Aurora Crew is a crew-operations platform used by an airline (the “Operator”) to roster its crew, run its operations desks and keep its flight records. This policy explains what personal data the platform holds about crew members and staff, why, who can see it, how long it is kept, and how it is removed. It describes what the platform actually does today; where a feature is optional for an Operator, it says so.
For the data your airline enters and the records its staff create, the Operator is the controller — it decides what is recorded and who may see it — and Aurora Crew is the processor, acting on the Operator's instructions under the data-processing terms in Schedule 1 of the Terms of Service. Aurora Crew handles that data only to provide, secure and support the service and never for its own purposes.
Two kinds of data are different. If you write to Aurora Crew directly — through the contact form on this site or by email to support — Aurora Crew is the controller of that enquiry. And Aurora Crew is the controller of the operational and security telemetry of its own platform (request logs and sign-in risk evaluation), which it holds to run and protect the service for every airline on it. Requests about your own crew data should normally go to your employer first; requests about an enquiry you sent us come to us.
| Category | What exactly | Why |
|---|---|---|
| Identity & employment | Name, employee number, work email, date of birth where the Operator records it, role (captain, first officer, flight attendant), home base, fleet-type qualification, in-charge status, special-airport authorisation. | To build legal rosters and know who may operate which flight. |
| Crew documents | Licence type, number and expiry; medical certificate class and expiry; passport
number and expiry; visa status (for example C1/D and B1/B2); type ratings; recurrent training,
check and simulator dates, and simulator session records where the chief pilot plans them.
Where document upload is enabled for your Operator, the uploaded files themselves (PDF, JPEG or PNG, up to 10 MB). An uploaded file contains whatever the document contains — a scanned medical certificate, for instance, shows the class and any limitations printed on it. The platform stores the file; it does not read, extract or analyse its contents, and it shows the file only to the people listed under Who can see what. |
To prevent assigning crew whose documents have lapsed, and to warn before they do. |
| Roster & duty | Flight assignments, positioning (deadhead) rides, standby shifts, leave and other blocks, hotel and rest records, duty sign-ins (time, on-time or late, whether from mobile, web, or entered manually by a scheduler), and flown block hours taken from post-flight records. | To operate the schedule and to check duty-time and rest limits. |
| Operational records | Post-flight records (times, fuel, passengers, cargo, notes), delay records, dispatch readiness checks and releases, aircraft changes, aircraft-restriction and station-equipment entries, and warning acknowledgements. Each is stored with the account that entered it and the time. Fuel invoices and simulator reports uploaded to the platform are stored as files. | They are the airline's flight records; the attribution is the accountability trail. |
| Requests & messages | Day-off, leave and shift-swap requests with any note written; notifications sent to you, including whether each was opened and acknowledged; your acceptance of these documents. | To process what you ask for, and to show whether a roster change reached you. |
| Account & security | Sign-in attempts with date, time, IP address, approximate location, device and browser and a risk assessment (held by the identity provider); a device identifier and a label such as “Chrome on macOS” for each device an operational account has used, and whether it is approved or blocked; whether two-step verification is enabled; for each device you enable push notifications on, the delivery address the mobile platform issues for it. | To keep crew and roster data from being accessed by anyone else, and to detect account takeover. |
| Change history | An append-only record of who changed which crew document field, from what value to what value, and when; and an activity view of who filed which operational record, when. | Accountability: document changes affect who may legally fly. |
The platform records no health information as data fields other than a medical certificate's class and expiry date. It holds no bank details, payroll data, or national identity numbers beyond passport and visa details, and no advertising or cross-site tracking identifiers. There are no third-party analytics, advertising or telemetry scripts anywhere in the application, and none in the mobile apps.
Data is held in Amazon Web Services in the US East (Ohio) region. Each airline's data lives in database tables, a file store and an identity pool that belong to that airline alone; no other customer's data is stored with it. Sign-in and account security are handled by Amazon Cognito. Traffic to and from the application is encrypted in transit, and stored data and files are encrypted at rest.
Push notifications are delivered through the push service of the platform your device uses — Apple, Google or Mozilla. To deliver a notification, that service receives its title and text (for example “Roster update — your Tuesday changed”). If you prefer, the app can send only a generic “You have a new notification” to the lock screen; the detail is then visible only inside the app.
The application contains links to Flightradar24 (from an aircraft's registration) and to WhatsApp (to contact your scheduling department). Those open only when you tap them, and carry nothing from the platform except the registration or the message text you can see before you tap.
Nothing else leaves the platform. No crew record, roster, document or message is sent to any generative-AI or machine-learning service, to any analytics provider, or to any other third party.
Because the Operator and its crew may be located outside the United States, using the platform involves transferring personal data to the United States for hosting. As the controller, the Operator is responsible for the lawful basis of that transfer under the law that applies to it; Aurora Crew processes the data only on the Operator's instructions and applies the controls described in this policy throughout.
| Data | Kept for | How it is removed |
|---|---|---|
| Notifications | 7 days | Marked expired automatically; the database then physically deletes the record — Amazon states typically within a few days. During that short period the record still exists and may still be returned to the application; the application itself hides notifications older than 7 days regardless. |
| Duty sign-ins | 14 days | |
| Reminder and delivery markers (so a reminder is sent once) | 1 to 150 days depending on the reminder | |
| Queued notifications waiting to be sent | Minutes | Deleted when sent. |
| Crew records, documents and uploaded files, rosters, post-flight, delay and dispatch records, flown hours | No automatic expiry | Held until the Operator deletes them or ends its use of the platform. The Operator keeps them for at least the period its aviation authority requires and instructs deletion once no legal or operational reason remains; we delete on that instruction and confirm. |
| Change history and activity attribution | No automatic expiry | Retained as the accountability record for as long as the Operator uses the platform. |
| Devices, security baselines, two-step settings, push registrations | Until access is revoked | Removed when the sign-in is disabled or the device is forgotten. |
| Sign-in and risk events | Two years, as stated by Amazon Cognito | Removed by the identity provider on its own schedule. |
| Enquiries sent to Aurora Crew (name, email, company, message, IP address, browser) | No timer | Reviewed periodically and removed when no longer needed; deleted on request to support@auroracrew.app. |
| Application request logs (address, IP, outcome) | 90 days | Deleted automatically. |
| Backups | Database point-in-time recovery 35 days · daily backups 35 days · monthly backups 365 days · previous versions of uploaded files 365 days · backup files in the platform's vault up to 400 days | Age out on that fixed cycle. A deletion from the live platform does not reach into backups; they are never restored except to recover the platform itself, and a restore is followed by re-applying any deletion the Operator has instructed. |
Depending on the law that applies to you, you may have the right to see the data held about you, have it corrected, object to certain processing, or have it deleted where there is no longer a legal or operational reason to keep it. Some data cannot be deleted while it is needed for aviation record-keeping. For crew data, ask your employer first; we support the Operator in responding. For an enquiry you sent us, ask us. To exercise any of these rights, contact your Operator or email support@auroracrew.app; requests are answered without undue delay. If you are not satisfied with the response, you may complain to the data-protection authority with jurisdiction over your Operator.
Deleting your sign-in and deleting the personal data held about you are two different things, and they are asked for in different places. You can remove your own sign-in from inside the app. Removing the data held about you is administered by your airline, because your account is created for you by the Operator and the record is the Operator's, not ours to delete on request.
In the Aurora Crew crew app, open Settings and then Delete account. Your sign-in is scheduled for deletion and removed 48 hours later. Until then it keeps working and you can stop the deletion from the same screen; once the window closes, the sign-in is deleted and can no longer be used.
That removes the sign-in and nothing else. Your crew record, your personal details and your documents are not touched by it, and neither are your approved devices, your two-step enrolment or your push registrations. Because your crew record remains, a new sign-in can be issued to you later from that same record — deleting the sign-in does not remove you from the airline. Your airline's crew scheduling department can also remove a sign-in for you, and does so immediately rather than after a waiting period.
This is requested through the Operator, and we act on it. There are two ways to start:
A request of that kind has three distinct effects, because three different things are involved:
So the disabled sign-in is not a lingering account: it is a name on records that are themselves scheduled for deletion. Nothing about you remains once those records go.
Rosters are built by a rule-based algorithm, not by artificial intelligence. It applies the duty, rest, qualification and fairness rules configured for the Operator in a fixed, repeatable way. There is no machine-learning model involved, it is not trained on your data, and any assignment it produces can be traced back to the specific rules that led to it. Every roster is reviewed by crew scheduling before it is published.
Your data is not sent to any AI service. See Where it is held above.
There is one automated assessment of you personally: when you sign in, Amazon Cognito evaluates the attempt for risk — using its own detection models, based on signals such as the device, location and whether the credentials appear in known breach data. Depending on the Operator's settings, a high-risk attempt may be challenged (asked for a two-step code if you have one) or refused; an attempt using credentials found in a known breach is refused. This protects roster and document data from someone using your account. It does not assess your work or affect your employment, and a refused attempt can always be resolved through your scheduling department.
The platform makes no disciplinary, performance or employment decisions, automated or otherwise.
Material changes increment the acceptance version, and you will be asked to accept the updated documents when you next sign in. The version you accepted is recorded against your account.
Data protection contact: support@auroracrew.app. Your Operator can also tell you who to contact within the airline about your data.