METARLAB

Privacy.

What is held about you, why it is held, who else sees it, how long it stays, and how to take all of it back. Written from the code, so it says what is true rather than what is usual.

The short version

MetarLab needs an email address to have an account at all, and after that it holds what you put into it: the aerodromes you follow, how the quiz is going, any chart you upload, the flashcards you write, and your settings. Nothing is sold, nothing is shared for advertising, and there is no analytics or tracking script on any page.

Two things are worth knowing before the detail. The aerodromes you follow say where you fly, which is more personal than a list of four-letter codes looks. And charts are opened from the authority's own servers by your browser, so those authorities see your IP address directly, without MetarLab in the middle.

Who is responsible

MetarLab is run by a private individual as a personal project. The legal notice has the name, tax number and address that Spanish law requires, and is the place to write to about anything on this page. What an account gives you and who you buy it from is in the terms; changing your mind about a subscription is on the refunds page.

What is held

Your account
Email address, an optional display name, whether the account is active, when it was created, when the address was confirmed, and when you last signed in.
Where you fly
The aerodromes you follow and when you added each one. This is the entry on this page most worth thinking about: over time it is a record of where you fly and when you were planning to.
What you write
Your flashcards — the text on both sides, the subject and topic, and any photograph you attach to one. These are your own words and your own pictures, and they are the most personal thing here.
Charts you upload
The PDF itself, the name you gave it and its size. These are your files — a plate you annotated, your school's material, something you scanned — and they are kept on Cloudflare's storage in Europe so they are on every device you sign in on. They are private to your account and are never shared with another account. Nobody at MetarLab reads them, and there is no way for anybody else to open one: every request for a file is checked against the session it came from. ENAIRE's own aerodrome plates and VFR500 sheets are not among these — those are fetched by your browser from ENAIRE and never reach MetarLab's server at all.
How the studying is going
Scores per category, which box each card is in, when it is next due, and the calendar days on which you did a quiz.
Settings
Preferences, your personal minima, and your profile photograph if you set one.
Alerts, if you turn them on
For Telegram: your chat id, your Telegram username, your timezone, which aerodromes and products you subscribed to, and a record of what was sent so the same observation is not sent twice. For browser notifications: the push endpoint your browser issued.
Signing in
A hash of your password, and hashes of your session tokens and sign-in links. Hashes, in every case: the originals are not stored and cannot be recovered from what is. If you add a passkey, its public key is held here with the name you gave it — a public key is not a secret, and it cannot be used to sign in as you. The private half never leaves your device and MetarLab never sees it.
What it costs
Which plan the account is on, when it runs to, and the payment provider's own reference if there is one. Card details never reach MetarLab, and are not stored anywhere in it.
Abuse counters
Failed sign-in attempts and how often an address has asked for a link, so that somebody guessing passwords can be slowed down.

There is no advertising on MetarLab today and therefore no advertising identifier, no cookie for one, and no third-party script placing either. If that changes, this page changes first and you will be asked before anything is set.

Why, in law

To give you the thing you asked for
Your account, your aerodromes, your cards, your alerts, and — if you buy one — your subscription. Performance of a contract, GDPR Article 6(1)(b).
To keep it standing up
The abuse counters, and the server logs Cloudflare keeps. Legitimate interests, Article 6(1)(f): an app anybody can hammer is an app that stops working for everybody.
Because the law says to
Anything an accounting or tax rule requires to be kept once money changes hands. Article 6(1)(c).

There is no profiling and no automated decision-making with a legal or similarly significant effect. The spaced-repetition scheduler decides when to show you a card again; that is the extent of it.

Who else sees it

Two different things happen here and the difference matters, so they are separated rather than pooled into one list.

Asked for by MetarLab's server, on your behalf
These see the request, not you: the server asks, and the aerodrome codes travel without your address attached.
aviationweather.gov (NOAA) for METAR and TAF · api.open-meteo.com for winds aloft · api.core.openaip.net for airspace · www.ngdc.noaa.gov for magnetic variation.
Opened by your own browser
These see your IP address directly, the way any site you visit does, because your browser goes to them itself. Charts are not copied or re-hosted here — they are opened from the authority that publishes them, which is deliberate, and this is the cost of it.
aip.enaire.es (Spain) · nats-uk.ead-it.com (United Kingdom) · www.sia.aviation-civile.gouv.fr (France) · server.arcgisonline.com for map tiles.
Only if you set them up
api.telegram.org — only for accounts that have linked Telegram, and only what is needed to send you the message you asked for. Telegram is its own controller for whatever it holds about your chat.
Doing a job for MetarLab
Cloudflare hosts the app and the database, and keeps its own request logs. Resend sends sign-in links and confirmation emails, and therefore handles your address. Both are processors: they act on instruction and not for their own purposes.

Some of these are outside the European Economic Area, chiefly in the United States. Transfers rest on the European Commission's standard contractual clauses and, where it applies, the EU–US Data Privacy Framework.

How long

Most of it is kept until you delete it, because most of it is the thing you came here for — a card you wrote is not litter to be swept up on a schedule. What does expire, expires for a reason:

Your account and everything in it
Until you delete it, and then immediately. Deletion removes the rows; it does not mark them.
Charts you upload
Until you remove one, or delete the account, and then the file itself goes and not only the record of it. A subscription running out lowers how many new ones you may add; it never deletes what is already there.
Sign-in links
Fifteen minutes. Password reset links, one hour. Address confirmation, one day.
Sessions
A year at most, and sooner if you sign out. Signing out ends that session on the server, not only in the browser.
Abuse counters
One day after the last attempt, swept automatically.
The record of alerts already sent
Kept while the subscription exists, so the same observation is not sent to you twice. It goes when you unsubscribe from that aerodrome, when you unlink Telegram, or when you delete the account.
Anything tax law requires
Once there are payments, the invoice records for as long as Spanish law requires them to be kept, even after the account is gone.

Your rights, and the buttons

You have the rights the GDPR gives you: to a copy of your data, to correct it, to erase it, to restrict or object to what is done with it, and to complain to a supervisory authority. Two of them do not need a request at all, because they are built in:

A copy of everything
In the app, under Settings → Your data. It downloads a JSON file containing every row held about the account — your cards and their pictures included. Password hashes, session tokens and passkey public keys are deliberately left out: a copy of your data should not be a copy of your credentials.
Erasure
In the same place. It asks you to type your address out, and for your password if the account has one, because there is no undo behind it and a session left open on a shared laptop should not be enough. It then deletes the account and every row that refers to it, in one transaction.

For anything else, write to the address in the legal notice. If you think this has been handled badly you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es).

Age

You must be at least fourteen to have an account, which is the age Spanish law sets for consenting to an information-society service on your own. A student pilot can be younger than this page assumes, so it is worth saying plainly rather than burying: below fourteen, a parent or guardian has to be the one agreeing.

Keeping it safe

Passwords are hashed, never stored. Session tokens and sign-in links are stored as hashes too, so a copy of the database is not a way into anybody's account. Everything travels over HTTPS and the site asks browsers to refuse anything else.

None of that is a promise that nothing can go wrong. If something does go wrong in a way that puts you at risk, you will be told, and so will the authority, within the time the GDPR allows.

Changes

If this page changes in a way that matters, the change is announced in the app rather than made quietly. Last updated 6 September 2026.

Back to MetarLab