Privacy policy
Effective 18 August 2026 · VAT Ledger
What we collect
When you sign in through VATSIM Connect, we store your VATSIM CID and, if you grant the requested scope, your display name. We store API-key names, non-secret key prefixes, cryptographic key hashes, creation and last-used times, quota usage and key-management audit events. Complete API keys are never stored and VATSIM access tokens are discarded after sign-in.
Network archive
VAT Ledger receives public VATSIM network data including CIDs, names, callsigns, controller positions, flight plans, aircraft positions and connection times. We process this information to provide searchable operational history and statistics. See the data policy for retention and inference details.
Cookies and security
We use an essential, HttpOnly session cookie to keep Developer users signed in and a short-lived cookie to protect the OAuth callback. We do not use advertising cookies. API usage is stored as daily aggregates by account, key, endpoint and response status; VAT Ledger does not intentionally place IP addresses in these analytics tables, although infrastructure providers may retain security logs.
Retention and sharing
Operational archive records are retained for up to 24 months. Expired login sessions are removed, and revoked keys remain only as security and audit records. We share information only with infrastructure providers necessary to operate the service, when required by law, or when needed to protect the service and its users. We do not sell personal information.
Your choices
You may request access, correction, restriction or deletion of account information. Some public-source or security records may need to be retained where an applicable legal basis permits it. Revoking a key immediately prevents further API use. This policy does not replace VATSIM’s own privacy policy.
Contact
The service operator must configure a privacy contact before production launch.