Legal
Privacy
What PAVE collects, why, who it goes to, and how you get it deleted. Plain words, because a policy nobody reads is not a policy.
DRAFT — not yet published · last written 2026-09-29
Who this is. PAVE is operated by Alles Company, of Placerville, California.
The short version. PAVE is a flight-training record. A CFI or school enters what training law requires — a student's identity, credentials, hours, grades, endorsements. We store it with Supabase, run the service on Render, serve this site through Cloudflare, and send email through Resend. We never sell your data. The in-app AI helpers strip full names, emails, phone numbers, street addresses and dollar amounts before anything leaves this service — but your first name and, for the teacher, your instructor's own notes about you are sent; see The in-app AI helpers for exactly what each helper sees. Error reports go to Sentry with no personal data in them, by design. PAVE's beta is free — no card is charged for anything until PAVE declares the beta over. You can ask for your data to be deleted at any time — write to [email protected] — and we tell you exactly what stays, why, and until when, if anything has to.
- 1What PAVE collects
- 2Why we collect it
- 3Who it goes to
- 4We do not sell your data
- 5The in-app AI helpers
- 6Outside AI assistants — the PAVE connector
- 7Error reports
- 8Retention and deletion
- 9Students under 18
- 10Text messages
- 11Your choices
- 12Changes to this policy
- 13Contact
1. What PAVE collects
PAVE is a working training record, not a social app — almost everything it holds is entered by an instructor or a school because a certificate, a checkride sheet or a federal recordkeeping rule requires it. Records live in one Postgres database, run for us by Supabase.
Account and sign-in
- Your email address, used to sign you in (a magic link or a one-time code) and to reach you about your account.
- Instructors and school admins are required to sign in with an authenticator app; other users may turn two-factor sign-in on if they choose. Either way, the authenticator secret needed to check your code is held by Supabase, our sign-in provider, not by PAVE itself. We do not see the code itself.
- Your phone number, your mailing address and your preferred name — ordinary record fields your school, your CFI, or you yourself can enter, whether or not text alerts are turned on. Your phone number is additionally used to send text alerts if you opt in — see Text messages below.
The training record
Entered by your CFI or school as part of admitting and training a student. Where a field is entered depends on who is responsible for its accuracy under 14 CFR — for example, your CFI enters your legal name, date of birth and IACRA FTN because those are the words that end up on a certificate; you or your instructor may enter your own phone number and preferred name.
- Identity — legal first, middle and last name, preferred name, date of birth, IACRA FTN.
- Contact — email, phone, mailing address, emergency contact name and phone.
- Credentials — medical certificate class and dates, pilot certificates and ratings, flight review date, citizenship/TSA verification status.
- Training progress — lesson grades, hours flown, endorsements issued (in the FAA's own words, verbatim), checkride readiness.
- Logbook data you import or export, and — if you use the paper-logbook reader or send a photo of a logbook page — the image and the text PAVE reads out of it.
- Document images — medical certificates, pilot certificates, knowledge-test reports, photo ID, TSA papers, profile photos and aircraft papers, where your school requires one on file. These are encrypted on your own device before they are uploaded, so PAVE's storage holds only the encrypted file.
- Identity or citizenship documents, where your school requires one on file (49 CFR 1552.15).
Money
PAVE keeps a record of charges, payments and balances between a student and a school. A student does not pay PAVE, and PAVE is never in the flow of a student's funds. A student pays their school directly, by whatever method the school accepts — cash, check, Venmo, Zelle, card or other — and PAVE records that payment; where a school publishes a Venmo handle or a Zelle address for students to pay to, PAVE stores and shows that address. PAVE never sees or stores a card number, CVC, expiry date or cardholder name. Stripe is used only when PAVE bills a school, a CFI or an admin for PAVE's own subscription — never a student — and that billing runs through Stripe's own hosted checkout and billing portal, where Stripe, not PAVE, holds the card. During the beta, PAVE does not charge any card for anything. That billing path exists in the code but stays switched off until PAVE declares the beta over — a decision, not a date — so no beta tester's card is charged regardless of what a school signs up for while the beta runs.
Device and technical data
Ordinary web request data (IP address, browser type, the page requested) as any web server logs it, kept briefly for security and abuse prevention. PAVE's own error-reporting tool (Sentry) is built specifically to never receive your name, email, phone, address, certificate number, logbook text, notes or money figures — see Error reports.
What we do not collect
- No advertising identifiers, no ad tracking, no analytics pixels.
- No card numbers or bank details on our own servers.
- No calendar data, unless you personally choose to connect one — see Who it goes to.
2. Why we collect it
To run the training record your CFI or school is required to keep, to let the right people see the right parts of it (a student sees their own record; a parent invited onto it sees the student's training progress, upcoming flights, and any file the student chooses to share with them; nobody sees another student's file), to bill correctly when a school has billing on, to keep the record secure, and to satisfy the federal recordkeeping duties named in Retention and deletion below. We do not collect anything "because it might be useful later" — PAVE's own engineering rule is that an undeclared field is refused, not guessed at.
3. Who it goes to
Only the processors below, each doing one job, and never a data broker or an advertiser. Every one of them publishes its own data-processing terms (a "DPA"), and most take effect the moment PAVE agrees to that vendor's terms of service — no separate signature needed. Where a vendor instead requires PAVE to actively request or countersign its DPA, that is called out below rather than assumed.
| Who | What for | Its DPA |
|---|---|---|
| Supabase | The database that stores your record, and sign-in (magic links, codes, two-factor). | supabase.com/legal/dpa — self-serve, takes effect on accepting Supabase's terms, no separate signature. |
| Render | Runs PAVE's backend service — every request to PAVE passes through it in transit. | render.com/dpa — self-serve, incorporated into Render's Terms of Service. |
| Cloudflare | Serves this website and PAVE's app, holds backup storage and your encrypted document files (R2), and — if PAVE's own mailbox is switched on — routes PAVE's hello@ and delete@ mail. | cloudflare.com/cloudflare-customer-dpa — self-serve, incorporated by reference into Cloudflare's Self-Serve Subscription Agreement. |
| Resend | Sends PAVE's email — sign-in links, receipts, notices. | resend.com/legal/dpa — self-serve, takes effect on accepting Resend's terms. |
| Sentry | Receives error reports only. No personal data reaches it, by design — see below. | sentry.io/legal/dpa — not automatic — Sentry requires a separate signature for its DPA, and PAVE has not signed it, because no personal data is sent to Sentry (see below). |
| Anthropic | Powers Tracker, the in-app helper that can look up or do things in your own record and, when a CFI uses it, a student's record — including Tracker's own web search and web fetch, used to check government sites (faa.gov, ecfr.gov, tsa.gov and similar) plus five named flight-instructor publications (NAFI, SAFE, AOPA's Air Safety Institute, Boldmethod, CFI Notebook) when PAVE's own regulation library does not settle a question. Also powers a separate internal assistant on PAVE's own operator console, used only by PAVE's operator to administer the app; that assistant can look up a person's account details (name, email, school, access state) and PAVE's own mail history with that person, unscrubbed, through tools built for the operator's own use — it does not reach a student's or CFI's training record itself. Full names, emails, phones and addresses are stripped before anything reaches Anthropic from Tracker or the connector; money FIELDS (balances, rates, charges) are stripped the same way, but a dollar figure typed into free text is not — see below for what is not. | anthropic.com/legal/data-processing-addendum — self-serve, incorporated into Anthropic's Commercial Terms of Service for API customers. |
| xAI | Powers the teacher, the in-app helper that answers flying and regulation questions (with a narrower web search covering five sites: faa.gov, tsa.gov, faasafety.gov, and two flight-instructor publications, Boldmethod and CFI Notebook), and the logbook reader that reads a photographed logbook page — a photo is sent unredacted, but PAVE keeps nothing of it afterward, only a fingerprint (sha256) that it was read. Will also power the document reader, once it ships, for any paper you drop into PAVE's Files — not live yet. | x.ai/legal/data-processing-addendum — self-serve, incorporated by reference into xAI's Enterprise Terms of Service. |
| Twilio | Not live. No text is sent and no phone number is sent to Twilio today. Texting is being tested by the PAVE team only — see Text messages. | twilio.com/.../data-protection-addendum — self-serve, incorporated into Twilio's customer agreement. |
| A push-notification provider | Not live. PAVE has not yet built or turned on phone/browser push notifications for anybody. When that ships, this page will name the specific provider, what it can see (typically just a device token, never your record), and its DPA, before it reaches any beta tester's device. | — |
| Only if you personally connect your Google Calendar. PAVE then reads the calendars you choose and writes your own bookings onto your own primary calendar, the same way a scheduling app would. Nothing is sent to Google unless you connect it, and disconnecting stops it. | Governed by your own Google account terms, since you are the one connecting it — not a PAVE-signed processor agreement. | |
| Stripe | Only when PAVE bills a school, a CFI or an admin for PAVE's own subscription — never a student, and not switched on for anybody during the beta (see Money). Handles card payment on its own hosted pages; PAVE never touches the card number. | stripe.com/legal/dpa — self-serve, auto-applied on signing up for a Stripe account. |
Beyond this list: your own CFI, your own school's staff with a reason to see your record, and — if a subpoena, court order or similar legal process requires it — the party that lawfully compelled it. We do not otherwise share your record with a third party. And see Outside AI assistants below for the one more way a person's own outside AI tool can read part of a record — always at that person's own request, never PAVE's.
4. We do not sell your data
PAVE does not sell, rent or trade your personal information to anyone, for any reason. It never has, and this policy will say so plainly if that ever changed rather than staying silent about it.
5. The in-app AI helpers
PAVE has two in-app assistants: Tracker (built on Anthropic's Claude), which can read a training record and do things in it that a person asks for — when a CFI uses Tracker, that can include a student's own record, not only the CFI's own — and the teacher (built on xAI's Grok), which answers flying and regulation questions and can read an instructor's private notes about a student as part of doing that. Both scrub full legal names, emails, phone numbers and street addresses typed as text from what they send before it reaches the model, and both scrub money FIELDS (a record's stored balance, rate or charge). What that scrub does not remove: your first name is sent to either helper; a dollar figure you type into a question or a note is sent as-is, not scrubbed; and the teacher is sent your instructor's private notes about you, as free text. If you use the paper-logbook reader, the photograph of your logbook page is sent to xAI unredacted — name, dates and hours on the page included, with no scrub applied to the image itself. Neither assistant writes into your record on its own; a person's own tap is what saves a change.
6. Outside AI assistants — the PAVE connector
PAVE has a connector that lets a person's own outside AI assistant (for example, Claude) read part of their PAVE record on their behalf, if that person chooses to connect it.
- Read-only. An outside assistant connected this way cannot sign, endorse, grade, move money, or write anything into a record. It can only read and hand back a card or a link for the person to act on themselves — the person's own tap is what writes, exactly as in the in-app helpers above.
- Only what that person can already see. The connector never widens anyone's access — a CFI connecting it sees what a CFI can already see in the app; a student connecting it sees only their own record.
- Only after that person signs in and taps Allow. Nothing is shared with an outside assistant until the person themselves authorizes the connection through PAVE's own sign-in, and they can revoke it at any time.
- The same personal-data scrub runs first. Full names, emails, phones and addresses are stripped before anything reaches the outside assistant, the same as for Tracker and the teacher. Money FIELDS in a record are stripped the same way; a dollar figure typed into free text is not.
- PAVE does not pay for, and cannot see inside, the outside assistant. Once a card or a fact reaches that person's own AI tool, what it does with the conversation is governed by that tool's own maker — Anthropic, or whichever company built it — not by PAVE. Read that provider's own privacy policy for how it handles what you ask it.
- Not open to everyone yet. During the beta the connector is limited to PAVE's own operator for testing; opening it to beta users or the public is a separate decision PAVE has not yet made.
7. Error reports
When something breaks, a report goes to Sentry so it can be fixed. That report is built to carry errors only, with no personal data in it, by design — not as a policy we hope holds, but as code that strips or drops student names, emails, phones, addresses, certificate numbers, logbook text, notes, money figures and login tokens before an event is ever sent, and drops anything it cannot confidently clean rather than guess. Full request logging, session replay and browsing history are switched off entirely.
8. Retention and deletion
You can ask for your data to be deleted at any time by writing to [email protected]. Here is what actually happens:
- We do not issue a "your data is deleted" receipt while anything is still outstanding. You get a receipt once it is genuinely done, or a plain statement of what is being held back and why.
- Federal recordkeeping law can require us to keep specific records even after you ask. By regulation, a flight instructor keeps certain training records for at least 3 years (14 CFR 61.189(c)), and a citizenship-verification record is kept for at least 5 years after it stops being used (49 CFR 1552.15(e)(1)). Where a rule like this applies, we tell you exactly which record is held, the citation, and when the hold ends — we never simply say "gone" while something is still on file.
- Deletion requests are carried out by hand today, not by an automatic system. A person on PAVE's side reads the request and acts on it record by record — PAVE's own code does not yet have an automatic deletion executor for a training record. PAVE's own code (
deletion-sla.js) also refuses to publish a promise on timing until two specific numbers are set and checked against the actual backup rotation — it will not default or guess. Until those numbers are set, this page makes no promise on timing. - Key destruction covers your uploaded document files, not your training-record history. Documents you or your school uploaded — medical certificates, photo ID, and similar — are encrypted under a key tied to you before they are stored, and destroying that key makes those files unreadable everywhere, including in backups, from the moment your request is processed. Your training-record history — grades, hours, endorsements, and the append-only audit trail of what changed and when — is stored as ordinary readable data, not encrypted per person, so it stays on file and readable unless a specific row is separately removed by hand. The audit trail is kept append-only by design, so a training record can be trusted; it is not deleted outright.
- Asking twice does not restart the process or produce a second, different answer — the second request is treated the same as the first.
9. Students under 18
Flight training starts well before adulthood — solo flight is permitted from age 16 (14 CFR 61.83(a)), and a private pilot certificate from age 17 (14 CFR 61.103(a)) — so PAVE's records do include minors. A minor's record is created and entered by their CFI, not by the student signing themself up, and a parent can be invited onto that same record to see the student's training progress, upcoming flights, and any file the student chooses to share with them.
Nobody under 13 has their own PAVE sign-in. A student under 18 needs a parent or guardian to accept this Privacy notice and the Terms of use before that student signs in. The student's CFI never accepts on the student's behalf, because the CFI is not the student's parent or guardian.
10. Text messages
If your school turns on text alerts and you opt in, PAVE can text you about safety alerts, an aircraft that has not returned, or a schedule change, and to send a one-time verification code. Texting is not switched on for any school yet — this describes the program as designed, ahead of that switch. Full program terms are on the Terms of use page.
Mobile numbers and SMS opt-in consent are never shared with third parties or affiliates for marketing or promotional purposes. Your opt-in consent is used only to send the alerts you chose.
11. Your choices
- See or correct your record through the app itself, or by asking your CFI or school administrator — most of your training record is theirs to enter under 14 CFR, for the same reason a DPE trusts it.
- Stop text alerts any time by replying STOP, or from the Texts panel in the app.
- Disconnect Google Calendar any time from the app; PAVE stops reading or writing to it immediately.
- Ask for deletion at [email protected] — see Retention and deletion.
12. Changes to this policy
If this policy changes in a way that matters, we will say so on this page with a new date, and for a material change we will tell current users directly rather than only updating the page quietly.
13. Contact
Questions about this policy: [email protected]. Deletion requests: [email protected]. Nothing else is published as a PAVE contact address today (checked against PUBLISHED-ADDRESSES).
This page is a plain-language description of PAVE's own data handling and is not itself a substitute for legal advice. The beta agreement governs beta testers; see also Terms of use.