1. Introduction
BlueSky Applications LLC ("we," "us," or "our") operates the 5-by-5 mobile application (the "App"). This Privacy Policy describes how we collect, use, store, and share your personal information when you use our App and related services.
By creating an account or using 5-by-5, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the App.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Full name
- Email address
- Password (stored in hashed form; we never have access to your plaintext password)
2.2 Member Profile Information
When you join or create a group, you may provide:
- Phone number
- Emergency contact name, phone number, and relationship
- Profile photo
- Country of residence (for localization)
2.3 Pilot Certification and Currency Data
To support pilot currency tracking, you may provide:
- Pilot certificate or license type (e.g., Private Pilot, Commercial, ATP / PPL, CPL, ATPL)
- Pilot ratings (e.g., Instrument, Multi-Engine)
- Medical certificate type and expiration date
- Flight review expiration date
- Instrument proficiency check date
2.4 Flight and Activity Data
- Flight records: date, departure/arrival airports, tach times, hours flown, landings, instrument approaches
- Flight comments and notes
- Currency event tracking data
2.5 Aircraft and Group Data
- Group/partnership name
- Aircraft registration (tail number), year, make, model, and category
- Home airport
- Aircraft photos
2.6 Booking and Scheduling Data
- Booking dates, times, destinations, routes, and estimated hours
- Trip names and comments
2.7 Maintenance and Squawk Data
- Maintenance item descriptions, due dates, and tach readings
- Squawk reports: title, description, priority, status, and associated photos
2.8 Billing Information
Payment processing is handled entirely by Stripe, Inc. We do not collect, store, or have access to your credit card number or payment card details. We store only:
- Stripe customer ID (a reference identifier)
- Subscription tier, billing period, and expiration date
2.9 Bank Account and Transaction Data (Optional)
5-by-5 offers an optional bank account integration powered by Plaid. If you choose to connect your bank account, we collect and store:
- Your bank institution name (e.g., "Chase", "Wells Fargo")
- Transaction records: date, merchant/description, and amount — for the connected account
- Current account balance (fetched on demand)
We do not collect, see, or store your bank login credentials, account numbers, routing numbers, or any other sensitive account identifiers. Your credentials are entered directly into Plaid's secure interface and never transmitted to or stored by 5-by-5.
Bank transaction data is used solely to display your group's actual expenses alongside planned expenses on the Finances page. It is not used for advertising, credit assessment, or any purpose beyond aircraft expense tracking.
Transaction data is stored only while the bank connection is active. If you disconnect your bank account (available in the web dashboard), all cached transaction data is permanently deleted from our systems.
2.10 Device Permissions and Local Data
With your consent, the App may access:
- Camera and Photo Library: To take or select photos of aircraft, profiles, and squawks
- Calendar: To sync bookings to your device calendar
Authentication tokens are stored securely on your device using encrypted storage (device secure enclave). Calendar sync preferences are stored locally on your device.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the App's core features (scheduling, flight logging, maintenance tracking, currency tracking)
- Authenticate your identity and manage your account
- Facilitate group management and communication between co-owners/members
- Process subscription payments through Stripe
- Send transactional emails (e.g., group invitations)
- Generate calendar feeds for booking synchronization
- Display bank balance and transaction data on the Finances page (only when you opt in to the Plaid bank integration)
- Respond to support requests
We do not use your data for advertising, and we do not sell your personal information to third parties. Bank transaction data is used exclusively for aircraft expense tracking within the App and is never shared with or sold to any third party.
4. How We Share Your Information
4.1 Within Your Group
Certain information is visible to other members of your aircraft group, including your name, profile photo, phone number, pilot certifications, bookings, shared flight records, and squawk reports. This sharing is essential to the App's purpose of coordinating shared aircraft use.
4.2 Third-Party Service Providers
We share data with the following service providers, solely for the purpose of operating the App:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Backend database, authentication, file storage | All app data (encrypted in transit via HTTPS) |
| Plaid | Optional bank account integration (read-only) | Bank institution selection; Plaid returns transaction data and balances to us — we never share your data back to Plaid beyond what is required to establish and maintain the connection |
| Stripe | Payment processing | Email, group name, member count, subscription details |
| Resend | Transactional email delivery | Recipient email, group name, inviter name, invite codes |
| Expo (EAS) | App distribution and updates | Anonymous app performance data |
| Apple / Google | App store distribution | Standard app store analytics |
4.3 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request.
5. Data Storage and Security
- All data is transmitted over HTTPS (TLS encryption in transit)
- Backend data is hosted on Supabase (cloud infrastructure with encryption at rest)
- Authentication tokens are stored in your device's secure enclave via encrypted storage
- Passwords are hashed using industry-standard algorithms; we never store plaintext passwords
- Row-level security policies restrict database access so users can only view data within their own group
- Payment card data is handled entirely by Stripe (PCI DSS Level 1 compliant) and never touches our servers
6. Data Retention
We retain your data for as long as your account is active. If you delete your account (available in Settings), we delete:
- Your member profile and all associated data
- All flights, bookings, currency events, and squawk reports you created
- Your authentication account
- If you are the last member in a group: all group data, including aircraft records, maintenance items, and all associated member data
Uploaded photos may take up to 30 days to be fully purged from storage backups after account deletion.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data (editable in Settings)
- Delete your account and associated data (available in Settings)
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent for optional features (e.g., calendar sync, camera access via device settings)
To exercise any of these rights, contact us at support@blueskyapplications.com.
7.1 California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information. To make a request, contact us at the email above.
7.2 European and International Users (GDPR)
If you are located in the European Economic Area, United Kingdom, or other jurisdiction with similar data protection laws, our lawful basis for processing your data is:
- Contract performance: Processing necessary to provide the App services you signed up for
- Legitimate interests: Improving the App, preventing fraud, ensuring security
- Consent: For optional features such as calendar access, camera access, and marketing communications
8. Children's Privacy
5-by-5 is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected information from a child under 18, we will delete it promptly.
9. Calendar Feed Disclosure
5-by-5 offers an optional ICS calendar feed that allows external calendar applications (e.g., Apple Calendar, Google Calendar) to display your group's bookings. This feed is accessible via a unique URL containing your group's identifier. Anyone with this URL can view booking information (dates, times, trip names, and the name of the member who booked). Share this URL only with trusted individuals.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy in the App or on our website. Your continued use of the App after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
BlueSky Applications LLC
Email: support@blueskyapplications.com
Website: blueskyapplications.com