FAA instructor workspace · iPhone & iPad
Privacy, in plain language.
How NextFlight uses information to connect an instructor with invited students and their training records.
Who operates NextFlight
Krishna Hiren Patel operates NextFlight. Contact support@nextflightapp.com with privacy questions or requests. This policy covers the NextFlight app and its account and training service.
Information you provide
We use your name, email and account identifier to provide your instructor or student account. Passwords are stored as salted hashes. Session credentials are stored in the app’s Keychain; the server stores hashes of account access and one-time credentials.
Training information includes schedules, user-entered locations and aircraft details, selected pathways, checklist values, task reviews, syllabus items, training dates, notes, exclusions and edit history. We also store private instructor/student messages, lesson briefings and student acknowledgments.
We also store your declared age group and when you provided it. For students ages 13–17, we store the parent or legal guardian’s email, name, approval or decline, request and decision times, the policy version and their statement that they are an adult parent or legal guardian. We do not ask for a date of birth. If you contact support, we use the details you provide to help with your request.
Enter only information needed for training. NextFlight has no medical-document upload feature. Avoid placing sensitive medical, financial or identity documents in free-text notes or messages.
Who can see training information
An instructor manages the records of students they invite. A student can access only their own workspace. The instructor and that student can see their shared notes, messages, briefings and recorded reviews. The app does not provide public student profiles or a public message feed. A parent or guardian receives an approval request naming the student and instructor; approval does not create a guardian account or access to the student’s training workspace.
We use this information to operate accounts, schedule and organize lessons, record progress, deliver account emails, provide reports and keep access secure. Hosting: Render for the production API, account database, messages and local database snapshots; Cloudflare for the static website, DNS and domain services. Email: SMTP2GO for transactional account and guardian-approval email, and Cloudflare Email Routing for support forwarding. Backups: the NextFlight operator, using verified SQLite snapshots on the app's existing persistent disk; no automated offsite copy is configured and R2 storage is not part of the launch setup.
Apple subscriptions
Apple handles instructor subscription payments. NextFlight does not receive payment-card details. We verify purchase records and associate subscription identifiers, product, renewal state, expiry and verification dates with the instructor account. We do not store raw signed purchase receipts in the application database. Students do not buy subscriptions.
Deleting a NextFlight account does not cancel Apple renewal. Use the app’s Manage Apple subscription control to manage or cancel the plan. Apple handles its own account and purchase records under its policies.
Information kept on your device
The app keeps a protected copy of the last complete roster, schedule and training-record sync for read-only access during connection problems. Offline recovery lasts up to seven days after that sync. It excludes messages, briefings, invitation codes and pending edits. The app removes its copy on sign-out, a rejected session, account deletion or a server/account change.
Reports and account exports use app-owned temporary files. The app clears those copies at session boundaries. Copies you choose to save or share remain wherever you placed them; NextFlight cannot recall them. Optional lesson reminders use the most recently downloaded schedule and are cleared on sign-out.
Security and service records
NextFlight uses protected account credentials and access restrictions. Security controls retain hashed email, account and IP identifiers, the type of account action, time windows and attempt counts to limit abuse. These are used to protect the service, not to measure advertising. Hashing does not make these records anonymous. Hosting and mail providers may process technical information needed to operate and protect their services.
The app does not request device GPS location or contacts, and the current app includes no advertising or third-party analytics SDK. Lesson locations are entered by users. This website uses no analytics script or advertising cookies.
Information is processed in the configured service regions of our providers. The SMTP2GO account is hosted in the USA. The Render API and database are deployed in Ohio, United States. These selections do not establish that all provider administration, security records, support access or recipient-mailbox processing stays in the United States. A worldwide App Store listing does not mean records are stored in every country.
Retention and deletion
You can export or delete your account from Today → Your account → Your data & account. When age confirmation or guardian approval is pending, use Your data & account on the account-access screen. Deletion requires your current password and the confirmation DELETE. It revokes your sessions and account codes.
Deleting a student account removes that student’s profile, progress, messages, briefings and lessons from the active service, including the instructor’s view. Deleting an instructor account removes its instructor account identity and private conversations and briefing acknowledgments, cancels every lesson still marked scheduled and preserves shared student records and briefings under Former instructor. User-entered text may still identify people within retained shared records. Eligible remaining students can read and export their records. An instructor may also hold training or logbook records outside NextFlight; deleting an app account does not delete those independently held records.
Age declarations remain with the account. The current guardian request or decision is retained with the student account, including after an approval, decline or code expiry. A new permitted request replaces the prior guardian request or decision details. Deleting the student account removes this record from the active service. If an instructor is also the student’s guardian, deleting their instructor account does not remove their separate guardian record while that student account remains.
Guardian codes expire after 48 hours and work once. Code expiry does not automatically delete the account or decision record. Security attempt records older than 24 hours are removed when a later counted request is processed; this is not a guaranteed 24-hour erasure deadline.
Local subscription bindings are removed with the instructor account. Notification identifiers used for duplicate protection are pruned on later notification processing once more than 90 days old; these identifiers have no account link.
Account deletion does not immediately rewrite existing backups. Backup recovery must reconcile later deletions and revoked access before service resumes. Backup retention and deletion: The configured backup worker attempts a consistent SQLite snapshot at startup and daily, verifies each completed snapshot, and keeps up to seven successful copies on the app's persistent disk. It removes older copies only after a replacement verifies. Rotation is by copy count, not a guaranteed seven-day deletion deadline; failures can leave older copies in place. Existing snapshots are not immediately rewritten after account deletion. No automated offsite copy is configured, so these local snapshots do not protect against loss of the host or its disk. Separate provider-held copies follow the provider's retention practices.
Provider/security log retention: Application HTTP request access logs are disabled. Hosting, DNS and mail providers may retain operational, security and account records under their own policies. No single maximum deletion deadline has been verified for all such records; dashboard history windows are not a promise of complete erasure.
Delivered account email retention: SMTP2GO Free exposes five days of delivery activity. SMTP2GO's published policy states that email headers are retained for 35 days and one message per 1,000 sent may be retained for abuse review for 35 days. Some suppression records, including spam complaints and unsubscribes, can remain indefinitely. Other necessary account, support, legal and security records have separate retention. Copies delivered to a recipient's inbox follow that mailbox's settings. Expiry of a NextFlight code does not erase an already delivered email.
Copies already delivered to your inbox or shared by you remain subject to those destinations. Contact us if you cannot access the app to request help with your information.
Student ages
NextFlight accounts are for people age 13 or older; instructor accounts require age 18 or older. We ask for a self-reported age group, not a date of birth. Students ages 13–17 must join through an instructor invitation and provide a separate parent or legal guardian email. Training access stays paused until that person uses a private email code, gives their name and confirms that they are age 18 or older and the student’s parent or legal guardian before approving. The code confirms access to that inbox; it does not independently verify age, identity or family relationship. An instructor invitation alone is not guardian approval. A guardian can decline, and a pending or declined student cannot activate access by signing in again or resetting a password. Existing accounts must also confirm their age group, and existing records remain stored while access is paused. An instructor may already have supplied a student’s email when inviting them. Contact support about an unfamiliar request, correcting an age group, turning 18 or withdrawing approval.
Questions and changes
Email support@nextflightapp.com to ask about accessing, correcting or deleting your information. Parents and legal guardians may also ask about an approval request, an age-group correction or withdrawal of approval. We may need to verify that a request concerns the relevant account or guardian before acting. Do not email passwords, one-time codes or full private training exports.
When this policy changes, the updated version and effective date will appear here.