The short version: CabinKit is built to know as little about you as possible. There are no accounts, no ads, no analytics, and no tracking. Fly-Right operates no servers of its own and collects no personal data. Your working data lives on your device; syncing and community features run through Apple's iCloud under your own Apple ID; passenger profiles are encrypted and can never be exported.
1. Who we are
CabinKit is published by Fly-Right LLC ("Fly-Right," "we"), a New Jersey company. Contact: inquiry@flyrightconsulting.com.
2. Data that stays on your device
Everything you create in CabinKit — checklists, stocking counts, trips, expenses and their attached receipts (photos and PDFs), crew documents, bar inventory, vendor notes — is stored locally on your iPhone, protected by iOS file encryption.
Passenger profiles get stronger treatment. Profiles are designed to hold code names and service preferences only — the app warns if an entry looks like a real name. Profile data is additionally encrypted at rest with a key held in your device keychain, unlocked by Face ID / Touch ID / passcode. Biometric data itself never leaves Apple's secure hardware and is never available to us. Profiles have no export, share-sheet, or copy-out function of any kind, by design.
3. Data we collect: none
Fly-Right does not collect, receive, sell, or share your personal information. We run no analytics, no crash-tracking SDKs, no advertising identifiers, and no server of our own. The app never asks for your name, email, or account credentials.
4. iCloud sync and end-to-end-encrypted sharing
- Crew vault (optional): if you invite keyholders, crew-vault profiles sync between the participants' devices through Apple iCloud sharing. Payloads use CloudKit's encrypted fields — end-to-end encryption whose keys live in the participants' iCloud Keychains. Neither Fly-Right nor Apple can read them. The vault owner controls the participant list; removal takes effect server-side immediately.
- Shared tail stocking (optional): stocking sections shared with crew travel the same way — end-to-end encrypted between invited participants, with a separate invite list per aircraft.
- iCloud storage is provided by Apple under your Apple ID and Apple's privacy policy.
5. Community features are public
If you use the Lounge, what you post — posts, replies, and shared checklists, recipes, meal templates, and vendor listings — is visible to all CabinKit users, attributed to the pseudonymous handle you choose. Don't post anything you wouldn't want public. The app blocks tail-number and phone-number patterns and offensive language before posting; users can report content, and reported content is reviewed within 24 hours. You can delete your own posts at any time in the app. Community content is stored in CloudKit's public database, operated by Apple; a technical iCloud user record identifier accompanies it (as with any CloudKit app), but no name, email, or contact information.
6. Third-party lookups the app performs
| Feature | Service | What is sent |
|---|---|---|
| Weather cards on the Trip Sheet | Apple WeatherKit | The airport's geographic coordinates. No identifiers about you. |
| Barcode scanning | Open Food Facts, Open Beauty Facts, Open Products Facts (community databases); UPCitemdb (product directory), tried only if the community databases have no match | The barcode digits only. No identifiers about you. Products you confirm are remembered on your device, so repeat scans need no lookup at all. |
| Geocoding unknown airport codes | Apple geocoding services | The airport code text. No identifiers about you. |
| Trip calendar-feed import (optional) | Your scheduling software's calendar host | Only if you paste your scheduling provider's calendar link: the app fetches that link directly from its host. Nothing else is sent, and CabinKit never reads your device calendar. |
Airport locations, cities, and countries come from a public-domain airport database bundled inside the app — looking up an airport sends nothing anywhere. Only a code the bundled database doesn't know falls back to Apple's geocoding services, as above.
7. Device permissions and how they're used
- Camera: scanning barcodes and photographing documents, drinks, and stock references. All image processing happens on your device.
- Photo library: only to let you attach photos you choose.
- Face ID: unlocking the profiles vault, on device only.
- Calendar: write-only access, used solely to add document-expiration reminders you request. CabinKit cannot read your calendar.
8. Retention and deletion
- On-device data: deleted when you delete it in the app, or entirely when you delete the app.
- iCloud share data: leave a shared vault or stocking (or, as owner, stop sharing) and it is no longer available to others; iCloud data associated with your Apple ID can be managed through Apple.
- Community posts: delete your own posts in the app, which removes them for everyone. For anything you cannot remove yourself, email us and we will remove it.
9. Children
CabinKit is a professional tool intended for users 17 and older. It is not directed to children, and we do not knowingly collect information from children.
10. Your rights
Because we don't collect personal data, there is usually nothing for us to access, correct, or delete on our side — your data is in your hands and your iCloud. If you believe we hold anything about you (for example, an email you sent us), or you want community content removed, contact us and we will respond. We do not sell or share personal information as those terms are defined under U.S. state privacy laws.
11. Security
Data at rest is protected by iOS encryption; passenger profiles carry an additional layer of on-device encryption behind biometric unlock; crew sharing uses CloudKit end-to-end encrypted fields. No system is perfectly secure, but CabinKit's architecture means there is no Fly-Right database of user data to breach.
12. Changes to this policy
If we change this policy materially, we will update the effective date above and note the change in the app. The current version always lives at this address.
13. Contact
Fly-Right LLC
Email: inquiry@flyrightconsulting.com