Aviatus ("we", "us", or "our") provides an aviation inspection collaboration service. This policy explains the personal information we process when you visit our website, request access, create or use an account, participate in a project, connect an external service, or contact us.
1. Scope
This policy applies to Aviatus websites, web and mobile applications, APIs, support, and related communications. External services such as Box and Smartsheet have their own privacy policies and are responsible for their own processing.
2. Information we collect
- Account and access information: name, email address, language and theme preferences, organization, role, invitations, authentication records, and access-request details.
- Project and inspection content: project and asset details, OIL items, comments, assignments, evidence, pictorial findings, activity, chat, Records, and file metadata.
- Connected-service information: OAuth tokens, connected-account identifiers, connection status, and metadata needed to browse Box or import from Smartsheet at your direction.
- Notification and device information: notification preferences, push tokens, delivery status, and the device platform used for notifications.
- Technical and usage information: IP address, browser and device details, request and security logs, errors, and privacy-safe workflow events used to operate and improve the Service.
- Support and communications: messages and information you send when requesting access, asking for support, or contacting us.
- Avi Light interactions: prompts, authorized project context selected for a request, tool results, and generated responses when you choose to use the AI helper.
3. How we use information
We use information to:
- provide, authenticate, secure, and support the Service;
- apply organization and project permissions;
- enable collaboration, evidence handling, Records access, imports, archives, and deletion workflows;
- send invitations, transactional email, push notifications, and preference-controlled updates;
- maintain Box and Smartsheet connections requested by users;
- respond to support, access, security, and privacy requests;
- detect abuse, troubleshoot failures, monitor reliability, and protect users; and
- understand privacy-safe product usage and improve Aviatus.
5. Box and Smartsheet connections
Box and Smartsheet connections belong to the individual user who authorizes them. Aviatus stores the tokens needed to maintain the connection and uses them only for the requested integration.
- Box: each viewer uses their own Box account and existing Box permissions. Files remain in Box when browsed or linked through normal use, and linking a Box file to an OIL item does not copy its bytes.
- Smartsheet: Aviatus reads a selected sheet for a one-shot import. Imported OIL history becomes Aviatus project data; there is no ongoing sync or stored sheet link.
Disconnecting an account stops future access through that connection. It does not delete data already imported into Aviatus or content retained by the external provider.
6. Avi Light and AI providers
Avi Light is optional. When you use it, Aviatus sends your prompt and the authorized project context needed to answer the request to the configured AI provider. Normal OIL, Records, and collaboration workflows remain available without using Avi Light.
Do not include information in an AI prompt unless you are authorized to use it for that project. AI output may be inaccurate and should be reviewed against the underlying project record.
7. Retention, archives, and deletion
We retain account, organization, project, and operational information while needed to provide the Service, preserve authorized audit history, meet legal obligations, resolve disputes, and protect the Service.
Organization admins can start staged organization deletion. Aviatus makes the organization read-only, closes its projects, and prepares one Final Project Archive per project. Every archive must be downloaded once before final confirmation removes the organization and its project data. Individual user accounts remain separate and are not deleted with the organization.
To delete your personal Aviatus account (sign-in credentials and profile), follow the instructions on the Delete account page. Account deletion is separate from organization deletion.
Native evidence and Records may be included as files in a Final Project Archive. Box content remains in Box and appears in the archive as metadata and links that require the recipient's own Box access.
Final Project Archives stored by Aviatus are removed with confirmed organization deletion. Download and retain any archive your organization needs before confirming.
8. Security
We use reasonable technical and organizational safeguards designed to protect information, including encrypted transport, authenticated access, role-based permissions, tenant scoping, and restricted storage paths. No system can guarantee absolute security.
You are responsible for protecting your credentials, choosing appropriate roles, maintaining access to connected services, and reporting suspected unauthorized use.
9. International processing
Aviatus and its service providers may process information in countries other than where you live or work. Where required, we use appropriate safeguards for international transfers.
10. Your choices and rights
You can update profile details, language, theme, notification preferences, and connected services from the product. Access and correction of project data may depend on your organization role and the audit requirements of the project.
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information. Contact us to make a request. We may need to verify your identity and may retain information where required by law or necessary for security and authorized audit history.
Account deletion requests are described on the Delete account page.
11. Changes to this policy
We may update this policy as Aviatus, our providers, or applicable requirements change. We will update the date above and provide additional notice when required.
12. Contact
For privacy questions or requests, contact privacy@aviatus.app.