Privacy Policy
Who we are
Rach is developed by an individual developer, contactable at support@rangtaw.com. Rach is not affiliated with, endorsed by, or sponsored by any airline.
Data on your device
Rach stores the following on your device only:
- Your roster (flights, duties, off days)
- Your crew diary entries — encrypted at rest on the device
- Your pre-flight checklist
- Places you've saved for offline viewing
- Your Ask Rach conversations
- Your layover plans
- Your settings — home currency, per-diem rates you've entered, rest-schedule preferences
Your profile name, birthday, and crew role are kept in your device's secure keychain (Keychain on iOS, Keystore on Android) for extra protection.
Backup differs by platform: on iOS, this data rides your phone's normal iCloud backup, so it survives a phone replacement the same as photos or notes. On Android, Rach opts out of Google's automatic backup for privacy hardening — none of this data is included in a Google account restore, so a phone reset or replacement does not carry it over. Use "Export roster & settings" and "Export crew diary" beforehand if you want to move data to a new Android device yourself.
No accounts
Rach has no user accounts. We cannot see, access, or recover your data; it lives on your device. Requests the app makes to our server carry only a random per-install identifier — not your name, email, or anything tied to your identity — used solely to rate-limit the service. Reinstalling the app generates a new one.
Roster import
Roster text or files you submit for import are sent to our server (hosted on Cloudflare), which uses Anthropic's Claude AI to extract your schedule, and are processed, not retained: they are not stored, logged, or used for any other purpose — including AI training — after the parse completes. Nothing is saved in the app until you review and confirm the result. Imports are limited to a small number per day and per month per install to protect the service; the app tells you when a limit is reached and when it resets. Importing is always free.
Ask Rach questions
Questions you type to Ask Rach — and the context needed to answer them (a summary of your roster, your current layover, and local time) — are sent to our server (hosted on Cloudflare) and Anthropic's Claude to produce the answer. This is processed, not retained: it is not stored, logged, or used for AI training after the answer returns to you. Your conversations themselves are saved on your device only — Rach's server keeps no copy. You can clear a conversation any time with "New chat," or remove all of them with "Delete all data."
Layover plans
When you ask Rach to build a layover plan, your stated preferences, any specific places you name, and your chosen time window are sent to our server and Anthropic's Claude the same way — processed to build the plan, not retained. The plans Rach generates for you live on your device only.
Layover guides
To build the layover screen for a city on your roster, the app sends that layover's city name, airport code, and hotel name/address (as printed on your roster) to our server. The server looks up nearby places and ratings (Google, Geoapify), weather (Open-Meteo), exchange rates, and a destination photo (Pexels) around that location. These lookups carry no name or identity — crew at the same hotel receive the same shared, cached guide, and the cached guide itself stores no identifier at all. Guides are only built for layovers on your own roster, shortly before the trip or when you open one.
Flight number lookup
Typing a flight number while adding a duty manually looks up its route and times online (AirLabs) to help fill in the form. Only the flight number is sent — nothing else about you or your roster. The lookup is optional and only runs when you're online.
Maps & directions
The map screen requests map tiles from OpenStreetMap for the area you're viewing. Tapping "directions" hands a place's coordinates to whichever maps app you choose. Neither carries your name or roster — just a location, the same as looking it up in any maps app.
Purchases
Premium purchases are processed by Apple or Google. Entitlements are managed by RevenueCat under an anonymous device identifier — not your name, email, or any account. "Restore Purchases" re-activates your premium features on a new device using your Apple ID or Google account purchase history.
App updates
When Rach starts, it checks Expo's update service (u.expo.dev) for a newer version of the app's code and downloads it if there is one. That check carries the platform you're on, the app's runtime version, the release channel, and identifiers for the update itself and this install — never your roster, diary, chat, or anything about you. It is how a fix reaches you without waiting for an app-store review.
Error reports
From version 1.1.2, when Rach hits a problem it sends a short report to Sentry so the problem can be found and fixed. There are two kinds, and both are listed here in full.
If the app itself breaks (an error in Rach's own code), the report contains: what went wrong and where in the code (the stack trace), your device model, your operating system version, the app version, the runtime version, which update your app is running and on which channel, and the time it happened.
If something Rach was doing for you fails in a way you can see — a plan that couldn't be built, a roster import that didn't work, an Ask Rach answer that didn't arrive, a city guide that wouldn't download — the report contains only a fixed label naming which of those it was and why (for example “plan couldn't be generated”), plus the same device, version and update details. The labels are a short list written into the app; there is no field in them for your own words, so nothing you typed can travel in one.
Neither kind carries your roster, your diary, your Ask Rach conversations, or your location, and neither has a field for anything you typed. The only free text in a crash report is the technical error message produced by the code that failed, and it is capped at a short fixed length. Rach attaches no name, no email, and no install identifier, so a report is not linked to your identity. Reports are never used for advertising or for tracking you across apps or websites. Sentry's own settings are configured to discard IP addresses.
This version reports problems in Rach's own JavaScript code, which is where the app's features live. It does not yet report the rarer crashes that happen in the underlying native layer.
Your controls
Settings → More gives you these controls at any time: "Export roster & settings" and "Export crew diary" (as plain text, via your device's normal share sheet) and "Delete all data" (removes everything from this device — cannot be undone). All act on-device, since there is no server copy to reach.
Children
Rach is not directed at children and does not knowingly collect data from children.
Your rights (GDPR / Philippine Data Privacy Act)
Because your data lives on your device and Rach has no accounts, your rights to access, correct, and erase your data are exercised directly through the app's own Export and Delete controls — there is no server-side copy of your schedule or diary to request or erase, beyond the ephemeral roster-parse request described above. Shared layover guides contain no personal identifiers to erase.
Changes & contact
We may update this policy as Rach's features change. Material changes will be reflected here with a new effective date. Questions: support@rangtaw.com.