1. Controller
Alexander Stolte
Mansfelder Straße 1, 06108 Halle (Saale)
Germany
Email: privacy@mode1090.com
2. Hosting and technical access data
This website is delivered by a self-hosted Appwrite installation on a virtual server operated by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, in a Nuremberg data centre. When you access the website, technically necessary connection data is processed. This can include your IP address, date and time, requested path, referrer, user agent, HTTP status and the amount of data transferred.
We process this data to deliver the website securely and reliably, diagnose errors and prevent abuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website. We do not use this information to build usage profiles. Technical logs are retained only for as long as necessary for operations, security or investigation of a specific incident and are then deleted or overwritten. Hetzner processes data on our behalf. See the Hetzner privacy policy for further information.
3. DNS and redirects through Cloudflare
We use services from Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, to manage domains and redirect requests from mode1090.de, mode1090.app and associated www addresses. When you visit one of these redirect addresses, Cloudflare may process your IP address, request time, request headers and requested URL. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is reliable DNS resolution, secure redirects and protection of the domains.
Processing outside the European Economic Area cannot be ruled out. Cloudflare identifies the EU-US Data Privacy Framework and the EU Standard Contractual Clauses as safeguards. Details are available in the Cloudflare Data Processing Addendum and the Cloudflare privacy policy.
4. Optional MODE 1090 account
You can voluntarily create an account in the MODE 1090 app. The app remains usable locally without an account. For registration, sign-in, email verification and password recovery, we process data including your name, email address, verification status, session data and security data in our self-hosted Appwrite installation. Passwords are encrypted in transit and stored only as hashes.
Processing is necessary to provide and secure the account you choose to create. The legal basis is Article 6(1)(b) GDPR; abuse prevention and technical security are additionally based on Article 6(1)(f) GDPR. Account emails are sent through our separately self-hosted mail server. Signing in alone does not upload your collection.
You may separately enable the free collection sync. We then store a privacy-reduced record for each synchronized sighting in Appwrite: the aircraft identity, observation and source time, confidence, optional human-readable place label, a pseudonymous account identifier and technical schema/conflict metadata. Exact coordinates, camera or compass evidence, pointing geometry, raw tracks, notes and photos remain on your device. The purpose is to make the same compact collection available on your signed-in iPhone, iPad and Mac. Processing is based on Article 6(1)(b) GDPR. You can disable sync on an individual device without deleting the separate local guest collection.
You can permanently delete the account at any time from the app settings. This removes the Appwrite account and the Appwrite data currently supported by the deletion process – profile data, sightings, saved places and alert rules – from the active system. Backup copies may remain until they are removed during the regular backup rotation. Sightings and settings stored separately on your device remain local and can be managed or deleted independently.
5. Verification and recovery links
Email-verification and password-recovery links lead to dedicated pages on this website. The link contains a time-limited user identifier and secret Appwrite token. These values are used only to send the verification or password change you initiated to api.mode1090.com. After reading them, the page removes them from the visible browser address, does not share them with third parties, and contains no analytics or advertising scripts. The originally requested URL is nevertheless transmitted to our hosting infrastructure when the page is first requested.
6. Local preferences
If you select light or dark appearance, your browser stores the choice under the key mode1090-themein local storage. This setting remains on your device and is not transmitted to us for profiling or advertising. If you dismiss a website announcement, a technically necessary cookie records only that announcement's identifier for up to 30 days so it does not immediately reappear.
7. Support and feature requests
If you contact us by email or through the support form, we process your email address, selected topic, message and the device, operating system and app-version details you choose to provide. Optional screenshots and diagnostic files are stored in a private, access-restricted bucket. Feature requests also contain the title, description and contact email you submit. These records are handled in the self-hosted MODE 1090 system and through our separately operated mail server; no external form provider receives them.
Processing is based on Article 6(1)(b) GDPR where your request concerns a contract or pre-contractual steps, and otherwise on Article 6(1)(f) GDPR. Our legitimate interest is answering support requests and improving the product. Messages and attachments are deleted when the matter has been resolved unless legal retention duties or a documented legitimate interest require continued storage.
8. Privacy-friendly reach measurement
On public website pages only, our own server records a limited page view event so we can understand which help and product pages are useful. The record contains the path without query parameters, time, language, broad device type, country supplied by the delivery infrastructure and the referring domain. It does not contain the full referrer URL. A daily changing cryptographic identifier derived from connection data prevents simple duplicate counting without storing the raw IP address or creating a long-term visitor profile. The admin and authentication routes are excluded.
We process these limited measurements on our self-hosted Appwrite installation on the basis of Article 6(1)(f) GDPR. Our legitimate interest is operating and improving the website and its help content. We do not use advertising networks, social-media pixels, third-party analytics or marketing cookies, and we do not use these events for automated decisions or cross-site profiling. Fonts, images and brand assets are served from our own infrastructure.
9. Your rights
Subject to the applicable legal requirements, you have rights including access, rectification, erasure, restriction of processing and data portability. You may object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. Please use the privacy contact above to exercise your rights.
You also have the right to lodge a complaint with a data protection supervisory authority. In particular, you may contact the State Commissioner for Data Protection of Saxony-Anhalt, Otto-von-Guericke-Straße 34a, 39104 Magdeburg, Germany.
Last updated: 27 July 2026