1. Controller
Alexander Stolte
Mansfelder Straße 1, 06108 Halle (Saale)
Germany
Email: privacy@mode1090.com
2. Hosting and technical access data
This website is delivered by a self-hosted Appwrite installation on a virtual server operated by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, in a Nuremberg data centre. When you access the website, technically necessary connection data is processed. This can include your IP address, date and time, requested path, referrer, user agent, HTTP status and the amount of data transferred.
We process this data to deliver the website securely and reliably, diagnose errors and prevent abuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website. We do not use this information to build usage profiles. Technical logs are retained only for as long as necessary for operations, security or investigation of a specific incident and are then deleted or overwritten. Hetzner processes data on our behalf. See the Hetzner privacy policy for further information.
3. DNS through Cloudflare
We use services from Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, as the authoritative DNS provider for mode1090.com, mode1090.de, mode1090.app and associated www addresses. A DNS lookup may involve the requested hostname, request time, DNS metadata and the address of the requesting recursive DNS resolver. Website content and redirects are served by our server without Cloudflare's HTTP proxy. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is reliable DNS resolution and protection of the domains.
Processing outside the European Economic Area cannot be ruled out. Cloudflare identifies the EU-US Data Privacy Framework and the EU Standard Contractual Clauses as safeguards. Details are available in the Cloudflare Data Processing Addendum and the Cloudflare privacy policy.
4. Optional MODE 1090 account
You can voluntarily create an account in the MODE 1090 app. The app remains usable locally without an account. For registration, sign-in, email verification and password recovery, we process data including your name, email address, verification status, session data and security data in our self-hosted Appwrite installation. Passwords are encrypted in transit and stored only as hashes.
You can alternatively use Sign in with Apple. Apple provides Appwrite with an account-specific identifier and, when you choose to share them, your name and either your real email address or an Apple relay address. We use this data only to create and sign in to your account; Sign in with Apple is not used for advertising or tracking.
Processing is necessary to provide and secure the account you choose to create. The legal basis is Article 6(1)(b) GDPR; abuse prevention and technical security are additionally based on Article 6(1)(f) GDPR. Account emails are sent through our separately self-hosted mail server. Signing in alone does not upload your collection.
You may separately enable the free collection sync. We then store a privacy-reduced record for each synchronized sighting in Appwrite: the aircraft identity, observation and source time, confidence, optional human-readable place label, a pseudonymous account identifier and technical schema/conflict metadata. Exact coordinates, camera or compass evidence, pointing geometry, raw tracks, notes and photos remain on your device. The purpose is to make the same compact collection available on your signed-in iPhone, iPad and Mac. Processing is based on Article 6(1)(b) GDPR. You can disable sync on an individual device without deleting the separate local guest collection.
You can permanently delete the account at any time from the app settings. This removes the Appwrite account and the Appwrite data currently supported by the deletion process – profile data, sightings, saved places and alert rules – from the active system. Backup copies may remain until they are removed during the regular backup rotation. Sightings and settings stored separately on your device remain local and can be managed or deleted independently.
5. Verification and recovery links
Email-verification and password-recovery links lead to dedicated pages on this website. The link contains a time-limited user identifier and secret Appwrite token. These values are used only to send the verification or password change you initiated to api.mode1090.com. After reading them, the page removes them from the visible browser address, does not share them with third parties, and contains no analytics or advertising scripts. The originally requested URL is nevertheless transmitted to our hosting infrastructure when the page is first requested.
6. Local preferences
If you select light or dark appearance, your browser stores the choice under the key mode1090-themein local storage. This setting remains on your device and is not transmitted to us for profiling or advertising. If you dismiss a website announcement, a technically necessary cookie records only that announcement's identifier for up to 30 days so it does not immediately reappear.
7. Support and feature requests
If you contact us by email or through the support form, we process your email address, selected topic, message and the device, operating system and app-version details you choose to provide. Optional screenshots and diagnostic files are stored in a private, access-restricted bucket. Feature requests also contain the title, description and contact email you submit. These records are handled in the self-hosted MODE 1090 system and through our separately operated mail server; no external form provider receives them.
Processing is based on Article 6(1)(b) GDPR where your request concerns a contract or pre-contractual steps, and otherwise on Article 6(1)(f) GDPR. Our legitimate interest is answering support requests and improving the product. Messages and attachments are deleted when the matter has been resolved unless legal retention duties or a documented legitimate interest require continued storage.
8. Privacy-friendly reach measurement
On public website pages only, our own server records a limited page view event so we can understand which help and product pages are useful. The record contains the path without query parameters, time, language, broad device type, country supplied by the delivery infrastructure and the referring domain. It does not contain the full referrer URL. A daily changing cryptographic identifier derived from connection data prevents simple duplicate counting without storing the raw IP address or creating a long-term visitor profile. The admin and authentication routes are excluded.
We process these limited measurements on our self-hosted Appwrite installation on the basis of Article 6(1)(f) GDPR. Our legitimate interest is operating and improving the website and its help content. We do not use advertising networks, social-media pixels, third-party analytics or marketing cookies, and we do not use these events for automated decisions or cross-site profiling. Fonts, images and brand assets are served from our own infrastructure.
9. Mapbox airport detail maps in the app
The MODE 1090 app uses Mapbox to display detailed airport maps. No connection to Mapbox is made merely because you open an airport's information. Only when you choose to open the detailed map does the app connect directly to Mapbox services to retrieve the map style, fonts and vector map data needed for that view.
Mapbox may receive technically necessary connection and usage data, including your IP address, device and app information, identifiers, requested map resources, interaction and diagnostic data. The Mapbox Maps SDK can also send de-identified location and usage telemetry when the app causes such data to be gathered. This processing is necessary to provide the map you request and is based on Article 6(1)(b) GDPR. Processing in the United States cannot be ruled out. Details about Mapbox's processing and safeguards are available in the Mapbox privacy policy.
The Mapbox attribution control remains visible on the map. It gives you access to Mapbox's telemetry setting, where you can opt out of Mapbox telemetry for your device.
10. Your rights
Subject to the applicable legal requirements, you have rights including access, rectification, erasure, restriction of processing and data portability. You may object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. Please use the privacy contact above to exercise your rights.
You also have the right to lodge a complaint with a data protection supervisory authority. In particular, you may contact the State Commissioner for Data Protection of Saxony-Anhalt, Otto-von-Guericke-Straße 34a, 39104 Magdeburg, Germany.
Last updated: 11 August 2026