Our approach
- No developer-hosted user account is required in the current release.
- No third-party behavioral advertising or cross-app tracking.
- Public web pages are delivered using encrypted HTTPS connections.
- Website forms are avoided; support is handled by direct email so users can see what they send.
- Temporary Crew Rooms use unguessable invitation links, limited retention, rate limits, and encrypted HTTPS connections.
- Private schedule links are encrypted on the device; the hosting service stores ciphertext and never receives the link fragment that contains the decryption key.
- Access to operational systems and support information is limited to people and providers who need it for their role.
Private schedule-link security
A complete schedule link acts as the viewing credential. Only send it to intended recipients, because anyone it is forwarded to can open the selected schedule until the link expires or is ended. Flight Duty Pro cannot recover a lost decryption key or identify who opened a link.
Schedule contents use authenticated AES-GCM encryption before upload. Updating a link replaces its encrypted payload without changing the private viewing URL. The creating device stores the management token and encryption key in its Keychain.
Crew Room security
A Crew Room invitation link acts as the invitation credential. Anyone who receives or is forwarded that link can join until the creator locks invitations or replaces the link. Creators can remove participants, close a room, and replace a link that may have been shared beyond the intended crew.
Crew Room traffic is encrypted in transit, but the first release is not end-to-end encrypted. Do not use Crew Rooms for credentials, identification documents, hotel room numbers, medical information, emergency communication, or official operational decisions.
Optional website push subscriptions and app device tokens act only as delivery addresses for generic alerts; message text is not included in those alerts. A subscription is tied to a temporary room and is removed with that room. Participants can mute another participant or report a concern, while creators can remove participants or end access.
Protecting your information
Use a strong device passcode, enable available Apple account protections, install current iOS updates, and review the destination before exporting or sharing records. Never use Flight Duty Pro as the sole source for an operational or regulatory decision.
Report a vulnerability
Email support@onlinedevusa.com with the subject “Security report.” Include a clear description, affected version, reproduction steps, and impact. Do not access other users’ information, disrupt the service, use destructive testing, or publicly disclose an unremediated issue.
We will acknowledge good-faith reports and work to assess and address verified issues. This page is not a bug-bounty offer or authorization to access systems or data.
Security incident questions
If we determine that a security incident affects personal information under our control, we will investigate, contain, and provide notices required by applicable law.