Your crew data stays under your control.
This policy explains the information Boopo handles, why it is needed, who can receive it, and the controls available to you.
Last updated: 24 August 2026Boopo is operated by Joseph Soh in Singapore. Privacy and support enquiries: support@boopo.app.
Information Boopo handles
- Account and identity: your display name, friend code, home base, country, phone number or email, and identifiers from Apple, Google, or phone sign-in. When you use Sign in with Apple, Boopo stores an encrypted Apple refresh token only so that authorization can be revoked when you delete your account.
- Profile and crew: your profile photograph, friends, a small discoverability thumbnail derived from that photograph, requests, blocks, reports, sharing choices, and Heart Ping activity.
- Roster and flight: files you choose to upload and the duties, flight numbers, airports, dates, times, and trips extracted from them.
- Location: an approximate coordinate and permission state when you allow location access. By default, Boopo updates it while you use the app. If you separately turn on Update between app visits and grant Always location access in iPhone Settings, iOS may also deliver significant location changes while Boopo is not open. Friends receive the stored approximate coordinate only when your global and per-friend sharing choices allow it.
- Device and service: session records, push-notification tokens, delivery events, request timing, security events, and other operational records needed to operate and protect Boopo. If you separately enable Share diagnostics, Boopo also receives privacy-limited app version, iOS version, feature, result, status, timing, and bounded MetricKit performance or diagnostic-category counts. When Boopo crashes, its crash monitor may receive the app version and build, iOS version, device model, stack trace, and limited technical crash context. Support emails are handled separately through Boopo's support mailbox.
Location updates between app visits
Background location is optional and is not enabled merely because you allow location while using Boopo. To use it, you must turn on Update between app visits in Boopo and separately grant Always location access through iOS. When both are enabled, Boopo asks iOS for significant location changes so an approved friend can see a more recent approximate position after you leave the app—for example, after reaching a layover city. iOS decides when and whether to deliver those updates, so this is not continuous tracking and Boopo cannot guarantee a real-time position.
Boopo rounds the coordinate before publishing it. The app labels recent and older positions by freshness and stops showing a Globe pin once the last shared position is more than 24 hours old. You can stop new background updates at any time by turning off Update between app visits in Boopo, changing Location access to While Using or Never in iPhone Settings, or disabling location sharing globally or for an individual friend.
How Boopo uses information
- Create, authenticate, secure, and support your account.
- Turn roster files into the calendar and flight information you requested.
- Show approved crew, approximate location, and roster-based flight estimates on the Globe.
- Show a small profile thumbnail to signed-in people searching for you or viewing a pending friend request.
- Deliver Heart Pings, friend activity, and notifications you allow.
- Apply sharing restrictions, blocks, abuse limits, and safety reports.
- Diagnose failures, maintain reliability, and prevent misuse.
Friends and sharing
Your global Settings are the maximum you will share. Sharing & Access can further restrict Location on Globe and Flight on Globe for an individual friend. Roster access uses a separate request and approval flow, and can be revoked. Blocking removes the crew connection and prevents both people from seeing each other’s Globe location, roster-based flight estimate, roster, or profile photographs, including the smaller friend-search thumbnail.
Boopo does not sell your personal information or use your roster, location, or profile photograph for third-party advertising.
Service providers
Boopo uses providers only where needed to deliver a feature:
- Cloudflare for network delivery, application hosting, storage, and security.
- Google Gemini API to extract structured roster information from the redacted copies you approve for that purpose.
- Mapbox to display and interact with the Globe map.
- Apple and Google when you choose their sign-in services.
- Twilio when you choose phone-number verification.
- Apple Push Notification service to deliver notifications to your iPhone.
- Axiom to store and query privacy-limited server reliability, security, and optional iPhone diagnostic events.
- Sentry to receive and group iPhone crash reports needed to diagnose app failures.
These providers may process information in countries other than your own under their own infrastructure and legal obligations. Boopo limits the data sent to what the selected feature needs.
Diagnostics and monitoring
Boopo records limited server-side reliability and security events needed to operate, protect, and troubleshoot the service. On your iPhone, Share diagnostics is optional, disabled by default, and can be changed at any time in Boopo Settings. Turning it off stops new optional iPhone diagnostic events.
Diagnostic payloads are built from an allowlist. Boopo does not place names, email addresses, phone numbers, profile photographs, contacts, location coordinates, roster content, flight numbers, authentication credentials, raw URLs, or raw error messages in Axiom telemetry. Events may contain random request or app-launch identifiers so related technical steps can be investigated. MetricKit summaries contain only bounded payload counts and categories such as crash or hang. Boopo does not export raw MetricKit JSON, call stacks, device metadata, or signpost content to Axiom.
Axiom telemetry is routed to Boopo datasets in the European Union and retained for 30 days. Apple, TestFlight, and MetricKit remain the primary sources for detailed iOS crash and performance diagnostics; Axiom receives only Boopo's bounded summaries, app events, and client/server request journeys rather than advertising or cross-app tracking.
Sentry is configured as a crash-only monitor in its European Union region. Boopo disables performance tracing, profiling, session replay, screenshots, view-hierarchy capture, app-hang monitoring, request-failure capture, breadcrumbs, and Sentry's generative-AI features. Boopo does not identify a signed-in person to Sentry, and server-side IP storage and data scrubbing are enabled. Sentry's technical crash reports are separate from the optional Share diagnostics setting because they are needed to identify serious app failures affecting the service.
International data transfers
Some providers may process information outside Singapore or the country where you use Boopo. Boopo limits transferred information to what the selected feature needs and uses provider and contractual safeguards intended to provide protection comparable to applicable Singapore data-protection requirements. Axiom diagnostic-event ingestion and datasets are configured for its EU Central region; limited account administration, support, or subprocessor activity may still occur in other countries under the provider's contractual terms. Sentry crash-event storage is configured in the European Union; limited account administration, support, and subprocessor processing may similarly occur in other countries under Sentry's contractual terms.
Retention and deletion
Active account, roster, profile, friendship, and sharing records are kept while your account or the relevant feature remains active. Removing a roster upload takes it out of active use immediately; its superseded or deleted record and parsed roster data are permanently purged within 30 days. Deleting your account removes its active profile, roster, social, sharing, notification, photo, and session records.
- Expired or revoked sign-in sessions: 30 days.
- Read notifications: 90 days; unread notifications: 180 days.
- Inactive or stale push-notification tokens: 30 days.
- Background refresh diagnostics: 30 days.
- Server reliability and optional iPhone diagnostic events in Axiom: 30 days.
- Sentry iPhone crash events: up to 90 days under the active Sentry plan.
- Authentication and social-action rate-limit counters: 2 days.
Account deletion also removes active block and report records associated with the account. Provider infrastructure logs, recovery copies, and support correspondence follow the relevant provider's configured or contractual retention schedule and may persist after active Boopo records are removed.
Your choices
- Change global and per-friend sharing choices in Boopo.
- Approve, limit, or revoke roster access person by person.
- Mute, remove, block, or report another user.
- Turn updates between app visits on or off in Boopo Settings.
- Change location, photo, contacts, and notification permissions in iPhone Settings.
- Remove uploaded rosters or permanently delete your account.
See the account deletion guide for the in-app steps. You may also contact support to ask about access, correction, deletion, or another privacy right available where you live.
Privacy questions
Can I turn optional diagnostics off?
Yes. Share diagnostics is off by default and can be changed in Boopo Settings. Turning it off stops new optional iPhone diagnostic events; limited server reliability and security records may still be processed where needed to operate and protect Boopo.
Does Boopo share my exact live location?
Boopo’s service stores an approximate coordinate for the Globe. A friend sees it only when iOS location permission, your global setting, and that friend’s individual access all allow sharing. If you explicitly enable updates between app visits and grant Always access, iOS may provide significant changes while Boopo is not open; this remains approximate and is not guaranteed to be continuous or real time.
Who can load my full profile photograph?
You and accepted friends can load it. A blocked person cannot load your full photograph through the authenticated profile-photo endpoint. Signed-in people may see a separate, small thumbnail while searching for you or viewing a pending friend request, so they can confirm they found the right person. Blocked people cannot load that thumbnail.
What happens to a roster sent for extraction?
Boopo first checks the selected pages on your iPhone and covers recognised crew lists, colleague names, staff numbers, passenger details, and security information. You review that private copy and explicitly approve sending it to the paid Google Gemini API to produce structured calendar data, with interaction storage disabled. The original selected file is not sent by Boopo. Google states that paid-service prompts, files, and responses are not used to improve its products. Limited provider logging may still occur for abuse detection, reliability, or legal requirements. Boopo does not keep the original or redacted file in D1. The resulting structured roster data remains in Boopo until you remove it or delete your account.
Security, age eligibility, and changes
Boopo uses access controls and technical safeguards intended to protect your information, but no internet service can promise absolute security. Boopo is intended only for people aged 18 or older. Do not create or use a Boopo account if you are under 18. If you believe an under-18 user has provided personal information to Boopo, contact us so the account and associated data can be reviewed and removed.
This policy may change as Boopo and its legal obligations change. The current version and update date will remain on this page.
Contact
Email support@boopo.app with a privacy question or data request. This address reaches Boopo's privacy contact and data protection officer.