VTSD.app

Data Handling / Privacy Policy

This policy describes the register and data processing practices for the VTSD.app website, cloud dashboard, APIs, application telemetry, and diagnostic uploads.

Effective and last updated: June 22, 2026

VTSD is a simulator tool and is not certified for real-world aviation, navigation, safety, emergency, or operational use.

1

Data Controller

VTSD.app / Virtual Tactical Situation Display project maintainer.

2

Contact for privacy and register matters

Privacy questions and data requests should be sent through the public GitHub repository or to email: [email protected].

Do not include passwords, access tokens, share codes, or private credentials in public GitHub issues.

3

Register

User, access, cloud collection, telemetry, and diagnostic register for VTSD.app, the VTSD cloud dashboard, public APIs, and optional VTSD desktop application telemetry.

4

Purpose of processing and legal basis

The purpose of the register is to provide authentication, device login, dashboard access, cloud collection storage, collection sharing, application telemetry, support diagnostics, abuse prevention, and service security.

Processing is based on providing the requested service, maintaining service security, fulfilling legitimate maintenance and support needs, and, where applicable, user consent for optional actions such as debug-report submission.

5

Data contents of the register

The following categories of data may be stored depending on which VTSD.app features you use.

Identifiers and account data

  • VATSIM CID and profile data returned by VATSIM sign-in.
  • Name and email address when provided through VATSIM authentication.
  • Internal user ID, account status, organization memberships, roles, and access records.

Authentication and access data

  • Strictly necessary session cookie for signed-in users.
  • Hashed session tokens and hashed device-login tokens.
  • Session type, creation time, expiry time, and related audit records.
  • Hashed share codes and collection access grants.

Cloud collection data

  • Collection names, descriptions, settings, and ownership data.
  • Pages, markdown content, map features, notes, and related metadata.
  • Organization, user, and share-code permissions related to collections.

Telemetry and diagnostics

  • Anonymous installation ID, app version, platform, event name, and event timestamp.
  • Optional account or collection association where relevant.
  • Limited diagnostic settings such as OS version, simulator data source, enabled features, display modes, range option count, and kneepad page count.
  • Debug report files and metadata if you choose to upload a report.

Local browser data

  • Light or dark theme preference stored locally in your browser.
6

Data that must not be submitted

VTSD is intended only for flight simulation. Do not submit real-world operational, safety-critical, classified, or otherwise sensitive information.

Do not submit through telemetry, collections, debug reports, or support channels

  • Passwords, access tokens, or private credentials.
  • Share codes or session tokens.
  • Real-world mission briefs, safety-critical information, classified information, or private operational notes.
7

Regular sources of data

Account data is received from VATSIM when you choose VATSIM sign-in.

Cloud collection and sharing data is provided by users through the dashboard, APIs, or the VTSD desktop application.

Telemetry and diagnostic data is sent by the VTSD desktop application or submitted by the user.

8

Recipients and service providers

Data is processed by hosting, database, and private object-storage providers as needed to operate VTSD.app.

Current infrastructure includes Vercel services and Neon. VATSIM processes authentication and provides your profile when you choose VATSIM sign-in.

9

Disclosure and transfers

Data may be disclosed when required by law, to protect the service or its users, or at your direction.

Examples of user-directed disclosure include publishing a collection, granting another user access, or using a share code.

Service providers may process data in the locations required by their infrastructure and contractual terms.

10

Data retention period

Data is retained for as long as reasonably needed to operate, secure, maintain, and improve the service.

Session and device-login records have expiry times. Share codes can expire or be disabled.

Submitted debug reports can be deleted by an administrator.

Some data may be retained where necessary for security, legal compliance, backups, or audit integrity.

11

Data protection principles

Session tokens, device-login tokens, and share codes are stored as hashes where they are used for verification.

Private debug-report files are stored with restricted access.

Cloud content is protected by account, organization, collection, and share-code permissions.

No online service can guarantee absolute security. Keep credentials and share codes private.

12

Right of access

You may request information about personal data concerning you that is stored by VTSD.app. The request must include enough information to identify the relevant account or installation.

13

Rectification, deletion, and restriction

You may request correction or deletion of your personal data.

Processing may be restricted where applicable and technically feasible.

Deletion may be limited where retention is necessary for security, legal compliance, backups, or audit integrity.

14

Right to data portability

Where technically feasible and applicable, you may request data you provided in a structured, commonly used, machine-readable format.

15

Right to withdraw consent

If processing is based on consent, you may withdraw that consent. Withdrawal does not affect processing that took place before the withdrawal.

16

Right to object

Where processing is based on legitimate interests, you may object to processing in accordance with applicable data protection law.

17

Automated decision-making and profiling

VTSD.app does not use personal data for automated decision-making or profiling.

18

Complaints

You may lodge a complaint with a competent supervisory authority if you believe applicable data protection rules have not been followed.

19

Changes to this policy

This policy may be updated when VTSD.app, its infrastructure, or its data practices change. The latest version is published on this page.

Contact and data requests

For privacy questions or requests concerning your data, contact the project maintainer through the public GitHub repository or to email: [email protected]. Include enough information to identify the relevant account or installation, but do not post private credentials or access tokens in a public issue.