Privacy & your data
AeroRadar privacy notice
Effective date: September 17, 2026
RiseMode Media LLC, 4400 Park Brooke Trce, Alpharetta, GA 30022-3413, United States, is the controller. Contact support@risemodemedia.com.
Where account data is stored
Supabase is the durable authority for AeroRadar user profiles and related durable user records. Redis/Valkey provides a volatile flight-data cache and short-lived airport operations observations; it is not the durable store for saved, tracked, profile, billing, support, or transactional-email data.
Data used by the shipped feature set
- Account identifiers, sign-in provider facts, profile details, verified factors, and preferences.
- Saved searches, tracked flights and aircraft, alerts, replay links, and other app activity.
- Location when a feature uses it.
- Email or Calendar itinerary content imported at the user’s request.
- Google Play purchase, entitlement, order, subscription, void/refund, and RTDN reconciliation evidence.
- Push/device identifiers, diagnostics, support correspondence, and support screenshots submitted by the user.
- Transactional-email delivery data, such as recipient address fingerprints, message category, provider delivery identifier, delivery status, bounce or complaint status, and timestamps for verification, password recovery, receipts, security notices, or requested service notifications.
- Coarsened aggregate analytics.
Maps, optional inputs, and community reports
Google Maps and other Google SDKs process device and app identifiers, request metadata, map interactions, and performance or crash information to operate, secure, maintain, and improve their services. AeroRadar does not use device identifiers for advertising or sell personal information. Optional location features use the location permission you grant; you can turn that permission off in Android settings.
Google Maps processes information under the Google Privacy Policy. Weather requests can send the coordinates of the selected location or map area to the weather provider used for that feature, including the US National Weather Service, MET Norway, or OpenWeather. A selected location can be your device location when you enable that feature. These providers receive network request information such as your IP address and apply their own privacy terms.
Voice search uses the speech-recognition service configured on your Android device. That service may send audio to its servers, and its own privacy settings and retention terms apply. AeroRadar uses the resulting text to perform your requested search. Camera preview and itinerary text recognition run on the device; when you save an imported itinerary, extracted travel details can be synchronized to your account. This can include details extracted from an email, calendar event, boarding pass, or document.
Airport Pulse in the app and on this website accepts optional, predefined airport-condition reports after sign-in. Website reports identify whether you observed a condition yourself or are relaying a recent firsthand observation from someone at the airport. The website uses your location only locally when you request a nearby airport; coordinates are not included in these reports. A home-airport preference is stored in your browser for your account. Their contribution to airport summaries is visible to other users; the app does not provide free-form public chat, photo posting, or audio messaging. Operational observations and history expire within 24 hours. Support messages, private feature requests and screenshots that you choose to submit are retained privately for investigation and follow the support retention and deletion rules below. They are not temporary memory-only processing.
How transactional-email data is used
AeroRadar uses Resend (Plus Five Five, Inc.) as a transactional-email processor to send account verification, password recovery, security, purchase receipt, license acceptance, and requested service messages; monitor delivery; prevent abuse; and honor bounce, complaint, and suppression requirements. AeroRadar sends the recipient email address and, when available, display name; sender, subject, plain-text and HTML message content; message category; opaque request identifier; and, for verification or password-reset messages, a time-limited Firebase action link. Resend returns provider message and delivery identifiers plus signed delivery-event metadata. AeroRadar does not sell this information or use it for advertising.
Resend states that email content and logs are retained for 30 days. Because its public materials currently describe backup retention as either 7 or 30 days, AeroRadar conservatively treats provider backups as potentially retained for up to 30 days unless Resend confirms a shorter period.
Optional email-open and link-click tracking are disabled for AeroRadar's Resend sending domain.
Resend's provider terms and subprocessors govern its processing in the United States and other disclosed locations.
Deletion and retention
AeroRadar deletes account, profile, imported itinerary, support, and associated user content when account deletion is completed. Limited commercial, fraud-prevention, and deletion-confirmation records may be retained for the stated periods when required for compliance, dispute handling, or security. These records are access-restricted and are not used for advertising.
Transactional-email delivery and suppression records may also be retained for delivery troubleshooting and security, for the periods described below. These records are access-restricted and are not used for advertising.
Account deletion removes associated user data except narrowly retained evidence. Commercial, replay, and administrative evidence is retained for seven years after terminal state. Lifetime evidence is retained while restoration remains possible and then for seven years after refund or void. Aggregate-only analytics is retained for 24 months. A sanitized deletion receipt is retained for two years. A status credential expires after 30 days and only its server-side hash is stored. Support correspondence is deleted 30 days after completion; support rows and stored support objects are deleted immediately during account deletion. Transactional-email delivery events and rate-limit records are retained for 90 days. Dispatch metadata is retained for 90 days, except purchase-receipt dispatch metadata is retained for 13 months. Hard-bounce suppressions are retained for 180 days. Complaint suppressions remain until verified remediation and re-enablement. Provider-originated and manual suppressions also remain until verified remediation and re-enablement. These operational records use a keyed HMAC identifier instead of storing the raw recipient email address.
Retained evidence uses a versioned, domain-separated pseudonym; the raw Firebase UID is nulled after the retention transform. A deleted account cannot be reopened. A returning user who receives a new account identifier is treated as a new account under the normal trial rules. This does not automatically restore paid access or grant a promotion. Paid portability requires fresh Google Play verification and a reviewed transfer.
Deleting AeroRadar does not cancel a Google Play subscription. Manage it at Google Play subscriptions or contact support.
Legal holds
Legal holds: RiseMode Media LLC has no active legal holds and does not routinely retain personal information for litigation. If a specific legal preservation obligation arises, deletion will be suspended only for the affected records and required duration. Access will be restricted, and deletion will resume when the obligation ends.
Processors and recovery copies
Service-provider backups and disaster recovery: RiseMode Media LLC uses Google Cloud/Firebase and Supabase as service providers for AeroRadar App. When account deletion is completed, associated information is removed from active AeroRadar systems. Limited residual copies may remain temporarily in encrypted, access-restricted backup or disaster-recovery systems until they expire or are overwritten under the provider’s normal retention cycle. These copies are not used for advertising or ordinary product operations. If data is restored for disaster recovery, completed deletion instructions and deletion safeguards are reapplied before the restored information returns to normal service.
These backup and disaster-recovery safeguards also apply to the transactional-email processor described above.
Owner-attested Supabase infrastructure facts: Pro plan; East US (Ohio) region; daily backups; point-in-time recovery not active; Supabase Storage contains user objects.
Request deletion
Use the prominent in-app Account & Security action or the external deletion request and status page. A request requires recent authentication; deleting Firebase Auth is the final server stage, followed by terminal local app-data erasure.