Privacy Policy
MyRoster — Privacy Policy
Last updated: 26 September 2026
Who operates MyRoster
MyRoster is operated by Damiano Miazzi. Contact: damianomiazzi@gmail.com. MyRoster is an independent app, not affiliated with or endorsed by an airline.
Account and private cloud data
We use Firebase Authentication and Firestore to manage your account and sync your email, name, company, staff number, rank, profile preferences, roster files and parsed duties, crew identifiers in your roster, manual flight details and annual-leave planner. Subscription status and Apple transaction identifiers support purchases and restoration. Private roster files are not published to colleagues. Authorized support administrators have technical access to cloud data for support and operation; this is not end-to-end encryption. If you add them in Contact & Birthday, your phone number, contact e-mail and date of birth are stored in your private profile. Your date of birth is used only on your device for a birthday greeting and is never shown to anyone. Your phone and e-mail are shown to colleagues of the same airline only while you turn on “Show phone & e-mail to colleagues”; turning it off removes them.
Sharing with colleagues
Allow roster sharing controls publication and access to shared roster features within the same company: duty summaries, flights, stations, times and rostered crew identifiers; standby, Friends, Trip Trade and Crew Lounge also handle the names, messages and offers you choose to share. New accounts start with sharing off. Older accounts keep their existing access until a preference is saved; a saved off choice is respected. Turning sharing off removes your published roster summaries when the app can reach the server. Names and ranks in the company crew directory remain available to resolve crew already listed in personal rosters, even with sharing off. A colleague’s private imported roster may still list your staff number. Optional photos can be removed from your profile.
Optional diagnostics and local logs
Share diagnostic counts is off by default and separate from roster import and cloud sync. If enabled in More → Diagnostics & Logs, it sends your account identifier, app version, error count and submission time to support. It does not send raw roster lines, dates of duties, PDF/XLS attachments, diff contents, crew names, passwords or Health data. Turning it off stops future submissions; records expire after 30 days and are deleted by daily cleanup. Earlier app versions sent raw diagnostic lines and reconciliation files; these are covered by cleanup and account deletion. Local logging is a separate, optional setting. Local logs may include roster details and identifiers: review them before choosing to share a log. Logs are not uploaded automatically.
Location and Apple Maps
If you enable commute estimates and grant location permission, the app reads your location while in use and sends the route origin and destination to Apple Maps to calculate travel time. It does not upload your current location to the MyRoster Firebase database. Local commute history stores durations and time-of-day information; turning the feature off clears that history. Apple processes Maps requests under its own privacy policy.
Health, calendar and notifications
With your permission, sleep data from Apple Health is read on your device for the Fatigue Monitor. Sleep data, manual sleep entries and reaction-time test results are not uploaded to MyRoster servers. Account deletion clears app-local sleep/test data and preferences; it does not delete original Apple Health records. Calendar export writes events to the calendar you select. Notifications and alarms use the permissions you grant. Live Activities may send duty schedules and activity push tokens to Firebase and Apple’s push service. Biometric templates remain managed by iOS.
Crew Lounge safety
Reports are accessible to authorized MyRoster administrators and include reporter and reported account identifiers, the reason, details and relevant content, including a reported photo when available. Reports and moderation audit records expire after 90 days and are removed by daily cleanup, or earlier when an involved account is deleted. Blocks prevent Lounge trade interactions in both directions and can be undone in Tools → Lounge safety. Block records are removed when unblocked or when an involved account is deleted. Contact support to appeal a moderation decision.
Company services
MyRoster registration is separate from company portal access. Import requires valid employer-issued portal credentials. Portal sessions run in the app; credentials are sent to the relevant company service, not stored in your MyRoster cloud profile. If you use Remember me in LTC Web, its credentials are saved in the device Keychain. iOS AutoFill credentials are managed separately by iOS. Online parsing sends roster documents to MyRoster Cloud Functions for processing; private roster backup is part of account sync. When you confirm an LTC submission, the app writes the selected flight information to the company portal. Follow your employer’s rules for these services.
Retention and account deletion
Account and synced roster data are retained while your account exists. More → Delete Profile starts server deletion of the account, private data, stored roster files, your shared directory/photo/roster records, social interactions, diagnostic reports and purchase-to-account mappings. The app reports a failure if cleanup cannot finish, so it can be retried. A short-lived deletion marker prevents stale sessions from recreating the account. On the device, deletion removes app-managed rosters, shared import copies, profile caches, salary and leave records, sleep/test data, saved LTC credentials and local logs, and stops notifications, alarms and Live Activities. Copies you exported to Files, calendars, LogTen or company systems are outside this cleanup. iOS AutoFill, original Apple Health data and backups managed by iOS remain under your control. Uninstalling the app alone does not delete the cloud account, and Keychain items may survive uninstall. Deleting an account does not cancel an Apple subscription: use Manage Apple subscription in the deletion dialog or Apple account settings.
Your choices and service providers
You can change profile information, disable sharing or diagnostic uploads, remove your photo, revoke device permissions and delete your account in the app. Contact support for access, correction or export requests. Firebase/Google provides authentication, storage and Cloud Functions; Apple provides purchases, Maps and push services; Google Sign-In is used only if you choose it. Service providers may process data outside your country. We do not sell personal data, use it for advertising, track you across other companies’ apps or use roster/Health data to train AI models. Data may be disclosed when legally required. Transport encryption and access controls protect service communication and cloud access.
Changes and contact
Updates are published here and in the app with a fixed revision date. Optional diagnostic consent is separate from accepting this policy. Contact damianomiazzi@gmail.com for privacy questions or support. MyRoster is intended for adult flight crew.