Privacy Policy
Effective: August 15, 2026 · Last updated: September 7, 2026 · Publisher: RNP Labs LLC
This Privacy Policy explains what RNP Labs LLC ("RNP Labs," "we," "us") collects when you use
WidgetBid, why we collect it, who processes it, how long we keep it, and what we never collect. RNP Labs LLC
is the controller of this information.
The short version. We collect the minimum needed to verify you are a pilot, sign you in, compute your
seniority standing, and save your bids. We never ask for or store any employer credential. We never store
pilot names. We run no advertising trackers and no analytics pixels. We do not sell or rent your personal
information, and we do not use it to train machine learning models.
1WHAT WE COLLECT
Information you give us
| What | Why we have it |
| Company personnel number | Checked against the published seniority list to confirm you are a line pilot, and it enforces one account per pilot. |
| Company email address | Held only on accounts created before August 2026, when it was used once to verify employment. It is deleted as soon as that account sets a personal sign-in address, and it is not collected from new accounts. |
| Personal recovery email | Where password reset codes are sent, because company mail systems commonly quarantine outside mail. |
| Password | Stored only as a salted hash by our authentication provider. We never see it. |
| Seniority number, base, equipment, seat, hire date | Computes your category standing, feasibility estimates, and longevity based pay figures. |
| Home and commute airports | Drives commutability scoring. |
| Bidding preferences, weights, favorites, saved bids, bid history | The product. Saved per bid month so a new month can start from your last one. |
| Documents you choose to upload | Parsed into facts, then the original is discarded. See Section 5. |
| Support correspondence | To answer you and keep a record of the issue. |
| Feedback you send from inside the app, and any screenshots you attach to it | To reproduce and fix what is broken, correct figures that look wrong, and decide what to build next. Screenshots are stored in private object storage that only the operator can open, and are never made public. |
Information generated by your use
- Assistant usage counts. How many questions you asked the in-app assistant on a given day, and token
totals, for rate limiting and cost control.
- Access records. A record that your account opened a dataset, with a timestamp.
- Server logs. Our hosting and database providers record IP address, user agent, and timestamps for
security, abuse prevention, and debugging.
- Billing status. A customer identifier from our payment processor and your subscription state.
We never receive or store your card number.
- Browser storage. Session token, theme choice, and interface preferences, stored on your device.
See the Cookies & Local Storage Notice.
What we never collect
Never. Your company sign-on or any other employer password, PIN, or credential. We will never ask for one, and no
part of the Service connects to any employer system on your behalf. If anything claiming to be WidgetBid asks
you for a company credential, it is not us. Report it to
support@widgetbid.com.
We also do not collect pilot
names. Names are removed when source materials are parsed and are not
stored anywhere in the Service. We do not collect precise location, contacts, your photo library, or biometric data, and
we do not use advertising cookies or third party analytics.
2HOW WE USE IT
- To verify you are a current pilot and to create and secure your account.
- To compute your category standing, feasibility estimates, pay figures, and commute assessments.
- To save, restore, and carry forward your preferences and bids.
- To send transactional messages: password reset codes, account notices, billing notices, and material
changes to these policies.
- To send optional bid-window alert emails, if you leave the email alerts switch on: a short note when
a new bid package for your category is available. Alert emails contain no links, on purpose, and the
switch to turn them off is on your Account page.
- To provide support, prevent fraud and abuse, enforce our Terms, and keep the Service secure.
- To act on feedback you send us: to reproduce and fix defects, correct data, and decide what to build
next. If your report needs a follow up question, we reply to the email address on your account.
- To operate billing and meet tax and accounting obligations.
- To improve the Service in aggregate, using totals and patterns rather than identified personal data.
- To comply with law and to respond to lawful requests.
We do not use your data to train machine learning models. We do not sell or rent personal information, and
we do not share it for cross-context behavioral advertising.
3LEGAL BASES (WHERE GDPR OR UK GDPR APPLIES)
- Contract: creating your account, delivering the Service, and billing.
- Legitimate interests: security, abuse prevention, service improvement, and defending legal claims.
- Legal obligation: tax, accounting, and responses to lawful requests.
- Consent: anything optional, which you may withdraw at any time.
4WHO PROCESSES YOUR DATA
We use a small set of providers. Each processes data only to provide its service to us.
| Provider | Role | What it can see |
| Supabase | Database, authentication, server functions (United States) | Account and profile records, preferences, saved bids, feedback you send and any screenshots you attach, server logs |
| Netlify | Web hosting and content delivery | Request logs: IP, user agent, timestamp |
| Resend | Transactional email delivery | Recipient email address and message contents |
| Stripe | Payments and subscription management (when paid plans are active) | Billing details and payment method. Card data goes to Stripe, never to us |
| Anthropic | Optional in-app assistant | Your question and the parsed schedule facts needed to answer it. No names |
| AeroDataBox | Published airline schedule data for commute checks | Airport pairs and dates. No personal identifiers |
We may also disclose information to professional advisers, to comply with law or valid legal process, to
protect rights and safety, or in connection with a merger, acquisition, or sale of assets, in which case we
will give notice before your information becomes subject to a different policy.
The in-app assistant
If you use the assistant, your question and the parsed schedule facts relevant to it are sent to Anthropic's
API to generate an answer. Pilot names are never included. Content sent through the API is not used to train
models. If you would rather nothing leave the app, do not use the assistant. Every other feature works without
it.
Bid Transfer, as a button or as a browser extension
If you use the optional Bid Transfer, it reads your saved bid sheet from your account so it can fill it
into the page you have open, and it fetches the field-label mapping it needs from us. The button runs from a
bookmark you added yourself and uses the WidgetBid session already in your browser, the same session this
site uses. The extension signs in with your WidgetBid email and password and keeps that session only in your
browser's temporary extension storage, which clears when the browser closes. Either way it sends nothing
else to our servers: no employer credential, no contents of any employer page, and no record of the system
it filled. Neither one signs in to any employer system.
5SOURCE DOCUMENTS AND AWARD DATA
Two points about the data behind the Service, stated plainly:
- Originals are not kept and not published. Bidding materials are parsed into factual data. The
original files are removed from working storage after a validated parse. The Service has no document viewer
and no document download.
- Award records contain personnel numbers, not names. Historical award rows are derived from award
documents distributed to the pilot group. Names are stripped. The company personnel number that appears in
the source is retained in those rows so that a pilot can look up what their own number was awarded. If you
want the rows carrying your personnel number removed, email us and we will remove them. See
Your Data.
- Upload records unlock your access. When you contribute a bid package or award file, we keep a
record of that upload (which package, when, and whether it matched the shared library) with your account,
because that record is what unlocks the matching category for you. If your copy differed from the shared
library, the parsed facts of your copy are also kept and served to you until they match. These records
are deleted with your account.
The seniority roster used to compute standing stores only a salted one-way hash of the personnel
number alongside published seniority figures. It contains no names and cannot be reversed to a person by
someone who does not already know the number.
6HOW LONG WE KEEP IT
- Account and profile: for as long as your account exists.
- Preferences, saved bids, bid history: for as long as your account exists, so history stays useful
across months.
- Deleted accounts: removed from production systems within 30 days of a verified request, and
from routine backups within 90 days.
- Uploaded source documents: discarded after a validated parse, typically the same day.
- Feedback and attached screenshots: kept while the issue is open and for up to 24 months
after it is closed, so a problem that comes back can be traced to what was reported before. Deleted sooner
if you ask us to.
- Billing records: kept as long as required by tax and accounting law, generally seven years.
- Security and server logs: retained on a short rolling window by our providers.
7SECURITY
- Encrypted transport (HTTPS) everywhere, and encryption at rest by our database provider.
- Passwords stored only as salted hashes. We never see them.
- Row level security so an account can read only its own records.
- Personnel numbers in the seniority roster stored as salted one-way hashes, with the salt held in a
service-role-only store.
- Secrets held in managed secret stores, never in application code.
- Role based access to production data, limited to what operating the Service requires.
No system is perfectly secure. If a breach affects your personal information, we will notify you and any
required regulator as the law requires.
8YOUR RIGHTS AND CHOICES
You can view and edit most of your information inside the app. For access, correction, a copy, deletion, or
any other request, see Your Data, which describes the rights available under
California law (CCPA and CPRA), the GDPR and UK GDPR, and other state privacy laws, and how to exercise them.
We do not sell or share personal information, so there is nothing to opt out of on that front. Transactional
messages are part of the Service and cannot be turned off while your account is open.
9DATA LOCATION AND TRANSFERS
The Service is operated from the United States and data is stored there. If you use it from outside the
United States, you are transferring information to the United States, where privacy laws may differ. Where
required, transfers rely on Standard Contractual Clauses or another lawful mechanism.
10CHILDREN
The Service is for professional pilots aged 18 and over. We do not knowingly collect information from anyone
under 18. If we learn we have, we will delete it.
11CHANGES TO THIS POLICY
If we change this policy materially, we will update the effective date above and notify you in the app or by
email before the change takes effect. Prior versions are available on request.
12CONTACT
RNP Labs LLC · WidgetBid · Privacy
support@widgetbid.com
We answer privacy requests within 30 days, or tell you why we need longer.
Independent product. Not affiliated with any airline, union, or vendor. WidgetBid is an independent
product of RNP Labs LLC. It is not affiliated with, sponsored by, endorsed by, approved by, or connected to
any airline, any pilots union, or any crew-scheduling software vendor, and nothing in the Service is an
official company or union communication. The Service refers to employer and vendor systems generically, and
all trademarks are the property of their respective owners.