← Back to App
ATC Sync
https://tolinktouslot.pages.dev
Privacy Policy
Effective Date: April 25, 2026
ATC Sync ("the Application") is a coordination tool for Air Traffic Controllers. This Privacy Policy explains how we collect, use, and protect your information when you use our service at https://tolinktouslot.pages.dev.
1. Information We Collect
- Personal Profile Data: Name, Email Address, Callsign, and Profile Picture via Google OAuth.
- Schedule Data: Shift schedules generated within the app to calculate overlaps.
- Usage Data: Anonymized technical data via PostHog to improve performance.
2. Use of Google User Data
ATC Sync requests access to your Google Calendar (via the auth/calendar scope). This access is used for the following strictly limited purpose:
Dedicated Synchronization: We use this permission exclusively to create and manage a dedicated secondary calendar named "ATC Sync". This allows your work shifts to be visible on your devices without modifying, reading, or cluttering your primary personal calendar. We do not read, delete, or modify any events on your primary or other personal calendars.
3. Google API Disclosure (Limited Use)
ATC Sync's use and transfer to any other app of information received from Google APIs will adhere to the Google API Service User Data Policy, including the Limited Use requirements.
4. Data Protection & Security Mechanisms
We implement robust technical and administrative security measures to protect your sensitive Google user data (including Google Calendar API data, profile details, and access tokens):
- Encryption in Transit: All data transferred between the Application, Google APIs, and our servers is encrypted in transit using Secure Socket Layer (SSL) and Transport Layer Security (TLS 1.2 or higher) protocols (HTTPS).
- Encryption at Rest: All stored Google OAuth tokens, credentials, and user profile data are saved in our PostgreSQL database hosted on Supabase, which enforces industry-standard AES-256 encryption at the storage layer.
- Database Access Control (Row Level Security): We enable Row Level Security (RLS) on our database tables, enforcing policies that restrict data access exclusively to the authenticated owner of the account. No other users can read or modify your data.
- Server-Side Token Refreshing: Google refresh tokens are stored securely in our database. The token refresh process is handled strictly via server-side Supabase Edge Functions. Client secrets and API keys are kept in secure environment variables on the server and are never exposed to the frontend or browser.
- No Sharing of OAuth Tokens: Your Google OAuth tokens, credentials, and raw calendar sync data are never shared, sold, or transferred to any third parties or advertising networks.
- Automatic Data Deletion (Cascade): When you delete your account, database foreign key constraints automatically trigger a cascade delete, permanently and immediately purging your profile, shift history, and Google OAuth tokens from our servers.
5. Data Sharing & Third Parties
We do not sell your data. We share information only with Supabase (Database/Auth) and PostHog (Analytics) as necessary for app functionality.
6. Your Rights & Data Deletion
You can delete your data at any time via the Delete Account feature in settings. This results in the immediate and permanent erasure of your profile, shift history, and integration tokens from our servers.
7. Contact Us
Developer: Vasileios Evangelakos
Email: vasilis.app.contact@gmail.com