Legal

Legal & policies

The disclaimers, privacy policy, cookies statement, terms of use, organisation agreement, and accessibility statement for Pilot EFB, in one place. Each document shows when it was last updated.

Published by

Azimuth Labs Ltd · Registered in England and Wales.
Company No. 17289059 · ICO No. ZC178458.
Registered office: 82A James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom.

Compliance

Disclaimers

The verbatim disclaimer text shown inside the app. Pilot EFB is an informational reference only, never a replacement for certified systems, official sources, or your operator's approved procedures.

Important

General disclaimer

Pilot EFB is NOT a certified Electronic Flight Bag. It is an informational and organisational tool only. All outputs: weather, NOTAMs, FTL calculations, descent planning, and any other aviation data are for personal reference and planning purposes only. Pilots must always verify all data against official, certified sources before making any operational decisions. The developer accepts no liability for decisions made based on information displayed in this app.

Per-module disclaimers

Weather
Reference only - verify officially.
NOTAMs
May be incomplete - verify officially.
Live traffic
Community ADS-B - incomplete and delayed. Not for traffic separation or collision avoidance.
Flight & duty time
Personal planning only.
Logbook
Personal record only.
Descent planning
Approximate - use approved procedures.
Checklists
Reference only - not a certified checklist.
V-speed cards
Personal reference - verify against the AFM.
Fatigue indicator
Estimate only - not a certified FRMS.
Community board
Community-submitted ideas - not endorsements, commitments, or official roadmap. Posts are written by other users.
Per-diem tracker
Records & estimates only - not financial advice.
Credentials
Personal record - verify against official records.
Voyage reports
Personal record only - not a formal occurrence report.
Online Flying (simulation)
For simulation use only - not for real-world flight.
General reference
Reference only - verify officially.

Privacy

Privacy policy

Last updated: 2026-09-13

Pilot EFB is a personal, informational flight companion for pilots, offered as an iOS app and as a web edition at app.pilotefb.com, and described on this website at pilotefb.com. It is not a certified Electronic Flight Bag and is not intended for operational decisions, dispatch, primary navigation, or regulatory compliance. This policy covers this website, the Pilot EFB app, and the Pilot EFB web edition: the section immediately below explains how the website handles your data, and sections 1 to 11 explain what the app and web edition store, what they send to third parties, what they do not collect, and how to delete it.

The data controller for any personal data described below is Azimuth Labs Ltd, a company registered in England and Wales under company number 17289059, with its registered office at 82A James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom. We are registered with the Information Commissioner's Office under registration number ZC178458. If anything here is unclear, or to exercise any of your rights, email support@pilotefb.com.

This website (pilotefb.com)

This website is an informational marketing site for the Pilot EFB app, and it is privacy-by-design:

  • No accounts, one form. The website has no accounts, sign-up, newsletter, or login. Its one form is the free NOTAM lookup at /notams, described in the next bullet. The only personal data connected with the website is what is described in this section: the NOTAM lookup, optional analytics if you opt in, the technical data involved in serving pages, and anything you choose to email us.
  • NOTAM lookup. When you look up a station on the NOTAM pages, the four-letter station code you typed and your IP address are handled by a small server function (a Netlify Function, on the same hosting as the site) that fetches the NOTAMs for you. The IP address is used only to count how many lookups have come from the same address in the last minute, so we can limit abuse; the counter lives in the function's memory, holds only timestamps, and is dropped after a minute. We do not store or log your IP address or tie a lookup to you; the station code can appear in the function's error log if the NOTAM feed fails, on its own. Results for a station are cached for a short time so a repeat lookup is served without another fetch, and the cache contains NOTAMs, not anything about you. When bot protection is switched on, the NOTAM pages also load Cloudflare Turnstile, a bot check run by Cloudflare, Inc. (challenges.cloudflare.com). It loads only on those pages: your browser fetches the widget from Cloudflare, which therefore sees your IP address and browser details, and when you run a lookup our function sends Cloudflare the widget's one-time token together with your IP address to confirm the check passed. Turnstile may set a cookie of its own for the challenge; it is strictly necessary, so it needs no consent, and it is described in the cookie policy. Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/. If you opt in to analytics, the station code you looked up is also recorded as an analytics event, as the cookie policy explains.
  • Product analytics, only if you opt in. With your consent we use PostHog (EU Cloud, processed in Frankfurt) for product analytics - autocapture of interaction events (page views, clicks, and similar) - together with Cloudflare Web Analytics (cookieless) for aggregate traffic. They load only after you opt in through the cookie banner, and nothing runs before then. We do not record your session, set no advertising cookies, run no advertising pixels, and embed no third-party content such as social widgets or video players, with one exception: Cloudflare Turnstile, the bot check on the NOTAM lookup pages, which loads only there and only while bot protection is switched on (see "NOTAM lookup" below). See the cookie policy for the specifics of what each one stores.
  • Browser storage. Unless you opt in to analytics, the only things stored on your device are your light/dark theme choice and a record of your cookie choice. They set no identifier and never leave your browser, so under the Privacy and Electronic Communications Regulations (PECR) they do not require consent. If you opt in to analytics, PostHog additionally stores the first-party cookies and identifier described in the cookie policy.
  • Optional analytics: off unless you allow it. A cookie banner lets you opt in to analytics. It is off by default; only when you opt in do we load PostHog (product analytics, EU Cloud) and Cloudflare Web Analytics, never before. You can change or withdraw your choice at any time via "Cookie settings" in the footer, and withdrawing stops further collection and deletes PostHog's cookies and stored id. See the cookie policy for details.
  • Hosting and server logs (Netlify). This website is hosted by Netlify, Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). When you load a page, Netlify may briefly process the technical data your browser sends (such as your IP address, the page requested, your browser user-agent, and a timestamp) in order to deliver the page and maintain service security. We have a Data Processing Agreement with Netlify in place and rely on our legitimate interests for this processing. We do not use these logs to identify or profile you. Netlify's privacy policy: https://www.netlify.com/privacy/.
  • Website analytics retention. If you opt in, PostHog event data is kept in PostHog's EU (Frankfurt) project and we delete events older than 12 months; Cloudflare Web Analytics keeps only aggregate counts, which contain no personal data. Withdrawing consent stops collection and resets your PostHog identifier.
  • If you email us. When you contact us at support@pilotefb.com, we process your email address and the contents of your message solely to reply and to keep a record of the correspondence. We rely on our legitimate interests in responding to enquiries, and we keep your message and our response for up to 3 years from the date of last contact so that we can deal with any follow-up or dispute, then delete it. You can ask us to delete it sooner at any time.

The remainder of this policy (sections 1 to 11) describes how the Pilot EFB app and the Pilot EFB web edition (Pilot EFB Desk) handle data. It carries the same text as the in-app Settings > About > Privacy Policy screen, with the website analytics providers above added to the "International transfers" list so that this single page covers everything we operate.

Data controller

For the limited personal data processed when you sign in or contact us, the data controller is Azimuth Labs Ltd (company number 17289059), trading as Pilot EFB, registered office 82A James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom, contactable at support@pilotefb.com.

Because Pilot EFB is offline-first, most of your data never reaches us and stays solely on your device, where you are in sole control of it.


1. What data we store on your device

Pilot EFB is offline-first. The on-device SQLite database is the source of truth for everything the app shows you. Nothing in this section ever leaves your device unless you explicitly export or share it, or you sign in - in which case some of it syncs to your own account so it follows you to a new device. Two tiers (see "Cloud Sync" in section 2): your profile and app setup (an allow-list of preferences plus your config such as checklists, favourites and minimums) sync for any signed-in user, free, and your records (logbook, duties, weather/NOTAM history, expenses) and photo/PDF attachments are backed up for any signed-in user too; Cloud Sync (Pro) adds continuous automatic two-way sync. Sync is always opt-in by signing in and never required - the app is offline-first: everything you have saved keeps working without a connection, while fetching fresh weather, NOTAMs or a roster needs one. A defined set of items is never synced and stays on-device (see "Cloud Sync").

The database holds:

  • Logbook entries - date, aircraft type and registration, route, off/on block times, role, landings, night/IFR time, remarks.
  • Carry-forward totals - hours flown before you started using Pilot EFB.
  • Duty periods (FTL) - reporting time, sectors, rest facility, crew complement, augmented flag, and derived FDP results.
  • Flight folders and snapshots - the immutable weather and NOTAM payloads you saved, plus any notes you attached. Snapshots are SHA-256 hashed and verified on display.
  • Photo attachments - any photos you choose to attach to a logbook entry or flight folder (taken with the camera or picked from your photo library). These are copied into the app's local storage at full quality. The local copy never leaves your device unless you explicitly export or share it, or you are signed in: then a compressed copy and a small thumbnail are uploaded to your own private storage area so the attachment is backed up with your records and restores on your other devices (see "Cloud Sync"). The full-quality local original is never modified or sent.
  • Cached weather and NOTAMs - last-fetched payloads per ICAO with staleness timestamps. Capped at 200 entries with LRU eviction.
  • Recently-viewed airports - last 30 ICAO codes you opened.
  • Settings - units, home base ICAO, FTL regime, theme, app-lock preferences, accessibility toggles, notification preferences, and - only if you use Online Flying - your network-flying identifier (IVAO VID).
  • Scratchpad notes and active timers.
  • Disclaimer acceptance and onboarding state (timestamped).
  • Anonymous install id - a random UUID stored in the iOS keychain. It is used to deduplicate analytics events and handed to RevenueCat as the anonymous purchase id when you are not signed in (see section 2). It is not a device identifier and you can rotate it from Settings → Privacy → Analytics.
  • Web edition - on app.pilotefb.com the same database is kept in your browser's private storage for that site (the Origin Private File System), and your sign-in session is kept in the browser's local storage so you stay signed in. Both are strictly necessary for the app to work; we set no advertising or tracking cookies. Clearing site data for app.pilotefb.com in your browser removes them.
  • Free-trial record - a separate random device id (minted by the app, never a hardware identifier) kept in the iOS keychain together with a small record of free-trial use: when your free weather-history trial started and how much of the free logbook/duty allowance has been used. It exists only to enforce free-trial limits per device, is never used for analytics or marketing, and is not rotatable (rotating it would reset the limits). If you sign in it is also stored with your account (see "Cloud Sync" in section 2).

You can wipe everything in this section from Settings → Delete all data - except the free-trial record, which by design survives that wipe and app reinstalls so free-trial limits cannot be reset.


2. What data we send to third parties

Supabase Edge Functions - weather and NOTAM proxy

Every weather, NOTAM, or chart lookup goes through a Supabase Edge Function so that third-party API keys never live on your device. We log:

  • The ICAO code(s) you queried.
  • The timestamp of the request.
  • The endpoint (for example metar, taf, notams, charts, winds, airport, pireps, roster-extract).
  • The HTTP status, latency, and whether the response was a cache hit.
  • Your authenticated user id only if you are signed in (used for per-user rate limiting). Guest mode submits no user identifier.

Some of these lookups relay your request to a third-party data provider (the upstream weather/NOTAM/chart services). Those providers receive only the lookup itself (such as an ICAO code or a map region), never your identity, logbook, or duty data.

This log is used for cost monitoring and rate limiting only. It is retained for 40 days and then deleted by a scheduled sweep. The log is not joined with any other data about you.

Cloudflare - map data hosting

Optional offline map packs, and the app's periodic check for newer map data, are downloaded from a public storage bucket hosted by Cloudflare. The freshness check runs during ordinary use of the app, so this happens even if you never open a map screen. Cloudflare receives your IP address and which map file was requested - no account identifier, no logbook, and no flight data. There is no key and no sign-in on that bucket: the request tells Cloudflare nothing about who you are beyond the IP address any web request carries. Cloudflare acts as our processor under its Data Processing Addendum, with the UK Addendum and the EU Standard Contractual Clauses for transfers outside the UK and EEA.

Hosting and content delivery (web edition)

The Pilot EFB web edition at app.pilotefb.com is served as static files by Netlify, Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA), which processes the technical data your browser sends to deliver a page and keep the service secure - your IP address, the page requested, your browser user-agent and a timestamp - as our processor under its Data Processing Agreement. We rely on our legitimate interests for this processing. Netlify's privacy policy: https://www.netlify.com/privacy/.

Supabase auth (only if you sign in)

If you create an account or sign in with Apple or Google, Supabase stores your email address (or the provider-relayed email) and a hashed credential. If you choose Sign in with Apple or Sign in with Google, that provider handles the sign-in and shares your email address and basic profile with us via a secure token. Skipping sign-in during onboarding is supported - the app works fully without an account.

Cloud Sync (only if you sign in)

If you sign in, some of your on-device data is replicated to your own account so it follows you to a new device. It is stored under row-level security that makes it private to your account - no other user can read it.

  • Free, for any signed-in user - your profile and app setup: an allow-list of preferences (units, home base, profile fields - including the optional profile name and profile picture you set in Settings; the picture is stored in a private, owner-only Supabase Storage area and deleted with your account - FTL regime, a few weather / time / NOTAM-keyword settings, and - if you use Online Flying - your IVAO VID) plus your config (currency rules, personal minimums, checklists, V-speed cards, weight presets, favourite airports and collections, logbook smart groups, flight templates, per-diem rate cards) and an onboarding-completed marker.
  • Backed up for any signed-in user - your records: logbook entries (including remarks and any co-pilot or crew names you enter), flights and flight notes, duties, voyage reports, signatures, your pilot credentials (such as medical and licence details), your private per-airport notes, roster feed addresses, weather and NOTAM history, manual and starred NOTAMs, and per-diem expenses - plus your photo / PDF attachments (a compressed copy + thumbnail uploaded to a private, owner-only Supabase Storage area; the full-quality local original is untouched). These are stored under the same owner-only row-level security as everything else, so they are private to your account.
  • Cloud Sync (Pro) adds continuous automatic two-way sync.
  • Free-trial ledger (any signed-in user) - the device id and free-trial record described in section 1 are also stored on our own servers (the same EEA-hosted backend as your account), linked to your account and to the device, so free-trial limits follow your account and this device and cannot be reset by signing out, reinstalling, or creating a new account. They are used for nothing else.
  • Recorded against your account (not as a synced setting) - the version of the terms you accepted and when, so you are not asked to accept again on another device or browser. It is deleted with your account.
  • Never synced (stays on-device only), even when signed in - device-specific settings (theme, app-lock, accessibility, notifications, network and cache preferences). These are deliberately excluded by an allow-list enforced both when sending and when receiving, so they can never be uploaded or overwritten from the cloud.

Cloud Sync is opt-in (it only runs once you sign in) and is never required - the app always works offline.

Sentry - crash reporting

If the app crashes or hits a JavaScript error, Sentry receives:

  • The stack trace and JS error message.
  • The OS version, device model, and app version.
  • Recent breadcrumbs (which screens you opened, in chronological order - no ICAO codes, no logbook content, no PII).

Crash events carry no account identifier and no install id - we never attach a user to a Sentry event, and a scrubber strips any user object before the event is sent.

Sentry data is retained according to Sentry's defaults (90 days for events). We use this only to fix bugs.

Expo (EAS Observe) - app performance telemetry

Production builds send anonymous performance metrics to Expo so we can monitor startup health:

  • Launch and screen-render timings (cold/warm launch, time-to-interactive) and the route name.
  • The app version and build number, device model and OS version, and language.
  • A random per-session id.

No account identifier, no install id, and no flight data are included in this telemetry. We use it only to keep the app fast. (The separate, optional NOTAM-alert push service below does involve your account - see "Expo Push Service".)

Expo Push Service - NOTAM alerts (optional)

NOTAM alerts notify you when a new NOTAM appears for an airport you watch. They are on by default once you are signed in and have allowed notifications for Pilot EFB (iOS asks for that permission explicitly); you can turn them off at any time in Settings → Notifications. When alerts are active:

  • Your device push token is stored on our server together with your account id, your platform, and your quiet-hours preference and its timezone, so alerts reach the right device at the right time. It is removed when you turn alerts off, when delivery reports the device unregistered, and with your account (see section 4).
  • The airports you watch for alerts are stored with your account so the server knows which NOTAMs matter to you.
  • Each alert is delivered through Expo's push service and Apple Push Notification service. Expo and Apple receive the push token and the notification content - the watched airport's ICAO code, the NOTAM id, and a severity word. No name, email, or other account detail is sent to them. Expo acts as our processor under its terms (with EU Standard Contractual Clauses; Expo is certified under the EU-US Data Privacy Framework).

If you never sign in or never allow notifications, no push token is created and nothing in this section applies.

Expo Push Service - Online Flying ATC alerts (optional)

Online Flying (the optional flight-simulation section) lets you watch up to five airports and be told when a controller comes online at one of them, even when the app is closed. Watching an airport is an explicit action - you tap the star on the ATC lookup. When you are watching at least one airport:

  • The ICAO codes of the airports you watch are stored with your account, so our server knows which airports to check for you. That is all that is stored - four-letter codes and the time they were added. We do not store the controller positions, the alerts you were sent, or anything about where you actually fly.
  • The list is removed when you stop watching an airport, when you turn sim mode off, when your Online Flying subscription ends, and with your account (see section 4).
  • Delivery uses the same push token described above. If you have not allowed notifications there is no token, so no alert is sent.
  • Each alert goes through Expo's push service and Apple Push Notification service. Expo and Apple receive the push token and the notification content - the watched airport's ICAO code and the controller position(s) that just came online. No name, email, or other account detail is sent to them.
  • These alerts describe a flight-simulation network (IVAO) only. They are never a real-world operational service.

If you do not use Online Flying, or never watch an airport, nothing in this section applies.

Expo Push Service - weather alerts (optional)

Weather alerts tell you when a watched airport's flight category worsens (or, if you choose, improves back to VFR) or its current TAF is amended. They are off by default - turn them on any time in Settings → Notifications. When weather alerts are active:

  • The ICAO codes of the airports you watch for weather are stored with your account (removed when you stop watching them and with your account).
  • Your personal-minimums thresholds are deliberately never sent to or read by the alert server - that alert family fires only from the app's own foreground checks on your device.
  • Delivery uses the same push token described above, with the same quiet-hours handling. Each alert goes through Expo's push service and Apple Push Notification service, which receive the push token and the notification content - the watched airport's ICAO code and a flight-category or TAF-change summary. No name, email, or other account detail is sent to them.

Web edition push delivery

On the web edition, the alerts above are delivered through your browser's own push service (Apple, Google, or Mozilla, depending on your browser) instead of Expo. Your browser mints a delivery address (a push subscription) that is stored with your account, and each alert is sent to it as an encrypted payload the push service cannot read. The subscription is removed when you turn alerts off in that browser and with your account.

Anonymous usage analytics - our own servers, no analytics company

Analytics are off by default. We ask once during onboarding, and you can turn them on or off at any time in Settings → Privacy → Analytics.

There is no third-party analytics provider. If you opt in, a small set of event counts is stored on our own Supabase backend inside the EEA - the same project that holds your account. Nothing is shared with an analytics company.

  • flight_logged, export_triggered, snapshot_saved, fdp_calculated, paywall_viewed, purchase_completed, sign_in_lockout, onboarding_step, app_open, onboarding_completed, first_duty_created, first_flight_created, first_brief_opened, first_logbook_entry, purchase_started, notifications_optin.

Each event carries the anonymous install id, the event name, and only a small fixed set of non-identifying properties (for example an export type or FTL rule-set id) - never free text, names, ICAO codes, times, or logbook/duty values. Two separate checks in code enforce that: one on the property names, one on their types, so a free-text field cannot be added by accident. The full event list is shown in-app at Settings → Privacy → Analytics so there are no surprises.

The events are never linked to your account. They are tagged with the anonymous install id and nothing else - even when you are signed in, your account id is not recorded beside them, and the table they are stored in has no column for it. You can rotate the install id at any time from that screen, and turning analytics off both deletes any events still waiting on your device and rotates the id automatically, so nothing already stored can be connected to whatever you send if you ever switch analytics back on.

RevenueCat - in-app purchases (App Store)

When you purchase an unlock on iOS, RevenueCat sees the App Store receipt for that purchase and the anonymous user id Pilot EFB hands them (your Supabase user id if signed in, otherwise the install id). They do not receive your name, email, or any flight data.

Stripe - web subscription payments

If you subscribe to Pro on the web, payment is handled by Stripe. Stripe receives the payment and billing details you enter at checkout (for example card details and billing email) and an identifier linking the subscription to your account. We never see or store your full card details. Stripe acts as a processor under its Data Processing Agreement (with the UK International Data Transfer Agreement / EU Standard Contractual Clauses for any transfer outside the UK/EEA). This applies only to web checkout; iOS purchases go through the App Store / RevenueCat above.

Zoho ZeptoMail - support email

When you send feedback or a support message from the app, your message text and, if you provide it, your contact email address are relayed through Zoho ZeptoMail (a transactional email service) so it reaches our support inbox. The submission - your message, the optional contact email, an optional screenshot if you attach one, the app version and build number, the OS version and device model, and the same per-install device id the app uses for sync (a random id that identifies the install, not you; it lets us throttle abuse and match a report to the device that sent it) - is also stored in our support backend (Supabase) so we can track it until it is resolved; it is anonymised if you delete your account. If you turn on the optional email digest (off by default, web edition), a scheduled summary of the weather and NOTAMs for your watched stations is also sent to your account email through ZeptoMail at the hour you choose; turn it off any time and no further digest is sent. On the web edition you can also email yourself a Watch Desk handover report: it is sent once, on your request, to your account email through ZeptoMail and contains the watched-station changes you selected and any notes you typed into the report. ZeptoMail is used for transactional email only and acts as a processor under Zoho's Data Processing Agreement.

Organisation seats (optional)

If you accept an organisation's invitation to hold a seat, that organisation's administrators and managers can see your name, email address, role, seat status, the date you joined, and a crew code if the organisation assigns one. They cannot see your logbook, duty records, flight folders, weather or NOTAM activity, settings, or any other content. In this phase the organisation and we are independent controllers: we process nothing on the organisation's instructions beyond sending the one invitation it asks for, and no organisation can see any pilot's records through Pilot EFB.

When an organisation invites you, it gives us your email address so we can send one invitation; we keep the invitation record for up to 30 days after it is accepted, expires, or is revoked. Administrative actions about your seat (who invited you, when you accepted, seat assignments) are recorded in an audit trail the organisation's administrators and managers can read; it is append-only, holds record ids and timestamps rather than your email address or name, is kept for 24 months on a rolling basis, and is deleted when the organisation is deleted. If you leave the organisation or your seat ends, that visibility ends; your account and your data are unaffected and remain yours.

Organisation enquiries and seat requests (optional)

Organisation enquiries and seat requests (optional): if you ask us to set up an organisation from the Desk, we record the organisation name, your name, the work email on your account, country, an approximate seat count, your message and your account id, and we email that enquiry to our support mailbox through ZeptoMail. If you administer an organisation and ask for more seats from its Billing page, we record the request (current and requested seat count) in the organisation's audit log and email it, with your email address and any note you add, to our support mailbox. We use this only to reply and to set up or change the organisation's subscription; it is never used for marketing.

Google Gemini - roster import (optional)

Roster import is optional - it runs only if you choose to import a roster file. If you do, the roster file (which can contain your name, crew names, and duty/report times) is sent to Google's Gemini API to extract the schedule into structured duties. Google processes this as a processor under its Cloud Data Processing Addendum on the paid tier (no model training on your content). The extracted duty data is cached on our server for up to 90 days (to de-duplicate a re-import) and then deleted; the original file is not retained. If you never use roster import, none of your duty or crew data is ever sent off your device.

Two further roster paths exist, both optional and under your control:

  • Roster calendar feed (optional). If you choose to connect a roster ICS feed, its content is fetched on refresh through our Supabase edge proxy (so the feed provider never sees your device or IP directly). The feed content transits the proxy and is not stored there.
  • Reporting a bad import (optional). If you tap "report a bad import" after an import looks wrong, a PII-scrubbed copy of the roster text - which we show you for consent before it is sent - is stored on our Supabase backend so we can improve support for that roster format. Names, emails, and staff ids are stripped before sending, and the stored copy is de-linked from your account if you delete your account.

Online Flying (optional)

If you choose to use Online Flying and enter an IVAO VID, that identifier is used on our servers to pick your own connection out of the network's public live feed. It is a public identifier, not a password, and nothing is sent unless you use the feature. If you are signed in, it syncs to your own account with your other profile settings (see "Cloud Sync" above). IVAO is an independent third-party service governed by its own privacy terms.

Online Flying - other people connected to the network

Online Flying also shows who else is online, so you can see the traffic and controllers around you in the simulator. To do that, our servers read the network's own public live feed and keep a short-lived snapshot of it: the callsigns, network member numbers, aircraft types, filed routes and connection times that IVAO publishes itself, along with session data such as the aircraft's current altitude, speed and heading.

This is data about other members, not about you, and it is handled on our servers, never on your device. We keep only the most recent snapshot - each new one replaces the last - so no history of any member is ever built, and we do not store members' real names or free-text remarks.

If you are an IVAO member and want to know how the network publishes your session data, see its own privacy notice.

Community feature board (optional)

If you post or vote on the in-app feature board, your post (title, body, category) and your votes are stored on our server with your account id. Posts are visible to other users of the app, including people who are not signed in, but are shown without your name or email. The board is moderated under the community guidelines you accept before first posting; you can report any post in-app, remove your own votes, and ask us to remove one of your posts at support@pilotefb.com. All your posts and votes are deleted when you delete your account. If you never use the feature board, nothing in this section applies.

International transfers

Your account and your synced records are stored inside the EEA: our Supabase project is hosted in AWS Europe (Ireland), eu-west-1. Sentry receives our events in its EU region, and the anonymous usage analytics never leave our own EEA-hosted Supabase project.

Some of the other processors above operate outside the UK and the EEA - in particular RevenueCat, Stripe, Google (Gemini), Expo, Netlify, and Cloudflare, whose global network may serve a map-pack request from outside the UK/EEA. Netlify (web-edition hosting) processes data in the United States under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, both incorporated in its Data Processing Agreement. Where personal data is transferred outside the UK/EEA, that transfer relies on an appropriate safeguard - an adequacy decision, the UK International Data Transfer Agreement (IDTA) / Addendum, or the EU Standard Contractual Clauses - as offered in the relevant provider's data-processing terms. The personal data that can leave the UK/EEA this way is limited to your account/billing identifier, web payment details (Stripe), support-message content and, if you enable the email digest, your account email and the digest summary, and any handover report you choose to email yourself (ZeptoMail), the invitation email an organisation asks us to send you (your email address and the organisation's name - ZeptoMail), your device push token and watched-airport codes if you use NOTAM, weather, or Online Flying ATC alerts (Expo, or your browser vendor's push service on the web edition), the IP address behind a map-pack or map-freshness request (Cloudflare), the IP address and request details behind a web-edition page load (Netlify), and - only if you use roster import - the roster file you choose to import (Google Gemini). Your logbook, duty history, and flight folders otherwise stay on your device or in your own EEA-hosted account.

  • PostHog (website analytics, only if you opt in): product analytics hosted on PostHog's EU Cloud in Frankfurt, Germany, so this data stays within the EEA. PostHog acts as our processor under its Data Processing Agreement. See PostHog's privacy policy at https://posthog.com/privacy for details.
  • Cloudflare Web Analytics (website analytics, only if you opt in): a cookieless, privacy-first analytics service operated by Cloudflare, Inc. in the United States. It sets no cookies and does not fingerprint or profile visitors. Safeguards: EU Standard Contractual Clauses and the UK International Data Transfer Addendum, incorporated into Cloudflare's data processing terms. See Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy/ for details.

3. What we DO NOT collect

  • Logbook entries. Your logbook never leaves your device unless you explicitly export it (CSV) or sign in, in which case it backs up to your own private account under owner-only row-level security (see section 2).
  • Duty / FTL details. Reporting times, sector lists, rest periods, and FDP results stay on-device - with three exceptions you control, all described in section 2: (a) the optional roster import, which sends a roster file you choose to import to Google Gemini to extract the schedule; (b) a roster ICS feed you choose to connect, whose content transits our Supabase edge proxy on refresh and is not stored; and (c) reporting a bad import, which stores a PII-scrubbed copy of the roster text (shown to you for consent first) to improve format support. If you use none of these, your duty data never leaves your device.
  • Flight folder contents. Your saved weather, NOTAMs, and notes stay on-device.
  • Names, emails, phone numbers. We do not collect these except: the email you use to sign up (Supabase auth, relayed by Apple or Google if you sign in with them); the optional profile name you enter in Settings, which syncs to your own account with your other profile settings when you sign in; any co-pilot or crew names you enter on a logbook entry, which back up to your own private account when you sign in (see section 2); a contact email you choose to include in a support message (ZeptoMail); and any names contained in a roster file you choose to import (Google Gemini). We never ask for a phone number.
  • Online Flying network identifier - only if you use Online Flying. An IVAO VID you choose to enter is stored with your settings, used on our servers only when you look up your own connection, and syncs to your own account with your other profile settings when you sign in (see section 2). It is a public flight-simulation identifier, not a password. If you never use Online Flying, none of this is stored or sent.
  • Location - only when you tap "Nearby airports". The app then asks iOS for a one-time location fix to sort airports by distance. Your coordinates are used on your device only, to query the bundled airport database. They are never stored, logged, sent to analytics or crash reporting, or transmitted off your device. There is no continuous tracking and no moving map.
  • Contacts, microphone, calendar. Pilot EFB does not request these permissions.
  • Photos - only when you ask. Camera and photo-library access are requested only at the moment you choose to attach a photo to a logbook entry or flight folder. The full-quality original never leaves your device. When you are signed in, a compressed copy plus a thumbnail is uploaded to your own private, owner-only storage area so your attachments are backed up with your records (see sections 1 and 2).
  • Advertising identifiers. None. There are no ads.

4. Data deletion

  • On-device data. Settings → Delete all data wipes the entire SQLite database and returns the app to the onboarding flow. This is immediate and irreversible.
  • Account data on Supabase. If you signed up, the quickest route is Settings → Profile & Account → Delete account in the app, which deletes your account, your synced data, any uploaded attachments and profile picture, your push token and watched airports, and your feature-board posts immediately and irreversibly. As a fallback you can email support@pilotefb.com from the address you used and we will delete your account and any associated proxy logs within 30 days.
  • Encrypted database backups. Deleting your account removes your data from the live database at once. Like any hosted database, ours is also covered by our provider's rolling daily encrypted backups, so a copy can persist in those backups for a short recovery window (currently 7 days) before it ages out. Those backups are never used to serve the app or to rebuild a deleted account; they exist only so the database can be restored after a failure.
  • Our own backups. We also keep periodic encrypted backups of the database and of uploaded files (attachments and profile pictures) on hardware we control, made solely for disaster recovery. They are always encrypted at rest, are never used to serve the app or to rebuild a deleted account, and are pruned on a rolling cycle, so a deleted account's data also leaves our own backups within 90 days at most.
  • Administrative audit records. Actions taken through our admin console are kept in an append-only audit log that survives account deletion. We keep it because an audit trail that can be erased by the person it records is not an audit trail. For administrators this includes the email address they were signed in with. If an administrative action ever touched your record (for example a support-driven correction), the log also keeps the acted-on record id and a before/after snapshot of the changed fields. Simply deleting your own account is not an administrative action and writes nothing to this log; ordinary users' emails are deleted with the account.
  • Billing and subscription records. To meet accounting and legal obligations, records of purchases survive account deletion. Stripe retains its transaction records (see section 5), and our own backend keeps its record of subscription events - the internal account id the subscription belonged to plus the raw billing event as received from RevenueCat or Stripe. After deletion that id no longer resolves to any account, and these records are used only for billing history, accounting, and fraud prevention.
  • Free-trial records. A device-level record of consumed free trials (the random device id, trial start date, and usage counters) survives account deletion with its account links removed, so deleting an account cannot be used to reset free-trial limits. After deletion it identifies the device only and no longer resolves to any account.
  • Organisation agreement records. If you accepted an organisation agreement on an organisation's behalf, the record of that acceptance (your name and email as given at the time, the agreement version, and when) is kept for 6 years after acceptance and survives account deletion, because it is evidence of a contract (UK GDPR Art 17(3)(e) - the establishment, exercise or defence of legal claims). Ordinary organisation membership is deleted with your account and any seat it held is released. If you are the only administrator of an organisation, or its subscription is still active, the app asks you to hand the organisation to another administrator or cancel its subscription first; deletion then proceeds as normal.
  • Anonymous analytics. Rotate your install id from Settings → Privacy → Analytics. Future events are sent under the new id and the old id cannot be linked back to you on the server.

5. Data retention

  • Organisation enquiries (Supabase): 24 months from the enquiry, then deleted automatically; the support mailbox copy is deleted when the enquiry is closed or after the same period. Seat requests live in the organisation audit log under its 24-month retention.
  • Edge Function logs (Supabase): 40 days, then deleted by a scheduled sweep.
  • Roster import cache (Supabase): extracted duty data is cached up to 90 days for re-import de-duplication, then deleted; the original file is not kept.
  • Sentry crash events: 90 days (Sentry default).
  • Anonymous usage analytics (only if you opt in): up to 400 days, then deleted. The only identifier is the anonymous install id, which you can rotate at any time - and which rotates automatically if you turn analytics off.
  • RevenueCat receipts: retained for the lifetime of the entitlement so that "Restore purchases" works on a new device.
  • Subscription records on our backend: kept after account deletion (the internal account id the subscription belonged to plus the raw billing event from RevenueCat or Stripe) for billing history and accounting - see section 4.
  • Stripe (web payments): Stripe retains transaction and billing records after account deletion where statutory or legal-retention obligations require it, under its Data Processing Agreement.
  • Push tokens and watched airports (only if you use NOTAM or weather alerts): kept while alerts are enabled; removed when you turn alerts off, when delivery reports the device unregistered, and with your account (web-edition push subscriptions follow the same rule).
  • Email digest preference and schedule (only if you enable the digest): kept while the digest is enabled; removed when you turn it off and with your account.
  • Handover emails (only if you email yourself a Watch Desk report): the send itself is logged (your account id, template, status, time - never the address) for de-duplication and deleted with your account; the report body is not kept on our servers.
  • Watched airports for Online Flying ATC alerts (only if you use Online Flying): kept while you are watching them; removed when you stop watching, when sim mode is turned off, when the Online Flying subscription ends, and with your account.
  • Support feedback (Supabase): stored until resolved; anonymised when you delete your account.
  • Free-trial records: kept per device for as long as the app offers free trials (see section 4).
  • Organisation invitations: 30 days after acceptance, expiry, or revocation.
  • Organisation audit trail: append-only, kept 24 months, rolling; deleted sooner with the organisation.
  • Organisation agreement acceptance records: 6 years from acceptance (see section 4).
  • Website analytics (PostHog, only if you opt in on pilotefb.com): event data is deleted after 12 months; Cloudflare Web Analytics holds aggregate counts only.
  • On-device data: retained until you delete it.

6. Children

Pilot EFB is not directed at children under 13 and we do not knowingly collect data from children. The app is intended for licensed pilots and student pilots in formal training.


7. Security

  • API keys for third-party providers (weather, NOTAMs) are held only as Supabase Edge Function secrets. They are never shipped in the app binary.
  • App-lock PINs are stored as a salted Argon2id-derived key (a memory-hard hash) in the iOS keychain via expo-secure-store. The plaintext PIN is never persisted.
  • Network calls use HTTPS.
  • We do not write to any third-party service from inside the app's fast-path beyond what is listed in section 2.

8. Our lawful basis (UK / EU GDPR)

For the limited personal data we actually process (described in section 2), our lawful bases under Article 6 of the UK GDPR / EU GDPR are:

  • Contract (Art 6(1)(b)) - processing your account email and purchase identifier so we can provide the account, cloud sync, and "Restore purchases" features you signed up for; processing your payment details via Stripe when you subscribe on the web; storing the posts and votes you choose to publish on the in-app feature board so that feature works; and providing an organisation seat you accepted (the membership record your organisation's administrators and managers can see), and handling your request to set up an organisation before any contract is entered (steps at your request prior to a contract).
  • Legitimate interests (Art 6(1)(f)) - serving this website and its hosting logs (Netlify) and replying to your email, keeping short-lived, rate-limiting and cost-monitoring proxy logs, fixing crashes via Sentry, monitoring startup performance via anonymous Expo (EAS Observe) telemetry, serving offline map packs and the periodic map-freshness check from Cloudflare's storage network (which receives your IP address to deliver the file - see section 2), relaying and tracking your support messages via ZeptoMail so we can reply, sending a single organisation invitation at an organisation's request and keeping the organisation audit trail (security and accountability), keeping a record of organisation enquiries and seat requests for 24 months to answer follow-up questions, preventing free-trial abuse (a device-level record of consumed free trials - a random app-minted device id, a trial start date, and usage counters - kept to enforce one free allowance per device and account; fraud prevention, GDPR recital 47), and keeping the short-lived Online Flying network snapshot (data about other connected members that IVAO publishes itself - see section 2) so the feature can show who is online. We have balanced these against privacy by keeping the data minimal, pseudonymous where possible, and short-retained - the network snapshot in particular holds only the latest feed state, with no history, no real names, and no free-text remarks.
  • Consent (Art 6(1)(a)) - website product analytics on pilotefb.com (PostHog and Cloudflare Web Analytics), off until you opt in through the cookie banner; anonymous in-app product analytics, which are stored on our own servers rather than with an analytics company, are off by default, and which you opt into (and can turn off again at any time) in Settings → Privacy → Analytics; NOTAM and weather push alerts, which run only after you explicitly allow notifications for Pilot EFB (weather alerts are additionally off by default) and which you can turn off at any time in Settings → Notifications; the optional email digest, which is off by default and sends nothing until you enable it; and the optional roster import, which sends a roster file you choose to import to Google Gemini for extraction. You give each by an explicit, separate choice.

The data that stays on your device is under your sole control and is not processed by us at all.

9. Your rights

Depending on your jurisdiction (UK GDPR, EU GDPR in the EEA, CCPA in California, and similar regimes elsewhere) you may have the right to:

  • Access the data we hold about you.
  • Correct inaccurate data.
  • Delete your data.
  • Object to or restrict processing.
  • Withdraw consent (e.g. turn off analytics) at any time.
  • Receive a copy in a portable format.

To exercise any of these rights, email support@pilotefb.com. We will respond within 30 days. Because Pilot EFB is offline-first, most of your data already lives only on your device - you can export or delete it yourself without contacting us.

Right to complain

If you are in the UK and believe we have not handled your personal data lawfully, you can lodge a complaint with the Information Commissioner's Office (ICO) - ico.org.uk, helpline 0303 123 1113. If you are in the EEA, you may complain to your local data-protection supervisory authority. We would, of course, appreciate the chance to address your concern first.


10. Contact

Questions, concerns, deletion requests, or feedback:

support@pilotefb.com


11. Changes to this policy

We will tell you about material changes through the in-app What's new release notes and update the "Last updated" date at the top of this page. The current version is always available at https://pilotefb.com/legal/#privacy and from within the app at Settings → About → Privacy policy.

Cookies

Cookies & storage

Last updated: 2026-09-17

This statement explains the cookies and similar browser storage used by this website (pilotefb.com). It is provided so you know exactly what is stored on your device when you visit, as required by the Privacy and Electronic Communications Regulations (PECR) and the UK GDPR.

The short version

This website sets no advertising or cross-site tracking cookies and includes no third-party embeds, apart from Cloudflare Turnstile, the bot check on the NOTAM lookup pages, which loads only there and only while bot protection is switched on. The only optional storage is privacy-respecting product analytics, which is off until you opt in through the cookie banner and is processed in the EEA. We do not record your session, sell your data, or profile you for advertising.

Always-on storage (strictly necessary and appearance)

These are essential for the site to function or to remember a display choice you have made. They set no advertising identifier, are first-party only, and never leave your browser. Under the Privacy and Electronic Communications Regulations 2003 (PECR), with the consent exemptions now set out in Schedule A1, neither requires your consent: the record of your cookie choice is strictly necessary, because it stores a selection you made on the site; and your theme preference falls under the separate exemption for storage that only adapts how the site appears or functions to your preferences. For the theme we give you this clear information, and you can object at any time simply by clearing this site's local storage (see "Managing or withdrawing your choice" below). The first two items below are always active; the third appears only on the NOTAM lookup pages:

  • theme (browser local storage): Remembers whether you chose the light, dark, or system colour theme, so the correct theme is shown on your next visit and the page does not flash the wrong colours while loading. The site defaults to the dark theme; this value is written when you choose a theme (including "system", which follows your device's appearance setting).
  • cookie_consent (browser local storage): Records the cookie choice you make below, so we can honour it and not ask you again. Storing your own consent decision is itself strictly necessary. Your choice is kept for 12 months, after which the banner asks you again.
  • Cloudflare Turnstile (NOTAM lookup pages only): When bot protection is switched on, the free NOTAM lookup at /notams loads Cloudflare's Turnstile widget from challenges.cloudflare.com to check that a lookup comes from a person, not a scraper. It runs only on those pages and nowhere else on the site. Turnstile may set a cookie of its own for the challenge; that cookie exists only to run the check, is not used for advertising or cross-site tracking, and is strictly necessary for the lookup to work, so it needs no consent. Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/. See the privacy policy for what the lookup itself processes.

Optional analytics and performance (off by default)

When you opt in to analytics, this category loads two tools that help us understand usage and improve the site. They run only with your prior consent, never before, and you can withdraw consent at any time (see below), which stops further collection and clears the cookies and stored entries set below.

  • PostHog (EU Cloud, processed in Frankfurt) provides product analytics. With your consent it captures page views and interaction events (autocapture, such as which links and buttons you click), plus a few named events: which App Store or Desk link you chose, when you click an email or other outbound link, and which station code you looked up in the NOTAM search. This is so we can see how the site is used and improve it. We do not record replays of your session. PostHog stores first-party cookies and browser local storage to keep a consistent anonymous id across pages, typically ph_<project-id>_posthog (expires after up to 12 months) plus related ph_/__ph entries in local storage and in session storage (cleared when the tab closes). It is processed in the EEA and is not used for advertising or cross-site tracking. See the privacy policy for details.
  • Cloudflare Web Analytics is cookieless: it stores nothing on your device and does not fingerprint or profile you. It records aggregate page views, referrers, country, and page-performance metrics.

None of this runs until you turn the analytics category on. It defaults to off, and withdrawing consent opts you out and deletes PostHog's cookies and stored id.

Managing or withdrawing your choice

You can change or withdraw your choice at any time, as easily as you gave it, using the "Cookie settings" link in the site footer (or the "Manage cookie preferences" button in this section), which reopens the consent options. You can also clear this site's local storage in your browser's privacy settings, which resets everything to the defaults above (theme back to the dark default, and the consent banner will appear again).

If we materially change the categories of optional storage we use, we will ask for a fresh choice rather than relying on your previous decision, and your choice expires after 12 months in any case. This ensures your consent always covers what we actually do.

Related

For how the website and the Pilot EFB app handle personal data more broadly, see our privacy policy.

Terms

Terms of use / EULA

Last updated: 2026-09-16

These Terms of Service and End User License Agreement ("Terms") govern your use of the Pilot EFB iOS application and the Pilot EFB web edition, Pilot EFB Desk, at app.pilotefb.com (together, "the app"). Pilot EFB is a personal, informational flight companion for pilots. It is not a certified Electronic Flight Bag and is not intended for operational decisions, dispatch, primary navigation, or regulatory compliance.

By downloading, installing, signing in to, or using the app you agree to these Terms. If you do not agree, do not use the app. If anything here is unclear, email support@pilotefb.com.

This page, at https://pilotefb.com/legal/#terms, is the governing version of these Terms. The same Terms are shown in-app under Settings > About > Terms of Service on both editions; if an in-app copy is ever older than this page, this page prevails. Where a section differs by edition it is split into an iOS part and a web part; everything else applies to both.


1. Agreement to these terms

These Terms of Service and End User License Agreement ("Terms") govern your use of the Pilot EFB iOS application and the Pilot EFB web edition, Pilot EFB Desk, at app.pilotefb.com (together, "the app"). By downloading, installing, signing in to, or using the app you agree to these Terms. If you do not agree, do not use the app.

These Terms are a binding agreement between you and Azimuth Labs Ltd (company number 17289059, England and Wales), trading as Pilot EFB - "we", "us", or "the developer of Pilot EFB" in these Terms. The app is licensed to you, not sold.

Who may use the app. You must be at least 16 years old to use the app or create an account. By using the app you confirm that you are 16 or over and that you are able to enter into a binding agreement. If you use the app on behalf of anyone else, you confirm that you are permitted to accept these Terms for them - but see the personal-use limits in section 3, which apply regardless.


2. What Pilot EFB is - and is not

Pilot EFB is a personal, informational flight companion for pilots. It is provided for reference, planning support, and personal record-keeping only. You are solely responsible for verifying any information against authoritative sources before acting on it.

Pilot EFB is NOT, and must never be treated as:

  • A certified Electronic Flight Bag (EFB).
  • A source for operational decisions, dispatch, or primary navigation.
  • A means of regulatory or flight-time-limitation compliance.
  • A replacement for your company operations manual, official meteorological sources, or NOTAM authorities.
  • An authoritative source of any aviation data. Outputs are informational and may be incomplete, delayed, or incorrect.

Nothing in the app, on this website, or in any communication from us is professional, legal, medical, financial, meteorological, or operational advice, and none of it creates any duty of care to you beyond what the law imposes and these Terms do not exclude. Every flight, planning, and compliance decision remains yours, made against your operator's procedures and official sources.


2a. Electronic Flight Bag approval

If your operator wishes to use any output of this app in an operational context, obtaining any required Electronic Flight Bag approval or evaluation for that use is the operator's responsibility under its own regulator's EFB rules, not ours. We publish a personal, informational tool; we do not seek, hold, or claim any EFB approval for it.


3. Licence grant

3a. iOS app

Subject to these Terms, you are granted a limited, non-exclusive, non-transferable, revocable licence to install and use the app on Apple-branded devices that you own or control, as permitted by the App Store Terms of Service. This licence is for your personal, non-commercial use as a pilot or student pilot.

3b. Web edition

Subject to these Terms, you are granted a limited, non-exclusive, non-transferable, revocable licence to access and use the web app on devices that you own or control. This licence is for your personal, non-commercial use as a pilot or student pilot.

3c. Organisation-provided seats

If your access to the app is provided through a seat that an organisation - for example your employer, operator, or flight school - holds under a separate written agreement with us (the prior written agreement referred to in this section), these Terms still govern your use. The licence in this section, the disclaimers in sections 2 and 2a, the assumption of risk and the limitation of liability in section 8, and your responsibilities in section 8a apply to you personally, whether or not you use the app in the course of your profession or employment.

The organisation pays for the seat; you pay nothing for it. The organisation controls whether you hold a seat and may end it at any time. When an organisation's subscription ends, its seats end after a wind-down of up to 30 days; we tell the organisation's administrators when that wind-down starts, and the app tells you when your seat has ended. Ending a seat ends web access unless you subscribe personally; it does not delete your account or your data, which remain yours under section 6.

Holding an organisation seat does not make the app suitable for operational use and does not change sections 2 or 2a in any way. Your organisation cannot direct you to rely on the app for any operational, dispatch, or regulatory purpose, and nothing in its agreement with us allows it to.

Your organisation's administrators and managers can see your name, email address, role, seat status, the date you joined, and a crew code if the organisation assigns one. They cannot see your logbook, duty records, flight folders, weather or NOTAM activity, settings, or any other content.

Personal use (both editions)

Personal use means use by you, as an individual, for your own reference, planning support, and record-keeping - including alongside your own professional flying. It does not extend to any commercial purpose: the app and its outputs may not be used by or on behalf of any airline, operator, flight school, or other organisation, offered or resold as part of any product or service, or otherwise commercially exploited. No commercial use of any kind is permitted without our prior written agreement.


4. Restrictions

You agree that you will not:

  • Copy, modify, reverse-engineer, decompile, or disassemble the app, except to the extent that applicable law expressly permits.
  • Rent, lease, lend, sell, redistribute, or sublicense the app.
  • Use the app or its outputs for any commercial purpose, including deploying it within an airline, operator, flight school, or other organisation, or incorporating it or its outputs into any product or service offered to others.
  • Remove, obscure, or alter any disclaimer, attribution, or proprietary notice.
  • Use the app in any way that breaks applicable law or the rights of others.
  • Rely on the app as a primary source for any safety-of-flight decision.
  • Attempt to gain unauthorised access to the app, its servers, other users' data, or the networks connected to it, or interfere with their operation.
  • Use automated tools to scrape, bulk-download, or harvest data or content from the app or its services, except as applicable law expressly permits.

4a. Your account

Some features require an account. You are responsible for keeping your sign-in credentials confidential and for activity that takes place under your account until you tell us it has been compromised, except where the activity results from a failure on our part (for example a security weakness in the app or its services). Tell us at support@pilotefb.com straight away if you believe your account has been accessed without your permission. You must give us accurate account information and keep it up to date so that we can contact you about your account.


5. Subscriptions

The two editions are sold separately under different names. On iOS, paid features are unlocked by Pilot EFB Pro, bought through the App Store. The web edition, Pilot EFB Desk, is bought on the web only. Neither purchase unlocks the other.

5a. iOS app (App Store)

The iOS app is free to use. Some features are unlocked by Pilot EFB Pro, a single auto-renewable subscription.

  • Pilot EFB Pro is billed yearly or monthly, per the plan you choose in the app, through your Apple ID at the price shown in the app at the time of purchase, subject to change and to local pricing and taxes. Payment is charged to your Apple ID at confirmation of purchase.
  • The subscription renews automatically unless it is cancelled at least 24 hours before the end of the current period. Your Apple ID is charged for renewal within 24 hours prior to the end of the current period.
  • You can manage or cancel the subscription, and turn off auto-renewal, in your App Store account settings at any time.
  • Purchases are handled by Apple. Refunds are governed by Apple's App Store terms; the developer of Pilot EFB cannot issue App Store refunds directly.

5b. Web edition - Pilot EFB Desk (Stripe)

Access to the web edition requires an active Pilot EFB Desk subscription - purchased by you, or provided to you as an organisation seat under section 3c. Pilot EFB Desk is a single auto-renewable subscription sold by us, Azimuth Labs Ltd, as the seller. The web edition has no free tier.

  • Pilot EFB Desk is billed yearly or monthly, per the plan you choose at checkout, through our payment processor, Stripe, at the price shown at the time of purchase, subject to change and to local pricing and taxes. Payment is charged at confirmation of purchase, or, where you start with a free trial, at the end of the trial. The price and billing period are shown before you pay.
  • Free trial: we may offer a free trial of Pilot EFB Desk to accounts that have not subscribed to it before. The trial length and the plan that follows it are shown at checkout. A payment card is required to start a trial; if you cancel before the trial ends, nothing is charged, and otherwise the plan you chose starts and is charged at the end of the trial. We allow one free trial per person and per payment card. If a trial is started with a card or on an account that has already had one, we cancel that subscription at once, nothing is charged, and you may still subscribe without a trial.
  • The subscription renews automatically at the end of each billing period unless it is cancelled before the end of the current period. You can manage or cancel the subscription, and turn off auto-renewal, from Settings > Subscription (the Stripe billing portal) at any time. Cancelling stops future charges; your access continues until the end of the period you have paid for.
  • Price changes: if we change the price of Pilot EFB Desk, the new price applies only from your next renewal after we have told you, by email to your account address, at least 30 days in advance. If you do not want to pay the new price, cancel before the renewal and you will not be charged it. The price is the price of the service itself: any tax that the law requires us to collect on it is shown separately at checkout and on each invoice, and today there is none, because we are not VAT registered. If that changes, the tax is added to the price and we will tell you at least 30 days before the first renewal it affects, with the same right to cancel before that renewal. We do not promise that the price you first paid stays fixed for the life of your subscription.
  • Price lock given under the Terms dated 13 September 2026: between 13 and 16 September 2026 these Terms offered a price lock on the yearly plan of Pilot EFB Desk. A yearly subscription started in that period keeps that lock on the words under which it was given, for as long as that subscription continues without a break; the lock ends if the subscription is cancelled, lapses because a renewal payment fails and is not made good, is switched to the monthly plan, or is terminated under section 12. No lock is offered on subscriptions started after 16 September 2026.
  • Web purchases are processed by Stripe. Unlike App Store purchases, refunds for web subscriptions are handled directly by the developer of Pilot EFB; contact support@pilotefb.com to request one. Refunds are given where the law requires them (for example where the service does not conform to the contract) and otherwise at our reasonable discretion.
  • Your right to cancel: when you subscribe on the web you ask us to start your access immediately. If you are a consumer you may still cancel within 14 days of subscribing by emailing support@pilotefb.com; if you do, we refund what you paid less a proportionate amount for the days of access already supplied, as the UK Consumer Contracts Regulations 2013 provide. After the 14 days you can still turn off auto-renewal at any time, and you can contact support@pilotefb.com about a refund.
  • Your web subscription is separate from any App Store / iOS purchase: subscribing on iPhone or iPad does not unlock the web app, and a Pilot EFB Desk subscription does not unlock Pilot EFB Pro on iOS or affect your App Store billing.

6. Free usage allowance and access to your data

6a. iOS app - free usage allowance

You may use the app's logbook and flight-and-duty-time features free for your first 300 manually logged hours and 20 manually logged duties, and you may keep up to 3 flight folders. Imported history does not count toward this allowance. Weather, NOTAMs, the calculators, and the airport reference are free without a usage cap.

Your existing data is never held hostage. After the free allowance is reached, your previously entered logbook and duty records always remain viewable, editable, and exportable as CSV; only creating new entries beyond the allowance requires Pilot EFB Pro.

6b. Web edition - subscription access

The web edition has no free usage tier. Signing in to and using the web app requires an active Pilot EFB Desk subscription, purchased by you or provided as an organisation seat (section 3c). The free usage allowance described above applies to the iOS app only.

Your existing data is never held hostage. Your logbook and duty records remain yours: they stay viewable, editable, and exportable as CSV through the Pilot EFB iOS app, including under its free tier, if your subscription ends.


7. No warranty

Where you pay for Pilot EFB Pro or Pilot EFB Desk, the Consumer Rights Act 2015 requires the digital content to be of satisfactory quality, fit for purpose and as described, and nothing in this section reduces those rights. Beyond those rights we make no other promise about the app: it is provided "as is" and "as available".

Aviation data shown in the app (including weather, NOTAMs, airport reference data, and computed values) may be incomplete, out of date, unavailable, or incorrect. The developer does not warrant that the app will be uninterrupted, error-free, or that any data is accurate or current.

Beta and preview features. We sometimes label features as beta, preview, experimental, or early access. Those features may be incomplete, may change or be withdrawn without notice, and may behave unpredictably. Use them with extra care and verify everything they produce. This paragraph manages expectations; it does not remove any right you have under the Consumer Rights Act 2015 or other consumer law in respect of features you have paid for.

Online services. Sync, backups, live weather and NOTAM data, alerts, and the web edition depend on our servers, on third-party providers, and on your own connection. We do not promise any particular availability, and outages, delays, or data gaps can occur without warning. Keep your own copies of anything you need, and never rely on an alert arriving.


8. Limitation of liability

To the fullest extent permitted by law, the developer of Pilot EFB shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of data (other than where section 46 of the Consumer Rights Act 2015 applies), profits, or goodwill, arising out of or in connection with your use of, or inability to use, the app - even if advised of the possibility of such damages.

To the fullest extent permitted by law, our total aggregate liability to you for all claims arising out of or in connection with the app or these Terms, whether in contract, tort (including negligence), or otherwise, shall not exceed the greater of the amount you paid for Pilot EFB Pro or Pilot EFB Desk in the twelve months before the claim arose and GBP 50 (or its US dollar equivalent).

You use the app entirely at your own risk. Without limiting section 2, we accept no liability for any operational, flight-safety, dispatch, regulatory, or compliance outcome, or for any decision made or not made in reliance on anything shown in the app.

You acknowledge that you are a trained pilot and that all flight, planning, and compliance decisions remain entirely your responsibility. You agree that nothing in the app reduces your obligation to consult authoritative sources.

We are not liable for any failure or delay caused by events outside our reasonable control, including the unavailability, withdrawal, or inaccuracy of third-party data feeds, hosting or payment providers, network or power failure, regulatory or governmental action, or the acts of third parties.

Nothing in these Terms excludes or limits any liability that cannot be excluded or limited under applicable law, including liability for death or personal injury caused by our negligence, or for fraud or fraudulent misrepresentation, and nothing in these Terms affects your statutory rights as a consumer.


8a. Your responsibility and indemnity

You are responsible for your use of the app. If your use of the app in breach of these Terms - including any commercial use, or any use of the app or its outputs for operational decisions - gives rise to a claim against us by a third party, you agree to compensate us for the losses, damages, and reasonable costs we incur as a result of that claim.


9. Intellectual property

The app, including its design, code, text, and branding, is owned by the developer and protected by intellectual-property laws. Except for the licence granted in these Terms, no rights are transferred to you.

Aviation reference data is sourced from third parties and remains the property of those providers, used under their respective licences.

"Pilot EFB", "Pilot EFB Desk", the Pilot EFB mark, and "Azimuth Labs" are trade names and marks of Azimuth Labs Ltd. You may refer to the app truthfully by name (for example in a review or a link), but you must not use our names, logos, or branding in a way that suggests endorsement, partnership, or that a product or service is ours, without our prior written consent.


10. Third-party data and attributions

The app incorporates third-party data and libraries, including airport reference data from OurAirports (public domain), map, runway and taxiway geometry from OpenStreetMap (Open Database License), map and border geometry from Natural Earth (public domain), and solar-position calculations based on the NOAA algorithm. Weather and NOTAM data are retrieved from upstream providers through a secure proxy. Such data is provided by its respective owners and is subject to their terms. Full acknowledgements are listed in Settings > About.

Third-party data sources can change their terms, coverage, format, or availability, or withdraw entirely, at any time and without notice to us. If that happens we may change, reduce, or remove the affected feature or data layer. Where the change is material to a paid subscription we will follow the process in section 15; where a provider's terms require it, your use of that data is also subject to those terms.


11. Privacy

Your use of the app is also governed by the Pilot EFB Privacy Policy, available in Settings > About > Privacy policy and at the hosted address. Pilot EFB is offline-first: your data lives on your device, and if you sign in, your records also back up to your own private account so they follow you to a new device - see the Privacy Policy. Questions: support@pilotefb.com.


12. Suspension and termination

These Terms take effect when you first download, sign in to, or use the app and continue until ended by you or by us.

Ending by you. You may end these Terms at any time by ceasing to use the app and deleting it from your devices. If you have an account, you can delete it at any time from within the app or by emailing support@pilotefb.com; deleting your account permanently removes your backed-up records from our servers, as described in the Privacy Policy. Deleting the app or your account does not by itself cancel an active subscription:

  • iOS app: an active Pilot EFB Pro subscription must be cancelled through your App Store account settings.
  • Web edition: an active Pilot EFB Desk subscription must be cancelled through the Stripe billing portal, linked from the web app's Settings > Subscription page.

An organisation seat ends under the organisation's agreement with us (section 3c); this does not delete your account or your data.

Suspension by us. If we reasonably believe you have breached these Terms, we may suspend your access to online features (including sync, backups, live weather and NOTAM data, alerts, and the web edition) while we investigate. We will tell you that we have done so and why, unless the law prevents us or doing so would compromise the investigation.

Termination by us. Where practicable we will contact you first and give you a reasonable opportunity to put things right. If a breach continues after we have warned you, or if it is serious - for example fraud, unlawful use, automated scraping or resale of data, attempts to compromise the service or other users' data, or commercial deployment in breach of section 3 - we may end these Terms immediately, close your account, and revoke your licence. We will tell you the reason and, unless the breach makes it inappropriate, give you a reasonable opportunity to export your data first. Termination for breach does not entitle you to a refund of any subscription period already paid, except where the law requires otherwise; your statutory rights are unaffected.

If we retire the service. If we discontinue the app's online services or the web edition entirely, we will give you at least 90 days' notice by email to your account address and keep your export tools available during that period. If you have paid for a subscription period that would be cut short, we will refund the unused portion of a Pilot EFB Desk subscription, and you may be entitled to a refund from Apple for the unused portion of a Pilot EFB Pro subscription; your statutory rights are unaffected.

On termination for any reason you must stop using the app and delete all copies. Sections 2, 2a, 3 (personal-use limits), 4, 7, 8, 8a, 9, 10, 14, 15a, and 16 continue to apply after these Terms end.


13. Apple-specific terms

These Terms are between you and the developer of Pilot EFB only, not with Apple. Apple is not responsible for the app or its content. The following apply where the app is obtained through the Apple App Store:

  • Apple has no obligation to furnish any maintenance or support services for the app.
  • In the event of any failure of the app to conform to any applicable warranty, you may notify Apple, and Apple may refund the purchase price (if any); to the maximum extent permitted by law, Apple has no other warranty obligation with respect to the app.
  • The developer, not Apple, is responsible for addressing any claims relating to the app, including product-liability, legal or regulatory, and consumer-protection claims.
  • The developer, not Apple, is responsible for investigating and resolving any third-party claim that the app infringes that party's intellectual-property rights.
  • You represent that you are not located in a country subject to a U.S. Government embargo, and are not on any U.S. Government restricted-parties list.
  • Apple and its subsidiaries are third-party beneficiaries of these Terms and may enforce them against you.

14. Governing law

These Terms are governed by the laws of England and Wales, without regard to conflict-of-law principles, except where superseded by mandatory consumer-protection law in your country of residence or by the Apple App Store Terms of Service.


15. Changes to the app and to these terms

Changes to the app. The app and its online services evolve. We may add, change, or withdraw features (i) to comply with law, a regulator, Apple's requirements, or a third-party data provider's terms, (ii) for security or technical reasons, or (iii) to improve or extend the app. Changes will not remove your ability to view and export the data you have already created. If a change materially reduces the core functionality of a paid subscription during a period you have paid for, you may cancel: for Pilot EFB Desk we will refund the unused portion of the current period on request; for Pilot EFB Pro you may be entitled to a refund from Apple for the unused period. Your statutory rights are unaffected.

Changes to these Terms. We may update these Terms from time to time, for example to reflect changes in the app, in the law, or in how we operate. The "Last updated" date at the top of this page changes whenever we do. A change that only adds to your rights or benefits, corrects a wording error, or is needed to comply with the law takes effect when it is published here, and we may make it without prior notice. For any other material change we will give at least 30 days' notice, through the in-app What's new release notes and, where you have an account, by email to your account address, before the change takes effect. If you do not accept a material change, stop using the app and cancel any subscription before the change takes effect, and the previous Terms continue to apply until then. Continued use after the effective date means you accept the revised Terms. A revision never removes or shortens a price lock held under the Terms dated 13 September 2026 (see section 5b); that lock continues on the words under which it was given, for the life of that subscription. The current version is always available at https://pilotefb.com/legal/#terms and from within the app at Settings > About > Terms of Service.

15a. Website terms of use

These paragraphs apply to your use of the pilotefb.com website, including its Learn articles, glossary, and other content, whether or not you use the app.

  • Educational content only. Everything published on the website is general educational material for personal reference. It is not professional, operational, or regulatory advice, it is not an aeronautical information source, and it must not be relied on for any operational decision. Always use official, certified, and approved sources.
  • No warranty. We work to keep the website accurate, but we do not warrant that its content is accurate, complete, or current, and, to the maximum extent permitted by law, we accept no liability for reliance on it. Nothing in this section excludes or limits our liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot be excluded under the laws of England and Wales.
  • Our content. The website and its content (excluding the third-party material credited on the legal page) are owned by or licensed to the developer and protected by copyright. You may read the website, link to it, and share links to it freely. Except as permitted by applicable law, you must not scrape, bulk-download, or republish the website's content, or use it to train a machine-learning system, without our prior written consent.
  • Governing law. These website paragraphs are governed by the laws of England and Wales on the same basis as section 14.

16. General

If something goes wrong. If you have a complaint or a dispute with us, please contact us first at support@pilotefb.com with the details; we aim to acknowledge within 5 working days and to work with you in good faith to resolve it. This is an informal step only: it does not limit your right to bring a claim in court, to complain to a regulator, or to use any dispute-resolution service available to you under the law of your country of residence. We do not require arbitration.

Transfer of these Terms. We may transfer our rights and obligations under these Terms to another organisation (for example, if the app is acquired by another company). We will tell you in writing if this happens, and the transfer will not reduce your rights under these Terms. You may not transfer your rights or obligations under these Terms to anyone else.

Feedback. If you send us suggestions, ideas, or feedback about the app, including through the community feature board, we may use them without restriction or obligation to you. This does not apply to your personal data or to the content you create in the app, which remain yours.

If a court finds part of these Terms unlawful. Each paragraph of these Terms operates separately. If any court or authority decides that any of them is unlawful or unenforceable, the remaining paragraphs stay in full force.

Delay in enforcing. If we delay in enforcing any part of these Terms, we can still enforce it later.

Entire agreement. These Terms, together with the Privacy Policy and the disclaimers shown in the app and at https://pilotefb.com/legal/, are the entire agreement between you and us about the app. Nothing in them excludes or limits any liability for fraud or fraudulent misrepresentation.

No third-party rights. Except for Apple under section 13, no one other than you and us has any right to enforce these Terms.


17. Contact

Questions about these Terms, a subscription, or your account:

support@pilotefb.com

The contracting party is Azimuth Labs Ltd (company number 17289059), trading as Pilot EFB, registered office 82A James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom.

Organisations

Organisation Agreement

The business agreement an organisation accepts when it buys Pilot EFB Desk seats for its pilots. Pilots who hold a seat are not party to it: their use is governed by the Terms of use above (section 3c).

Last updated: 2026-09-10 - Version 2026-09-10

This document is the canonical copy of the in-product click-through at /org-setup. The hosted page at https://pilotefb.com/legal#org-terms is the governing version; the set-up flow shows the same text and records which version the Organisation accepted. Not a consumer contract: each pilot who holds a seat uses Pilot EFB under the Terms of Service at https://pilotefb.com/legal#terms, which this Agreement does not vary.


About this agreement

This Pilot EFB Organisation Agreement ("this Agreement") is between Azimuth Labs Ltd, a company registered in England and Wales with company number 17289059 whose registered office is at 82A James Carter Road, Mildenhall, Suffolk, IP28 7DE, trading as Pilot EFB ("we", "us"), and the organisation named in the set-up flow or on an order form ("the Organisation", "you"). It governs the purchase and administration of seats on the Pilot EFB web edition, Pilot EFB Desk, at app.pilotefb.com ("the Service").

Version 2026-09-10. The current version is always available at https://pilotefb.com/legal#org-terms. If the copy shown in the set-up flow is ever older than that page, the page prevails. Words in this Agreement mean the following: a "seat" is a paid entitlement that lets one named individual use the Service; a "Seat Holder" is the individual who holds a seat; an "administrator" or "manager" is a person the Organisation has given that role in its console; the "Terms of Service" are the Pilot EFB Terms of Service and End User License Agreement at https://pilotefb.com/legal#terms; an "order form" is a document we and the Organisation both sign that records seats, prices and any negotiated term.

Pilot EFB is a personal, informational flight companion for pilots. It is not a certified Electronic Flight Bag. It is not a tool for operational decisions, primary navigation or the discharge of any regulatory obligation, and it is not a replacement for an operator's operations department, meteorological sources or NOTAM authorities. Every clause below is read in that light.


1. Parties and authority

This Agreement is formed when we countersign the Organisation's order form or, where we offer online purchase, when an individual acting for the Organisation accepts it in the set-up flow and the first payment completes. We may countersign an order form by an email from us that confirms the seats, the price per seat and the start date. The individual who accepts confirms, by ticking the authority box, that they have authority to enter this Agreement on behalf of the Organisation, and the Organisation warrants that this is so.

The Organisation confirms that it is entering this Agreement for purposes relating to its trade, business, craft or profession and not as a consumer. That is so whether the Organisation is a company, a partnership, a sole trader, a school, a club or an unincorporated association. A club, school or association accepts through an officer or member who has authority to bind it, and buys seats for the Organisation's own purposes even where some Seat Holders are private pilots or students. Where the individual accepting pays with a personal card on the Organisation's behalf, the purchase is still made for the Organisation and not as a consumer purchase by that individual.

We keep a record of each acceptance of this Agreement: the Organisation's name, the accepting person's name and email address, the version accepted and the time of acceptance. We keep that record for six years from the date of acceptance so that either of us can establish what was agreed. It survives deletion of the Organisation.

We may contact the Organisation about this Agreement at the billing email address it gives us, and the Organisation may contact us at support@pilotefb.com. Each of us must keep those addresses current.

2. Relationship to the consumer Terms of Service

The Terms of Service permit only personal, non-commercial use of the Service and say that no commercial use of any kind is permitted without our prior written agreement. This Agreement is the prior written agreement referred to in section 3 of the Terms of Service. It lifts the personal-use limit only for two things: the Organisation purchasing and administering seats under this Agreement, and each Seat Holder's own use of the Service under the Terms of Service. It lifts nothing else. In particular it does not permit operational deployment of the Service, embedding it or its outputs in any product, procedure or system, or resale.

Every Seat Holder uses the Service under the Terms of Service in their own name, including section 2 (what Pilot EFB is and is not), section 2a (Electronic Flight Bag approval), section 3c (organisation-provided seats), section 8 (limitation of liability) and section 8a (responsibility and indemnity). Those sections apply to each Seat Holder personally whether or not they use the Service in the course of their profession or employment. Nothing in this Agreement reduces any right a Seat Holder has under the Terms of Service or under consumer law, and the Organisation cannot accept, waive or vary the Terms of Service on any Seat Holder's behalf.

The Organisation may require a person to hold a seat as a condition of their role, training or membership, and may decide who holds a seat and in what role. Requiring a seat is not the same as directing reliance: the Organisation has no right to direct operational reliance on the Service, as clause 4 explains. Where a Seat Holder is not a consumer in respect of a particular use, the Organisation acknowledges, as between the Organisation and us, that the disclaimers, assumption of risk and limitation of liability in the Terms of Service describe the basis on which the Service is provided for that use too.

Between the Organisation and us, this Agreement governs. For a Seat Holder's use, the Terms of Service govern. Clause 15 sets the order of precedence where the documents overlap.

3. Seat licence

Subject to this Agreement and to payment, we grant the Organisation a limited, non-exclusive, non-transferable, revocable licence to hold the number of seats it has paid for, to invite named individuals to take those seats, and to administer seats, roles and invitations through its console. Seats are bought on an order form under the Schedule. Where we offer online purchase, it is available for the seat range shown in the set-up flow; a larger purchase, or any purchase on negotiated terms, is made on an order form.

Seats are named. One seat is held by one individual at a time. A seat becomes active when the invited individual accepts the invitation and the Terms of Service in their own account. The Organisation may release a seat at any time. A released seat is held for 24 hours before it can be given to a different individual; the same individual can be re-seated at once. The Organisation must not invite anyone under 16, must not share one seat between several people, and must not use automated tools to create, accept or cycle seats.

The console shows the Organisation's administrators and managers, for each member, that member's name, email address, role, seat status, the date they joined and a crew code if the Organisation assigns one, together with an append-only audit trail of seat actions that records identifiers and timestamps. The Organisation has no access through the Service to any Seat Holder's logbook, duty records, flight folders, weather or NOTAM activity, settings or other content, and this Agreement grants none.

The Organisation has no right to direct operational reliance. It must not require, instruct or encourage any Seat Holder to rely on the Service, or on anything shown in it, for the planning, release or conduct of any flight, for any duty or scheduling decision, or as a means of meeting any regulatory obligation of the Organisation or of the Seat Holder. The Organisation must not incorporate the Service or its outputs into any operations manual, procedure, checklist or system of operational control.

The restrictions in section 4 of the Terms of Service apply to the Organisation as they apply to each user, read with the two permissions in clause 2. The Organisation is responsible for the acts of its administrators and managers in the console.

4. Awareness, not dispatch

The Service informs and records. It shows a Seat Holder their own records, reference material and third-party data with sources and timestamps, and it lets them keep a personal logbook and duty history. It does not dispatch, release, plan or navigate any flight, and no output of the Service is an operational, meteorological or NOTAM authority. Outputs may be incomplete, delayed, unavailable or incorrect, and every value must be verified against authoritative sources before anyone acts on it.

Flight and duty time limitation rules bind the operator and the crew member, not the Service. Examples are EASA ORO.FTL, the retained UK air operations rules and FAA Part 117. Nothing in this Agreement and nothing the Service shows changes those rules, and the Service does not discharge any regulatory obligation of the Organisation or of any Seat Holder. Any figure the Service computes is an informational readout of the records a pilot has entered, not a determination that a flight or duty is permitted.

If the Organisation wishes to use any output of the Service in an operational context, obtaining any required Electronic Flight Bag approval or evaluation for that use is the Organisation's responsibility under its own regulator's rules. We publish a personal, informational tool; we do not seek, hold or claim any such approval for it, and this Agreement does not support any application for one.

The Organisation must not hold the Service out, to any regulator, auditor, insurer, customer, crew member or other person, as part of its operational control system, as its Electronic Flight Bag, as a record it relies on to meet a regulatory obligation, or as anything other than a personal tool that its pilots may use for their own reference and record-keeping.

5. Liability

Nothing in this Agreement excludes or limits our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot be excluded or limited under the law of England and Wales. Nothing in this Agreement limits any liability we have to a Seat Holder under the Terms of Service or under consumer law, and nothing in it limits any liability that product liability law does not allow to be limited, including under the Consumer Protection Act 1987 and, for an individual in the European Economic Area, under the national law that implements Directive (EU) 2024/2853 for products placed on the market after 9 December 2026.

Subject to the first paragraph of this clause, we are not liable to the Organisation, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for any indirect or consequential loss; for any loss of profit, revenue, business, contracts, anticipated savings, goodwill or reputation; for any loss or corruption of data beyond the restoration we describe in clause 6; or for any operational, flight-safety, scheduling or regulatory outcome, or any decision made or not made in reliance on the Service by the Organisation, a Seat Holder or anyone else.

Subject to the first paragraph of this clause, our total aggregate liability to the Organisation for all claims arising out of or in connection with this Agreement and the Service in any period of twelve months is limited to the greater of the fees the Organisation paid us under this Agreement in the twelve months before the event giving rise to the first such claim and USD 500. This cap reflects the price of the Service, that the Service is an informational tool sold on standard terms to organisations that keep their own operational systems, and that the Organisation can insure its own operational risks; it applies to the Organisation and not to any Seat Holder.

The Organisation will compensate us for the losses, damages and reasonable costs we incur as a result of any claim by a third party that arises from the Organisation's breach of clause 3 or clause 4, from any operational deployment or holding-out of the Service by the Organisation, or from the Organisation giving us the details of an individual it had no right to give us. This obligation is limited to claims caused by that breach.

We are not liable for any failure or delay caused by events outside our reasonable control, including the unavailability, withdrawal or inaccuracy of third-party data feeds, hosting or payment providers, network or power failure, regulatory or governmental action, or the acts of third parties.

6. No service-level commitment

We give no service-level commitment. We do not promise any particular availability, response time, uptime, support response or data-feed freshness, and we owe no service credit. The Service depends on our servers, on third-party providers and on each user's own connection; outages, delays and data gaps can occur without warning and may not be announced in advance.

We may change, add to or withdraw features of the Service, and we may carry out maintenance at any time. If a change removes something the Organisation relies on for administering seats, we will give the Organisation reasonable notice by email where we can. Features labelled beta, preview or experimental may change or be withdrawn without notice.

We keep backups of our systems for our own recovery. That is not a record-keeping or archival service for the Organisation or for any Seat Holder, and each Seat Holder is told in the Terms of Service to keep their own copies of anything they need.

7. Exportability and continuity

Seat Holders keep their personal accounts and all their personal data regardless of the termination of this Agreement, of the ending of a seat or of the Organisation's deletion. A Seat Holder's logbook, duty records, flight folders and other content belong to that Seat Holder under section 6 of the Terms of Service. The Organisation acquires no right to that content, to a copy of it, to its return or to its deletion.

When a seat ends, the Seat Holder's web access ends unless they subscribe personally, and the Service offers them a personal subscription on the same account. A Seat Holder whose seat has ended can still export their logbook and duty records from the Service without a personal subscription, and their records remain viewable, editable and exportable on the iOS app under the Terms of Service.

The Organisation can export its own roster (the items listed in clause 3) and its audit trail from the console while this Agreement is in force. After termination we delete the Organisation's data, including its audit trail, other than the acceptance record in clause 1 and the billing records we must keep under accounting law.

8. Termination and seat wind-down

The Organisation may end this Agreement by written notice to support@pilotefb.com at least 30 days before the renewal date, or, where we offer online purchase, by cancelling its subscription in the billing portal linked from its console; the seats then run to the end of the paid period and this Agreement ends with them. The Organisation may end any individual seat at any time from the console, with immediate effect.

If a renewal payment fails, the Organisation stays entitled while our payment provider retries the payment and we tell the Organisation's administrators. If the payment is not made, if the subscription is cancelled by the payment provider, or if the Organisation's subscription is otherwise ended, a wind-down of 30 days starts. We tell the Organisation's administrators in the console and by email when the wind-down starts; the seats keep working during it; at its end every seat ends and the Service tells each Seat Holder that their seat has ended. A disputed card payment does not end seats at once: we record it and tell the Organisation's administrators, and seats end only through the notice and wind-down in this clause.

We may end this Agreement by written notice if the Organisation materially breaches it and, where the breach can be remedied, does not remedy it within 14 days of our notice. Holding the Service out or directing operational reliance in breach of clause 3 or clause 4, resale or embedding in breach of clause 12, and a breach of clause 10 are material breaches that cannot be remedied. Where we end this Agreement for breach, seats end at the end of a 30-day wind-down unless the breach makes continued access unsafe or unlawful, in which case we may end seats sooner and will say why.

Voluntary 14-day cancellation on a first purchase. Although the Organisation is not a consumer and no statutory cancellation right applies, the Organisation may cancel its first purchase under this Agreement within 14 days of the first payment by emailing us, and we will refund that payment in full and end the seats. This applies once, to a first online purchase only, and not to renewals, seat additions or purchases on an order form.

Termination does not affect rights and obligations that accrued before it. Clauses 1 (acceptance record), 2, 4, 5, 7, 9, 10, 13, 14 and 15 survive termination.

9. Data protection

In this phase of the Service the Organisation and we are independent controllers. We are the controller of every Seat Holder's account and content, of the Organisation's account and billing data, of the acceptance record and of the audit trail. The Organisation is the controller of its own decisions about who to invite, who holds a seat and in what role, and of the roster information it holds outside the Service. We process nothing on the Organisation's instructions beyond sending the invitation it asks for, and no processor relationship under Article 28 of the UK GDPR arises. A further written agreement between the Organisation and us is required before any Seat Holder's records can become visible to the Organisation, and none is visible in this phase.

When the Organisation invites someone, it gives us that person's email address so that we can send one invitation. The Organisation warrants that it has a lawful basis for giving us the address and that the person can reasonably expect an invitation from it. The invitation email tells the person that the Organisation gave us their address, that we keep the invitation record for up to 30 days after it is accepted, expires or is revoked, and where to find our privacy policy. We honour any suppression the person has placed on email from us and send no marketing to invitees.

We describe our processing of Seat Holders' and administrators' personal data, its lawful bases, retention and each person's rights in our privacy policy at https://pilotefb.com/legal#privacy, whose "Organisation seats" section applies to the Service. The audit trail is append-only, records identifiers and timestamps, is readable by the Organisation's administrators and managers, and is deleted with the Organisation. The acceptance record in clause 1 is kept for six years from acceptance under Article 17(3)(e) of the UK GDPR for the establishment, exercise or defence of legal claims.

Each of us complies with the UK GDPR and the Data Protection Act 2018 in respect of the personal data it controls. The Organisation must keep its console access secure: it is responsible for who it makes an administrator or manager, for their credentials and for their actions. The Service asks for recent re-authentication before destructive console actions and recommends an authenticator app; the Organisation should enrol one for every administrator.

10. Consent is never a condition

This clause is agreed now and becomes operative if and when we offer a way for a Seat Holder to share any of their records with the Organisation. Any such sharing happens only on the Seat Holder's own choice, scoped to what they select, revocable by them at any time and visible to them. The Organisation acquires no right to any Seat Holder's records by this Agreement, by a request or by any later agreement between the Organisation and us.

The Organisation must not make holding a seat, employment, engagement, training, membership, duty allocation, pay, progression or any benefit or detriment conditional on a Seat Holder sharing anything, and must not penalise or pressure a Seat Holder who declines or withdraws. The Service is designed so that the Organisation cannot see which Seat Holders have declined, and we will not tell it. A breach of this clause is a material breach of this Agreement.

11. Payment terms

Prices are the per-seat prices recorded on the Organisation's order form, in the currency stated there, exclusive of VAT and of any other tax, duty or withholding, which the Organisation pays in addition where applicable. The Organisation gives us its VAT or tax registration number for the order form if it has one and keeps it current. We invoice through our payment provider, Stripe; an invoice is payable by card or bank transfer within 30 days of the invoice date unless the order form says otherwise. Where we offer online purchase, the published per-seat annual prices shown in the set-up flow and at checkout apply, payment is by card annually in advance, and seats activate when payment completes.

A subscription renews for successive periods of one year at the price on the order form, or for an online purchase at the then-current published price, unless the Organisation gives notice under clause 8 before the renewal date. We give at least 30 days' notice by email of any change to the price that will apply at renewal. Seats added during a period are invoiced pro rata at once for the rest of that period; seats removed during a period take effect from the next renewal unless the order form says otherwise, and for an online purchase are credited pro rata against the Organisation's next invoice. Other than under the 14-day window in clause 8, fees are not refundable.

A purchase of 25 seats or more, or any purchase on negotiated terms, is made on an order form under the Schedule: we invoice, payment is due 30 days from the invoice date, and seats activate when we create the Organisation's subscription after countersigning the order form. If an invoice is not paid within 14 days after it is due we may suspend the seats until it is paid, and we may charge statutory interest under the Late Payment of Commercial Debts (Interest) Act 1998. The Organisation may not withhold or set off any amount against fees due.

Any discount or trial we agree is recorded on the order form. Where we offer online purchase, the published prices apply to seats bought online and a change to them applies from the Organisation's next renewal after the notice in this clause. We do not offer a free trial of seats; a trial we agree is recorded on the order form or, for an online purchase, as a coupon applied at checkout.

12. No resale

Seats are for the Organisation's own personnel, contractors, students and members. The Organisation must not resell, sublicense, rent, lend or transfer seats or the Service; must not offer the Service or any of its outputs to third parties as part of any product or service; must not white-label, rebrand or embed the Service or its outputs; and must not use the Service to build or train a competing product. The Organisation must not copy, modify, reverse-engineer, decompile or disassemble the Service except to the extent that applicable law expressly permits, and must not scrape, bulk-download or harvest data from it.

13. Publicity and marks

Each of us keeps its own name, logo and marks. We will not name the Organisation as a customer, in a customer list, case study, press release or otherwise, without its prior written consent, which it may withhold or withdraw at any time. The Organisation may tell its pilots and staff that it provides Pilot EFB seats and may use our name for that purpose.

The Organisation must not state or imply that Pilot EFB is certified, approved, or endorsed by any authority, regulator or manufacturer, or that we endorse the Organisation; must not present the Service as part of an operational or regulatory system; and must not use our marks in any other way without our prior written consent.

14. Governing law

This Agreement, and any dispute or claim arising out of or in connection with it or its subject matter, is governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction over any such dispute or claim. Before starting proceedings each of us will first raise the matter with the other by email (for us, support@pilotefb.com) and try in good faith to resolve it within 30 days. We do not require arbitration. This clause does not affect any right a Seat Holder has under the Terms of Service or under the mandatory consumer law of their country of residence.

15. Entire agreement

This Agreement, any order form and our privacy policy are the entire agreement between the Organisation and us about the Service, and replace every earlier proposal, representation and understanding about it. Each of us confirms that it has not relied on any statement that is not set out in them; nothing in this clause excludes liability for fraud.

Order of precedence. If the documents conflict: an order form we have countersigned prevails over this Agreement for the matter it addresses; this Agreement prevails over the Terms of Service as between the Organisation and us; and the Terms of Service govern each Seat Holder's use and are not varied by this Agreement or by any order form.

Changes. We may publish a new version of this Agreement. It takes effect for the Organisation at its next renewal, or earlier if one of its administrators accepts it in the console. Until an administrator accepts the new version the console asks them to do so before continuing to administer seats; existing seats are not affected by that step. A change that materially reduces the Organisation's rights is notified by email at least 30 days before it takes effect, and the Organisation may cancel under clause 8 before then.

General. The Organisation may not assign or transfer this Agreement without our written consent. We may transfer our rights and obligations to a successor to our business and will tell the Organisation if we do. If any part of this Agreement is found unlawful or unenforceable the remainder stays in force. A delay in enforcing any part of this Agreement does not waive it. Notices are given by email to the addresses in clause 1. No one other than the Organisation and us may enforce this Agreement under the Contracts (Rights of Third Parties) Act 1999; a Seat Holder's rights under the Terms of Service are theirs directly and are not affected by this sentence.

16. Term

This Agreement starts when it is formed under clause 1 and continues for an initial term of one year from the date seats first activate. It renews for successive one-year terms in step with the Organisation's subscription period with our payment provider, so that the term of this Agreement and the paid subscription period are always the same, until it ends under clause 8. A purchase on an order form runs for the term stated on the order form.

This version of the Agreement is dated 2026-09-10.


Schedule - Order form terms

This Schedule applies to every purchase on an order form, which is how seats are bought unless we offer online purchase for a stated seat range, and in any case to any purchase of 25 seats or more and to any purchase on negotiated terms. Where online purchase is offered, a purchase of 25 to 250 seats can be started online; the Organisation still accepts this Agreement in the set-up flow, and the purchase is completed on an order form under this Schedule rather than by online payment alone. Above 250 seats no online purchase is possible.

The order form records: the Organisation's legal name, registered address and VAT or tax number; the billing contact; the number of seats; the price per seat and any discount; the start date and the term; the Organisation's purchase order number if it uses one; payment terms (30 days from the invoice date unless the order form says otherwise); and any negotiated term. A negotiated term is effective only if it is written on the order form and the order form is signed by the Organisation and countersigned by us.

Seats on an order form activate when we create the Organisation's subscription after countersigning it. If the first invoice is not paid within 14 days after it is due we may suspend the seats until it is paid. Our invoice carries our company particulars, our VAT number once we are registered, reverse-charge wording where the Organisation is a business customer outside the United Kingdom, the Organisation's purchase order number, and the due date on the order form.

Where an order form and this Agreement conflict, the order form prevails for the matter it addresses. An order form never varies the Terms of Service as they apply to any Seat Holder, never grants the Organisation any access to a Seat Holder's records, and never permits operational reliance, holding-out or resale.

Accessibility

Accessibility statement

Last assessed: 2026-09-13

This statement applies to pilotefb.com.

Our target

We aim for this website to meet the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. WCAG 2.1 AA is the standard referenced by the UK's Public Sector Bodies Accessibility Regulations 2018 and is widely recognised as the appropriate benchmark for commercial websites.

What we do

  • Semantic HTML landmarks (<header>, <main>, <footer>, <nav>) are used throughout so keyboard and screen-reader users can navigate by region.
  • All interactive elements (links, buttons, form controls) have visible focus indicators that meet the WCAG 2.1 AA focus-visible requirement.
  • Touch targets in the mobile menu and cookie consent panel meet the 44 x 44 px minimum.
  • The colour-contrast ratio between body text and background meets or exceeds 4.5:1 in both light and dark themes.
  • Motion that scrolls elements into view is suppressed for users with prefers-reduced-motion: reduce set in their OS preferences.
  • Images that carry meaning have descriptive alt text; purely decorative images use alt="".
  • Pages use a logical heading hierarchy.
  • The cookie preferences dialog can be operated entirely from the keyboard, closes with Escape or its Close button, and can be reopened from the "Cookie settings" link in the footer.

Known limitations

  • PDF logbook export (in the app): Exported PDFs are not currently tagged for screen-reader access. We intend to address this in a future app update.
  • Third-party content: Links to the App Store and to Pilot EFB Desk open in a new tab and say so in their accessible name; other external links open in the same tab. We cannot guarantee the accessibility of third-party websites we link to.

We are a small team and this site is under active development. If you find an issue not listed here, please tell us.

How to report an accessibility problem

If you experience any difficulty using this website, email support@pilotefb.com with the subject line "Accessibility". Please describe what you were trying to do and what happened. We aim to acknowledge reports within 5 working days and to resolve or explain issues within 30 days.

Enforcement

If you are not satisfied with our response and you are in the UK, you can contact the Equality Advisory and Support Service (EASS): equalityadvisoryservice.com.

Credits

Open-source licences

Last updated: 2026-09-10

This website is built with open-source software and openly licensed data. We are grateful to their authors and reproduce the required notices below.

Fonts

The following typefaces are bundled and served by this website under the SIL Open Font License 1.1:

  • IBM Plex Sans and IBM Plex Sans Condensed - Copyright IBM Corporation, with reserved font name "Plex".
  • JetBrains Mono - Copyright The JetBrains Mono Project Authors.

Software

  • posthog-js - Copyright PostHog/Hiberly, Inc. (derived from mixpanel-js, Copyright Mixpanel, Inc.), licensed under (Apache-2.0 AND MIT): the Apache License 2.0, with portions derived from Sentry, Metro, Expo, and AgentCat under the MIT License - see the package LICENSE for the full notices. Loaded in your browser only if you opt in to analytics.
  • SQLite Wasm (@sqlite.org/sqlite-wasm) - the SQLite database engine compiled to WebAssembly, shipped by our content framework for client-side content queries. SQLite itself is in the public domain; the JavaScript/WebAssembly packaging is licensed under the Apache License 2.0.

Map data

  • The world map on our homepage is derived from Natural Earth, which is in the public domain. No attribution is required; we credit it here as a courtesy. Made with Natural Earth.
  • Screenshots of the Ops Map and the Aviation Map on this site contain map data (c) OpenStreetMap contributors, available under the Open Database License; airspace data (c) openAIP, used with permission; and satellite imagery from NASA Worldview / GIBS.

Pilot EFB

One companion for every leg,on every screen.

Free on iPhone, iPad and Apple Watch. Pilot EFB Desk brings it to the browser. Offline-first, so the tools work before, during and after the flight.

Azimuth Labs Ltd · Registered in England and Wales.
Company No. 17289059 · ICO No. ZC178458.
Registered office: 82A James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom.

© 2026 Pilot EFB. All rights reserved. Pilot EFB is not a certified Electronic Flight Bag and is not affiliated with any aviation authority, airline, or aircraft manufacturer. Apple, the Apple logo, App Store, Apple Watch, iPhone, iPad, iPadOS, Siri, Face ID, Live Activities, Spotlight, Stage Manager and Dynamic Island are trademarks of Apple Inc., registered in the U.S. and other countries and regions.