Privacy Policy
Effective 17 August 2026 · Last updated 4 October 2026
Your pay data is yours. We do not sell it, we do not advertise against it, and we never share it with your employer, your union, or anyone else who asks.
CheckSix is operated by Xon Designs, a business established in Texas, United States. This policy explains what we collect, where it is stored, and how you remove it. If anything here is unclear, email contact@checksix.co and ask.
1. What we collect
Your browser account
Your email address, and a password you set. Passwords are handled by Amazon Cognito. We never see or store your password.
The pay data you enter
Everything you record about your flying: bid periods, flights, deadheads, reserve days, supplements, notes, and the pay figures CheckSix calculates from them. You enter this data and it belongs to you.
Browser billing information
If you subscribe, Stripe collects and stores your name, billing address, and payment card. Stripe is our payment processor. CheckSix never receives or stores your card number. We store a reference that links your account to your Stripe customer record, and your subscription status.
The iPhone app
The native app uses your Apple account for iCloud and App Store purchases. It does not require a CheckSix browser account or send your pay records through our browser sync API. Apple handles purchase details. We receive purchase and subscription status through StoreKit, without your card number or Apple account password.
Feedback you send
If you use Send Feedback in the app or on this website, we receive what you write, the kind of feedback you chose, and the app version, build, and device model you were using. If you give an email address, we receive that too, so we can reply. If you turn on Attach my data, we also receive a copy of your profile and bid periods — the same file the export button saves. Attaching data is off unless you turn it on. You do not need an account to send feedback.
Technical records
Our servers keep short-lived operational logs, and counters used to limit sign-in attempts and prevent abuse. These records do not contain your pay data.
2. What we never do
- We do not sell, rent, or trade your data. There is no circumstance in which we would.
- We do not run advertising, and we do not share your data with advertisers or data brokers.
- We do not report your data to your employer, your airline, or your union. CheckSix has no relationship with any of them.
- We do not send marketing email. Every message we send relates to your own account.
3. How we use your data
We use it to run the service you signed up for: to sign you in, to store and sync your entries across your devices, to calculate your pay, and to bill your subscription. That is all.
Feedback is emailed to the two people who run CheckSix, who read it to find and fix problems. It is read by people. Nothing answers it automatically, and nothing in it changes how your pay is calculated until a person has checked it against the contract.
The pay calculations run on your own device, in your browser or the iPhone app. Our browser sync servers store entries; they do not compute your pay.
4. Where your data is stored
In the browser, your working copy is stored in local browser storage. When browser accounts and sync are enabled, account and synced pay data are stored on Amazon Web Services in the United States (US East, Northern Virginia). Signing out clears the working copy and preserves a local recovery copy.
On iPhone, pay records and pending changes are saved on the device. Cloud backup uses your private CloudKit database in iCloud. The app keeps recovery copies before imports, conflict resolution, and iCloud account changes. These copies remain on the device until app data is removed. We do not receive your private iCloud pay records unless you choose to attach them to feedback. Apple controls iCloud storage locations and protection. Network traffic is encrypted in transit.
Who else handles it
| Service | Role | What they hold |
|---|---|---|
| Amazon Web Services | Hosting, database, email delivery | Your account and pay data, and feedback while it is delivered |
| Apple | Native iCloud storage and App Store purchases | Private iCloud pay records and purchase information |
| Stripe | Payment processing | Your name, billing address, card, and invoices |
We use no other processors. We add none without updating this policy.
5. How long we keep it
The account retention periods below apply to browser accounts and AWS data. Native pay data stays on your device and in your private iCloud storage until you remove it; canceling an Apple subscription does not start our browser retention job.
| Data | Kept for |
|---|---|
| Your account and pay data | While your account is open, and for 12 months after you cancel. Then it is deleted. We email you twice before that happens, and if we cannot reach you we hold your data rather than delete it unannounced. |
| Saved copies of a bid period (created when two devices conflict) | 400 days. A copy that is the only record of that period does not expire. |
| Billing records held by Stripe | Under Stripe's own retention terms, for as long as tax and accounting law requires. |
| Feedback you send | Only as long as it is useful for resolving what you reported. Ask us at contact@checksix.co and we will delete it. |
| Operational logs | 30 days. |
6. Your rights
- Export. You can download all of your CheckSix data at any time, in any account state, including after your subscription lapses. This never requires our help.
- Correct. You can edit or delete entries while your account permits changes. Reading and export remain available after a lapse.
- Delete. You can delete your account yourself. See below.
- Ask. Email us and we will tell you what we hold about you.
When you delete your browser account
This is deleted: your profile, all of your bid periods and every entry in them, any saved copies of a bid period, and your sign-in details. Your subscription is cancelled at the same time.
This is kept: your billing records — the invoices for what you paid, and the name and billing address on them. Stripe holds these for tax and accounting records, under their own retention terms. We keep no other information about you.
Deletion is scheduled and takes effect after 30 days. You can cancel it during that time, until deletion execution begins. After that, your data cannot be recovered. Export your data first if you want to keep a copy.
Removing native data
Removing the iPhone app removes its local working and recovery copies. Remove its iCloud data through your Apple iCloud storage controls as well if you want to remove the cloud copy. Exported files and copies on other devices must be removed separately. Cancel an Apple subscription in Apple subscription settings; deleting browser data or uninstalling the app does not cancel it.
7. Security
Data is encrypted in transit and at rest. Your browser session is held in a cookie that JavaScript cannot read. We never store card numbers. No system is perfectly secure, and we do not claim otherwise — but we do not collect data we do not need, which is the strongest protection available.
8. Children
CheckSix is a professional tool for working airline pilots. It is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18.
9. Changes to this policy
We post the current policy and its date on this page. For material changes affecting browser accounts, we email the account address before the change takes effect. The iPhone app does not require an account email; check this page for its current policy.
10. Contact
Xon Designs, Texas, United States — contact@checksix.co
11. Independence
CheckSix is an independent product. It is not affiliated with, endorsed by, or connected to Air Transport International, any airline, or any pilot union. Nothing in CheckSix is an official record of your pay.