Privacy
What we know about you.
Without an account: nothing. Last updated 7 October 2026.
LocalTC is a hobby project, not a company. It runs on your own computer and needs no account. There is one optional thing that involves a server, the account behind the online dashboard and the companion app, and it only exists for you if you create one. This policy covers this website, the program you install, and that optional account.
The short version. This website stores nothing on your device and runs no analytics. The software processes your voice entirely on your own computer and sends it nowhere. Once a day it asks GitHub whether there's a new version, and you can turn that off. If you create an account, we store your email address and a summary of each flight you sync, plus a flight's track and radio transcript only if you upload its replay, and a public card only for a flight you choose to share. Never your voice or recordings, and you can export or delete all of it yourself at any time.
1. This website
The site is a handful of static files. There are no analytics, no tag manager, no advertising, no tracking pixels and no embedded third-party content. The two fonts are served from this site rather than from a font CDN, so loading the page does not tell anyone else that you did. There are no cookies and nothing in local or session storage, with one exception: if you sign in to the dashboard, the account server sets one sign-in cookie (see the cookie policy). Only the dashboard talks to that server, and only when you use it. The dashboard's two maps (your flights, and the Flight Tracker) load map tiles from OpenStreetMap, which sees your IP address and which part of the map you're looking at.
Support messages
Support messages need the account. The dashboard's Support section and the app's Support card send what you write and, from the app, the LocalTC version and your operating system; the account's email address is added by the server. The account server doesn't store the message: it's emailed straight to LocalTC's developer through Resend, with your address set as the reply-to, and kept in that inbox to answer you and fix what you reported. Ask and it's deleted. The server keeps a short-lived counter per IP address and account to stop spam, deleted within a day. Legal basis: answering you (legitimate interest, GDPR Art. 6(1)(f)).
Hosting
The site is hosted on GitHub Pages and served through Cloudflare. To deliver a page, they handle technical data such as your IP address, your browser and the time of the request, and may keep it for a short time to run the service and stop abuse. That processing is theirs, under the GitHub Privacy Statement and the Cloudflare Privacy Policy. We don't use their visitor statistics.
Links that leave
Links to GitHub, Buy Me a Coffee and other sites are ordinary links: nothing is loaded from those services until you click. If you donate, Buy Me a Coffee handles the whole transaction; your payment details never pass through this site, and the author sees only what Buy Me a Coffee shows a creator: a name or handle, an amount and any message you write.
2. The software
LocalTC is air traffic control and a copilot that run on your computer. It's local by default and built to keep working with the network cable pulled out. The few things that can reach the internet are all yours to turn on, and are listed below, every one of them.
- Your voice is captured by push-to-talk and transcribed on your own CPU or GPU. It is never uploaded.
-
The language model runs locally through Ollama, on
127.0.0.1: your own machine talking to itself, unless you bring your own key for a cloud model (below). -
Recordings, logs, settings and the logbook are written to your own disk, under
%LOCALAPPDATA%\LocalTCand therecordingsfolder. Nothing reads them but you. - There is no telemetry, no crash reporting, no usage counting and no licence check.
The connections it makes
- Setup. Downloading LocalTC, the speech model, the ATC voice and the language model from the services that publish them (GitHub, PyPI, Hugging Face, Ollama). After that, flights work offline.
- A cloud language model: bring your own key (only if you turn it on). Off by default. It's your choice and your account with the provider: you add your own key (most have a free tier) in Quick Settings → Cloud language model. While it's on, the words of your transmissions (as transcribed) and your flight's details (callsign, route, clearances, position, the airports' weather and what was said on the radio, and what you say to the copilot) go to the provider that answers, from the ones you've added: Mistral, Groq, Google AI Studio, Cloudflare Workers AI, NVIDIA, SiliconFlow, or Pollinations (no key). They go straight from your PC to that provider, under its own privacy policy: never to us, and never your audio. Your keys are kept in your system's credential store (Windows Credential Manager), never in a file, and are sent only to the provider they belong to.
- Experimental traffic control (only if you turn it on). It talks only to the sim on your PC: it reads which aircraft are around and, in "reinject", puts some back in the sim, writing their flight plans to your own disk. Nothing leaves your computer.
- The update check. At most once a day, the app asks GitHub's public API what the latest release is. GitHub sees an ordinary request from your IP address with LocalTC's version in it; nothing about you or your flights is sent. Turn it off in Settings (the gear) → Updates.
- SimBrief import, if you use it: the username or Pilot ID you type is sent to SimBrief to fetch your own flight plan, under their privacy policy.
- Map background, if it's on: the Live Map loads tiles from OpenStreetMap (the IFR view) or OpenTopoMap (the VFR view), which see which area of the map you're looking at. Turn it off in Settings (the gear) → Sim.
- The optional account, if you create one: section 3.
Sending a bug report
Developer mode records your flight, including the audio of everything you said, and Export session packs that into a zip in your Downloads folder. The program sends nothing. If you attach that zip to a bug report, you are choosing to share your voice recordings, settings and flight plan, so open it first to see what's in it. Anything posted in a public issue is public.
3. The optional account
An account copies your logbook to this website and lets the companion app follow your flight. You don't need one for anything else, and creating one changes nothing about how LocalTC works.
What it stores, and why
- Your email address: to sign you in. There are no passwords: each sign-in is a code and a link we email you, valid once for 15 minutes, stored only as a hash. We send no newsletters or marketing.
- Your signed-in devices: the kind (app, companion, browser), a name such as "Firefox on Windows", and when each was last used, so you can sign them out. Only a hash of each sign-in token is stored.
- A summary of each flight you sync: the date and times, callsign, aircraft type, the departure and arrival airports and their published coordinates, gates and runways, block and air time, distance flown, highest altitude, the vertical speed at touchdown, and how many readbacks were right and alerts were raised.
- While you fly, if the companion is on: the phase of flight, the frequency you're tuned to and the next one, and ATC's last transmission. Only the latest status is kept, and a new one replaces it.
- Your PC's local-network address (a private address such as 192.168.1.20) and a key that changes every time LocalTC starts, so the companion app on the same Wi-Fi can connect to the PC directly. When it does, nothing about the flight goes through the server at all.
- Only while the companion app watches from outside your Wi-Fi, or the dashboard's Flight Tracker is open, and only if you leave the setting on: your aircraft's position, nearby AI traffic and the radio log (ATC's transmissions and the text of your own calls). The server passes these straight to your phone (or browser) and keeps them in memory only. They're never written to the database or to disk, and they're gone when the flight ends or the server's memory is cleared. Turn it off in the app's Settings (the gear) → Account.
- Only for a flight whose replay you upload (from the Logbook in the app, one flight at a time, or all of them with the "upload each flight's replay" setting, which is off until you turn it on): the aircraft's track, a position every few seconds with its altitude, speed and heading, and the radio transcript as text (ATC's transmissions, what the app heard you say, and whether each readback was right), with the flight's phases and alerts. It's so you can rewatch the flight on the dashboard and in the companion app. It's stored with the flight until you remove the replay (in the app), delete the flight, or delete the account. Never audio, and never the recording itself.
- Only for a flight (or a Wrapped recap) you share: a public page at localtc.tech/f/… (or /w/…) that anyone with the link can open, without signing in. It shows a snapshot taken when you shared it: the callsign, aircraft and airports, the date (no times), air and block time, distance, the landing rate, the share of readbacks right, the runways and cruising level, and at most one line from the radio that you picked (a Wrapped card: the period's totals and a map of its airports and routes, no flight in detail), with the picture of the card your app drew. If you tick "Put the replay on the page" when sharing a flight whose replay is uploaded, the page also plays a small replay of it: the path flown, the altitude, the radio transcript (both sides, so whatever was said, gates included), the route you filed, the livery and the weather ATC gave, on a clock from the start of the flight. And "Flown by" with your display name, if you set one in the dashboard's Account page. Never your email address or the time of day; without the replay, never the track or the rest of the transcript. The link is random, the page asks search engines not to index it, and it's gone when you stop sharing, delete the flight or delete the account (copies cached by chat apps or browsers can linger for a few minutes).
- An iPhone's push token, if you allow the companion app's notifications.
- Short-lived counters of sign-in attempts per IP address and email address, to stop code guessing and email flooding. They're deleted within a day.
Apart from the replays you choose to upload, we never store your position or track or the radio log. We never store your voice, your recordings or your settings. Your voice never leaves your PC. The server drops any field it doesn't expect.
Legal basis
Providing the account you asked for (performance of a contract, GDPR Art. 6(1)(b)). The rate-limit counters are kept to keep accounts secure (legitimate interest, Art. 6(1)(f)).
Who processes it
- Cloudflare runs the account server and its database (privacy policy).
- Resend delivers the sign-in emails (privacy policy), and support messages to the developer.
- Apple delivers the companion app's notifications, if you turn them on.
These providers may process data in the United States and other countries, under their standard contractual clauses. We don't sell, rent or share your data with anyone else, and nothing is used for advertising.
How long
Until you delete it (a replay: until you remove it, or delete its flight). An account that's asked for but never signed in to is deleted after a day. Sign-ins expire after 30 days on the website and a year in the apps; expired ones are deleted daily.
Your rights
You can see, export and delete everything yourself on the dashboard: Download my data gives you all of it as a JSON file, individual flights can be deleted, and Delete everything removes the account and all its data at once, for good. You also have the right to correct your data, to object, and to complain to your data protection authority. For anything you can't do yourself, contact us (section 6).
4. Children
LocalTC isn't directed at children. Accounts are for people aged 16 or over; if you're younger, use LocalTC without one, which works just the same.
5. Changes, and how to check
If this policy changes, the date at the top changes with it, and every edit is in the public commit history of the repository. If a change affects account holders, we'll email them before it takes effect.
You don't have to take any of this on trust. The source
code, including the account server in server/, is public: what it
stores is written down in its database schema.
6. Contact
LocalTC is maintained by Peter Luedtke (duckiest428 on GitHub), who is responsible for the account data (the data controller). General questions belong in the issue tracker. For anything about your own account, email [email protected] rather than posting in public.