Privacy Policy
Last updated: 2026-08-21
This policy explains what the Flighter Android app
(name.gpm.flighter) does with data. It covers the app only.
The short version: Flighter reads your phone’s sensors and shows you what they say. There is no account, no server belonging to us, and your position is not sent anywhere unless you use the one optional feature that needs it — which is named below.
Who is responsible
Gabriele Proietti Mattia is the data controller for the processing described here. Contact: apps@gpm.name.
What leaves your device
Almost nothing, and only ever at your request.
There is exactly one feature that sends anything: calibrating the barometric altimeter from current weather data. Choosing it sends your approximate coordinates to Open-Meteo, which answers with the air pressure at sea level in your area. That request carries no identifier, no device information and nothing else about you, and Open-Meteo’s own privacy policy governs what they log. The other two ways of calibrating — from the satellites, or from a height you type in — send nothing at all.
Nothing else is transmitted. Not your coordinates, not your bearing, not your altitude, not the points you save, not how you use the app.
Writing in, and reading the answers
Flighter has a report screen — something is wrong, or an idea — and a messages screen where you can read what was written back. Both are optional and neither runs on its own: nothing is sent until you write something and press send.
What a report carries
- What you wrote: whether it is a bug or an idea, the title and the description.
- What makes it fixable: the app’s version, your Android version, the phone’s manufacturer and model, and your language tag. Typed into the message by the app — none of it is read from an identifier.
- A screenshot, only if you pick one. Nothing is captured for you. The picture is shrunk and re-encoded on your phone, and what you see before sending is exactly what leaves it — so if part of the screen has nothing to do with the problem, remove it first.
- Your email address, only if you type one. Without it a report is anonymous and cannot be answered; with it, it is how you get a reply.
- A random identifier for that single report, so that sending twice on a bad connection is not counted as two. It is not a device id, it is not stored on your phone, and a second report gets a different one.
It goes to apps-management.gpm.name, a service run by the author. It is not shared with
anyone, not used to build a profile and not published: reports are read, given a state and
answered by hand.
No advertising id and no install id, ever — in a report or anywhere else.
Reading the answers, and the key that costs
A report is answered by email, to the address you typed into it. That is the whole of what is needed, and if you never open the messages screen nothing below applies to you.
That screen shows what you sent and everything written back, without going to find the mail. Since your reports are yours, it has to be sure it is you: it asks for the address and sends a six-digit code there. Once the code is checked the app keeps a key, and it is the one thing here that resembles a login, so it is worth being exact about it:
- it hangs from the address you proved, never from your phone — nothing about the device goes into it, two phones that prove the same address get two separate keys, and removing the app throws the key away rather than recovering it;
- it works for Flighter only, and opens nothing in any other app;
- the service stores a one-way hash of it, not the key itself;
- it stops working after a year without use, and Sign out withdraws it at the service and not only on your phone.
Sending a report needs none of this. You can report something having proved nothing, and that report carries no identifier of any kind.
Feature requests and votes
The same screen lists what people have asked for in Flighter, and lets you ask for something and vote. Reading that list costs nothing and needs no address. Asking and voting do, for one reason: one vote per person is a promise, and without something to hang it on the count would mean nothing.
What is published is the request itself, once it has been read. Never your address, and never who voted for what.
What stays on your device
- Your settings. Units, coordinate format, true or magnetic north, and how much the needle is smoothed.
- Your saved points and bearings. The marks you create, with their coordinates.
- The barometer calibration, and when it was taken.
All of it is in the app’s private storage. Uninstalling removes it, as for any app. Saved points are included in Android’s backup so a new phone keeps them; the calibration deliberately is not, because a stale pressure reading restored onto another phone would present an old number as a fresh one.
Location permission
Precise location is what a compass and a satellite view need, and the app asks for it in context — when you first open something that requires it — never at launch.
It is used for four things, all of them on the device:
- the coordinates and accuracy shown on screen;
- the magnetic declination, which is what turns a magnetic heading into a true one and is computed locally from your position;
- the satellite view: Android reports satellite information only to an app holding precise location permission, which is the platform’s rule, not our choice;
- the course over ground used instead of the magnetometer once you are moving.
You can decline it. The compass still works, showing magnetic north and saying so on the dial.
Background location is never requested. Nothing in this app runs when it is not on screen, so there is no reason to know where you are then — and no way for the app to find out.
Diagnostics
The version distributed on Google Play contains optional crash reporting and usage statistics, both switched off unless you turn them on. When enabled they report crashes and anonymous feature counters — never coordinates, never a bearing, never an altitude, never a saved point.
The version distributed through the F-Droid repository and as a direct APK download contains no such code at all.
What the app never does
- No account and no sign-up, and no password anywhere. An email address only if you type one in yourself — to be answered about a report, to read those answers in the app, or to vote for a request — and never for anything else.
- No account, sign-up or email address.
- No advertising, and no sale or sharing of data with anyone.
- No tracking, across this app or any other.
- No background location, no movement history, no route recording.
- No reading of your contacts, messages, call history, photos or files.
Legal basis (GDPR)
For readers in the EU/EEA and the UK: Gabriele Proietti Mattia receives no personal data from this app, so there is no processing on that side to which a legal basis under Article 6 would attach. The one outbound request described above is one you instruct the app to make, to a service that is an independent controller of what it then holds.
Optional diagnostics in the Play build, where you switch them on, rest on your consent, which you may withdraw at any time by switching them off again.
Retention
A sign-in key stops working a year after you last use it, and is withdrawn the moment you press Sign out. Deleting the app removes the copy on your phone.
Reports are kept while they are useful — an open one until it is answered, a closed one as the record of a decision. A screenshot is part of the report it came with and goes when it goes. Ask and yours is deleted, including the address you sent it from.
Gabriele Proietti Mattia holds nothing. On your device, settings and saved points remain until you delete them or uninstall the app.
Your rights
Under the GDPR you may request access to, correction of, or deletion of your personal data. Because Gabriele Proietti Mattia holds no data about you from this app, there is nothing to access, correct or delete on that side; deleting the local data is done by removing a point or uninstalling the app. You retain the right to lodge a complaint with a supervisory authority.
Write to apps@gpm.name for any request.
Children
Flighter is not directed at children under 13 and knowingly collects no data from them — or from anyone.
Changes
Material changes will be published on this page with a new date at the top, and significant ones will be noted in the app’s changelog.
Last updated: 2026-08-21