AURORA

AURORA UAS
FLIGHT CONTROL

Free · Non-Profit · Community Driven
Last updated: 9 August 2026

Privacy Policy

This transparent technical privacy description is complete for the current platform functions. The controller’s postal details still need to be confirmed in the legal notice before final legal release.

1. Controller and contact

The operator named in the legal notice is responsible for processing. Privacy requests must be sent through the verified contact details published there.

2. Hosting and server logs

The website is hosted by one.com. When pages are requested, technically necessary connection data such as IP address, timestamp, requested resource, referrer and browser information may be processed in server logs for delivery, security and fault analysis.

3. Account and flight data

Registration stores email address, password hash, display name, country, language and verification status. Optional profile and drone data may include operator ID, qualification, drone details, serial number, Remote ID, insurance details, notes and images. Flight preparation can store mission data, location, coordinates, checklist states, weather, NOTAM confirmation, readiness and timestamps. Passwords and one-time tokens are not stored in plain text.

4. Cookies and email

A technically necessary session cookie keeps users signed in and protects forms. Transactional email is used for address verification and password reset. Mail events are recorded for delivery auditing and rate limiting. No advertising or analytics cookies are currently used.

5. Device location and external services

Location is requested only after an active browser permission. The browser sends coordinates to BigDataCloud for a readable location and to Open-Meteo for current weather. The cockpit loads icons from unpkg and opens official AIS/UAS-zone websites only when selected. These providers may receive connection data and the data contained in the request.

6. Retention and user rights

Data is retained while the account and associated records are needed. Expired one-time tokens become unusable; operational mail logs may be kept for security and rate-limit evidence. Subject to applicable law, users may request access, correction, deletion, restriction, portability or object to processing and may complain to a supervisory authority. A self-service account deletion function is not yet available; verified requests must use the legal-notice contact.