Privacy Policy
Effective Date: August 14, 2026. Last Updated: August 27, 2026. Applies to users in the United States.
This version is in effect until October 6, 2026. It is kept here as a record. Read the updated Privacy Policy.
PrismSkies LLC ("PrismSkies," "we," "us") operates the Services, an aviation training and management platform. This Privacy Policy explains how we collect, use, and protect information. We built this platform for flight schools, flying clubs, instructors, and their students, and we take the privacy of training records seriously.
1. Who this policy covers
This policy applies to visitors to our website and to users of the PrismSkies application, all of whom are based in the United States. Where a flight school or club (a tenant) uses PrismSkies to manage its own students and staff, that organization decides what information to put into its workspace, and this policy describes how we handle information on the platform overall.
2. Information we collect, and why
The information we collect depends on how you use PrismSkies. We do not store your full payment card number; card details are handled by our payment processor. The table below lists the categories we collect, why, and how long we keep them.
| Category | Purpose | Retention |
|---|---|---|
| Identity (name) | Create and administer your account | Life of the account, plus the export window, then deleted |
| Contact (email, and phone if you provide it) | Sign-in, transactional messages, and support | Life of the account, plus the export window |
| Training records and flight-time logs | Provide the training and management features | Life of the account, plus the export window; subject to Provider custodianship |
| Scheduling data | Booking and, if you connect it, calendar synchronization | Life of the account, plus the export window |
| Uploaded documents | Store documents you or your Provider upload | Life of the account, plus the export window |
| Payment data (through Stripe) | Process subscription payments | Transaction records retained; card data held by Stripe, not by us |
| Support communications | Respond to and improve support | As needed for support, legal, and security purposes |
We disclose these categories only to the service providers listed in the Service providers and subprocessors section below.
3. How we use information
We use the information we collect to:
- provide, maintain, and improve the platform and its training features;
- create and authenticate your account and keep it secure;
- process payments and manage subscriptions through our payment processor;
- synchronize your scheduled sessions with Google Calendar when you connect it;
- send transactional messages, such as sign-in links, confirmations, and account notices;
- respond to your support requests; and
- comply with legal obligations and enforce our terms.
We use member and student data solely to provide the Service. We do not use it for advertising, for marketing to students, or for cross-customer model training, and we never sell it. Our AI study features are powered by Amazon Bedrock within our own AWS environment; we limit the personal information included in AI requests, and we do not permit that provider to use your data to train its models.
4. We do not sell your information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have no advertising business.
6. Service providers and subprocessors
| Vendor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, storage, and encryption key management | United States (us-west-2) |
| Stripe, Inc. | Payment processing for platform subscriptions | United States |
| Google LLC | Calendar synchronization via Google Calendar (OAuth, at the user's direction) | United States |
| Google LLC | Display of a Provider's Google Business Profile reviews | United States |
| Zoom | Video session scheduling links (Zoom receives only the session details needed to create meetings) | United States |
| Resend, Inc. | Transactional email delivery | United States |
We will update this list before any new subprocessor begins processing member personal data. To receive notice of changes, email privacy@prismskies.com with the subject "Subprocessor updates."
We do not use third-party analytics, advertising networks, session-replay tools, or tracking cookies, and we do not sell or share personal information.
7. Google user data
When you connect Google Calendar, we access only the Google Calendar data needed to synchronize the training sessions you schedule: we create, update, and delete calendar events that correspond to those sessions, and we read only the start and end times of your existing events within the booking window so we do not double-book you; we never read, store, or log event titles, descriptions, locations, or attendees. We use this data solely to provide calendar synchronization at your direction. It is stored encrypted, is never transferred to anyone except the subprocessors listed above as needed to provide the feature, and is never used for advertising. You can disconnect at any time, which stops all further access. PrismSkies' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
8. How we protect your information
Identifying personal information, including email addresses, phone numbers, connected-service tokens, and application secrets, is envelope-encrypted using a dedicated AWS Key Management Service key that PrismSkies manages. Email addresses are additionally protected by a blind index, so we can look up an account without keeping the address in plain text.
Each tenant's data is isolated at the database layer, so one organization's records do not cross into another's. Data is encrypted in transit using industry-standard TLS, and our infrastructure runs in the United States. No system is perfectly secure, but we work to protect your information using safeguards appropriate to its sensitivity.
10. Your privacy rights (all users)
We extend the following rights to all users in the United States, regardless of whether a particular state privacy law applies to us: the right to know and access, correct, and delete the personal information we hold about you.
PrismSkies does not sell or share personal information as those terms are defined in the California Consumer Privacy Act, and has not done so in the preceding 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16 years of age. Because we do not sell or share personal information, we do not provide a "Do Not Sell or Share My Personal Information" link and do not process opt-out preference signals such as Global Privacy Control, which apply only to sale or sharing.
11. How to submit a privacy request
To exercise these rights, email privacy@prismskies.com. We commit to responding within 45 days. To protect your information, we verify requests by matching them to your account email and, where possible, to your login. You can also review and update much of your information directly in your account settings. We will not discriminate against you for exercising these rights.
You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your signed permission, and we may require you to verify your identity with us directly or confirm that you granted the agent permission.
12. Children and members under 18
Our Services support flight training, which includes teenage students. They are not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. Registration requires a date of birth, and we do not permit accounts for anyone under 13. If you believe a child under 13 has provided us personal information, contact privacy@prismskies.com and we will promptly delete it.
For members we know are under 18, we use personal information only as necessary to provide and support the Services, such as scheduling, training records, and communications about their training. We do not sell or share any member's personal information, do not serve targeted advertising, and do not profile members, including minors. A parent or guardian of a minor member may review the minor's information through the enrolling flight school or instructor, which controls its students' training records, or by contacting us.
13. Retention and deletion
Provider tenant data is retained for the life of the account plus an export window of at least 60 days. After that, it is deleted from production within 30 days and from encrypted backups within our normal backup cycle (up to 90 days), except information we are required to keep for legal, billing, or security purposes. Individual members may export their own flight-time logs, training records, and documents during the export window.
14. Institutional customers
Institutional customers, such as colleges and Title IV-participating schools, may request a signable Data Processing Addendum and a FERPA school-official rider. Contact legal@prismskies.com.
15. Changes to this policy
We may update this policy from time to time. For material changes, we will announce them by email and in-app notice at least 30 days in advance. Any materially expanded use of information we already collected will apply only with your opt-in consent, and never retroactively. After the first revision, we will show both an "Effective" date and a "Last Updated" date.
16. Contact
Questions about this policy, or about your information, can be sent to privacy@prismskies.com or by mail to PrismSkies LLC, 2108 N ST, STE N, Sacramento, CA 95816.
Start free, or ask us anything before you do.
Privacy or terms questions: privacy@prismskies.com