Privacy Policy
Version 1.2 (Effective August 7, 2026) · Last Updated: August 7, 2026
Introduction
This Privacy Policy describes how Torque Aviation LLC ("Torque," "we," "us," or "our") collects, uses, and protects information obtained through the Torque platform (the "Service"). Torque is a flight risk assessment and operational management system built for public safety aviation agencies.
IMPORTANT: By accessing or using the Service, you consent to the collection, use, and processing of your information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
Roles: Your Agency and Torque
Your agency is the controller of operational and personal data submitted to the Service in connection with agency operations. Torque processes such data solely on the agency's behalf and under its direction. Requests from individuals to access, correct, or delete personal data contained in agency operational records should be directed to the agency; Torque will provide reasonable assistance to the agency in responding to such requests. Torque will not delete or alter agency operational records at the request of an individual user absent direction from the agency or a legal obligation to do so.
Your personal logbook within the Service (the record of your individual flight time and experience, including historical logbook records you import and logbook entries derived from flight activity conducted through the Service) is your personal record, serving the role of a pilot's individual logbook under applicable aviation regulations. Imported historical records may be corrected or deleted by you at any time; entries derived from flight activity conducted through the Service reflect the agency's underlying operational records, and corrections to those entries are made through the agency's operational record processes. You may export your personal logbook in a portable, machine-readable format; where self-service export is not available within the Service (including after your access to the Service has ended), Torque will provide the export upon request.
Categories of Personal Data We Collect
1. Account Information
When you create a Torque account, we collect:
- Email address: Used as your primary account identifier and for authentication.
- First and last name: Associated with your user profile and crew records.
- Password: Used to sign in through our authentication provider (Supabase Auth) and stored only in hashed form. We never store your plaintext password.
- Phone number (optional): Normalized to E.164 format, used solely for delivering operational SMS notifications if you opt in.
- SMS opt-in preference: Your consent choice for receiving SMS notifications.
- Invitation and consent records: Account creation is by invitation only; we record the invitation and the date, time, and version of your acceptance of the Terms and Conditions and this Privacy Policy.
Purpose: We process this information to authenticate your identity, manage your account, and deliver operational notifications related to your duties. Your email address and password are required to sign in. Your phone number is collected only if you choose to receive SMS notifications.
2. Crew Member and Professional Information
When your agency profile is set up, the following professional data may be collected:
- Role and qualifications: Pilot, TFO, supervisor, mechanic, or other aviation roles.
- Date of birth: Used solely for FAA medical certificate validity calculations.
- Medical certificate information: Class, issuance date, and computed expiration dates as required by FAA regulations.
- Flight review date: Used for FAR 61.56 currency compliance tracking.
- Body weight: Used exclusively for aircraft weight and balance calculations.
- Flight hours and experience: Total flight hours, recent flight activity, recency data, and crew cohesion metrics for risk assessment and currency tracking.
- Pilot ratings and endorsements: Certificate types, aircraft category/class ratings, and endorsements held.
- Training records: Checkride dates, training completion dates, qualification status, and ground training records.
- Personal logbook records: Logbook entries generated from your flight activity in the Service, and historical logbook records you choose to import, including prior flight hours.
Purpose: This professional data is processed to perform flight risk assessments, validate crew currency and qualifications per FAA regulations, calculate weight and balance, generate training reports, and ensure operational safety compliance. This information is required for the core safety functions of the Service.
3. Aviation Operational Data
During use of the Service, we collect operational data including:
- Flight Risk Assessment Tool (FRAT) data: Departure/destination airports, destination locations for off-airport operations (coordinates or what3words addresses), weather conditions and accepted weather estimates, risk scoring factors, lighting conditions, mission type, density altitude, and other hazard assessments.
- IMSAFE self-assessments: Crew member self-reported fitness-for-duty responses covering illness, medication, stress, alcohol, fatigue, and external factors. These are used solely for flight risk scoring. IMSAFE requests are delivered as secure, tokenized links by email or SMS, issued only to provisioned account holders who have already accepted our Terms; a link permits completion of only that assessment, requires the recipient to be signed in as the account it was issued to, and expires automatically after a limited time. Within your agency, item-level responses are visible to the pilot conducting the assessment, and any category that adds risk points or triggers a No-Go appears by crew member name, with a standardized reason, in the resulting FRAT risk breakdown for personnel who can view that FRAT; categories reported as no-risk are not itemized there. The Service is not a medical record system; Torque is not a HIPAA covered entity or business associate, and IMSAFE and medical certificate information is processed solely for aviation currency and risk-assessment purposes.
- Flight logs: Departure and destination airports, flight times, hobbs/tach readings, and mission type.
- Crew flight logs: Individual crew debrief data including flight time breakdowns, takeoffs, landings, instrument time, and NVG operations.
- Fuel and oil records: Fuel and oil quantities added, fuel cost, and purchase location.
- Shift and duty period records: Duty period start/end times, assigned crew members, and linked operational records.
- Call for Service (CFS) records: Incident type, case numbers, location descriptions, GPS coordinates and what3words addresses (when manually entered by the user), disposition, outcome data, and video chain-of-custody references, including the name of the custodian officer.
- Aircraft data: Tail number, make, model, year, serial number, performance specifications, weight and balance configuration, hobbs/tach readings, and maintenance status.
- Maintenance records: Scheduled and unscheduled maintenance items, completion records, and squawk reports.
- Daily Observation Reports (DOR): Training evaluations, skill ratings, and FTO observations for trainee crew members.
- Safety and hazard reports: Voluntarily submitted safety concerns, hazard descriptions, and supervisor review outcomes.
- Weight and balance calculations: Computed takeoff/landing weights, center of gravity positions, and fuel burn trajectories.
Purpose: This operational data is the core of the Service's safety mission. It is processed to calculate flight risk scores, track crew currencies, manage aircraft maintenance, generate shift summary and activity reports, support training programs, and maintain regulatory compliance records. All operational data is scoped to your agency and is not accessible by other agencies.
4. Location and Airport Data
- Airport identifiers (ICAO codes): Entered by users to specify departure, destination, and alternate airports for flight planning and weather retrieval.
- GPS coordinates: Optionally entered by users in FRAT and Call for Service records to document scene and incident locations. We do not automatically collect device GPS data.
- what3words addresses: Three-word location identifiers optionally entered by users for scene locations; converted to and from coordinates via the what3words service.
Purpose: Airport identifiers are used to retrieve weather data (METAR/TAF) for risk assessments and to calculate distances. Scene coordinates are used for incident documentation and to derive modeled weather estimates for off-airport locations from publicly available NOAA datasets; those datasets are downloaded from public sources, and your coordinates are not transmitted to NOAA.
5. Technical and Security Data
When you use the Service, we automatically collect limited technical data:
- IP address: Recorded in audit logs for security purposes and in DOR sign-off records for non-repudiation.
- Client application version: Logged via the X-Client-Version request header to assist with troubleshooting and compatibility.
- Request timing: API response times are logged to monitor performance and identify issues.
Purpose: This technical data is processed to maintain the security and integrity of the Service, support audit requirements, troubleshoot issues, and ensure system reliability. We do not use this data for tracking, profiling, or advertising purposes.
6. Communication Records
When notifications are sent through the Service, we log:
- Notification delivery records: Event type, delivery channel (email, SMS, or in-app), delivery status, timestamp, and a brief message summary. We do not store the full content of SMS messages after delivery.
Purpose: Communication records are maintained to ensure reliable notification delivery, troubleshoot delivery failures, and prevent duplicate notifications. These logs are used solely for operational purposes.
7. Feedback and Support Data
If you submit feedback or a bug report through the in-app feedback tool, we collect:
- Your submission: The feedback type, category, and message you write.
- Diagnostic context: Your name, role, and agency; the page you were on and recent in-app navigation; recent API errors encountered by your session; and your browser's user agent string.
Purpose: Feedback data is used solely to investigate issues and improve the Service. Feedback submissions are retained as historical product records (see Data Retention below).
How We Use Your Information
We use the information we collect exclusively for the following purposes:
- Account Management: To create and maintain your account, authenticate your identity, and manage access permissions.
- Flight Safety Operations: To calculate flight risk scores, validate crew currencies, perform weight and balance calculations, and assess operational readiness.
- Regulatory Compliance: To track FAA currency requirements, medical certificate validity, flight review currency, and other regulatory obligations.
- Operational Notifications: To send you time-sensitive, operationally relevant notifications via email, in-app messaging, and/or SMS, such as IMSAFE assessment requests, flight log completion reminders, currency expiration warnings, and shift notifications.
- Reporting: To generate shift summary reports, activity reports, and training reports for your agency, including scheduled report delivery to recipients designated by your agency.
- Data Export: To generate complete export archives of your agency's data, on request and on a recurring schedule, for your agency's own records.
- Audit and Security: To maintain audit trails for accountability, support non-repudiation of official records, and detect security incidents.
- System Maintenance: To monitor performance, diagnose technical issues, and improve the reliability of the Service.
We do not use your information for marketing purposes. We do not use your information for advertising. We do not use your information to build user profiles for any purpose other than delivering the Service.
SMS and Phone Number Usage
If you provide your phone number and opt in to SMS notifications:
- Your phone number is used exclusively to deliver operational notifications related to your aviation duties through the Service.
- SMS messages may include IMSAFE assessment requests, flight log reminders, crew log reminders, currency expiration alerts, DOR sign-off requests, and other time-sensitive operational notifications.
- You may opt out of SMS notifications at any time by updating your notification preferences within the Service, or by replying STOP to any Torque SMS message.
- We do not use your phone number for marketing, promotional messages, or any purpose unrelated to the operational functions of the Service.
- We do not sell, rent, or share your phone number with third parties for their marketing or promotional purposes.
- Message frequency varies based on your operational activity. Message and data rates may apply.
How We Share Your Information
We do not sell your personal information. We do not rent your personal information. We do not share your personal information with third parties for their marketing or promotional purposes.
We share information only with the following categories of service providers, solely to operate the Service:
Service Providers (Data Processors)
| Provider |
Data Shared |
Purpose |
| Twilio |
Phone number, SMS message content |
Delivery of operational SMS notifications |
| SendGrid |
Email address, email message content |
Delivery of operational email notifications |
| Supabase |
All application data (encrypted in transit and at rest) |
Database hosting, authentication, and file storage (agency logos and agency data export archives) |
| Render.com |
Application runtime data |
Backend application hosting |
| Netlify |
Standard web request data (IP address, user agent) |
Web application hosting |
| AVWX |
Airport ICAO codes and coordinates |
Aviation weather data retrieval (METAR/TAF). No personal information is transmitted. |
| what3words |
what3words addresses and coordinates entered for scene locations |
Conversion between three-word addresses and GPS coordinates. No names or other personal identifiers are transmitted. |
These service providers process data solely on our behalf and are contractually prohibited from using your data for any purpose other than providing their services to us.
Modeled surface weather estimates for off-airport locations are derived from publicly available NOAA Real-Time Mesoscale Analysis datasets. These datasets are downloaded from public sources; no user or agency data is transmitted to NOAA.
Legal and Safety Disclosures
We may disclose your information if required to:
- Comply with applicable law, regulation, legal process, or enforceable governmental request.
- Enforce our terms of service or other agreements.
- Protect the safety, rights, or property of Torque, our users, or the public.
- Detect, prevent, or address fraud, security, or technical issues.
Data Security
We implement industry-standard security measures to protect your information:
- Encryption in transit: All data is transmitted over TLS/HTTPS.
- Data location: All agency operational data of record is stored in the United States. Certain data elements are transmitted transiently to third-party processors in the course of providing specific features, as described under How We Share Your Information.
- Security incident notification: Torque will notify your agency's designated administrator without undue delay, and in any event within seventy-two (72) hours, of confirming a security incident affecting the confidentiality or integrity of agency data, and will provide known details and remediation status as the investigation progresses.
- Scoped access links: Operational request links are issued only to provisioned agency users, are single-purpose, expire automatically, and function only when the recipient is signed in as the account the link was issued to. No operational function of the Service is accessible without a provisioned account.
- Password security: Authentication is handled by Supabase Auth; passwords are stored only in hashed form and are never stored in plaintext by Torque.
- JWT authentication: Sessions are managed via cryptographically signed JSON Web Tokens.
- Agency data isolation: All data is scoped to your agency through multi-tenant architecture. Your agency's data is not accessible by other agencies.
- Audit logging: Changes to critical records are tracked via database-level audit triggers, recording the user, action, and timestamp.
- Rate limiting: Sensitive endpoints are rate-limited to prevent abuse.
- Role-based access control: Access to data and features is governed by a granular permission system based on user roles.
- Support access: A limited number of authorized Torque personnel may access agency data for support, maintenance, and troubleshooting. Platform administrative actions are subject to the same audit logging.
While we take extensive measures to protect your data, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security.
Cookies and Local Storage
The Service stores your authentication session token in your browser's local storage (managed by our authentication provider, Supabase Auth) so you stay signed in between visits; signing out removes it. We do not use advertising or cross-site tracking cookies. Our hosting providers log standard web request data (such as IP address and user agent) to operate and secure the Service, as described in Technical and Security Data above.
Data Retention
- Active accounts: We retain your personal data for as long as your account is active and your agency maintains its subscription to the Service.
- Operational records: Flight logs, FRAT assessments, shift records, and other operational data are retained as long as the agency account is active, in accordance with aviation recordkeeping requirements.
- Soft-deleted records: Certain records (including but not limited to shifts, flight logs, FRAT assessments, CFS records, maintenance items, safety reports, and currency logs) support soft deletion, meaning they are marked as deleted but retained for audit and compliance purposes.
- Audit logs: Audit trail data is retained for the life of the agency account to support compliance and accountability requirements.
- Export archives: Agency data export archives are stored in a private storage bucket accessible only to your agency and Torque; the twelve most recent archives are retained and older archives are automatically deleted.
- Feedback submissions: Feedback and bug reports are retained as historical product records and are not automatically deleted when an account is removed. They can be deleted on request.
- Subscription termination: Following termination of an agency subscription, data is retained for up to 90 days to allow the agency to export its data, then deleted, except as required for legal or regulatory compliance, consistent with our Terms and Conditions.
- Account deletion: Upon request, we will delete or anonymize your account and profile data (contact details, credentials, preferences), subject to any legal or regulatory retention obligations. Personal data embedded in your agency's operational records (flight logs, FRAT assessments, DOR sign-offs, and similar) is part of the agency's compliance file and is governed by the agency as controller; deletion of those records requires the agency's direction.
Children's Privacy
The Service is designed for use by public safety aviation professionals and is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete such information promptly.
Your Rights
You can act on the following directly with Torque at any time:
- Opt-out of SMS: Update your notification preferences, or reply STOP to any Torque SMS message.
- Profile contact details: Update your name, phone number, and notification preferences within the Service.
- Account credentials: Change your password at any time through the Service.
- Personal logbook: Correct or delete historical logbook records you imported, and export your personal logbook in a portable format (see Roles above).
Requests to access, correct, or delete personal data contained in your agency's operational records (flight logs, FRAT assessments, shift records, training records, and similar) should be directed to your agency, which controls those records; Torque will provide the agency reasonable assistance in responding. Your agency can generate a complete export of its data from within the Service at any time, and you may request your personal data in a portable format where technically feasible.
To exercise any right that requires Torque's help, contact us using the information provided below.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a notice within the Service. The "Last Updated" date at the top of this policy indicates when the most recent revisions were made. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy. Where an agency has an active subscription agreement with Torque, material changes will take effect at the start of that agency's next renewal term rather than during the then-current term, except where a change is required to comply with law.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Torque Aviation LLC
924 Crestwood Drive
Modesto, CA 95350
Email: support@torqueaviation.com
This Privacy Policy is effective as of August 7, 2026.