1903 Systems LLC
Privacy Policy
Version draft-1. Terms of Service
Draft for legal review. This text has not yet been reviewed by a lawyer and is not yet in force. Highlighted notes mark what is still to be decided.
This explains what CurrentOps collects, who can see it, who else handles it and how long it is kept. It covers the console and the app. CurrentOps is built so that the safety signal an operator sees cannot be traced to a single pilot, and most of this policy is about how.
Who we are, and whose information this is
1903 Systems LLC provides CurrentOps. Most of what is in it belongs to your operator: its documents, its bulletins, and the records of who acknowledged them. For that information we act on the operator's behalf and by its instructions. For your account, for keeping the service secure and for billing we decide how information is used ourselves. [For counsel: confirm how to describe our role under the laws that apply, and whether a data-processing addendum should accompany the operator's order form.]
What we collect
- Your account: your email address, a name if one was given, your role, which operator you belong to, and your password (stored only as a one-way hash by our authentication provider).
- Your devices: a registration for each device signed in under your seat, so the operator's device limit can be applied.
- Acknowledgments: for each bulletin or manual revision you acknowledge, your name, the version, your answers to any comprehension check, the manual revisions you held at that moment, the device, and the server's time.
- Your notes, highlights and bookmarks, so you can keep them across revisions and on a new device.
- Flags you choose to raise about content. These are anonymous unless you sign one.
- Study and question activity: which topics were drilled and missed, which passages were marked, and what subjects were asked about. These leave your device only as counts, never as your words, and are made so that no report can single out a person (below).
- Ask Orville usage: that a question was asked, for which operator, the outcome and the amount of text processed. We do not store the question or the answer.
- Your agreement to these terms: which edition, when, whether you gave it in the console or the app, and your email address.
- Records of what administrators change in the console, kept for the operator's own audit.
- When you write to us: what you send.
- For an operator's billing contact: what our payment provider holds, such as a name, email and billing address. We never see a full card number.
What your operator can see, and what it cannot
Your operator's administrators can see who has a seat, how many devices are registered to each seat, who has acknowledged which bulletin and revision, who has not, and the flags you raise. They can see the acknowledgments, including names, because they are the operator's records. The same record, and the list of who is outstanding, can be read by people the operator has named as read-only viewers and, for a limited time, by an inspector it has chosen to give access to.
They cannot read your notes, highlights or bookmarks. They cannot see how you personally did in a study drill, which passages you personally marked, or what you personally asked Ask Orville.
What they see about study and questions is a summary across the crew, and a summary is shown only when enough pilots contribute that nobody can be singled out. A small operator therefore sees fewer details, on purpose. The link between a report and a pilot is a one-way digest that the operator cannot compute and that is kept only where a minimum-pilots rule needs it.
What our own staff can see
Our staff see how much an operator uses the service, counts and states, without opening its documents. To read an operator's information they must open an access window, which states a reason, is shown to the operator's administrators, is recorded in a log the operator can read, and ends on its own or when the operator ends it. We do not read pilots' notes.
Ask Orville and Pilot's Discretion, in particular
When you ask a question or take a generated drill, your device finds the relevant passages in your operator's own documents, removes the operator's name, and phrases built from it, from them, and sends the question and those passages through our server to Anthropic, the provider of the AI model. Our server checks that you are signed in, attributes the use to your operator and passes the request on. It keeps a count of the use and does not keep the text.
Redaction is not a guarantee: it does not remove names, tail numbers or anything else a person types into a question, so do not type personal information into one. Anthropic processes the text to produce the answer. [Owner to confirm: against our agreement with Anthropic, before this policy is final, that content sent through the API is not used to train models and how long Anthropic retains it, and state both here.]
Who else handles information for us
We use a small number of providers to run the service, and share with them only what each needs:
- Supabase: our database, sign-in service, file storage and server functions. [Owner to confirm: the region the production project is hosted in, and state it here.]
- Anthropic: the AI model behind Ask Orville and Pilot's Discretion, as described above.
- Postmark: sending email such as invitations and password links.
- Stripe: processing an operator's subscription payments. Pilots' information is not sent to Stripe.
- [Owner to confirm: the company hosting the console web pages, to be named when the console is deployed.]
We do not sell personal information and we do not use it for advertising. We may disclose information if the law requires it, and we will tell the operator when we are allowed to.
How long we keep it
Acknowledgment records are kept for as long as the operator is a customer, even after a pilot leaves, because the operator may need them. They cannot be edited or deleted by anyone through the product. Usage counts are kept so an operator, and we, can see how the service is being used. When an operator ends its subscription and asks us to delete its information, we do so through a deliberate, logged process after it has taken its export. Notes and highlights stay with your account. [For counsel: confirm these periods and any longer period we should state for backups.]
Your record that you agreed to these terms is kept, with your email address, if your account is later removed.
How we protect it
Each operator's information is separated from every other's in the database itself, not only in the software on top of it, and the app keeps each operator's documents apart on the device. Information is protected in transit and by our infrastructure provider at rest, passwords are stored hashed, files on the device use the system's file protection, and what staff can open is limited and logged. No system is perfectly secure; if something goes wrong that affects you we will tell the operator and, where required, you.
Your choices and requests
You can ask what we hold about you, ask us to correct it, or ask us to delete what the law lets you have deleted. For anything that is the operator's record, such as an acknowledgment, the operator decides, and we will pass your request to it. You can choose whether to sign a flag you raise.
To make a request, or to ask a question about this policy, write to support@1903systems.com.
Changes to this policy
When this policy changes in a way that matters we publish a new version, and ask signed-in people to agree to it as described in the Terms of Service.