Privacy Policy
WingRoster Staging Backups · Effective September 7, 2026
This policy describes the WingRoster staging service at staging.wingroster.com and its Google Drive backup connection. It is a testing environment, not a statement of production availability. Questions and privacy requests can be sent to fulcherphilip@gmail.com.
Information processed
WingRoster processes account and school membership details, and records entered by authorized users: contact and profile information, training and flight records, assessments, signing evidence, aircraft and scheduling records, qualifications and compliance information, documents, and audit history. The information present depends on what the school enters. Use synthetic records for staging tests.
Authentication cookies support sign-in. The optional remember-me setting stores a username or email on your device. Hosting and database services may process request information, including IP addresses, timestamps, and technical error information, to operate and secure the service.
Purpose and access
Information is used to provide school operations, display and export training records, manage authorized access, maintain audit evidence, troubleshoot the service, and create and recover school backups. School access depends on assigned permissions. Backup administrators can export the school records covered by the backup feature.
Google Drive information
Connecting Google Drive is optional. WingRoster requests the drive.file permission to create and manage files created by or explicitly used with this app. It creates a private backup folder and uploads encrypted school archives. It processes folder and file identifiers, ownership and permission information, file sizes, checksums, and encrypted file contents to verify delivery and manage tracked backups. It does not request access to unrelated Drive files, Gmail, or Google contacts.
Google authorization tokens are used on the server to carry out these operations, including scheduled backups while you are signed out. Refresh tokens are encrypted in the server database. Uploaded files are read back in encrypted form for verification. Optional cleanup can delete tracked backup files only when enabled and after a newer verified upload.
Google user data is used only for the backup features described here. It is not sold, used for advertising, or used to train general-purpose AI models. WingRoster follows the Google API Services User Data Policy, including its Limited Use requirements, for information received through Google APIs.
Service providers and disclosure
Vercel provides application hosting, Supabase provides database, authentication and storage services, and Google provides connected Drive storage. These providers process information needed to deliver their services. School records and exports are available to authorized school users and destinations chosen by backup administrators. Information may also be disclosed where required by law. This staging service does not promise that all processing occurs in one country.
Security and recovery keys
Controls include authenticated access, school-scoped permissions, encrypted network connections and public-key encryption of backup archives before storage or upload. Only the public recovery key is registered with WingRoster. The private recovery key is generated in the browser and is not sent to WingRoster. No system can guarantee absolute security; keep the private key separately and securely.
Retention, disconnection and deletion
School records remain until removed through supported operations or an operator-assisted request, subject to recordkeeping obligations. There is no general automatic deletion period for staging school records. Encrypted downloadable archives currently remain in the WingRoster database without automatic expiry. Optional Drive retention applies only to tracked Drive copies; it does not remove database copies.
Disconnect / revoke Google Drive in Admin → Backups revokes the connection and disables its schedule. You may also revoke access through your Google Account settings. Disconnecting does not delete existing backup files. You can delete files you own in Google Drive. Deleting a Drive file does not delete the server copy or downloaded copies.
Contact your school administrator for access to or correction of school records. Contact the address above to request deletion of staging data, stored backup copies, or integration information. We will verify your authority and explain any records that must be retained; we cannot delete copies independently held by a school or another recipient.
Changes
Updates will be published on this page with a revised effective date. Material changes to Google data use require appropriate notice and consent before that new use.