Policy 01
Privacy policy
This privacy policy applies to the FlightNet applications for Android, iOS, and iPadOS. FlightNet is designed for communication between nearby devices on a temporary local network. FlightNet does not require an account and does not include advertising, analytics, tracking, or telemetry. FlightNet is developed and operated by Avi Titievsky; the privacy and safety contact is avititievsky@gmail.com.
Information kept on your device
The full FlightNet app stores a randomly generated passenger identifier, the name you choose to display, language and app preferences, local moderation choices, accepted-policy version, queued safety reports, optional assistant conversations and assistant memory, and app-managed cabin download copies. On Android, an assistant model file is also stored on the device if you choose to install it. Assistant conversations and memory, app-managed cabin downloads and attachments, identity data, model files, and FlightNet preferences are excluded from Android cloud backup and device transfer. This exclusion does not cover a copy you deliberately save through Android MediaStore or Android Downloads, which is outside FlightNet's app-managed backup scope.
On iOS and iPadOS, FlightNet's app-managed assistant history, queued safety reports, and session-scoped imported or downloaded cabin-file copies are marked to be excluded from iCloud and device backups. At the start of every new iOS or iPadOS app session, including the next app launch, FlightNet purges both app-managed Shared and Downloads directories before enabling file storage. If that startup cleanup cannot complete, file storage remains disabled rather than retaining or serving old copies. The passenger name, random identifier, accepted-policy version, identity metadata, and other app preferences may be included in an Apple device backup under your Apple backup settings. A copy you export or share to Files, another app, or a storage provider is outside FlightNet's app-managed storage and follows the destination's retention and backup rules. On either platform, a queued report is removed from the sending device only after the safety intake acknowledges that exact report ID. Without that acknowledgement, it remains until app data is cleared or the app is uninstalled.
How nearby connection works
Android cabins can use Android Wi-Fi Direct. On iOS and iPadOS, FlightNet discovers and connects to cabins with Bonjour over a shared local network. An iPhone or iPad may ask iOS to join an Android tower's fixed DIRECT-FlightNet Wi-Fi network; iOS displays and controls the explicit system consent for that association. Joining the network only creates a local path and does not admit the passenger to the cabin. An iPhone or iPad cannot host an Android-compatible Wi-Fi Direct group. Its tower mode advertises a Bonjour cabin and accepts connections only while FlightNet is in the foreground.
Information shared across the cabin network
FlightNet automatically discovers nearby cabins and may send a join request, but that request does not put the device aboard. Before a first-time or changed-key passenger receives any cabin roster, chat, file catalogue, game state, or call signalling, the passenger hosting the cabin must explicitly Allow or Reject the request. The tower's approval screen shows only the passenger-chosen, unverified display name. A short SHA-256 fingerprint is derived internally from the installation public key; it is never displayed and is never accepted from the requesting phone as an authority value.
The request shares your chosen name, a stable randomly generated per-install UUID, your installation public key, and proof that your installation possesses the matching private key with the current cabin host. The private key remains in Android Keystore, or in the iOS Keychain with Secure Enclave protection where the hardware and key type permit it, and is never shared. Allowing the request remembers that exact UUID and public key locally on the tower device, so the unchanged installation can reconnect to a later cabin hosted by that phone without asking again. A changed key requires a new explicit decision. The tower can forget a trusted device, which disconnects it if currently aboard and requires approval next time, or bar it; a bar overrides remembered trust.
Only after admission do other passengers see your chosen name in the app. Protocol-level identifiers are used internally for routing and trust, not displayed as identity claims. Content is transmitted only when a feature requires it: cabin messages go to cabin members; direct messages and call signalling are routed through the current cabin host; file bytes and call media travel directly between nearby devices where possible. The app does not upload this content to the FlightNet developer unless you deliberately include a short excerpt in a safety report. Cabin traffic is not represented as end-to-end encrypted at the application layer, so share only with a cabin and passengers you trust.
Calls and background behavior
On iOS and iPadOS, FlightNet does not use PushKit and does not provide background incoming-call delivery. An incoming cabin call can ring only while FlightNet is open and connected. After you accept a call, its audio may continue in the background when iOS permits it. Moving an iOS tower to the background stops that foreground-only tower session.
Permissions
- Android nearby devices, Wi-Fi, and location: used to discover, create, and join the local cabin network. FlightNet does not derive, save, or transmit your physical location.
- Apple Local Network and Wi-Fi association: Local Network access is used for Bonjour discovery and cabin connections. When FlightNet asks to associate with the Android tower's fixed network, iOS presents the system-controlled consent.
- Camera and microphone: used only when you start or answer a call, record media, or intentionally give media to the on-device assistant.
- Speech recognition: used only when you deliberately ask the iOS or iPadOS assistant to transcribe audio; FlightNet configures this work for on-device recognition.
- Notifications and vibration: used where enabled for an active cabin connection, calls, game invitations, and transfer status.
The assistant and internet access
Assistant prompts, images, recordings, and responses are processed on your device. On compatible devices running iOS or iPadOS 26 or later, FlightNet uses Apple Foundation Models only when Apple Intelligence and the local model are available. There is no cloud fallback: the assistant is unavailable when that local model cannot run. Image text extraction and requested speech transcription are configured for on-device processing. FlightNet does not download its Android Gemma model on iPhone or iPad and does not send Apple-device assistant prompts to the FlightNet developer or model mirror.
On Android only, installing an optional assistant model makes an HTTPS request to FlightNet's model mirror, which FlightNet operates and Iomart/RapidSwitch hosts in the United Kingdom. The mirror receives the connecting IP address, request time, and requested path as needed to answer the request. Successful static-file access logging is disabled. Only when a request errors, a bounded rolling operational error log may record its IP address, request time, and requested path. The error log occupies up to 50 MB and overwrites its oldest content by size rather than using fixed-day retention. It is used only for diagnostics and security, not for advertising or profiling. The optional E2B and E4B assistant models are part of Google DeepMind's Gemma 4 family and are provided under the Apache License 2.0.
On-device safety safeguards
Assistant safety uses three on-device layers. A standing system instruction tells the model to refuse sexual content involving minors, exploitation, instructions for self-harm or violence, non-consensual sexual content, malicious code, fraud, credential theft, and deceptive impersonation, and not to follow requests to ignore those rules. Before model inference begins, a deterministic on-device check looks for unmistakable high-risk text requests in English, Russian, and Hebrew and returns a local refusal instead of sending a match to the model. The same check runs on the completed text answer; if it matches, FlightNet stops continuing speech and replaces the answer with a localized refusal before marking it final. This focused phrase guardrail is not a general-purpose content classifier and cannot detect every harmful request or response. You can report an assistant response as described below.
A related focused high-risk phrase check also runs locally on chosen passenger names and outgoing and incoming chat text in English, Russian, and Hebrew. Restricted names may be rejected or replaced with a neutral label, and restricted chat text is not sent or shown. This check does not upload names or chat to the developer and, like the assistant safeguard, is not a general-purpose classifier.
Safety reports
In the full FlightNet app on Android, iOS, and iPadOS, choosing Report prepares a text report and tries to send it over HTTPS to the same FlightNet safety-report intake. If you are offline, the intake is not accepting reports, or it does not acknowledge that exact report ID, the report remains in the app-private queue. Delivery is retried while FlightNet is open and when FlightNet is next launched; the app does not promise a background retry while it is closed. The report contains a mandatory random report ID, your selected reason, optional description, the reported subject ID and display name, your random app identifier, app version, language, and submission time. A content-specific report also contains a content ID, and a short message, filename, or assistant-response excerpt only when you opt in. No image, audio, video, or file attachment is uploaded. Reports are stored in a protected safety inbox only after acknowledgement and are reviewed only for safety, abuse prevention, legal compliance, and service protection.
Current activation status: the new CabinMesh-hosted intake is intentionally not accepting reports while independently verified off-host backups, external failure monitoring, individually attributable and revocable moderator access, and live infrastructure validation remain incomplete. During this period the app receives no acceptance acknowledgement and keeps the queued report for a later retry. This does not prevent the reporting passenger from using the local Block control or contacting the safety address below.
Report-intake abuse throttling
Once the intake is enabled and ready, the hosting edge supplies the connecting IP address to it. The intake uses that address only in memory to calculate a keyed one-way SHA-256 marker combined with the current ten-minute window. It stores only that marker, the window start, and a request count in a separate throttle table; it does not write the raw IP address or attach the marker to a safety report. Every admitted attempt, including a retry of an existing report ID or a request later rejected as invalid, uses a source and service-wide throttle slot. In each ten-minute window, the current limits are 30 attempts per source marker and 3,000 attempts across the service. A report containing a non-empty random app identifier also has a lower limit of 10 attempts for that identifier. FlightNet Family does not send that identifier, so Family reports use the source, service-wide, and in-flight protections only. Each service process also admits no more than 20 report requests at once. Expired throttle rows are removed in bounded scheduled sweeps rather than during a report or moderator request.
Retention, deletion, and recipients
Cabin data lasts for the local session and on participating devices. People who receive a message, file, or call may retain what you send. Assistant chats and Android-installed models remain until you delete them in FlightNet; uninstalling FlightNet removes its private app data. Files you save to Android Downloads or another MediaStore location are not app-private and remain there until you delete them. Android peer downloads saved there remain until you delete them through Android Downloads, a files app, or device settings.
On iOS and iPadOS, app-managed imported Shared copies and completed Downloads are session-scoped and excluded from Apple backups. During that session, Stop Sharing retracts the offer and deletes its imported Shared copy. Every completed download remains listed in the current-session Downloads section, including after the sending peer departs, with Share / Save and a visible, confirmed Delete copy action. When FlightNet moves to the background, even if accepted call audio continues, it retracts shared-file offers, stops serving app-managed file bytes, and cancels active downloads. Starting the next app session purges both the app-managed Shared and Downloads directories. If cleanup fails, FlightNet keeps file storage disabled for that session. A copy exported to Files, another app, or a storage provider is outside FlightNet and persists until it is deleted under that destination's retention and backup controls.
A report copy in the safety inbox cannot be deleted from the sending phone after delivery. The service starts a bounded retention sweep when it starts and repeats it approximately hourly. Each sweep deletes report rows received more than 180 days earlier unless a moderator has placed a legal hold. A large backlog can require more than one sweep. Legal holds are rechecked while deletion candidates are locked, are limited to preservation required by law or an active safety investigation, and are released when that need ends. To request earlier deletion, email the privacy contact with the subject “FlightNet report deletion.” Include the reported passenger or assistant target, the report reason or other context you remember, the cabin name if known, and the approximate submission date and time shown in the app receipt, plus your time zone. FlightNet does not display its internal report ID on iOS or iPadOS. If the Android receipt you see actually displays a report ID, include it, but a report ID is not required. Because FlightNet has no account, the operator will use the supplied details to locate a unique candidate and may ask you to confirm additional non-public details from the original report and verify control of the reply email address. A report will be deleted only after the operator can reasonably verify that the requester was the reporter and identify a unique matching report; otherwise the operator will explain what additional information is needed. Do not email illegal imagery. The protected inbox provides a permanent delete action; a request may be deferred only while that report is subject to the limited legal hold described above. FlightNet does not sell personal data. Depending on the action you choose, data is disclosed only to:
- nearby recipients you interact with and the current cabin host where routing or admission requires it;
- Android or Apple system components on your device needed to perform a requested action, such as local-network association, on-device speech recognition, or installing a missing Android text-to-speech voice;
- the FlightNet-operated model mirror hosted in the United Kingdom by Iomart/RapidSwitch when you request an Android model download;
- the policy and safety-report hosting edge when you load these policies or submit a report, including the report and throttle handling described above; and
- authorities where disclosure is required by law.
Security and questions
FlightNet limits data to local, app-private, user-directed, and encrypted safety-report paths, but no wireless system can guarantee absolute security. Keep Android, iOS, or iPadOS updated, leave cabins you do not recognise, and use the report and block controls when another passenger misuses the service. Privacy questions can be sent to avititievsky@gmail.com.
Policy 02
FlightNet Family for ages 13–17
FlightNet Family is the separate Android application with package name com.flightnet.family. It is designed only for ages 13–17 using a closed group created by a parent, guardian, or other responsible adult organizer. It is materially different from the 18+ FlightNet application: Family has no public cabin discovery, teen hosting, stranger join requests, custom member names, free-text chat, files, calls, generative assistant, combat games, advertising, analytics, or purchases.
Private invitation and assigned identity
The adult organizer creates one short-lived, single-use QR for one assigned human-readable roster name. The Family app has no address or manual-code field and does not search for public cabins. When Camera is missing, every Family app entry first shows a large blocking explanation. Android's permission sheet opens only after Allow camera; X continues without scanning for that foreground visit, and the next entry checks again. Camera is used only for the in-app live QR scanner. It recognizes the code automatically from preview frames processed only on this phone; no shutter is required, and the frames are never saved, shared, uploaded, placed in media storage, or included in backup or device transfer. X closes the scanner without staging an invitation. FlightNet Family requests no media, location, Nearby Wi-Fi, microphone, notification, or foreground-service permission.
The signed invitation contains the assigned name, organizer display name, random group/member/invitation identifiers, a private-network numeric route, expiry, organizer public key, and a high-entropy one-time secret. Before the encrypted session begins, bounded random identifiers, public keys, non-secret challenge material, and cryptographic proofs cross the local network without transport confidentiality. They authenticate enrollment but are not described as encrypted. The invitation expires after five minutes and can be used only once. Do not photograph, post, or forward it to anyone else.
Enrollment, reconnect, and revocation
A successful first enrollment binds the exact Family installation key to the assigned roster member only after the phone decrypts and validates the organizer's first authenticated roster. Later reconnects require proof from that same installation key. A replacement or changed key requires a new adult-issued enrollment and is never trusted automatically. If the organizer's private Wi-Fi route changes, the organizer can issue a short-lived signed route-refresh QR for that exact existing member and installation; it changes no member identity, name, or trust key. The organizer can revoke membership at any time, after which reconnect and route refresh fail closed.
Enrollment and block state remain in backup-excluded app-private preferences until the user removes enrollment with the phone's device credential, clears app data, or uninstalls the app. The organizer keeps the exact member/key binding locally until revocation or Adult app-data removal. Roster actions show assigned names only; technical IDs, routes, keys, and fingerprints are not displayed as identity claims.
Local encrypted games
After enrollment, roster and game frames use per-session directional AES-GCM keys with strict sequence checking and travel only to the organizer's private IPv4/IPv6 LAN endpoint. Public/global addresses, DNS names, redirects, the Adult WebSocket path, binary frames, oversized frames, replayed frames, and traffic beyond bounded per-peer rates are rejected. Family permits only chess, checkers, tic-tac-toe, Mosaic Drift, and Snake. Every game member ID and assigned name must match the accepted roster; Family does not accept adult chat, files, calls, assistant, public-discovery, or combat-game frames hidden inside the encrypted channel.
Teen safety and reports
A teen can separately Block or Report another enrolled member by assigned name. Blocking refuses later game invitations from that member on the teen's phone; the adult organizer's revoke control is separate and applies to the whole group. A saved text report uses the same exact HTTPS intake, acknowledgement, retry, retention, deletion, and moderator process described in this policy. A Family report contains the selected reason, optional description, reported member ID and assigned name, random report ID, app version, language, and time. It does not include a reporter app ID. The queued local copy is removed only when the HTTPS intake acknowledges that exact report ID; without that acknowledgement, it remains until Family app data is cleared or the app is uninstalled. It contains no chat transcript, file, image, audio, or video attachment.
Google Play offline review access
The public Family reviewer page provides Google Play with one fixed signed QR for a clearly labelled offline review demo. That token is a separate review namespace, not a family invitation. It creates only an in-memory sample roster and the five Family game demonstrations on that phone, opens no socket, enrolls no member, contacts no person or device, stores no review membership, and disappears when the reviewer exits or the app process closes. A malformed review token is rejected and never falls through to normal enrollment.
Policy 03
Terms of use
By accepting these Terms in the full FlightNet application, you confirm that you are at least 18 years old and at or above the age of legal majority where you live. By accepting the separate FlightNet Family terms, the user confirms that they are 13–17 and have a private invitation created for them by a parent, guardian, or other responsible adult organizer. In either application, use FlightNet lawfully and do not join if you do not agree.
Your responsibility aboard
- Share only content you have the right and consent to share.
- Do not harass, threaten, impersonate, defraud, stalk, or expose another person's private information.
- Do not distribute malware, illegal content, sexual exploitation material, or content that endangers children.
- Do not interfere with another device, cabin, flight operation, crew instruction, or applicable aviation rule.
- Respect blocks, removals, and decisions made by the passenger hosting the cabin.
Service limits
FlightNet is a local communication tool, not an emergency service, telephone replacement, safety system, or guaranteed internet service. Availability depends on compatible Android, iOS, or iPadOS devices, radio conditions, the required permissions, and, for an iOS tower or an incoming iOS call, FlightNet remaining open as described above. An iPhone or iPad cannot host an Android-compatible Wi-Fi Direct group. The offline assistant may produce inaccurate or inappropriate answers; verify important information independently and do not rely on it for medical, legal, financial, safety, or flight operation decisions.
Moderation and enforcement
Passengers can block and report users or content. A cabin host may reject a first-time or changed-key join request before any cabin data is disclosed, forget a previously trusted device, or disconnect or bar a passenger. The approval screen shows only the passenger-chosen name, which FlightNet does not verify; the host should allow only someone they expect. Installation-key verification remains internal, and no fingerprint or device identifier is displayed as an identity claim. The developer can review a text report only after an enabled intake accepts and acknowledges it. The production intake is not currently accepting reports, so saved reports remain queued on the reporting device. The developer can update the app's safeguards and cooperates with lawful investigations when required. These Terms may be updated when the app or legal requirements change; a material update will require acceptance again in the app.
Policy 04
Community and child safety standards
Report and block
Use FlightNet's clearly labelled Report and Block actions on a passenger or assistant response. Report actions are also available for an incoming chat message and an incoming peer file. Including a short message or filename excerpt in a report is optional; no file bytes are included or uploaded. Blocking suppresses that passenger's messages, files, direct calls, signalling, and game interactions on your device. Reports are prepared inside FlightNet and try the configured HTTPS intake when an internet connection is available. The production intake is not currently accepting reports; unavailable or unacknowledged reports remain queued and retry while FlightNet is open and when it is next launched. Reports are text-only and never attach reported file or media bytes. For an urgent child-safety concern, also contact local law enforcement. In the United States, reports may be made directly to the NCMEC CyberTipline.
How reports are handled
If and when an enabled intake accepts and acknowledges a report, it is reviewed for violations of these standards and applicable law. The reporting passenger can block locally, and a cabin host can reject a new device before it boards, forget remembered trust, or disconnect or bar a passenger. Developer action may include preserving necessary report evidence, strengthening app safeguards, and reporting apparent CSAM to NCMEC or the relevant regional authority. Report text is subject to the scheduled 180-day deletion process described in the privacy policy above, including its narrowly limited legal-hold exception and report lookup and reporter-verification process.
Safety contact
Google Play, the Apple App Store, users, and authorities may send child-safety and abuse notices to avititievsky@gmail.com. Include “FlightNet safety report” in the subject, the displayed cabin and passenger names, what happened, and whether anyone is in immediate danger. Do not email illegal imagery; describe it and preserve it for lawful authorities.