Skip to content

Privacy & your data

Your workspace holds records you may be required to produce years from now — flight logs, maintenance history, currency evidence. This page explains where that data lives, who can reach it, and how to get it out.

Your data is your organization’s

Every record belongs to exactly one organization, and that boundary is enforced in the database itself rather than only in application code. A query that arrives without an organization attached returns nothing. Two organizations sharing the same Tobren Operations installation cannot see each other’s records, and there is no “all customers” view for support to browse casually.

Inside your organization, what someone sees depends on their role and their schedule-visibility tier — see Crew & roles.

What we store

  • Operational records — flights, aircraft, crew, maintenance, checklists, events, jobs, quotes and invoices.
  • Documents you upload — certificates, registrations, insurance, photographs.
  • Account details — name, email, and the sign-in method you chose.
  • Payment details are not stored by Tobren. Card data goes directly to our payment processor; the workspace keeps a reference and the last four digits so you can tell which card is on file.

Sharing outside your organization

Three things can be shared with someone who has no Tobren account: a compliance report, a quote, and an invoice. Each gets a private link containing a long random token.

Treat these links like passwords. Anyone holding the link can open that one document — that is the point of them, and it is also the risk. They are not indexed or guessable, but they are not tied to a person either, so forwarding a link forwards the access.

Three things make this manageable:

  • You can revoke a link. Every shared document has a Revoke link control. It kills the link you sent — anyone still holding it gets nothing — and issues a fresh one you can send instead. Use it the moment a link goes somewhere it should not have.
  • Report links record their use. The reports list shows how many times each share link has been opened, so an unexpected count is visible rather than silent.
  • The token itself is encrypted at rest, and the database stores only a cryptographic digest for lookup — so the share link cannot be read back out of a database copy.

Calendar feed links can be revoked the same way, which stops the feed for anyone still subscribed to it.

Getting your data out

Exports live in Settings → Your data. What you can download depends on your role in the workspace — the same rule the server enforces, so a button you are not shown is one the server would refuse.

Anyone in the workspace can export their own logbook: the filed flights they flew as pilot in command or were on the crew of, with their role on each flight. It comes as a CSV, or as a PDF ready to print or send — the same flights either way, with the PDF adding the totals (flights, flights as pilot in command, total flight time) at the end. A flight with no end time on file says so, and is left out of the total rather than counted as zero.

Admins and the owner can also export three registers as CSV files, from Settings or from an Export button on the page each one lives on:

  • Flight logs — every log, including drafts and the originals that a correction replaced. The status, superseded_at and correction_of_id columns say which is which, so nothing in your amendment history is dropped.
  • Maintenance history — every recorded service, with the item, aircraft, who did the work and the return-to-service sign-off.
  • Incident register — incidents, near misses and hazards, with their status and the §107.9 reportability call.

Admins can also export any crew member’s logbook, as CSV or PDF, from that person’s page.

The owner can export the whole workspace as one ZIP file. It contains a CSV for each of these:

  • Fleet and crew — aircraft, crew, components (tracked parts such as batteries), the hours and cycles recorded against each part, and battery health measurements.
  • Flying — flight logs and the crew on each, scheduled flights and their planned crew, events with their crew and reserved aircraft, the checklist templates your workspace wrote, and every completed checklist with each item’s result.
  • Maintenance and safety — maintenance items, maintenance history, incidents, waivers and compliance alerts, including dismissed ones.
  • Clients and billing — clients (with your billing details and notes for each), jobs, quotes and invoices with their line items, and the payments and credits recorded against each invoice.
  • Documents — every document’s details, and the document files themselves.

A README.txt in the ZIP lists every file and what is not included. The IDs in each CSV join the files together.

Because the ZIP is the whole workspace leaving in one file, it has two extra checks the other exports do not:

  • You confirm it’s you first. Unless you signed in within the last five minutes, Tobren asks you to confirm — with your password, or with Google or Apple if that is how you sign in — before it builds the file. Each confirmation covers one export, so a second export asks again. A browser tab left signed in cannot export the workspace on its own.
  • Three exports per workspace per hour. Past that, Tobren says how long to wait. Single registers and logbooks are not counted and stay available.

What the workspace export does not include, stated plainly:

  • Some records are not in it: compliance reports, your Tobren subscription’s billing history, event prep activity and spare substitutions, event layouts, crew availability, crew credential submissions, aircraft groups, per-aircraft checklist overrides, and Tobren’s built-in checklist templates (each completed checklist carries its template’s name and items). Compliance reports, quotes and invoices still download as PDFs from their own pages, and your subscription invoices from Settings → Billing.
  • Share links and credentials are never in it. Quotes and invoices are exported without their share links, so the file carries no way to open a client’s copy. Connected services (Airdata, a payment processor, calendar feeds) and their credentials are not exported.
  • Document files stop at 250 MB per export. Every document’s details are always in documents.csv. A file past that limit is marked “not included” there, and stays downloadable from the Documents library.
  • It is read in batches while it downloads. A record someone adds or changes during the download may or may not be in it.
  • No export can be run from a Tobren support session — not the workspace, and not a single register or logbook. Support can look at your screens; taking your records out is something only people in your workspace can do, signed in as themselves.

Tobren records every export — who ran it, which export, and when — in its audit log.

CSV files open in Excel, Numbers or Google Sheets. A cell that begins with =, +, - or @ (other than a plain negative number) is prefixed with an apostrophe, so a spreadsheet shows it as text instead of running it as a formula.

You can also, at any time:

  • download compliance report PDFs — the archived, timestamped artifact of any report;
  • download quote and invoice PDFs;
  • subscribe any calendar app to a calendar feed of your schedule.

Closing an account

Closing a workspace and deleting its records is a request, not a self-serve button, for the same reason downgrades ask you to archive first: deletion of compliance records is not something to trigger by accident. The organization owner makes the request in Settings → Organization, under Delete your account and data, by choosing Request deletion. You will be asked to confirm it is you with a recent sign-in. Nothing is deleted at that point: the request goes to the Tobren team, who review it and respond within 30 days. Admins and members do not see the control; ask your owner.

Note that flight and maintenance records often have a retention obligation of their own under the rules you operate by. Getting your export first, and confirming what you are required to keep, is worth doing before anything is deleted.

Securing your own account

Turn on two-factor authentication and store your recovery codes somewhere other than the device that generates the codes. Account & security covers both.