Notamify Privacy Policy

Last Updated / Effective: July 17, 2026

Introduction

Skymerse Inc. ("Skymerse," "we," "us," or "our") provides Notamify, an aeronautical information service that processes NOTAM and related aeronautical data and delivers interpretations, summaries, briefings, and other outputs through our website at notamify.com, our mobile application, our APIs, and related software, features, and support (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with the Service, and the choices and rights available to you.

Scope and markets. This Privacy Policy is written for a US-based company that also makes the Service available to individuals in Europe. Where a section applies only to individuals in the European Economic Area ("EEA") or the United Kingdom (together, "Europe"), it is identified in the "Notice to European Users" section below.

Data we process on behalf of business customers. This Privacy Policy does not apply to information we process on behalf of our business or enterprise customers (for example, flight or crew data submitted through a customer’s systems, or accounts a customer provisions and manages for its personnel). For that data we act as a processor/service provider, the customer is the controller, and our handling is governed by our agreement with that customer (including a data processing agreement where applicable). If your data reached us through a business customer, please direct privacy requests to that customer in the first instance; we will support them as required by law.

By using the Service, you acknowledge that you have read this Privacy Policy.

Personal Information We Collect

Information you provide to us

Depending on the features you use, the personal information you provide may include:

  • Account and profile data — name, email address, account identifier, sign-in method, professional role, referral source, briefing preferences, marketing choices, and account settings. Authentication is handled by our identity providers; we do not receive or store your plaintext password.

  • Contact data — email address and, where you choose to provide it, phone number or other contact details.

  • Flight operations data — information needed to provide flight-planning and NOTAM features, such as callsign, aircraft registration and type, departure/destination/alternate airports, route, dates and times, altitude and speed, runways, approaches, operational notes, saved flights, watchlists, alerts, filters, and related briefing references.

  • Scheduled briefing data — recipient, scheduled delivery time, flight details, and flight-plan information needed to prepare and deliver a scheduled briefing.

  • Files and content you provide — flight-plan PDFs, roster/calendar files, support messages, and other documents or information you submit (see "Flight-Plan Files You Upload" below).

  • Feedback data — ratings, issue selections, corrections, and comments you submit about a NOTAM interpretation or other output, together with the related interpretation context and submission time.

  • Subscription and transaction data — subscription tier and status, purchase history, transaction amount and currency, and the identifiers needed to manage your subscription. Payment-card details are handled by our payment provider; we do not receive or store full card numbers or card security codes.

  • Communications and marketing data — your marketing and communication preferences and records of your service, support, or marketing communications with us.

Information from third-party sources

We may combine the information above with information we receive from:

  • Authentication and identity providers, when you create an account or use a third-party sign-in option.

  • Service providers that support authentication, payments, hosting, analytics, security, communications, and other operational functions.

  • Business customers, where a customer provisions or manages an account for you (subject to the "processor" note above).

Information we collect automatically

When you use the Service, we and our service providers may automatically collect:

  • Technical and device data — IP address, device and browser type, operating system, language, application version, approximate location derived from IP address, security signals, and diagnostic information.

  • Usage data — pages or screens viewed, feature interactions, airport searches, API activity, performance information, and error or diagnostic events.

No precise device location. The Service does not collect precise device location. An optional "locate me" feature can display your location on a map when you choose to use it; this runs on your device only, and we do not receive, store, or process that location. Flight-plan locations you enter describe planned operations and are not treated as the current location of your device.

No sensitive personal information. We do not intentionally collect special categories of data (for example, health data). Please do not include sensitive personal information in your uploads or free-text fields.

Flight-Plan Files You Upload (Parsing)

When you upload a flight-plan PDF, we process it to extract structured flight data (such as callsign, aircraft registration and type, aerodromes, route/waypoints, flight level, and ETD/ETA). Depending on the document, it may also contain contact details (e.g., a pilot or dispatcher name/phone/email) that you chose to include. We do not extract or store those personal identifiers. We convert the PDF to text and use automated tools, including a third-party artificial-intelligence provider acting as our processor, to structure the data for Service features (e.g., alerts, route checks, or NOTAM workflows), using only vetted service providers for secure storage and processing. Any such provider acts as our processor, processes the data solely on our instructions, and is contractually restricted from retaining it or using it to train its own models.

Retention and use limits. We keep the original PDF no longer than necessary to complete parsing, validate results, and address immediate support or reliability issues. Derived structured data is retained in your account for as long as needed to provide the features you use. We do not use your uploaded PDFs to train our AI/ML models. Where you consent, we may use the derived structured flight data (such as route, origin, destination, times, alternates, and aircraft type), excluding personal identifiers such as crew or dispatcher names and contact details, to train and improve our models and the Service. Otherwise we use the data only to provide and improve the Service for you, to troubleshoot, and to ensure security and compliance.

Tracking and Other Technologies

Some automatic data collection is facilitated by cookies and similar technologies. For details and your choices, see the Cookie Notice below. The native portions of the mobile application do not use browser cookies; they use secure session information and local application storage.

AI and machine-learning technologies. The Service uses artificial-intelligence and machine-learning technologies to interpret, categorize, and summarize aeronautical information. Where a third party helps provide these technologies, we contractually require them to act only as our service provider/processor and prohibit them from using your data for their own generalized AI-model training.

How We Use Your Personal Information

We use personal information for the following purposes, or as otherwise described when we collect it:

  • Service delivery and operations — to provide, operate, secure, and personalize the Service; authenticate users; search airports; retrieve and interpret NOTAMs; create and deliver briefings; save flights; and synchronize account features across web and mobile.

  • Service improvement, evaluation, and analytics — to maintain and improve the Service, review ratings/corrections/issue reports and other feedback, and evaluate and improve the quality and accuracy of our NOTAM interpretations, other outputs, and the systems used to produce and assess them (using analytics tools such as PostHog and Google Analytics (GA4)). We do not use your personal information to train our artificial-intelligence or machine-learning models unless you give us your consent; where you consent, we may use your personal information to train and improve those models and the Service.

  • Communications — to send service and transactional messages (e.g., critical updates), and, where you have consented (or as otherwise permitted by law), marketing communications.

  • Security and fraud prevention — to detect, prevent, and address fraud, abuse, security incidents, and misuse, and to enforce our terms and usage limits.

  • Compliance and protection — to comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.

  • Aggregated and de-identified data — to create and use aggregated or de-identified data that no longer identifies you for our lawful business purposes, including improving the Service. We will not attempt to re-identify such data except to test our de-identification processes.

How We Share Your Personal Information

We share personal information only as needed to provide and improve the Service or as required by law, with:

  • Affiliates — entities under common ownership or control, to help operate and support the Service under the standards described in this policy.

  • Service providers — companies that support authentication, cloud hosting, databases, security, monitoring, analytics (including PostHog and Google Analytics (GA4)), payment processing, email delivery, customer support, and document processing, which may process personal information only for the services they provide to us.

  • Payment processor — our payment provider, Stripe, which acts as our merchant of record for some transactions, collects and processes your payment-method and billing information directly and sends us the subscription and transaction status needed to manage your access. Stripe handles that information under its own privacy policy at stripe.com/privacy. If you subscribe through the Apple App Store, Apple (not Stripe) processes your payment and billing information under its own privacy policy and sends us the subscription status needed to manage your access.

  • Professional advisors and authorities — advisors (e.g., lawyers, auditors, insurers) and law-enforcement or government authorities where necessary to comply with law, protect rights, or prevent fraud or abuse.

  • Business transferees — counterparties in an actual or prospective merger, acquisition, financing, or sale of assets, under appropriate safeguards.

No sale; no cross-context behavioral advertising. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or targeted advertising within the meaning of applicable US state privacy laws. The Service does not display third-party advertisements, use an advertising identifier, or track your activity across other companies’ apps or websites for advertising purposes. A current list of key subprocessors is available on request at [email protected]. We make commercially reasonable efforts to verify that the parties with whom our mobile application shares personal information provide a level of protection of personal information consistent with the practices described in this Privacy Policy, except that all such parties other than our service providers and affiliates may, to the extent permitted by law, use personal information as described in their own privacy policies.

Data Retention

We keep personal information only as long as necessary for the purposes described in this policy, including to provide the features you use, satisfy legal, accounting, or reporting requirements, and establish or defend legal claims. To determine the appropriate period, we consider the amount, nature, and sensitivity of the information, the potential risk of harm, the purposes for which we process it and whether we can achieve those purposes by other means, and applicable legal requirements. When we no longer need personal information, we delete or anonymize it; where deletion is not immediately possible (for example, in backups), we securely store and isolate it from further processing until deletion is possible.

Your Choices

  • Access or update — you can review and update certain account information by signing in to your account.

  • Marketing opt-out — you can opt out of marketing emails using the unsubscribe link in the message or by contacting us; you may still receive service and transactional messages.

  • AI/model-training consent — where we use your personal information to train or improve our AI/ML models based on your consent, you can give or withdraw that consent at any time through a setting in your account, without affecting processing that already took place.

  • Cookies and analytics — you can control cookies and analytics as described in the Cookie Notice below.

  • Delete your account — you can request deletion of your account at any time by contacting us; you can also request account deletion from within the mobile application. We delete account data in accordance with this policy, subject to legal retention requirements.

  • Do Not Track / opt-out signals — because we do not sell or share personal information for cross-context behavioral advertising, browser "Do Not Track" and Global Privacy Control signals do not currently change our practices; we will honor applicable signals if our practices change or where required by law.

  • Declining to provide information — some information is needed to provide certain features; if you do not provide it, we may be unable to provide the relevant feature.

International Data Transfer

We are based in the United States and use service providers in the US and other countries. Your personal information may be transferred to, and processed in, countries whose data-protection laws differ from those in your own. Where we transfer personal information from Europe to countries without an adequacy decision, we implement appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum, as applicable), together with additional technical and organizational measures. You may contact us for more information about these safeguards or a copy of them, subject to appropriate redactions.

Security

We use appropriate technical, organizational, and physical measures designed to protect personal information against loss, misuse, and unauthorized access, disclosure, alteration, or destruction, and we restrict access on a need-to-know basis. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Children

The Service is a professional aviation tool and is not directed to, or intended for use by, anyone under 18 years of age (or the age of majority in their jurisdiction, if higher). We do not knowingly collect personal information from anyone who does not meet this requirement. If you believe an ineligible minor has provided us with personal information, contact us at [email protected] and we will take appropriate steps to delete it.

Other Sites and Services

The Service may link to or integrate third-party websites, applications, or services that we do not control. We are not responsible for their privacy practices, and we encourage you to review their privacy policies. A link or integration does not imply endorsement.

Changes to This Privacy Policy

We review this policy periodically and update it when our practices or applicable laws change. We will post the updated version with a new "Last Updated" date and, for material changes, provide additional notice as required by law.

How to Contact Us

If you have questions or wish to exercise a privacy right, contact us:

  • Email: [email protected]

  • Mail: Skymerse Inc., 2261 Market Street STE 86173, San Francisco, CA 94114, United States

US State Privacy Rights Notice

California "Shine the Light." California residents may request information about disclosures of certain personal information to third parties for their direct-marketing purposes. Because we do not make such disclosures, there is nothing to report; you may direct any such request to [email protected].

Nevada. Nevada residents may request to opt out of the sale of certain personal information for monetary consideration. We do not conduct such sales; you may still submit a request to [email protected].

Notice to European Users

Where this applies. This section applies only to individuals in Europe (the EEA and the UK). References to "personal information" include "personal data" as defined in the EU GDPR and UK GDPR (together, the "GDPR").

Controller. Skymerse Inc. is the controller of personal data covered by this Privacy Policy. See "How to Contact Us" for our details.

Our GDPR representatives. If required, we appoint representatives in the EU and the UK under Article 27 of the GDPR. EU representative: Damian Szumski You may contact them directly on privacy matters.

Legal bases. We rely on the following legal bases: performance of a contract (to create and administer your account, provide core features including parsing your uploaded flight-plan PDF, deliver paid subscriptions, and provide support); legitimate interests (to secure, maintain, and improve the Service, including analytics, review feedback, and evaluate and improve the quality of our interpretations, other outputs, and the systems that produce and assess them, balanced against your rights — you can opt out of analytics cookies as described in the Cookie Notice); consent (for marketing where required, using your personal data to train or improve our AI/ML models, and other optional processing, which you can withdraw at any time); and compliance with law (for tax, accounting, and other legal obligations).

No sensitive data; no automated decision-making. We ask that you not provide sensitive personal data through the Service. We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects.

Your rights. You may access, correct, delete, restrict, or object to processing of your personal data; port a machine-readable copy; and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office). To exercise these rights, contact [email protected].

Transfers outside Europe. As a US-based company, we (and many of our service providers) process personal data in the US, which is not the subject of a general adequacy decision. Where we transfer personal data outside Europe to a country without an adequacy decision, we use appropriate safeguards (such as the Standard Contractual Clauses and the UK Addendum) or, in limited cases, a permitted derogation. Contact us for further information or a copy of the safeguards.

Cookie Notice

This Cookie Notice explains how we use cookies and similar technologies on our website and, where indicated, our mobile application (together, the "Sites"). Cookies are small data files placed on your device that help operate the Sites, remember your preferences, and understand usage. We use session cookies (which expire when you close your browser) and persistent cookies (which remain until deleted), and both first-party and, where applicable, third-party cookies.

Categories we use. We use (i) strictly necessary cookies required for core functionality; (ii) analytics cookies to understand usage and improve performance — provided by PostHog and Google Analytics (GA4) — which are enabled by default and can be turned off by choosing "Essential Only"; and (iii) preference cookies to remember settings. We do not use advertising or social-media cookies, do not display third-party advertisements, and do not use an advertising identifier. We may also use web beacons and local storage.

Your choices. You can review or change your cookie choice at any time through the Cookie settings control on the website, and you can block or delete cookies through your browser settings (though blocking strictly necessary cookies may prevent parts of the Sites from working). If analytics are enabled while you are signed in, analytics events may be associated with your account so we can understand how features are used and improve reliability; we do not use this information for third-party advertising.

Questions. If you have questions about this Cookie Notice, contact us at [email protected].