AIRBORED · THE DETAILS
Privacy Policy
Play locally. Sync when you choose. This policy separates what stays on your device from what an account or another service handles.
Last updatedWhat stays on your device
Airbored uses IndexedDB databases called “airbored” and “airbored-personal” to store game saves, activity history, favorites, journey plans and flight records, downloaded-content metadata, sync state and the last downloaded news edition. Guest play does not itself send this progress to a cloud account.
LocalStorage remembers theme and sound choices, installation guidance, account/sign-in helper flags and your versioned privacy choice. SessionStorage supports internal navigation. The service worker uses Cache Storage for app files, verified offline essentials and downloaded packs. These mechanisms are browser storage, not all cookies.
Flight-log records contain the airports, dates, planned duration and other journey choices you enter. Passport progress and statistics are derived from activity and journey records; Airbored does not request GPS location to create them.
Accounts and cloud progress
If you register, Firebase Authentication handles your email address, credentials and authentication identifiers. Airbored’s Firestore profile includes an account ID, email, display name, optional username, avatar choice, account preferences, role/status and creation/update timestamps. Airbored does not store your password in the profile database.
Google sign-in supplies account identity information such as your email and display name through Firebase. Google manages the Google credentials and sign-in interaction. Airbored uses a chosen avatar code rather than an uploaded profile photo.
Supported cloud data includes game-state/progress records and downloaded-pack markers, game starts/completions and activity duration, XP, achievements, challenge progress, favorites and flight records. Sync can transfer local history into the account when you sign in; review the account export and sync controls in Settings. Local news editions and downloaded pack files are not uploaded as your cloud profile.
Profile settings include visibility and leaderboard preferences. Those settings are not a promise of a public community or leaderboard feature. Account data is used to provide the implemented profile, sync, history and reward features.
Optional analytics
Google Analytics 4 is present, using measurement ID G-XFR9J977D4. It loads on public pages only after Analytics consent in this browser; it does not load on the account, admin, dashboard, profile, flight-log, passport, challenge, statistics or generated flight-pack pages. It can receive page-visit and interaction measurements, browser/device information and network information such as your IP address, and use first-party analytics cookie identifiers. Airbored omits URL query strings, fragments and referrer details from its page configuration to avoid sending sign-in link codes or journey state.
Airbored does not configure advertising trackers, Google Signals or advertising personalization. It does not send your email, display name, game-save contents or flight-log records to Google Analytics.
Limited product events, such as a pack download, flight-pack creation or playlist replacement, are recorded locally only with Analytics consent. They are uploaded to your account’s Firestore events collection only with that permission and the separate “Help make Airbored better” account setting. These events are linked to your account and are not described as anonymous.
Reject optional or change Cookie preferences to stop new optional analytics. Withdrawal clears accessible Google Analytics cookies and local product-event records; it does not undo processing that occurred while permission was in place or automatically delete previously uploaded account events. Account deletion covers those cloud events.
Service providers and external links
Google Firebase provides Authentication and Firestore. Firebase Hosting serves the auth.airbored.com authentication helper; the main static site uses Apache/DirectAdmin hosting. DirectAdmin is a control panel, not the name of the hosting provider. The operator must confirm the provider’s identity and log-retention settings.
Hosting receives the network details needed to serve requests and may keep access/error logs with IP addresses, requested paths, timestamps and user-agent information. Firebase Authentication processes IP addresses and user-agent information for sign-in security and abuse prevention. Provider-level technical logs are separate from the optional analytics choice.
The Guardian edition is fetched by a server-side script and served as a static JSON file from Airbored. Your browser does not call the Guardian API to obtain the edition. Opening an article or attribution link visits The Guardian, where its own privacy and storage rules apply. No full-article scraping or AI summarization is used.
No payment service, advertising platform, session-replay service or marketing-email system is part of this audited frontend. Password reset, verification and email sign-in use Firebase’s built-in email flows. Custom Resend email code exists in the repository but is not used by the current account flow.
Purposes and legal bases
Where GDPR applies, account and sync information is used to provide the service you request, and necessary technical information supports legitimate interests in operating and protecting the service. Optional analytics relies on your consent. Responding to a support/privacy request uses the information you supply to deal with that request; applicable legal obligations may also require processing.
You can use guest entertainment without consenting to analytics or providing an account email. Avoid entering sensitive personal information into optional names or journey records.
Retention and deletion
Local progress remains until you clear it, remove downloaded content, clear browser/site data or the browser evicts it. The news cache holds the latest successful edition rather than accumulating old editions. Old app-cache generations are pruned during updates. Clearing browser storage also removes the local consent choice.
Supported account records are retained while your account exists; this app does not implement an automatic inactivity-expiry period. Settings can export cloud data and delete the implemented user records and Firebase Auth account. Signing out alone does not delete cloud or local records.
Provider security logs and backups follow their provider’s retention processes and may not disappear immediately with an account deletion. Firebase documents that Authentication logs IP addresses for a few weeks and removes other authentication information from live/backup systems within 180 days after deletion is initiated. Hosting-log and Google Analytics property retention settings still require operator confirmation.
International processing
Google/Firebase and any hosting provider may process information outside your country. The operator must confirm the relevant locations, provider arrangements and applicable transfer safeguards. This policy does not invent a database region, a local-only hosting promise or an executed contract. Google publishes its Firebase privacy and data-processing information; see the provider references below.
Your choices and rights
Settings provides export, profile correction and account deletion; device-data controls are separate. Cookie preferences is always available in the footer. Optional consent can be withdrawn as easily as it is given without affecting guest gameplay or necessary account functions.
Where GDPR or equivalent law applies, you may request access, correction, erasure, restriction, portability or object to processing as appropriate. You may withdraw consent and complain to your competent data-protection authority. These rights can be subject to lawful exceptions and identity verification.
Use the Contact page for support and privacy requests. Contact details and the operator’s legal identity must be supplied in the legal configuration before this notice is published as a complete operator disclosure.
Your privacy controls
Settings includes profile, account export/deletion and device-data controls. Change optional tracking separately here.
Operator & contact
- Operator
- Legal identity awaiting confirmation.
- Country
- Awaiting confirmation.
- Service address
- Awaiting confirmation.
- Support & privacy
- Contact email awaiting confirmation. No unverified mailbox is listed.
Operator disclosure is incomplete until these details are confirmed. The description of the application and its privacy controls is implemented; no business identity or jurisdiction has been assumed.
- Hosting provider
- Awaiting confirmation; main site uses Apache/DirectAdmin.
- Hosting-log retention
- Awaiting confirmation.
- Analytics retention
- Google Analytics property setting awaiting confirmation.
- International transfers
- Locations and applicable safeguards awaiting confirmation.