Who we are and what this covers
Runbook Aviation is operated by Runbook Technologies LLC (Runbook). This policy covers our public website, authenticated web and mobile applications, and related support and operational communications. An operator or provider organization may also control information its members enter into Runbook.
Information we collect
- Account and organization information, including name, email address, phone number when provided, membership, role, and authentication and security records.
- Aircraft and event information, including aircraft identifiers and type, location, original reports and corrections, questions and answers, provider capabilities and coverage, offers, selected providers, activity, and completion records.
- Content you submit, including private event messages, support requests, and provider request documents. Documents may contain information supplied by the uploader that we do not request separately.
- Billing information for an organization that elects a paid plan, including plan, subscription, invoice and event-usage records. Our payment provider handles payment methods and billing address information used in checkout.
- Notification information, including email and optional SMS preferences and delivery records, and, if you enable mobile push alerts, a device installation identifier, push token, platform, and permission status.
- Technical information needed to operate and secure the service, such as browser or device information, access logs, and error diagnostics. On public website pages, we also measure aggregate page views, referring sites, and page performance. We do not use the app to track your aircraft or collect its GPS position.
A provider-access inquiry also supplies your name, email address, and service-provider role through the public form. You may choose to use the microphone for a report, answer, or message; typing remains available.
How we use information
We use this information to provide accounts and organization access; structure and coordinate aircraft events; determine which providers are eligible to receive an opportunity; present offers and selected-provider progress; send requested operational alerts; administer subscriptions and event usage; respond to support and privacy requests; prevent abuse; and meet legal and recordkeeping obligations. Runbook personnel may assist with provider outreach and coordination under explicit staff access.
We send report text to an AI service to suggest structured intake details. The operator reviews and confirms those details before they control the request; provider eligibility is checked separately. If you use voice input, audio is sent to a transcription service and the resulting words remain editable before submission. Live report dictation sends audio from your device to that service. Runbook does not save the audio recording as part of the event. The report or message text you choose to submit is retained with the relevant record. AI output does not diagnose an aircraft or authorize work.
We use Cloudflare Web Analytics on public website pages to understand which pages people visit and how those pages perform. It does not set analytics cookies or collect URL query strings. We do not load it in sign-in or the authenticated workspace, or send account, aircraft, or event information to it.
Our demo video page (runbookaviation.com/watch) records, without cookies, when the page is opened, whether and how far the video is played, and whether its contact links are used. A link we send you may include a code that we associate with you in our outreach records, so we can tell whether our message was useful and follow up appropriately. That page does not load Cloudflare Web Analytics.
Who receives information
Members of your organization can access information permitted by their role. Relevant event facts are shared with invited providers so they can assess an opportunity. The operator can review each provider’s offer. A provider’s private conversation and competing offers are not opened to other providers. Selected participants receive the contact and coordination details needed to work together. Authorized Runbook personnel can access records to provide assistance, safety recovery, and support. A provider request document becomes available to the event participants shown in the upload flow when its offer is submitted.
We use Clerk for authentication, cloud hosting and database providers for application records, Cloudflare for public website analytics, OpenAI for AI intake and transcription, Resend for email, Stripe for paid-plan billing, and Expo and device-platform providers for optional push delivery. Twilio is the planned provider for optional SMS if that channel is enabled. These providers receive information needed for their services and may process or retain it under their applicable terms. We may also disclose information when required by law, to protect people or service integrity, or in a business transfer. We do not sell or share mobile numbers, SMS opt-in data, or personal information with third parties or affiliates for marketing or promotional purposes.
Notifications and choices
Operational information remains available in the authenticated workspace when email, push, or SMS is unavailable. You can change eligible email, push, and SMS preferences in the app. Push alerts require your device permission and can also be disabled in device settings. SMS is optional and off by default. Pilots, aircraft operators, and provider representatives enroll an authorized mobile or SMS-capable dispatch number in Settings using a separate unchecked consent checkbox. You can disable SMS in Settings or reply STOP. Message frequency varies. Message and data rates may apply. See the SMS notification terms. Notification delivery does not mean a participant acknowledged or accepted an event action.
Retention, deletion, and security
We retain account and operational records while needed to provide the service and to preserve event history, billing, security, audit, dispute, and legal records. Published provider documents remain with their event; unpublished uploads can be removed by their uploader and may be cleared during routine cleanup. Temporary voice clips are discarded by the app after the transcription flow closes or succeeds; service providers may have separate retention periods. Backup and vendor copies may take additional time to expire. We use access controls and other technical and organizational safeguards, but no method of storage or transmission is perfectly secure.
You can request access, correction, or deletion of your personal information through our contact page. Signed-in users can also initiate account deletion from Account & about in the web or mobile app. We verify and review requests, delete or de-identify information that is no longer needed, and explain any information we must retain for another participant’s event, billing, security, or legal obligations. Deleting an individual account does not automatically delete an organization’s shared event history or cancel its subscription; contact us about those separately.
Children and changes
Runbook is a business service and is not directed to children under 18. We may update this policy when our practices change. The effective date above identifies the published version. We will provide additional notice when a material change calls for it. Questions and privacy requests can be sent through the contact page.