Legal

Privacy policy

Last updated: 29 September 2026

RosterAmigo (“the app”) is operated by Casamigo AS, org. no. 937 761 872, registered in Norway (“we”, “us”). Casamigo AS is the data controller for the personal data described in this policy. You can reach us at support@rosteramigo.com.

The short version: your roster, logbook and flight history live on your own phone. Our servers store your account, a private backup of your app data that only you can access (on by default, can be turned off), and your roster while you share it or have notifications switched on — always with your colleagues’ names removed before it leaves your phone. We show no ads, run no marketing analytics and never sell data; crash reports and basic diagnostic events (such as whether a sync succeeded) help us fix bugs.

1. Data that stays on your device

Most of what RosterAmigo works with never leaves your phone:

This data is stored locally in the app’s storage on your device. It is included in device backups according to your phone’s backup settings, and you can export and restore it yourself using the app’s backup feature. If you delete the app, this local data is deleted with it. So that a lost or replaced phone never costs you this data, the app also keeps a private cloud backup of it on your account — see section 3.

Your phone’s calendar. If you turn on Keep my calendar updated, RosterAmigo writes your duties (dates, check-in and check-out times, routes, flight numbers, standby and course titles, and optionally days off and vacation – and, if you choose, planned days off, vacation and pending vacation requests from your airline’s vacation planning) into the calendar you choose on your phone. Crew names and hotels are never written. This happens on your device; nothing is sent to us. RosterAmigo reads the chosen calendar only to find and update the events it created itself, and never changes other events. You can remove them at any time under More → Calendar.

If you choose a shared calendar (for example an iCloud or Google family calendar), everyone with access to that calendar can see these duty times, and your calendar provider (Apple or Google) syncs and stores them under its own terms.

Your logbook app. If you use Send to your logbook app, RosterAmigo hands your flown flights (date, route, block times, aircraft registration and type, flight number, the commander’s name, your own role and times, and any passenger count you have entered) directly to the app you choose – Logger or LogTen Pro – on your own phone. Nothing is sent to us or through our servers, and the receiving app handles the flights under its own privacy policy. RosterAmigo remembers on your phone which flights it has sent, so it can offer only the new ones next time.

2. Your airline crew portal login

To sync your roster, the app opens your airline’s own crew portal (NetLine/CrewLink) in a secure in-app browser window. To save you typing, the app fills in your crew-portal username (which you stored in the app; it is kept on your device and, if you have cloud backup switched on, in your own private backup so sync works on a new phone — never shared with anyone else) on your airline’s own sign-in page and submits it — you then approve the login yourself with your airline’s push authentication (e.g. HYPR) on your phone. Your airline password is never asked for, seen, transmitted or stored by us. The browser window runs hidden so you see a simple progress status instead of the raw portal; you can show the portal at any time from the sync screen. The app then reads your roster report from the portal session and stores the result locally on your device.

Live roster (version 1.1 and later). Live roster is on for Norwegian crew with an active subscription; its status is shown under More → Sync. When it is on, the app signs in to your airline’s crew system (NetLine Crew) the same way — on your airline’s own sign-in page, with your push authentication — and keeps the resulting access token, which your airline’s system issues for a few days at a time, in your phone’s secure storage (Android Keystore / iOS Keychain). The token never leaves your device: it is not included in backups, diagnostics or crash reports, and we never see it. With it, the app reads your roster directly from your airline’s system (read-only, a few small requests per day, including a short background check about every 15 minutes while it is on) so it can refresh your roster automatically and notify you of roster changes and newly published months. To make that check run sooner, our server sends crew a few silent push messages a day that contain no text and no data about you; they only wake the app so it can make the check itself, on your phone. The app reads only your roster, flight times, aircraft registrations, hotel details and the crew lists of your own flights — and, only when you open a standby hint, the crew list and aircraft of that possible flight, which stay in the app’s memory and are never saved or uploaded; it deliberately discards colleagues’ phone numbers and home bases, which your airline’s system may include. On standby days the app can also run the same flight search your airline’s web app offers, to see whether NetLine already lists you on a flight that is not on your roster; the result stays on your device and is never uploaded or shared. Signing out deletes the token immediately.

3. Data we store on our servers

An account is required to use the app. Sign-in happens with your Google or Apple account — we never see or store a password. When you use the app’s cloud features, we process:

DataPurpose
Email address and display name from your Google or Apple accountAccount creation and sign-in, and showing your name to people you share with
Your crew ID, airline and home base (read from your roster when you sync)Lets colleagues at the same airline find you by exact crew ID; the home base decides which features and announcements apply to crew at your base. You can turn the crew-ID search off in the app (Account → findable by crew ID)
Your roster as the app holds it, past months included, with colleagues’ names, course participants, hotels and remarks removed: your name and crew ID, duty dates and day types (including days off, vacation and sick days), flights with scheduled and actual times and aircraft registrations, hotel pick-up times, layover stations, standby and ground activities with their codes, and your vacation plan as day types. Uploaded while you actively share — with at least one connected person or an open invite code — or while notifications are switched on in the app (crew). Deleted from our servers when neither applies: you have removed your last share and turned notifications off (More → Notifications), or you sign out without sharing. If your phone is offline at that moment, the deletion is completed the next time you open the app with a connectionShowing your roster to friends and family you have invited, and finding shared days off with other crew members. Sharing your roster shares the roster — everyone you connect with sees the same view, and you choose per person whether they also get arrival notifications. Notifications are worked out on our server so they reach you when the app is closed (inbound aircraft delays, landing and “time to leave for work” notifications, and the Live Activity that starts by itself on iPhone) — that is why the roster is there while they are on. Without a connection to you, no other user can read it
Career statistics derived from your logbook: the number of times you have landed at each destination, and the date of your earliest logged flightShowing the people you share with career facts such as “5th time in Barcelona”. Uploaded together with the roster above and deleted with it. Only aggregated counts per airport are uploaded — never individual logbook entries, block times or aircraft registrations
Invite codes you generateConnecting you with the people you invite; codes expire automatically after 7 days
Swap market listings, if you post one (beta): your name, crew ID, rank, base, the duties or dates you offer, your note, and a work/off indication for the days around them. Interest you show in a colleague’s listing includes the duties you would give in return and your messageLetting verified colleagues at your own airline see what you want to swap and agree a swap with you. Visible only to signed-in users at your airline. Colleague names from your roster are never included. Listings are deleted 30 days after their last date, or when you remove them. Reports of inappropriate listings are reviewed by us
Your profile photo, if you choose to add one (stored as a small thumbnail)Shown on your row in colleagues’ crew lists, so the people you fly with can recognise you. Visible only to signed-in users at your own airline, and only while you are findable by crew ID. Remove the photo in the app at any time to delete it from our servers
A push notification token for your device, if you enable notificationsDelivering notifications such as “landed” alerts to people you share arrivals with. Removed when you turn notifications off or delete your account
Getting-home preferences, if you set them up: your home base, whether you travel by public transport, car or as a commuting passenger on your airline’s own flights, your chosen stop and saved destination — which may include an address with map coordinates when you actively pick one — or the airport you fly home to, and the notification and timing settings you chooseWorking out your journey home after landing and, if you switch it on, sending you the departure or drive time that matches your arrival. Stored only when you configure the feature, and deleted when you clear it or delete your account
A private backup of your app data: your roster, logbook, settings and colleague names as printed on your roster. Uploaded automatically after each sync and import while cloud backup is on (it is on by default and can be turned off in the app under More → Backup & sharing, which also deletes the server copy)Restoring your roster and logbook when you lose or replace your phone. The backup is visible only to you — access rules on our servers prevent anyone else, including people you share with, from ever reading it

Before any roster is shared, the names of your colleagues are removed on your device. Crew names are never visible to anyone you share with; they exist on our servers only inside your own private backup, which no other user can access.

The family view can also be opened in a web browser at rosteramigo.com/app instead of the app. The browser version reads exactly the same shared roster data as the app and stores nothing extra on our servers. Signing in on the web keeps your session and a copy of the rosters already shared with you in that browser’s local storage, so the page works when you reopen it; use More → Sign out to remove it, which also signs you out of that browser only — your phone stays signed in. This matters on a shared or family computer.

Our backend is provided by Supabase and hosted in the European Union (AWS region eu-north-1, Stockholm). Supabase acts as our data processor under a data processing agreement.

4. Data fetched from public sources

Some features fetch publicly available data directly from your device, such as weather reports (aviationweather.gov, Open-Meteo), airport status (Avinor), the live position of an aircraft looked up by its registration from the open ADS-B network adsb.lol, aircraft type and registration lookups (adsbdb.com, hexdb.io) and aircraft photos (Wikimedia Commons, with planespotters.net as a fallback — the lookup sends only the aircraft registration). For “landed” notifications to the family members you share arrivals with, our server makes the same registration lookup at adsb.lol for flights outside Norway (Avinor’s feed covers Norwegian airports); adsb.lol receives only the aircraft registration, never your name or account. The Getting-home feature queries Entur’s public Norwegian journey planner; when you search for a destination there, the text you type (which may be an address) is sent to Entur’s geocoder to find it. For bases outside Norway, and when Entur finds nothing, the same text is sent to the Photon geocoder (photon.komoot.io, built on OpenStreetMap data) instead, together with the coordinates of your base airport so nearby results come first. If you choose to get home by car, the drive time with live traffic comes from the Google Routes API (Google Ireland Ltd): our server sends Google the map coordinates of your base airport and of the destination you saved, and the intended departure time — never your name, account or roster. If you switch on the “time to leave for work” notification, our server asks the same services for the journey in the other direction: Google receives the coordinates of your saved address and of the airport with the time you need to arrive, and Entur receives your saved stop or address coordinates, the airport and the arrival time — never your name, account or roster. If your base is Stockholm Arlanda, public transport journeys (both directions) and destination search come from Trafiklab (Samtrafiken i Sverige AB) instead of Entur: our server sends Trafiklab the coordinates of the airport and of your saved stop or address, the time, and, when you search, the text you type — never your name, account or roster, and Trafiklab does not see your device or IP address. Google processes these requests under the Google Maps Platform terms; the request is made by our server, so Google does not see your device or IP address. The app’s maps load map tiles from OpenFreeMap, and the one-time logbook PDF import loads the PDF.js library from the cdnjs content delivery network (Cloudflare); your PDF itself is processed on your device and is never uploaded. These requests are made from your device and are subject to those services’ own terms. We send them only what is technically necessary for the lookup (for example a flight number, aircraft registration or the place you searched for) — never your identity or account details.

Amigo deals. The app downloads the list of places that offer a discount to RosterAmigo crew (name, category, discount, address, map position and contact details of each place) from our server and keeps a copy on your phone, so it works offline on layover. Which places are shown first, and the walking distance from your crew hotel, are worked out on your phone from your roster: to find your crew hotel on the map — for tonight and for your next layover — the app sends the hotel’s name together with its address or city (and the coordinates of the airport) to the Photon geocoder described above, directly from your phone. It never sends your name, account or roster, and it remembers the result on your phone. When you open a place, our server looks up its opening hours and Google rating in the Google Places API (Google Ireland Ltd); Google receives only the place’s own Google identifier — never your name, account, roster or location — and we do not store the answer. Your RosterAmigo card shows your name, profile photo and the month you became a member on your own screen only; nothing about the card is uploaded. When you open the card from a place, we count that the card was shown at that place in that month — the count is anonymous and never stored with who you are. To stop abuse, our server also keeps a counter per account of how many times the card was shown today (not where); it is deleted every night and with your account.

In the browser version, three of these sources (Avinor, adsb.lol and aviationweather.gov) cannot be contacted directly by a web page, so those requests are relayed by our own server instead. The relay passes on only what the lookup needs — a flight number, airport or aircraft registration — adds nothing about you, and stores neither the request nor the response. Every other lookup (aircraft photos and type, map tiles, place searches) is made straight from your browser, as on the phone.

5. Subscriptions and payments

The app’s subscription is purchased through Apple’s App Store or Google Play. Your payment details are handled entirely by Apple or Google — we never see your card number or billing details. To know which features to unlock, we use RevenueCat as a data processor: it receives your purchase receipt and an app-specific user ID from your device and tells the app whether a subscription is active. Manage or cancel subscriptions in your App Store or Google Play account settings.

6. Crash reporting and diagnostics

So we can find and fix bugs, the app sends crash reports via Sentry (hosted in the EU). A crash report contains technical information such as device model, operating system and app version, and what the code was doing when it failed. We configure Sentry to not include your identity, and reports are not used for advertising or profiling. Sentry acts as our data processor.

The app also sends a small number of diagnostic events to our own servers (the same EU-hosted backend as in section 3): whether a roster sync succeeded or failed, a short technical status message, the app version and platform, and a once-a-day “app opened” event. If you use Per diem, the app may also report the name of a ground-duty code it does not recognise (never dates, times, places or anything else from your roster), so we can teach the app the code. From version 1.1.6 the app also sends, at most once a day per feature, the name of a feature you used — for example “Per diem”, “Logbook” or “Flight search” — so we know which parts of the app are used and where to spend our time. It never includes what you looked at, searched for or entered. These events are linked to your account so we can help you if something breaks, but apart from such a code they never contain your roster, logbook or any flight data. They are used only to keep the app working — for example to spot the same day that a sync problem starts affecting users — never for advertising or profiling, and they are deleted automatically after 90 days (immediately if you delete your account).

Troubleshooting package (only if you choose to send one). If something in your roster is shown incorrectly, you can send us a troubleshooting package from More → Sync → Advanced, or when our support asks for one in the app. Nothing is sent unless you tap “Send”. The package contains your own roster as your airline’s crew system delivers it, how the app interpreted it, and the app’s technical sync logs. Before it leaves your phone the app removes your colleagues’ names and employee numbers and free-text remarks; it never includes your sign-in token or username. Packages are used only to fix the problem, can be read only by RosterAmigo support, and are deleted automatically after 30 days (immediately if you delete your account).

The same diagnostic events are sent from the browser version, where the platform is recorded as “web”. Crash reporting is not enabled in the browser version.

We process account, subscription and sharing data to provide the service you signed up for (GDPR Art. 6(1)(b), performance of a contract). We process crash reports and support enquiries you send us on the basis of our legitimate interest in keeping the app working and helping you (Art. 6(1)(f)).

8. No ads, no marketing tracking

The app and this website contain no advertising, no marketing or behavioural analytics beyond the once-a-day feature names in section 6, and no ad-tracking SDKs. The only third-party SDKs that send data off your device are the crash reporting described in section 6 and the subscription check described in section 5; the diagnostic events in section 6 go to our own backend. We do not build profiles and we never sell or rent personal data.

The browser version at rosteramigo.com/app sets no cookies and runs no analytics. The only things kept in your browser are what is needed to keep you signed in, your language and appearance choice, and an offline copy of the rosters already shared with you.

9. Retention and deletion

10. Your rights

Under the GDPR you have the right to access, rectify, erase and export your personal data, to restrict or object to processing, and to withdraw consent where processing is based on consent. Contact us at support@rosteramigo.com and we will respond within 30 days. You also have the right to lodge a complaint with a supervisory authority — in Norway, the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no).

11. Children

RosterAmigo is not directed at children under 13, and we do not knowingly collect personal data from them.

12. Changes to this policy

If we change this policy, we will publish the new version on this page and update the date at the top. For material changes affecting account holders, we will also notify you in the app.