User & Data Policy
Last updated: August 8, 2026
1. Overview
This policy describes how Caprock Innovations, LLC collects and handles personal information when you use Flight Log Converter — a web service that converts handwritten pilot logbook pages into structured, exportable flight records using automated image analysis.
We collect only what we need to run the service, keep accounts secure, process payments, and improve reliability. We do not sell personal information. For logbook extraction we use OpenRouter and only route to model providers that enforce Zero Data Retention (ZDR) policies. We do not allow models to train on your data. You stay in control of deletion and export from your account.
2. Service Operator
Caprock Innovations, LLC (“Caprock,” “we,” “us,” or “our”) operates flightlogconverter.com and related application infrastructure.
Privacy questions or data requests: support@flightlogconverter.com
3. Information We Collect
Information you submit
- Email address — account sign-in, password recovery, and service-related notices
- Billing address — collected on Stripe Checkout when you purchase page credits, used to calculate applicable sales tax (for example Texas) and to process payment. We do not collect a mailing address at account registration.
- Password — stored only as a one-way bcrypt hash; we cannot recover your plaintext password
- Logbook images — photos or scans you upload for digitization
- Structured flight entries — dates, aircraft, airports, times, and remarks produced from your uploads and any edits you make
- Support messages — content you send when contacting us for help
Information generated automatically
- Network and device metadata — IP address, browser type, and operating system from standard HTTP requests
- Security and usage logs — authentication events, rate-limit records, processing timestamps, and credit ledger activity needed for billing and troubleshooting
- Error diagnostics — when enabled, anonymized crash reports via Sentry (user identifier only; no logbook image content in reports)
- First-party site metrics — page path, referrer, coarse geo (country/region when available), truncated user agent, and anonymous visitor/session identifiers. IP addresses are retained up to 7 days for security and abuse review, then stored only as an irreversible hash
4. Information We Do Not Collect
- Legal name, phone number, mailing address, or government ID (unless you include them in uploaded logbook text)
- Payment card numbers — Stripe processes card data; we receive transaction metadata only
- Advertising identifiers, cross-site tracking profiles, or interest-based ad data
- Third-party marketing analytics — we do not run Google Analytics or sell browsing data to advertisers; site metrics are first-party only
5. Why We Process Your Information
| Activity | Data involved | Legal basis (where GDPR applies) |
|---|---|---|
| Operate accounts and projects | Email, password hash, project and image metadata | Performance of our contract with you |
| Run AI-assisted extraction | Uploaded images and resulting flight entries | Performance of our contract with you |
| Bill for page credits | Email, purchase and credit ledger records | Performance of our contract with you |
| Send transactional email | Email address | Performance of our contract with you |
| Protect the platform | IP address, request logs, abuse signals | Legitimate interests (security and fraud prevention) |
| Maintain financial records | Payment transaction metadata | Legal obligation |
| Improve extraction quality | Aggregated, non-identifying error statistics | Legitimate interests (service improvement) |
We do not use your information for unsolicited marketing or sale to data brokers.
6. Automated Logbook Extraction and AI Privacy
When you submit an image for processing:
- The file is transmitted to our servers over TLS (HTTPS).
- Our application sends the image and extraction instructions to vision models through OpenRouter solely to read handwriting and return structured fields. We use OpenRouter models from multiple underlying providers (for example Google, Anthropic, and others) to deliver the best accuracy and reliability for our customers. Every provider we use through OpenRouter must enforce a Zero Data Retention policy for your request.
- Extracted rows are stored in your project so you can review, edit, and export them.
- Original images remain in your project until you delete them, delete the project, or your account is removed under our retention rules.
Zero Data Retention and no model training
We configure every OCR inference request through OpenRouter so that your logbook data is handled under strict privacy rules:
- ZDR providers only — we use only OpenRouter model providers that enforce Zero Data Retention policies. Your prompts, images, and model outputs are not retained by those providers after the request completes.
- No training on your data — we do not allow models or providers to use your logbook content for training, fine-tuning, or improving their models.
- Multiple providers for service quality — we may route requests across different OpenRouter-hosted models and providers to improve speed, accuracy, and uptime. Privacy requirements apply to every route; we never fall back to providers that retain data or train on customer content.
- Purpose limitation — logbook images are sent to AI services only for the extraction you requested, not for unrelated analysis or marketing.
- No human review — extraction is performed by software, not people reading your logbooks.
If no ZDR-eligible provider is available for a given model, extraction may fail rather than silently using a provider that retains data — we prioritize your privacy over convenience. OpenRouter may also apply account-level privacy settings on our API key.
What we store vs. what AI providers receive
AI providers receive your image and instructions only for the duration of the inference request under ZDR routing. We store extracted flight data, project metadata, and uploaded images on our infrastructure (Railway encrypted storage) until you delete them or request account deletion. We do not sell or license your logbook data to third parties.
7. Third-Party Service Providers
We rely on vetted vendors to deliver the service:
| Provider | Role | Data shared |
|---|---|---|
| OpenRouter (multiple ZDR vision providers, e.g., Google, Anthropic) | Handwriting recognition and field extraction — ZDR-only, no training on your data | Logbook images and extraction prompts for the active request only; not retained by providers after processing |
| Stripe | Payment processing | Email, purchase amounts; card data stays with Stripe |
| Resend (transactional email provider) | Account and notification email | Email address and message content |
| Railway | Application hosting and encrypted storage volumes | All service data at rest on our infrastructure |
| Sentry (when enabled) | Application error monitoring | Technical error context; no logbook image payloads |
We contractually require vendors to protect data and use it only to provide their service to us.
8. Retention Periods
| Category | Retention | Notes |
|---|---|---|
| Account profile | While active; removed within 30 days after confirmed deletion | Deletion is initiated from account settings |
| Uploaded images | Until you delete them, or after 12 months of account inactivity | We email a warning before inactive-account image purge |
| Extracted flight data | Until you delete the project or your account | Export anytime in CSV or JSON |
| Payment records | Up to 7 years | Required for tax and accounting; anonymized after account deletion where possible |
| Security and rate-limit logs | About 90 days | Abuse investigation only |
| Error monitoring events | About 90 days (when Sentry is enabled) | Bug diagnosis |
9. Your Rights, Choices, and Control
You control your data. Depending on your location, you may have the right to:
- Access — request a copy of personal data we hold about you
- Export — download flight records (CSV, JSON) from projects, or a full account export (ZIP with structured JSON metadata) from Account Settings
- Correct — update your email address in account settings
- Delete granularly — remove individual uploaded images or entire projects from your dashboard at any time
- Delete your account — Account Settings → Delete Account → type DELETE → confirm via the email link we send. This removes your profile, projects, images, and extracted flight data. Anonymized payment records may be retained where tax or accounting law requires.
- Restrict or object — ask us to limit certain processing where applicable law allows
- Portability — receive machine-readable exports (EEA/UK users)
- Complain — lodge a complaint with your local supervisory authority (EEA/UK users)
Self-service export and deletion are available in your account without waiting for support. For requests we cannot fulfill in the product (for example, questions about anonymized payment records), email support@flightlogconverter.com. We respond within 30 days unless law permits a longer period.
10. Cookies and Local Storage
Our site uses minimal client-side storage:
- Session token in local storage — keeps you signed in between visits; contains only an access token and expiry metadata
- Theme and UI preferences — optional display settings stored locally
- First-party visit identifiers — anonymous visitor and session IDs used only for our own traffic metrics (pageviews, bounce rate, coarse geo)
We do not set third-party advertising analytics cookies. First-party metrics are not sold or used for cross-site advertising.
11. Security Measures
We apply commercially reasonable safeguards, including:
- TLS encryption for data in transit
- bcrypt password hashing (cost factor 12)
- Role-restricted database access and request rate limiting
- Encrypted infrastructure hosting with access controls
No online service can guarantee absolute security. If we learn of a breach affecting your personal data, we will notify you and regulators as required by applicable law (typically within 72 hours where GDPR applies).
12. International Processing
Our primary infrastructure is located in the United States. If you access the service from another country, your data may be transferred to and processed in the US. We work with providers that maintain appropriate contractual and organizational safeguards for cross-border transfers.
13. Health and Medical Information
Flight Log Converter is built for flight-time records, not medical records. We are not a HIPAA-covered entity. Do not upload medical certificate details, health conditions, medications, or other protected health information. If you accidentally include such content, delete the upload promptly and notify us so we can assist with removal.
14. Minors, Policy Changes, and Contact
The service is intended for adults 18 and older. We do not knowingly collect data from minors.
We may revise this policy. Material changes will be announced on the site and, when appropriate, by email before they take effect. Continued use after the effective date means you accept the updated policy.
Questions or data requests: support@flightlogconverter.com