Privacy Policy
Last updated: September 18, 2026
WingM8 ("the App", "we", "us") is a crew-roster and duty-planning tool built and operated by its creator (pITot Company) and made available to coworkers who use it voluntarily. This policy explains what data the App collects, how it is used, and how you can control it — including data accessed through Google Calendar and Microsoft Calendar integrations.
1. Who we are
The App is built and operated by its creator, under the name pITot Company. For any question about this policy or your data, contact us at firma.pitot@gmail.com.
2. What data we collect
- Account data you or your administrator provide: name, login, email address, role, and crew/duty information needed to build and display your roster.
- Usage data needed to operate the App (e.g. sessions, activity timestamps for support and troubleshooting).
- If you choose to connect a calendar (see below): an OAuth access/refresh token for the connected provider, stored encrypted, and the events the App creates on your behalf.
3. Google Calendar integration
If you connect your Google account under Account → Calendars, the App requests the
https://www.googleapis.com/auth/calendar scope. We use this access solely to:
- create, update, and delete calendar events that represent your own duty schedule (flights, standby, days off, etc.) on the calendar you choose to connect;
- read back only the events the App itself previously created, in order to keep them in sync with your roster and remove ones that no longer apply.
We do not read, modify, or share any other events, calendars, or Google data belonging to you. WingM8's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Microsoft Calendar integration
If you connect a Microsoft account instead, the App requests the Calendars.ReadWrite and
offline_access scopes, used the same way and for the same purpose described above, limited
to the calendar you connect.
5. Storage, retention, and security
Calendar access/refresh tokens are stored encrypted at rest and are never shared with third parties. Tokens and any events created by the App are retained only for as long as the connection stays active. Disconnecting a calendar (see below) revokes and deletes the stored token immediately.
6. Your controls
- You can disconnect a connected calendar at any time from Account → Calendars inside the App, which stops all sync and deletes the stored token.
- You can also revoke the App's access directly from your Google Account at myaccount.google.com/permissions, or from your Microsoft account's app permissions page.
- You can request access to, correction of, or deletion of your account data by contacting us at the email address above.
7. Data sharing
We do not sell your data and do not share it with third parties, except with the calendar provider you explicitly connect (Google or Microsoft), and only to the extent described above.
8. Use of data for development and testing
Providing data to the App (account details, roster/duty data, feedback, bug reports) is voluntary. We may use that data — including in non-production/test environments — to maintain, debug, secure, and improve the App, and to develop and quality-assure new or existing features. Where feasible for these purposes, we prefer anonymized, pseudonymized, or synthetic data over identifiable personal data. This does not extend to data obtained through the Google/Microsoft Calendar integrations, which is used only as described in Sections 3–4 above. See also Section 3 of our Terms of Service.
9. Cookies
The App uses only cookies that are strictly necessary to provide the service you request by logging in:
PHPSESSID— session cookie identifying your logged-in session; deleted when you close your browser or log out.REMEMBERME— set only if you choose "remember me" at login, to keep you signed in; expires after 7 days or on logout.- A CSRF-protection token tied to your session, used to protect forms against cross-site request forgery.
We do not use analytics, advertising, or third-party tracking cookies. Because we only use cookies that are strictly necessary for the service you explicitly request, no cookie consent banner is required under applicable law; you can still block or delete cookies via your browser settings, but doing so will prevent you from staying logged in. The App also stores your display-theme preference (light/dark) in your browser's local storage — this is not a cookie and is not transmitted to our servers.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
11. Contact
Questions about this policy or your data: firma.pitot@gmail.com.