Legal
PocketDPE Privacy Policy
About this website. This policy covers the PocketDPE app and the servers behind it. This website, pocketdpe.org, doesn't use cookies, analytics or advertising trackers. It is hosted by Vercel, which processes standard request information such as your IP address to deliver the site and keep it secure. See Vercel's Privacy Policy.
PocketDPE ("we", "our", "us") is an AI-powered aviation training application that simulates the oral portion of an FAA checkride. This policy explains what information the PocketDPE iOS app and its servers collect, exactly which companies receive it, how long we keep it, and how to delete it.
1. Information We Collect
Account Information
When you create an account we collect your email address and sign-in credentials through our authentication provider, Clerk. If you use Sign in with Apple, we receive the identifier Apple provides and, if you choose to share it, your email address. We never see or store your password.
Voice Data
During a practice session the app records your spoken answers through the microphone. Each answer is sent to OpenAI's speech-to-text models to be transcribed and to OpenAI's language models to be graded and answered. The audio file itself is deleted from our server as soon as it has been transcribed — we do not keep recordings. The temporary audio files the app creates on your device are deleted automatically within a day.
Session Transcripts and Progress
We keep the written transcript of each session (the examiner's questions and the text of your answers), your per-area grades, your debrief, and your study progress. This is what powers your session history, the ability to pause and resume a session, your Readiness Score, and syncing your history to a new device. Transcripts and progress are tied to your account.
Written Test Report Photo
If you use the written-test scanner, the photo you take of your FAA knowledge test report is sent to OpenAI's vision models to read the knowledge-area codes on it. That photo can include your name and FAA Tracking Number. The photo is deleted from our server immediately after the codes are extracted; only the list of codes is kept, with your account, to tailor your practice sessions. Nothing is scanned until you have seen and accepted an in-app disclosure that says the photo will be sent.
Subscription Status
Subscriptions inside the iOS app are sold by Apple through In-App Purchase. Apple handles all payment; we never receive your card details. We use RevenueCat to read your subscription status from Apple's receipt so the app knows what you have unlocked. Subscriptions bought on the web are processed by Stripe on Stripe-hosted pages; we receive only a confirmation and status.
Usage Analytics and Crash Reports
To understand which parts of the app are used and to find bugs, the app sends product-usage events (screens viewed, features used, subscription events) to PostHog, and crash reports to Sentry. These are associated with a random device identifier and, once you sign in, with your account identifier. They never include the content of your practice sessions, your voice, or your test report photo.
2. How We Use Your Information
- To run the AI examiner: transcribe your answers, grade them, and speak the next question
- To show your session history, debriefs, Readiness Score and weak areas, and to let you resume a paused session
- To tailor future practice sessions to the areas your written test report shows you missed
- To manage your account and know what you have subscribed to
- To find and fix crashes and to see which features are being used
- To improve the accuracy of our examiner and question content — we read sessions in aggregate to find grading errors and repeated questions
3. Third-Party Services
These are the only companies that receive your data, and what each one receives. We share the minimum each service needs.
- OpenAI — Your voice recordings (for transcription), the text of your session (for grading and the examiner's replies), and your written-test photo (to read the codes). Under OpenAI's API terms, this data is not used to train OpenAI's models and is retained by OpenAI only briefly for abuse monitoring. See OpenAI's Privacy Policy and OpenAI's API Data Usage Policies.
- Clerk — Sign-in and account management. Receives your email address and authentication tokens. See Clerk's Privacy Policy.
- Apple — All in-app purchases and subscription billing on iOS. See Apple's Privacy Policy.
- RevenueCat — Reads your App Store subscription status so the app can unlock what you bought. Receives your Apple purchase receipt and your account identifier. See RevenueCat's Privacy Policy.
- Stripe — Subscription billing for purchases made on the web only; not used inside the iOS app. Card details are entered on Stripe's own pages and never reach us. See Stripe's Privacy Policy.
- PostHog — Product-usage analytics (which screens and features are used). See PostHog's Privacy Policy.
- Sentry — Crash and error reports from the app. See Sentry's Privacy Policy.
- Railway — Hosts our servers and database in the United States. See Railway's Privacy Policy.
4. Your Consent Before Data Is Shared With OpenAI
Before any voice audio, session content or test-report photo is sent to OpenAI, the app shows a disclosure that names OpenAI, lists exactly what is sent and what is not, and requires you to tap "I Agree and Continue." If you decline, the AI features stay off and nothing is sent. You can withdraw this consent at any time under Settings → Privacy → AI Services; withdrawing it turns the AI features off immediately.
5. Data Sharing
We do not sell, rent, or share your personal information with anyone for marketing purposes. Your data goes only to the services listed in section 3, only as needed to run the app.
6. Data Retention and Deletion
- Voice recordings: deleted from our server as soon as they are transcribed. Never kept.
- Test report photos: deleted from our server as soon as the codes are read. Never kept.
- Session transcripts and progress: kept while your account is active so your history and Readiness Score keep working. Working copies of in-progress and recent sessions held on our server for pause-and-resume are automatically deleted 90 days after the session.
- Account deletion: use Settings → Delete Account in the app. This permanently deletes your account record, your session transcripts and progress, and your test-report codes from our systems. Deleting your account does not cancel an App Store subscription — manage that in your iPhone's Settings → Apple ID → Subscriptions.
- Analytics and crash data: retained by PostHog and Sentry under their own policies; it contains no session content.
7. Data Security
All data travels over encrypted connections (HTTPS/TLS). Access to our servers uses token-based authentication, and access to stored data is restricted to what is needed to operate the app.
8. Children's Privacy
PocketDPE is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with personal information, contact us and we will delete it promptly.
9. Your Rights
Wherever you live, you can:
- Access the personal data we hold about you
- Ask us to correct inaccurate data
- Delete your account and data yourself, in the app, at any time
- Withdraw your consent for AI processing, in the app, at any time
If you are in the European Economic Area, the United Kingdom or California, you have the additional rights those laws provide, including the right to receive a copy of your data and to complain to your local data-protection authority. Contact us and we will help.
10. Changes to This Policy
We may update this policy from time to time. We will announce material changes in the app or by email. Continued use of PocketDPE after a change means you accept the updated policy.
11. Contact Us
Questions about this policy or your data: support@pocketdpe.org