RosterSwift RosterSwift
Home Legal notice Support FR

Privacy Policy

Last updated: August 2026

1. Introduction

This Privacy Policy explains how RosterSwift ("we", "our", "the App"), operated by Squawk Labs SAS, handles your personal data when you use our mobile application.

Key Security Features:
  • Device Verification: on iPhone and iPad, Apple's App Attest technology cryptographically verifies that only genuine instances of our app can access your data. The Android app does not use device attestation; it relies on the same authentication tokens described below
  • Secure Authentication: JWT authentication with automatic token refresh
  • No Password Storage: We NEVER store your passwords on our servers — they are kept exclusively on your device, using Apple's secure Keychain on iPhone and iPad and the Android Keystore on Android
  • Secure Messaging: Messages are encrypted in transit and at rest on secure servers in Europe. The server-readable copy is deleted once every recipient has it; with end-to-end encryption we hold only ciphertext we cannot read
  • Encrypted Tax Vault: Tax data is encrypted on your device with AES-256-GCM before upload — we cannot read it

We are committed to protecting your privacy and ensuring compliance with the GDPR and French data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

Squawk Labs SAS
Contact: contact@squawklabs.app

3. Data We Collect

Stored locally on your device only (never sent to our servers):
  • Airline portal passwords (JetSched) — stored in the iOS Keychain, or the Android Keystore on Android
  • JWT authentication tokens — encrypted in the iOS Keychain, or the Android Keystore on Android
  • App Attest cryptographic keys — in the Secure Enclave (iPhone and iPad only)
  • Your message history (cached on your device)
  • Tax vault encryption key — derived from your passphrase, stored in the iOS Keychain, or the Android Keystore on Android
Stored on your device (SwiftData):
  • Employee trigram, employee number, email, home base, airline affiliation
Stored on our servers:
  • Flight schedules and rosters
  • Duty assignments, simulator sessions, training records
  • Layover information and aircraft registrations
  • Your email (for account identification only)
  • Device attestation records (for security verification) — iPhone and iPad only
  • Messages — the server-readable copy is deleted once every recipient has received it. Where end-to-end encryption is in use we hold only ciphertext we cannot read, and it stays until you delete the conversation or your account
  • Medical leave codes from your roster (sick leave, work accident, unfitness to fly) — health data, stored only if you have specifically allowed it in Settings → Privacy & Security → Medical leave details. Without that permission the day is stored as an undifferentiated absence with no reason attached
  • Roster diagnostic bundles — the source document returned by your airline portal together with processing artefacts, kept so we can investigate roster import faults. Encrypted at rest, capped per user and removed on a schedule (Section 10)
  • Encrypted tax vault backups (we cannot decrypt them)
  • Crew list visibility preference (visible or invisible)
  • Feedback submissions
  • Device identifiers for push notifications (an Apple Push Notification token on iPhone and iPad, a Firebase Cloud Messaging token on Android)
  • Basic diagnostic data (crash reports, error logs) to improve app stability
Stored on Cloudflare R2 (encrypted):
  • Tax vault documents (receipts, payslips) — encrypted with AES-256-GCM on your device before upload
  • Messaging file attachments — encrypted at rest
Photos and camera:
  • Accessed only when you send images in messages or capture receipts for the Tax Assistant
  • Photos sent via messaging are encrypted in transit
  • Receipt photos are encrypted on your device before upload to the vault

4. How We Use Your Data

We process your personal data for the following purposes:

  • Retrieving and displaying your flight schedules from airline systems (JetSched for Air Caraïbes and French Bee)
  • Calculating flight hours, duty statistics, and salary estimates
  • Managing bidding requests for days off and rotations
  • Maintaining your EASA logbook
  • Calculating tax deductions and generating tax reports
  • Delivering messages between crew members
  • Enabling roster sharing with other crew members (RosterShare)
  • Providing flight lookup information from community-shared data, with privacy-respecting crew list controls
  • Sending push notifications for schedule changes and messages
Legal Basis for Processing:
  • Contract — Art. 6(1)(b): retrieving, storing and displaying the roster, logbook, salary and expense data you asked the App to manage. This is the service itself
  • Legitimate interest — Art. 6(1)(f): keeping the service secure and working — account-security monitoring, moderation of reported content, and diagnosing faults
  • Explicit consent — Art. 9(2)(a): medical leave codes reveal health information and are a special category of data under Art. 9, which the contract basis above does not cover. We store them only where you have opted in specifically, separately from every other permission, and you can withdraw at any time in Settings → Privacy & Security → Medical leave details. Withdrawal removes the reason at your next roster update and changes nothing else. You are free to refuse. The cost of refusing is that a medical leave day is counted as an ordinary unpaid absence in your salary estimate, so that estimate may be lower than your actual pay; we state this plainly rather than let you discover it
  • Consent: optional features you switch on yourself, such as layover presence and roster sharing
How Authentication Works:

On iPhone and iPad, your device is verified once using Apple's App Attest. All communication then uses secure JWT tokens, on both iOS and Android. Your airline passwords are ONLY transmitted when actively fetching data from airline systems. They pass through our server but are NEVER stored, logged, or retained. They exist in server memory for approximately 5–30 seconds during authentication.

5. Messaging

RosterSwift includes a crew messaging feature:

  • Messages are encrypted in transit (TLS) between your device and our servers
  • They are processed on secure servers hosted in Europe
  • The server-readable copy of a message is deleted once every recipient has received it
  • Where end-to-end encryption is enabled we hold only ciphertext we cannot read. It remains until you delete the conversation or your account; group conversations are also deleted automatically after a period of inactivity
  • Private and group conversations are supported
  • File attachments (photos, voice messages, documents) are encrypted at rest

Moderation: You can report abusive messages and block users. When you submit a report, the reported message content is shared with our moderation team for review.

6. Crew List Visibility & Privacy Controls

RosterSwift includes a crew list visibility system that gives you control over whether other crew members can see your name on shared flight information:

Your Visibility Setting:
  • You can set your visibility to Visible or Invisible at any time in the Crew Hub settings
  • When set to Invisible, your name and trigram are hidden from other users' crew lists — they will see your role (e.g., CDB, OPL) but not your identity
  • This setting is stored on our servers and applies across all flights
Reciprocity Rule:
  • If you choose to be invisible, you also lose access to viewing other crew members' identities (except on your own flights)
  • This ensures fairness: you cannot hide from others while still seeing them
7-Day Cooldown:
  • Switching from invisible back to visible triggers a 7-day cooldown period
  • During this period, you remain unable to view crew lists on other flights
  • This prevents abuse of rapid visibility toggling
Access Levels:
  • Your airline may configure different access levels per function (cockpit, cabin, etc.)
  • Full access: see all crew members regardless of their visibility setting
  • Partial access: see the crew list, but invisible members appear with their role only (name and trigram hidden)
  • No access: crew lists are not available for flights you are not assigned to
What Others See When You Are Invisible:
  • Your role/function on the flight remains visible (e.g., "CDB", "PNC")
  • Your name, trigram, and base are hidden
  • A note indicates that some crew members have private visibility

7. Roster Group Discovery & Opt-Out

When creating a group chat from a flight roster, RosterSwift can show which crew members on your flight have an app account, even if they are not in your buddy list. This helps crew coordinate before flights.

How it works:
  • Discovery is flight-scoped: only crew members on a flight you are assigned to can be discovered
  • Your trigramme and user ID may be shared with other crew members on the same flight
  • No browsing or searching of arbitrary users is possible
Your control (GDPR opt-out):
  • You can disable "Allow Group Invitations from Roster" in Chat Privacy settings
  • When disabled, you appear as if you do not have the app to other non-buddy crew members
  • Buddies can always add you to groups regardless of this setting
  • This setting does not affect groups you are already a member of

8. Encrypted Tax Vault

The Tax Assistant includes an encrypted vault for storing sensitive tax data:

  • All data is encrypted on your device using AES-256-GCM before upload
  • Encryption key is derived from your passphrase via HKDF-SHA256 — it never leaves your device
  • Encrypted database backups are stored on Cloudflare R2 and deleted after 30 days; documents (receipts, payslips) are also on Cloudflare R2
  • We cannot decrypt your vault data — only you can, with your passphrase
  • If you forget your passphrase, your vault data cannot be recovered

9. Data Storage and Security

Server infrastructure:
  • Servers hosted on dedicated private infrastructure in France. A standby system in Finland (EU) can take over if the French site fails
  • All data encrypted in transit (HTTPS/TLS)
  • Database access restricted and protected
  • Daily encrypted backups with 30-day retention
Security measures:
  • Apple App Attest — cryptographic verification of genuine app installations (iPhone and iPad only)
  • JWT Authentication — secure tokens with automatic refresh and rotation
  • Secure messaging — encrypted in transit and at rest, with optional end-to-end encryption
  • AES-256-GCM — client-side encryption for tax vault
  • HTTPS/TLS — all data transmission encrypted
  • Per-device access control — revoke access for specific devices

10. Data Retention

  • Flight and schedule data: Retained as long as your account is active
  • Account information: Retained until you request deletion
  • Messages: the server-readable copy is deleted once every recipient has received it. End-to-end encrypted messages are held as ciphertext until you delete the conversation or your account; group conversations are removed automatically after a period of inactivity
  • Medical leave codes: kept only while your permission stands. Withdraw it and the reason is removed at your next roster update, leaving an undifferentiated absence
  • Roster diagnostic bundles: capped per user and deleted after 30 days, by a scheduled job that runs whether or not you keep using the App
  • Diagnostic logs: if you switch on diagnostics, the log lines it streams are deleted after 14 days
  • Diagnostic session recordings: deleted after 30 days
  • Sign-in and security events: kept for 180 days so that we can investigate suspicious activity, then deleted
  • Files you upload (logbooks, roster documents, payslips sent with a support request): kept while we need them for the purpose you sent them for, and removed — document and record together — when you close your account
  • Tax vault data: Retained until you delete it or reset your vault
  • Access tokens: Expire after 1 hour; refresh tokens expire after 1 year
  • Passwords: NEVER stored on our servers

Every table in our database has a written retention decision, and a single scheduled job applies them. You may request deletion of your server-side data at any time (see Section 12).

11. Data Sharing and Third Parties

We share your data with:
  • Airline Systems: JetSched (Air Caraïbes, French Bee) — your credentials are used to authenticate and retrieve your data
  • Cloudflare: object storage (R2) for encrypted tax vault documents (we cannot read the content) and messaging attachments, plus network services
  • Hetzner: standby hosting in Finland (EU), used only if our French infrastructure fails
  • Apple (APNs) and Google (FCM): delivery of push notifications to your device
  • Postmark and Mailgun: sending account email such as verification codes
  • Mistral (France): AI features — written summaries, hotel lookups, summarising feedback for our own triage, and screening content you report. It receives only the text or the derived facts needed for that task. Your roster is never sent to an AI model, and no AI processing leaves the European Union.
  • Google and Apple, if you subscribe to the calendar feed: the feed is a link you add to your own calendar, and their servers fetch it on a schedule of their choosing for as long as the subscription exists. It carries your duties, your destinations and your layover hotel name, address and telephone number. Medical leave reasons and other crew members' names are never included. The link is a long secret address — treat it like a password, and you can revoke or replace it at any time in the App.
Other crew members on your roster:

Your roster names the crew you are rostered to fly with, because your airline puts them there. We store those names so that we can show your roster accurately and so that Crew List can tell you who you are flying with. They are encrypted at rest, and they are removed from everything you share — your calendar feed, a family share link, or a roster comparison with another crew member. We never sell them, and we never use them for anything other than showing you your own roster and the Crew List feature.

International transfers:

Some of the providers above process data outside the EU/EEA. Those transfers are covered by the data-processing terms we accept with each provider, which incorporate the European Commission's Standard Contractual Clauses or rely on the EU–US Data Privacy Framework.

We do NOT:
  • Sell your personal data
  • Share your data with advertisers
  • Use your data for advertising, or make decisions about you by automated means that produce legal or similarly significant effects
  • Transfer your data to third parties for their own purposes
Security monitoring:

We do build a security profile of your account activity — sign-in patterns, the devices and networks you use, failed sign-ins and error rates — and flag anomalies automatically, so that we can detect someone else getting into your account. This is profiling in the sense of Art. 4(4) and we rely on legitimate interest under Art. 6(1)(f). No decision about you is taken automatically on the basis of it, and it is not used for advertising or shared with anyone.

We are not affiliated with, endorsed by, or officially connected to Air Caraïbes, French Bee, or any airline. This is an independent tool.

12. Your Rights (GDPR)

Under GDPR and French law, you have the right to: access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent.

To exercise these rights:
Write to contact@rosterswift.com or contact@squawklabs.app — both reach us, and either counts. We will respond within one month, as Art. 12(3) requires, and will tell you if we need longer and why.

Withdrawing permission for medical leave detail does not need a request to us: it is a switch in Settings › Privacy & Security, and turning it off removes the stored reason at your next roster update.

You can also delete local data at any time using "Delete All Data" in Settings or by uninstalling the app.

Complaints: You may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) at www.cnil.fr.

13. Children's Privacy

This App is intended for professional airline crew members only. We do not knowingly collect data from individuals under 18 years of age.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by displaying a notice within the App and updating the "Last updated" date above.

15. Contact Us

For any questions regarding this Privacy Policy or your personal data:

Email: contact@rosterswift.com

We aim to respond to all inquiries within 48 hours.

RosterSwift RosterSwift by Squawk Labs
Privacy Terms Support Contact
© 2026 Squawk Labs SAS. All rights reserved.