Log4Pilot does not require a Log4Pilot account and does not operate a developer server, database or API that stores your logbook. Your flights, licences, endorsements and signatures are stored on your iPhone, with automatic backup to your own Apple iCloud Drive folder. There is no analytics, advertising, tracking or third-party network SDK. Information leaves your device only when you tap Export, Share, Print or send a signing request. This summary does not replace the details below.
“Log4Pilot computes currency and totals from your own entries using published rules. It is not legal advice and does not replace your logbook responsibilities or an instructor’s or examiner’s judgement.”
Log4Pilot is a record-keeping and proof aid only. It is not an EFB, does not provide flight planning / weather / navigation, does not file with any authority, and is not approved or endorsed by FAA, EASA or the UK CAA. Currency outputs are informational computations labelled with rule + version — never “you are legal to fly”.
1. Who we are
Log4Pilot is published by M-PAX Group. For privacy enquiries, contact [email protected] with “Log4Pilot privacy” in the subject line.
2. Overview & scope
This policy describes how Log4Pilot handles information when you use the iOS app and when you visit this website. The app is local-first and offline-first: entry, projections, currency, PDF generation and CSV export all work in Airplane Mode with no developer backend.
We do not make unqualified claims such as “nothing ever leaves your device”. Records stay on your iPhone and in your own iCloud Drive except when you choose to export, share, print or send a signing request — at that point a copy goes wherever you send it (e.g. Files, Mail, AirDrop, your instructor / examiner). That moment is disclosed in the app and in §9 below. The in-app About & privacy screen should always be treated as the authoritative description for the shipped build.
3. Information Log4Pilot processes
Log4Pilot stores raw facts only — never stored derived quantities another authority could compute differently. Totals, currency and cross-country qualification are computed on read from these facts per jurisdiction profile. All of the below is stored on your device (§6):
| Category | Examples | Purpose |
|---|---|---|
| Pilot profile | Full name, address, employer (ANO 228), date of birth, signature image, time-display preference, active profiles | Identify the holder; head reports; apply your preferences |
| Licences & medicals | Licence type / number / issue / ratings, medical type (FAA 1/2/3, BasicMed, UK medical, PMD), examiner notes | Show in proof packs; drive expiry alerts (expiry projected, never stored) |
| Directories | Aircraft (registration, make/model, class, SE/ME, tailwheel …), aerodromes (code, coords, timezone), instructors (name, certificate no./expiry) | Pre-fill forms; compute night / distance; link endorsements |
| Flight entries | UTC instants (block-off/takeoff/landing/block-on), full route, aircraft snapshot, command facts (PIC/dual/PICUS/SPIC …), landings & takeoffs day/night, day/night/instrument minutes, approaches, remarks, entry basis (local/UTC) | Build your logbook; project totals; evaluate currency; print reports |
| FSTD & ground training | Device type/qualification, location, session minutes, capacity, approaches, topics, linked endorsements | Training-received evidence; FCL group 11 / flight-review ground element where signed |
| Endorsements & countersignatures | Type, template + version, body text, pilot/signatory names, certificate nos./expiry, dates, states (signed/pending/refused), signature images | Prove instruction, solo, tests, revalidation; chase pending items |
| Opening balances | As-of date, asserted figures, source note | Lifetime totals only; excluded from currency; labelled asserted |
| App data | Preferences (appearance, units), backup health, entitlement (StoreKit), generated-report catalogue (hashes, entry lists) | Remember settings; surface backup health; never silently regenerate reports |
Log4Pilot does not collect analytics, identifiers for advertising, location history, contacts, or HealthKit data. There is no account profile, no social graph and no advertising profile. The bundled aerodrome gazetteer is versioned app data; great-circle and night computations run on-device.
4. Attachments & signatures
Attaching photos (e.g. paper counterpart, Hobbs/tach) is optional. When you attach, a copy is imported into the app’s private on-device storage and included in your iCloud backup. Nothing uploads to a developer server and nothing is transcribed in v1.
- System pickers in context — if camera/photo capture ships, camera/photo permission is requested only after you tap a capture action, never speculatively. No broad library, contacts, calendar, location or HealthKit access is requested for logging.
- Signatures are evidence, not cryptography — a signatory draws on your device, or you send a signing request via share sheet and import the returned image. Stored: image, printed name, certificate number/expiry, date. The app states it does not provide cryptographic non-repudiation and never applies a signature anyone didn’t make.
- Signatures on paper — spaces an authority wants in wet ink are left blank with the printed name beneath. Stored images appear only where the profile accepts electronic signing, labelled as such.
5. Notifications (local only)
All notifications are local and scheduled on-device — currency / rating / medical expiry (30/14/7 days + lapse day), weekly pending-countersignature reminder (configurable), backup-failure alert. They work without a backend once scheduled.
- Permission is requested in context only, with an in-app explanation — never for marketing. There are no marketing notifications.
- If you deny permission, records remain fully usable; reminders show as off with an Open Settings action.
- Disable anytime in Settings → Notifications → Log4Pilot.
6. On-device storage, iCloud backup & offline operation
Your logbook is stored locally on your iPhone using SwiftData (versioned schema with migration tests). A failed write surfaces immediately; silent data loss is treated as release-blocking. Every feature works offline, including in Airplane Mode.
- Automatic backup to your own iCloud Drive: versioned archive (JSON of all records + signature/attachment blobs + manifest with schema and rule versions) written to the app’s iCloud Drive container on entry-count and weekly triggers. Backup health (last success, size, failure reason) is shown in More; failure raises a local notification.
- Restore is first-class: takes a pre-restore snapshot, validates manifest + totals reconciliation before committing. Manual “Export full backup” to Files is always available.
- Manual export anytime: full JSON archive, CSV set and proof pack — regardless of entitlement (paid or not).
- Your Apple relationship: iCloud Drive data is processed by Apple under your Apple services relationship — see Apple’s Privacy Policy. Backups count toward your Apple storage quota. There is no CloudKit database/sharing in v1 and no cross-device sync beyond your own backup/restore. Deleting the app deletes the on-device container; your iCloud Drive archives remain until you (the account holder) remove them.
7. No account required
Log4Pilot does not require you to create a Log4Pilot account, sign in with Apple, or join any portal. One pilot per install. Instructors / examiners never need an account: they sign on your device or via a share-sheet request. Authorities receive printed/PDF packs and never interact with the app. Any “sign-in” or “passcode” in the app is the local app lock (Face ID / Touch ID), not an account.
8. Third-party services & Apple frameworks
Apple platform services only
Log4Pilot uses Apple frameworks only (SwiftUI, SwiftData, UIGraphicsPDFRenderer, StoreKit 2, UserNotifications, PhotosUI/PHPicker + AVKit only if attachment capture ships). Their use is subject to Apple’s privacy policy and your device settings. No Firebase, analytics, ads, remote fonts, map-tile SDKs or third-party health SDKs are included, and the app contains no network service layer by construction. Hand-rolled CSV writer with tested escaping; no server-side computation.
No place-data or map providers
Night and cross-country math uses stored aerodrome coordinates + bundled gazetteer on-device. No coordinates are sent to any place-data provider. There is no map tile loading and no location tracking.
Websites you choose to open
This website and any links you tap (e.g. Apple EULA, CAA guidance) are governed by their own policies. Exported files you send via Mail, Messages, AirDrop or Files are governed by those services and recipients.
9. Data sharing — only when you tap Share
We do not sell your logbook, signatures or photos to third parties, share them with data brokers, or build advertising profiles from them.
We share data only as follows:
- On your device — processing stays local wherever possible.
- When you export, share, print or request a signature — PDFs, CSVs, JSON backups and signing-request files are presented in the system share sheet with explicit filenames. At that point a copy leaves your device to wherever you send it. Only share files you intend your instructor, examiner or authority to receive. UK packs note the CAA submission instruction (sign the certification page electronically or by hand before submitting).
- As required by law — if legally obliged.
Support emails you send to [email protected] are used only to answer you and deleted on request. A “Copy diagnostics” action, if present, copies only app/iOS/rule-bundle versions and counts — never entry contents — for you to paste if you wish.
10. Purchases
Log4Pilot offers a free allowance, then a single one-time non-consumable unlock via StoreKit 2 (exact allowance size and price per market confirmed at launch; hypothesis US$39–49 for validation). No subscription for record access, ever.
- Entitlement gates new entry creation beyond the allowance only. Viewing, searching, exporting, reporting and restoring existing records are never gated — enforced by acceptance test.
- Restore Purchases is available in More and on first launch after reinstall. Honest copy: “Pay once. Your logbook is yours.”
- Future add-ons (e.g. extra jurisdiction packs) will not gate records or exports created under the base unlock.
- Use of the app is governed by Apple’s Standard Licensed Application End User License Agreement: https://www.apple.com/legal/internet-services/itunes/dev/stdeula/.
11. Retention, revision history & deletion
Your logbook is retained on your device and in your iCloud Drive backups until you delete it:
- Entries are freely editable until first inclusion in a generated report; afterwards edits append a RevisionNote (timestamp, fields changed) and set editedAfterExport — history is never silently rewritten.
- Delete is soft-delete with Undo window; deleting an entry linked from a signed endorsement requires explicit unlink confirmation and writes a revision note.
- Opening balances are edited only by editing the balance record itself, with the same revision discipline.
- Delete all local data in Settings (typed confirmation), or delete the app (removes its local container on that device; iCloud archives remain until you remove them).
- Restore merges or replaces only from a backup file you supply, after a verified safety snapshot.
We cannot delete copies you already shared (e.g. a PDF you handed to an examiner). Have the final wording reviewed against the shipped build before publication.
12. Legal bases (UK / EEA)
Where UK GDPR / EU GDPR applies, we process on-device logbook data to perform the contract (provide the app you requested) and on the basis of your consent where you grant optional permissions (Notifications, Camera/Photos if attachment capture ships). You may withdraw consent by changing the permission in iOS Settings; this does not affect prior processing. Because processing is local, withdrawing consent simply disables the dependent feature. The pilot remains the data controller for their logbook; the app processes everything on-device and transmits nothing by itself.
13. Children
Log4Pilot is intended for student and GA pilots (typically 16+ for solo flight training, varying by jurisdiction) — not as a children’s app. We do not knowingly collect children’s data as a developer for advertising or profiling, do not use data for ads, and contain no social or messaging features. If the app is on a family device, the same local-first protections apply. Guardians should use Apple’s Screen Time and Family Sharing controls. Ensure the App Store age rating is appropriate and have this section legally reviewed.
14. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete or restrict processing of your information, and to object or withdraw consent. Because your logbook is on your device, you can directly access, correct, export and delete it in the app (Today, Log, Prove, More → directories / backup / settings). To exercise other rights, contact [email protected].
UK users may also lodge a complaint with the Information Commissioner’s Office (ICO).
15. Security
We design Log4Pilot to minimise collection and keep processing on-device: SwiftData + iOS Data Protection for stored files, OS-controlled permissions requested in context, optional Face ID / Touch ID app lock, Apple platform security, versioned backups with health surfacing, temporary export files deleted after sharing or on next launch, and no network attack surface. No method is 100% secure, so we avoid claims such as “100% secure” and instead describe these actual measures. The app never logs your flight details, remarks or filenames to any developer system.
16. Changes to this policy
We may update this policy to reflect app changes or legal requirements. The “Effective” date at the top will be updated and, where appropriate, we will note changes in release notes or in-app. If privacy practices change (e.g. a future optional purchase tier or analytics feature), this page and the App Privacy labels / manifest will be updated before release.
17. Contact
Developer: M-PAX Group.
Privacy / support: [email protected]
Support & launch page: https://m-pax.net/log4pilot/
If you are in the UK/EU and have a data-protection question, include “Log4Pilot privacy” in the subject line and we will respond.