Privacy Policy
Effective: September 2, 2026 — AIVIATION LLC
Privacy at a Glance: RegBrief has no accounts. We never ask for and never receive your name, email address, or a password. Your bookmarks, notes, highlights, reading history, and reading position are stored on your device and, unless you turn iCloud off for RegBrief in iOS Settings, in your own private iCloud account, which AIVIATION cannot read. On every tier, the app sends usage-analytics events to AIVIATION servers: which screens and regulations you open, which regulation a bookmark, highlight, or note was attached to, that a search ran, subscription and purchase events, and that an AI brief was generated for a particular regulation. Those events carry a device identifier, plus a cross-device identifier when you are signed into iCloud, plus a subscription identifier issued by Apple once you have bought a subscription. On-device AI features generate their text on your device — no regulation text and no generated RegBrief leaves your device — but the app still reports to us that the generation happened and for which regulation. Pro cloud Q&A sends your question text to AIVIATION servers, where it is kept for up to 90 days. We use no third-party advertising or tracking, and we do not sell or share your personal information.
1. Introduction and Scope
AIVIATION LLC ("AIVIATION," "we," "us") operates RegBrief. This Privacy Policy covers the RegBrief iOS app and the regbrief.app website, together the "Service."
RegBrief is offered only in the United States. This policy is written to United States federal and state privacy law. We do not offer the Service in the European Economic Area or the United Kingdom, and this policy does not create rights under the laws of those jurisdictions.
RegBrief is primarily an offline FAR/AIM reference app: after the app downloads its content database, reading, search, and browsing work with no network connection. We have no account system — no username, password, name, or email address — and we use no third-party advertising or analytics services.
2. Information We Collect
Your content, which we never receive:
- The text of your notes and the passages you highlight
- The names of your custom study collections
- Your reading position within a section, and the reading-history records the app keeps on your device
- Your app preferences, such as text size and appearance
- The plain-English RegBriefs generated on your device by Apple's on-device AI, which the app caches locally
- The text of your recent searches, which the app keeps so it can offer them to you again
All of the above is stored on your device. It is never transmitted to AIVIATION and we cannot read it. Everything in that list except your recent searches is also stored, by default, in your own private iCloud account; your recent searches stay on the device that made them and are not synced by RegBrief. See Section 4 for how iCloud sync works and how to turn it off.
What we do receive is the pointer, not the content. When you bookmark, highlight, note, or file a regulation section, or open one to read it, the app sends us the identifier of that section as a usage-analytics event, described under “Usage analytics” below. The text you wrote, the passage you highlighted, and the name of the collection you filed it in are not part of that event.
Usage analytics, on every tier: To understand how RegBrief is used and to improve it, the app sends usage-analytics events to AIVIATION servers. These events record:
- Product interactions — app launches, which screens you open, which regulation sections you open and how long you spend on them, which features you use, which certificate you select as your study focus and which study task you start under it, and which regulation section a bookmark, highlight, note, or AI brief related to
- That you exported your highlights or notes, which of the two it was, and how many items the export contained. The exported text itself is never sent
- That a search ran, together with the number of characters in your query and the number of results returned, and which result you opened. The text of the search itself is never sent
- That a Pro cloud Q&A question was submitted, together with the number of characters in it. The text of the question is not part of the analytics event; it travels separately, as described below
- Subscription and purchase events — which tier you hold, and when a purchase, renewal, or trial event occurs. Apple processes your payment; we never receive your payment details
- Your app version and iOS version
The identifiers attached to analytics events. Every analytics event carries one or more of the following. None of them is your name, email address, or a login account, because RegBrief has none of those.
- A device identifier. Created on your device the first time you launch RegBrief and stored in your device's keychain. It is not reset when you delete and reinstall the app — the keychain entry outlives the app, and the app reuses it. Erasing the device resets it. The same device identifier is used by every AIVIATION app installed on that device.
- A cross-device identifier. A random value stored in your own private iCloud account and sent with analytics events so that we can recognize activity from the same person across the devices they use. It is absent if you are not signed into iCloud. The same cross-device identifier is shared by every AIVIATION app you use under that iCloud account.
- A subscription identifier issued by Apple. Once you have purchased any RegBrief subscription, Apple gives the app an identifier for your original purchase, and the app attaches it to analytics events. It is stable for your Apple Account and is the same on every device signed into that Apple Account. Its purpose is to let us tell that two device identifiers belong to one person. Users who have never purchased do not have one. It is not your Apple Account name or email address, and it does not give us access to your Apple Account.
Because these identifiers persist and are used to associate activity with a single user, we treat all analytics data as linked to your identity under Apple's App Store privacy framework, even though we hold no name, email address, or account for you. See Section 12.
Internet protocol (IP) address. Every request your device or browser makes to AIVIATION servers — analytics events, Pro Q&A questions, and page views on regbrief.app — arrives with your IP address, as every internet request does. We record it in our server access logs and delete those logs after 30 days. We use it to operate and secure the Service, including to rate-limit abusive traffic. We do not use it to build a profile of you, and we do not join it to analytics events.
Pro tier — cloud AI Q&A. When you use the cloud AI question-and-answer feature, the app sends your question text to AIVIATION servers to generate an answer with citations. If you asked from within a regulation section, the identifier of that section is also sent, as a retrieval hint. The answer is produced by Anthropic's Claude model, which Amazon Web Services (AWS) hosts and runs for us as our service provider.
Your question is transmitted together with a credential issued by Apple that proves you hold an active Pro subscription. For that reason we treat the question text as linked to your identity at the point of collection. We do not store that credential, your Apple Account, or any device or cross-device identifier alongside the question or answer.
The app also keeps a list of your recent questions on your device, so it can offer them to you again. That list stays on the device that asked them and is not synced to iCloud. It is a local copy for your convenience; it does not change the fact that the question text itself was sent to AIVIATION when you asked it, and it does not affect the retention described below.
We keep the question and answer text for up to 90 days to check answer quality and to investigate abuse, after which it is deleted automatically. It is held apart from every identifier we hold, so AIVIATION does not maintain any way to look up an individual person's questions, and we do not attempt to. We cannot, however, tell you that such a link is impossible: our 30-day IP access logs and the 90-day question record both carry timestamps, and a determined analysis of both could in principle associate the two. We do not perform that analysis, and we would do so only if compelled by valid legal process.
Website visits (regbrief.app). See Section 3.
3. Tracking and Other Technologies
The regbrief.app website uses no cookies. It sets no cookie, writes nothing to your browser's local storage, and assigns you no visitor identifier. There is no third-party analytics, advertising, or social-media tracking code on this site.
The site runs a small first-party measurement script that reports two things to AIVIATION servers: that a page was viewed, and that a link to the App Store was clicked. Each report contains the path of the page you are on, the hostname (not the full address) of the site that referred you, any campaign parameters in the link you arrived on, and, for an App Store click, a label identifying which link you clicked. It contains no identifier for you, and nothing in it is carried from one page view to the next.
We honor Do Not Track and Global Privacy Control. If your browser sends a Do Not Track signal or a Global Privacy Control signal, the script sends nothing at all.
Website measurement reports are retained on the same schedule as app analytics — up to one year. Your IP address reaches our servers with these requests and is handled as described in Section 2.
4. iCloud Sync
RegBrief stores your bookmarks, notes, highlights, custom collections, reading history, reading position, app preferences, and locally generated RegBriefs in your own private iCloud account by default, so they follow you across your Apple devices. AIVIATION does not have access to your iCloud data, and we cannot read it.
RegBrief has no in-app switch for this. You control it in iOS Settings, under your Apple Account's iCloud settings, by turning iCloud off for RegBrief. If you are not signed into iCloud, or if iCloud is turned off or unavailable for RegBrief, the app stores this data only on your device.
Apple's privacy policy governs iCloud storage: apple.com/legal/privacy.
5. AI Features
On-device AI (Plus and Pro, on supported hardware): Plain-English RegBriefs, AI-enhanced search re-ranking, and selection RegBriefs are generated by Apple Foundation Models running entirely on your device. No regulation text and no generated RegBrief leaves your device for these features. Apple's on-device AI framework governs that processing. The app does report to AIVIATION, as a usage-analytics event, that a brief was generated or failed and which regulation section it related to.
Cloud Q&A (Pro only): Pro subscribers can ask questions answered by Anthropic's Claude model, hosted and run by Amazon Web Services as our service provider. Section 2 describes exactly what is transmitted, what is retained, and for how long. Before your first question is sent, the app asks for your permission. You can withdraw that permission at any time in the app under Settings > About > "Ask AI data sharing." Turning it off stops the app from sending new questions; the cloud Q&A feature does not work while it is off. It does not delete questions you have already asked, which expire on the 90-day schedule in Section 2.
6. Subscriptions
RegBrief offers three tiers: Free, Plus, and Pro. All subscription purchases are processed by Apple. We never receive your payment details. We receive a record that your subscription is active, so the app can unlock Plus or Pro features, and the subscription and purchase events described in Section 2. Apple's privacy policy applies to Apple's own processing of your purchase.
7. How We Use Information
- To provide the Service — to deliver regulation content and updates to your device, to unlock the tier you have purchased, and to answer a Pro cloud Q&A question
- To understand and improve the Service — to see which features are used, where users get stuck, whether a release helped, and whether AI answers are accurate
- To recognize the same person across their own devices, so that our product measurements count a person once rather than once per device
- To keep the Service secure and available — to detect and stop abuse, fraud, and attacks, and to diagnose failures
- To comply with law — to meet legal obligations, respond to lawful requests and legal process, and establish, exercise, or defend legal claims
8. How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We may disclose it to:
- Service providers that operate the Service on our behalf. Today that is Amazon Web Services, which hosts our servers, stores our data, and runs the AI model that answers Pro cloud Q&A questions. Service providers may use the information only to perform services for us.
- Professional advisors such as lawyers, accountants, auditors, and insurers, in the course of services they provide to us.
- Law enforcement, government authorities, and other parties, where we believe in good faith that disclosure is necessary or appropriate to comply with applicable law or legal process, to enforce our Terms, or to protect the rights, safety, or property of AIVIATION, our users, or others.
- A buyer or successor, in connection with an actual or prospective merger, acquisition, financing, sale of assets, or insolvency, bankruptcy, or receivership proceeding, in which personal information is transferred as a business asset.
Analytics identifiers are shared across the AIVIATION apps you use — see Section 9.
9. Tracking Across Apps and Sites
We do not track you across other companies' apps or websites, we do not use third-party advertising or analytics services, and we do not disclose your information to data brokers.
We do, however, join your activity across AIVIATION's own apps. The device identifier and the cross-device identifier described in Section 2 are the same in every AIVIATION app you use on that device or under that iCloud account, so analytics from RegBrief and from another AIVIATION app can be attributed to the same user. We use this only to count and understand users across our own portfolio.
10. How Long We Keep Information
- Usage analytics and website measurement: one year from collection, then deleted automatically.
- Pro cloud Q&A question and answer text: up to 90 days, then deleted automatically.
- Server access logs containing your IP address: 30 days, then deleted automatically.
- Operational logs recording that a request was served, and its timing and outcome: up to 90 days, then deleted automatically.
- Your on-device and iCloud content: kept until you delete it, or until you delete the app and remove its iCloud data. We hold no copy.
In setting these periods we consider how much information is involved and how sensitive it is, the harm that unauthorized use or disclosure could cause, why we collected it and whether we can meet that purpose another way, and what the law requires. We may retain information longer than the periods above where we must do so to comply with a legal obligation, or to establish, exercise, or defend a legal claim. When we no longer need information, we delete it or de-identify it.
11. Aggregated and De-Identified Information; AI Training
We produce aggregated and de-identified statistics from the information described in this policy — for example, how many users opened a given regulation in a week. We do not attempt to re-identify de-identified information, except to test that our de-identification works.
AIVIATION does not use your information to train AI models. We do not train, fine-tune, or otherwise build AI models on your questions, your content, or your usage data. Your Pro cloud Q&A questions are read by us only to check answer quality and investigate abuse, within the 90-day window in Section 10. Our AI service provider's own handling of the data we send it is governed by our commercial agreement with that provider and by its published service terms.
12. Apple's Privacy Categories
Apple asks developers to describe their data practices using a fixed set of categories. In that vocabulary, RegBrief's practices are:
- Identifiers — Device ID and User ID. The device identifier, the cross-device identifier, and the Apple-issued subscription identifier described in Section 2. Collected for analytics. Linked to your identity. Not used for tracking across other companies' apps or websites.
- Usage Data — Product Interaction. The interaction events described in Section 2. Collected for analytics. Linked to your identity, through those identifiers.
- Purchases — Purchase History. Your tier and your purchase and renewal events. Collected for analytics. Linked to your identity.
- User Content — your notes, highlights, bookmarks, collections, reading history, and reading position. Handled by the app for app functionality. This content stays on your device and in your own iCloud account; it is never transmitted to AIVIATION and we cannot read it.
- User Content — Pro cloud Q&A question text. Transmitted to AIVIATION servers to produce an answer, and read by us to check answer quality and investigate abuse. Transmitted alongside an Apple-issued subscription credential, so we treat it as Linked at the point of collection, and stored without any identifier as described in Section 2.
This policy governs. If you believe any information Apple displays about RegBrief is inconsistent with this policy, tell us at privacy@aiviation.dev and we will correct it.
13. Security
We use technical and organizational safeguards designed to protect the information we hold, including encryption of data in transit, encryption of stored data, restricting internal access to those who need it, and rate-limiting and filtering hostile traffic. Security risk is inherent in all internet and information technology, and we cannot guarantee the security of your information.
14. Your Choices and Controls
- Your content. Delete individual notes, highlights, bookmarks, or collections in the app. To remove everything, delete the app and remove its data from iCloud in iOS Settings. No request to us is needed, because we hold no copy.
- Pro cloud Q&A. Turn off Settings > About > "Ask AI data sharing" in the app to stop sending new questions, or simply stop using the feature. Questions already asked expire within 90 days.
- iCloud sync. Turn iCloud off for RegBrief in iOS Settings, under your Apple Account's iCloud settings. Your content then stays on your device only, and the cross-device identifier is no longer sent.
- Usage analytics. RegBrief does not currently offer an in-app switch to turn usage analytics off. Deleting the app stops new events being generated on that device, but it does not reset the device identifier, which persists in your device's keychain and is reused if you reinstall. Erasing the device resets it.
- Do Not Track and Global Privacy Control. On regbrief.app, both signals are honored and stop all website measurement. See Section 3.
15. U.S. State Privacy Rights
This section applies to residents of U.S. states whose privacy laws apply to us, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Nevada (NRS Chapter 603A). Not every right below is available under every state's law, and some rights are subject to exceptions, so we may decline a request where the law permits.
Categories of personal information we collect, and why. In the 12 months preceding the effective date of this policy, and currently:
- Identifiers — a device identifier, a cross-device identifier, an Apple-issued subscription identifier, and your IP address. Collected from your use of the Service. Used for analytics, and, for the IP address, to operate and secure the Service.
- Internet or other electronic network activity information — your interactions with the app and with regbrief.app, as described in Sections 2 and 3. Collected from your use of the Service. Used for analytics.
- Commercial information — your subscription tier and your purchase, renewal, and trial events. Collected from your use of the Service and from Apple. Used for analytics.
- Other user content — the question text you submit to the Pro cloud AI feature. Collected from you. Used to produce an answer, to check answer quality, and to investigate abuse.
We disclose these categories for a business purpose to the recipients listed in Section 8. We do not sell personal information, we do not share it for cross-context behavioral advertising or targeted advertising, and we have not done either in the preceding 12 months. We do not use personal information for profiling that produces legal or similarly significant effects. We do not intentionally collect or process sensitive personal information, and we do not use it to infer characteristics about you.
Your rights. Depending on your state, you may have the right to:
- Know the categories of personal information we collected, the sources, the purposes, and the categories of third parties to whom we disclosed it
- Access a copy of the personal information we hold about you
- Correct inaccurate personal information
- Delete the personal information we collected from you
- Opt out of sale, sharing, targeted advertising, and significant profiling — none of which we do
- Appeal our denial of a request. If we deny your request, you may appeal by replying to our decision at privacy@aiviation.dev with the word "Appeal" in the subject line. We will respond in writing with our decision and our reasons within the time your state's law allows, and, if we deny the appeal, we will tell you how to complain to your state attorney general
- Be free from discrimination for exercising any of these rights. We will not deny you the Service, charge you a different price, or give you a lower quality of service because you made a request
How to make a request, and an important limitation. Email privacy@aiviation.dev. You may also use an authorized agent; we may ask the agent for a valid power of attorney or for your signed written permission, and we may ask you to verify your own identity directly.
Because RegBrief has no accounts, we hold no name, email address, or password for you. Our records are keyed only to the identifiers described in Section 2, which we have no way to match to a person who contacts us. In most cases we therefore cannot verify that a given record belongs to you, and the law does not require us to collect additional information from you in order to be able to. Where that is the case we will tell you so, and we will explain the self-service controls in Section 14, which give you direct control without needing our help. We will not ask you for a government identification document in order to answer a request about data of this kind.
Additional notices for specific states.
- California — Shine the Light (Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct marketing purposes. You may confirm this by writing to privacy@aiviation.dev with "Shine the Light Request" in the subject line, your first and last name and mailing address, and a statement that you are a California resident.
- Nevada (NRS Chapter 603A). Nevada residents may direct a covered operator not to sell certain personal information. AIVIATION does not sell personal information. Nevada's designated request address for AIVIATION is privacy@aiviation.dev.
Residents of other states may have similar rights under their own laws. Contact us at privacy@aiviation.dev and we will apply whatever your state's law provides.
16. Children's Privacy
RegBrief is not directed to anyone under 16, and we do not knowingly collect personal information from anyone under 16. If we learn that we have collected personal information from a child under 16, we will delete it. If you believe a child under 16 has provided us information, contact privacy@aiviation.dev and we will act promptly.
17. Other Sites and Services
RegBrief and regbrief.app link to websites and services operated by others, including the FAA, the Government Publishing Office's eCFR, and Apple. Those links are not an endorsement and do not mean we are affiliated with the operator. We do not control those services and are not responsible for them. Read their privacy policies before using them.
18. Where Information Is Processed
AIVIATION LLC is located in the United States, and the information described in this policy is processed and stored in the United States. RegBrief is offered only in the United States. If you access the Service from elsewhere, you do so on your own initiative, and your information will be processed in the United States, where privacy laws may differ from those where you live.
19. Changes to This Policy
We may update this policy. Changes will be posted here with a new effective date. If a change is material, we will make it prominent, in the app or on this site, before it takes effect. Continued use after the new effective date means you accept the updated policy. We review this policy at least once a year.
20. Contact
Privacy requests and questions: privacy@aiviation.dev
General support: support@aiviation.dev
Telephone: 316-302-5551
AIVIATION LLC, c/o Northwest Registered Agent, 7901 4th Street North, Suite 300, St. Petersburg, FL 33702