain.app.

We do not sell personal data.

## 5. Retention and deletion

- Active account/profile/training data: while the account remains active.
- Synchronized Digital Logbook data: while the account remains active, until
  the user deletes an individual record, or until account deletion.
- Protected source scans retained on the device: until the user disables scan
  retention, account deletion clears the device cache, app data is cleared, or
  the app is uninstalled. Disabling retention removes stored source scans after
  recognition; review thumbnails remain only for the active in-memory screen.
- Access sessions: up to 30 days by default, or earlier when revoked.
- Four-digit verification codes: up to 10 minutes by default; backup
  verification links: up to 24 hours; password-reset tokens: up to 30 minutes.
- Invitations: up to 7 days; encrypted export payloads: up to 1 hour.
- Security/audit events: 365 days by default unless a shorter or legally
  required period applies.
- Deletion requests: a displayed 7-day grace period by default.
- Encrypted operational backups: 14 days by default.

Account deletion is available in Account centre. It revokes all sessions
immediately. During the displayed grace period the user can reauthenticate and
cancel. After the deadline, the retryable deletion worker removes account,
identity, profile, preference, organization, quiz, Digital Logbook, export, and
user-generated content records unless a specific legal obligation requires
minimum retention. The requesting device also removes that account's local
Digital Logbook cache after a deletion request succeeds.
Restored backups must replay overdue deletion jobs before general access.

## 6. User rights and choices

Users can update profile/preferences, change email/nickname/password, manage
MFA and sessions, withdraw optional choices, export their data, edit/delete
their community content, and request full account deletion in the app.

Subject to applicable law, users may also request information about processing,
access, correction, deletion, restriction, objection, portability, information
about recipients, and review of material automated decisions. Requests can be
sent to support@nextcaptain.app. We may verify identity before fulfilling a request
and will respond within the legally applicable period.

## 7. Security

Controls include TLS, salted memory-hard password hashing, token hashing and
rotation, iOS Keychain storage, encryption of MFA/export secrets, least-
privilege authorization, tenant isolation, rate limits, audit logging,
integrity-checked backups, and retryable account deletion. No system can
guarantee absolute security; suspected incidents should be reported promptly.

## 8. Children

The service is an aviation training product and is not directed to children.
Users who are below the minimum digital-consent age applicable in their country
must not create an account without any legally required parental authorization.

## 9. Changes

Material changes will receive a new policy version and, where required, an
in-app notice or renewed acknowledgement. Mandatory rights are not reduced by
this policy.

---

# NextCaptain Gizlilik Politikası ve Aydınlatma Metni

Yürürlük tarihi: 2026-07-21

## 1. Veri sorumlusu ve iletişim

NextCaptain, **Fatih Mah. Sanayi Cad. Armis 1 Sitesi No: 12/7 Gaziemir/İzmir,
Türkiye** adresindeki **Cankan Ahmet Günaydın** tarafından
işletilmektedir. İşletmeci, bu metinde açıklanan hesap ve eğitim verileri
bakımından veri sorumlusudur.

Gizlilik ve destek iletişimi: **support@nextcaptain.app**

## 2. Kapsam ve işlenen veri kategorileri

Bu metin NextCaptain iOS uygulaması, API, hesap hizmetleri, eğitim
ilerlemesi, liderlik tablosu, organizasyon ve topluluk özelliklerini kapsar.

İlgili özellik kullanıldığında şu veriler işlenebilir:

- Hesap: e-posta, kullanıcı adı, hesap durumu, dil, saat dilimi, doğrulama ve
  onay kayıtları.
- İsteğe bağlı profil: ad/soyad, havacılık rolü, eğitim hedefi, ülke/bölge,
  deneyim seviyesi, avatar bağlantısı ve biyografi.
- Güvenlik: tuzlanmış parola özeti, token/oturum özetleri, şifreli MFA anahtarı,
  kurtarma kodu özetleri, cihaz/platform tanımı, anahtarlı IP özeti, istek
  numarası, başarısız giriş ve izinli denetim kayıtları.
- Eğitim: ilerleme, cevaplar, puanlar, başarımlar, yanlış/işaretli sorular,
  indirilen paketler ve kayıtlı testler.
- Dijital Uçuş Defteri: kullanıcı tarafından girilen veya onaylanan uçuş tarihi,
  rota ve meydan kodları, uçak ve görev bilgileri, uçuş süreleri, pilot rolü,
  kalkış/inişler, usul alanları, doğrulama durumu, özel notlar, kişisel meydanlar
  roster satırları, tanınan logbook metni, içe aktarma inceleme kararları,
  kullanıcının sağladığı track/usul noktaları ve ekip isimleri. Kamera
  fotoğrafları, PDF ve videolar cihaz üzerinde işlenir ve mevcut sürüm kaynak
  medyayı sunucuya yüklemez. Tanınan metin ve güven bilgisi, satır onayından
  önce kullanıcıya özel bir içe aktarma incelemesi oluşturmak için
  eşitlenebilir. Kullanıcı ilgili satırları inceleyip onaylamadan Dijital Uçuş
  Defteri'ne hiçbir uçuş eklenmez.
- Kişisel belge geçerlilik verileri: kullanıcı isteğe bağlı olarak belge adı,
  kategori, düzenleyen kurum veya mevzuat çerçevesi, geçerlilik yöntemi,
  düzenlenme/son yenileme tarihi, belgede basılı bitiş tarihi ve kullanıcı
  tarafından onaylanmış tahmini bitiş hesaplama kaydını sağlık sertifikaları,
  pilot lisansları/sertifikaları, yetkiler, pasaportlar veya adını kendisinin
  verdiği başka bir kişisel belge için kaydedebilir. Bu alanlar şifreli olarak
  saklanır ve doğrulanmış hesapla eşitlenir. İsteğe bağlı EASA/FAA sağlık
  hesaplayıcısına girilen doğum tarihi yalnızca cihazda geçici olarak kullanılır;
  kaydedilmez, eşitlenmez, loglara yazılmaz ve hesaplama kaynağına dahil edilmez.
  Seçilen belge resimleri kaynak meta verileri kaldırılarak yeniden kodlanır,
  yalnızca ilgili hesabın cihazdaki korumalı alanında tutulur, iOS yedeğine dahil
  edilmez, sunucuya yüklenmez ve OCR ile işlenmez. Yerel yenileme bildirimleri
  kilit ekranında genel ifadeler kullanır ve yalnızca kullanıcı o cihazda açıkça
  etkinleştirdikten sonra planlanır.
- Organizasyon: üyelik, rol, davet ve organizasyonla sınırlı eğitim bilgileri.
- Topluluk: başlık, yorum, beğeni, bildirim, engelleme ve moderasyon işlemleri.
- Hesap yaşam döngüsü: dışa aktarma ve silme talepleri ile bu işlemlerin
  tamamlanması için gereken sınırlı denetim kayıtları.

Pasaport veya resmî kimlik numarası, pilot lisans numarası, belge resimleri,
geçerlilik hesaplayıcısında kullanılan doğum tarihi, klinik sağlık kaydı, kesin
konum, rehber, reklam kimliği veya kart verisi bilerek toplanmaz. İsteğe bağlı
belge meta verileri ve onaylanan tarihler yalnızca kullanıcı yukarıda açıklandığı
şekilde girdiğinde toplanır. Mevcut sürüm reklam ve uygulamalar arası takip
SDK'sı içermez.

## 3. Toplama yöntemi, amaçlar ve hukuki sebepler

Veriler uygulamadaki form ve işlemlerden, kimlik doğrulama/güvenlik isteklerinden
veya yetkili organizasyon davetinden elde edilir. Hesabın kurulması ve
güvenliği, ilerleme senkronizasyonu, talep edilen eğitim/topluluk hizmetleri,
zorunlu mesajlar, kötüye kullanımın önlenmesi, moderasyon, destek, veri aktarımı
ve hesap silme amaçlarıyla işlenir.

Uygulanabilir mevzuata göre hukuki sebepler; talep edilen hizmetin veya
sözleşmenin kurulması ya da ifası, hukuki yükümlülük, bir hakkın tesisi veya
korunması, kullanıcı haklarını zedelemeyen güvenlik ve hizmet bütünlüğü meşru
menfaati ve gerektiği yerde açık rızadır. Pazarlama, isteğe bağlı analiz ve
liderlik tablosu varsayılan olarak kapalıdır; temel quiz erişimi kaybedilmeden
geri alınabilir.

## 4. Alıcılar ve yurt dışına aktarım

Veriler yalnızca destek, güvenlik, moderasyon veya işletim için bilmesi gereken
yetkililerle sınırlıdır. Organizasyon yetkilileri sadece kendi organizasyonuna
ait üyelik ve eğitim bilgilerini görebilir; parola, token, MFA sırrı, özel onay
geçmişi ve diğer organizasyonları göremez.

Üretim altyapısı ve e-posta sağlayıcıları veri sorumlusunun talimatıyla veri
işleyebilir. Forum/liderlik verisi sadece paylaşım veya katılım halinde
gösterilir. Brief Live içerikleri veri sorumlusunun API'si tarafından izinli
herkese açık havacılık yayıncılarından alınır ve önbelleğe alınır; mobil cihaz
bu yayıncılara hesap belirteci veya profil verisi göndermez. Uygulama; yayıncı
tarafından sağlanan başlık, yayıncı adı, yayın tarihi, bağlantı ve özetleri,
güncel haberlerin yenilemeler arasında erişilebilir kalması için hesaptan
bağımsız yerel bir arşivde en fazla yedi gün saklayabilir. Verinin ülke
dışında işlenmesi halinde uygulanabilir mevzuatın
gerektirdiği aktarım mekanizması ve güvenceler kullanılır. Güncel alıcı/veri
işleyen bilgisi support@nextcaptain.app adresinden talep edilebilir. Kişisel veriler
satılmaz.

## 5. Saklama ve silme

Aktif hesap ve eğitim verileri hesap aktifken; senkronize Dijital Uçuş Defteri
verileri kayıt tekil olarak veya hesap tamamen silinene kadar; oturumlar
varsayılan olarak en fazla 30 gün; dört haneli doğrulama kodu varsayılan olarak 10 dakika, yedek
doğrulama bağlantısı 24 saat; parola sıfırlama tokeni 30 dakika; davet 7 gün;
şifreli dışa aktarma 1 saat; güvenlik/denetim kaydı varsayılan olarak 365 gün;
şifreli yedekler varsayılan olarak 14 gün saklanır.
Cihazda korumalı tutulan kaynak taramalar; kullanıcı tarama saklamayı kapatana,
hesap silme cihaz önbelleğini temizleyene, uygulama verisi silinene veya uygulama
kaldırılana kadar saklanabilir. Saklama kapalıysa tanıma tamamlandıktan sonra
kaynak taramalar silinir.

Hesap Merkezi'nden verilen silme talebi tüm oturumları hemen kapatır. Gösterilen
varsayılan 7 günlük sürede talep geri alınabilir. Süre sonunda hesap, kimlik,
profil, tercih, üyelik, quiz, Dijital Uçuş Defteri, dışa aktarma ve kullanıcı
içeriği kayıtları; özel
bir yasal saklama zorunluluğu yoksa yeniden denenebilir silme worker'ı tarafından
silinir. Yedekten geri dönüşte gecikmiş silme işleri genel erişimden önce
çalıştırılır. Silme talebi başarıyla alındığında talebi gönderen cihazdaki ilgili
hesaba ait yerel Dijital Uçuş Defteri önbelleği de kaldırılır.

## 6. İlgili kişinin hakları ve tercihleri

Kullanıcı profil ve tercihlerini düzenleyebilir, e-posta/kullanıcı adı/parola
değiştirebilir, MFA ve oturumları yönetebilir, isteğe bağlı tercihleri geri
alabilir, verisini indirebilir ve hesabını uygulama içinden silebilir.

Uygulanabilir mevzuat kapsamında; kişisel verisinin işlenip işlenmediğini
öğrenme, bilgi ve erişim talep etme, işleme amacını ve aktarılan kişileri
öğrenme, düzeltme veya silme isteme, otomatik analiz sonucuna itiraz etme ve
zararın giderilmesini talep etme hakları bulunabilir. Talepler
support@nextcaptain.app adresine iletilebilir; yanıt öncesi kimlik doğrulaması
istenebilir.

## 7. Güvenlik, çocuklar ve değişiklikler

TLS, güçlü parola özetleme, token rotasyonu, iOS Keychain, şifreleme, en az
yetki, tenant izolasyonu, hız sınırı, denetim kaydı ve doğrulanmış yedekler
kullanılır. Mutlak güvenlik garanti edilemez. Hizmet çocuklara yönelik değildir;
yerel dijital rıza yaşının altındakiler gerekli veli izni olmadan hesap
açmamalıdır.

Esaslı değişikliklerde yeni sürüm numarası ve gerektiğinde uygulama içi bildirim
veya yeniden onay sunulur. Zorunlu haklar bu metinle sınırlanmaz.