Cobalt
Creators Press
Get notified
Creators Press Get notified Support

Privacy Policy

Last updated September 11, 2026

This Privacy Policy explains how Cobalt Simulations (“Cobalt,” “we,” “us”) handles personal information when you use Cobalt Companion (iOS, and any other Companion clients we publish), Cobalt Bridge, Cobalt Peak, cobaltsim.com, api.cobaltsim.com, and relay.cobaltsim.com. It is written to match the product as shipped — not a generic template.

1. Who we are

Cobalt Simulations operates the Cobalt flight-simulation companion. The public site is cobaltsim.com. The API is api.cobaltsim.com. Away-from-home connections use relay.cobaltsim.com. Privacy and support mail: reports@cobaltsim.com.

For data-protection purposes Cobalt Simulations is the controller of personal data described here, except where a processor (for example Stripe) is an independent controller of payment data, or where a third-party network (VATSIM, IVAO, Giphy, Navigraph, SimBrief) is controller of data you give them directly.

2. Scope

This policy covers:

  • Creating and using a Cobalt account (email and password).
  • Using Companion on a phone, iPad, Apple Watch companion, widgets, and Live Activities.
  • Installing and running Cobalt Bridge on a Windows or Mac PC next to Microsoft Flight Simulator or X-Plane.
  • Peak billing on cobaltsim.com via Stripe, Bridge activation codes, and the Peak customer portal.
  • Community features (feed, comments, DMs, follows, Atlas/passport cards you publish).
  • The marketing and support website, including the launch waitlist at /notify and creator referral cookies.
  • Guest / demo use on a single device without an account (local only, until you sign in).

It does not cover third-party sites we link to (VATSIM, IVAO, SimBrief, Navigraph, ChartFox, SkyVector, AirNav, Discord, Apple, Google Play) except for the limited data we send or receive to make an integration you turned on work.

3. Information we collect

Account and profile

Email address and a hashed password (stored by our auth provider, Supabase Auth / GoTrue — we never store the password in plain text). Optional display name, handle, avatar, bio, and similar profile fields you enter. Account identifiers (user id) used to sync flights, Peak, Bridge licenses, and community.

Email is the key we use to attach a Peak purchase. Use the same address at Stripe checkout as in Companion.

Simulator telemetry and logbook

When Bridge is connected to your simulator, Companion receives live session data needed to draw the map, systems, logbook, Live Activity, Watch complications, and widgets: position and heading, altitude, speeds, aircraft type and systems state (autopilot, engines, fuel, electrical, pressurization, lights), phase of flight, and similar variables the sim exposes. Peak may additionally carry remote-control commands you issue and sim camera frames to your device.

On your LAN this traffic stays between your PC and your phone (plain HTTP/WebSocket on the local network, which is why Companion asks for Local Network permission). With Peak Relay, the same telemetry (and, if you use them, control and camera) is carried through relay.cobaltsim.com so you can leave the house. Bridge can keep recording on the PC (up to about 12 hours) if the phone disconnects, then sync the missing segment when you reconnect.

If you are signed in, flights and traces may sync to our database so Atlas, history, playback, debriefs, and share pages work on other devices. If you use Companion as a guest, that data stays on the device until you create an account.

Network overlays (VATSIM / IVAO)

Live traffic and ATC come from those networks’ public data feeds. We do not receive your VATSIM or IVAO password. If you optionally enter a VATSIM CID (or similar public identifier), we use it to show your public network hours on Atlas. Adopting a network flight as “yours” or a friend’s stores that association on your account so Live Activities and follows work. Cobalt is not affiliated with VATSIM Inc. or IVAO.

Peak and payments

Peak is sold on the web by Stripe (currently shown around US $9.99/month, US $79.99/year, and US $199.99 lifetime — the price and tax at checkout control). Stripe processes card, Link, Apple Pay, or other methods they support. We receive Stripe customer and subscription or payment identifiers, billing email, plan, status, and similar metadata — not your full card number or CVC. A Peak account gets a Bridge activation code (licensed for up to three PCs by default) which we email via Resend and show in Settings after Face ID / device passcode.

Community and user content

Posts, comments, likes, follows, direct messages, group-chat names and photos, and flight cards you share. Photos you attach are uploaded to our storage. GIFs you pick are fetched from Giphy using your search text; Giphy’s policy applies to that request. Public Atlas / share links (cobaltsim.com/u/…, /f/…, /p/…) show what you published.

Integrations you connect

  • SimBrief. Username you enter, to pull an OFP you already own.
  • Navigraph. If we have app credentials configured, OAuth tokens to load charts you are licensed for. We do not harvest Navigraph’s database.
  • Calendar. Write-only: we add events only when you ask to put a scheduled flight on your calendar.
  • Photos. Saving a share card to your library, or picking a photo for a post or hangar aircraft. We do not scan your library in the background.
  • Charts links. Opening ChartFox, SkyVector, or AirNav in a browser does not give us those sites’ accounts.

Onboarding, analytics, and diagnostics

Optional survey answers (simulator, experience, goals, how you found Cobalt). Coarse product events such as which onboarding step you reached (for example onboarding.peak) so we can see where people drop off. App version, OS, coarse connectivity and crash signals. Push tokens (APNs) if you allow notifications. We do not sell this data and we do not use flight traces to train public AI models.

Website

Standard request logs (IP address, user agent, path) on our host (Vercel) for security and debugging. If you arrive with a creator code (?code=, ?ref=, ?creator=), we store cobalt_ref in a first-party cookie for 180 days (and a copy in localStorage) so a later Peak checkout can attribute the sale. If you join the waitlist at /notify, we store that email to send a launch note and occasional product updates. Each of those emails includes an unsubscribe link (also one-click in supporting clients). Support forms send the message you type plus optional contact email.

Support

In-app reports and cobaltsim.com/support: category, subject, message, screenshots you attach, contact email, and basic app context.

4. iOS permissions (what they are actually used for)

  • Local Network / Bonjour (_cobalt._tcp). Find Cobalt Bridge on your Wi-Fi. We do not scan unrelated devices for advertising.
  • Face ID / Touch ID / passcode. Only to reveal your Bridge activation code in Settings. Biometric templates never leave the device.
  • Photo library (add). Save share cards you export.
  • Calendar (write). Add a scheduled flight when you tap to add it.
  • Notifications / Live Activities / background refresh. Flight phase, TOD, ATC, community, and widgets. Each notification category can be turned off in Settings.

Companion does not use the phone camera. “Camera” in Peak means views from the simulator, delivered by Bridge.

5. How we use information

  • Provide Companion, Bridge, Relay, accounts, sync, widgets, Watch, and Live Activities.
  • Match Peak to the Cobalt account with the same email; issue and enforce Bridge seats.
  • Operate community features you use, including public pages you publish.
  • Send transactional email we can deliver (Bridge code, support, Peak claim, sign-in) via Resend.
  • Send waitlist and launch emails you opted into, until you unsubscribe.
  • Secure the service (rate limits, abuse, fraud, debugging).
  • Improve onboarding and reliability using the survey and funnel events above.
  • Comply with law and App Store / Play disclosure rules.

6. Legal bases (EEA / UK)

Contract: running the service you signed up for, including Peak you purchased. Legitimate interests: security, preventing abuse, attributing creator referrals, product improvement with coarse events. Consent: optional survey, notification permission, calendar/photos/Face ID, the launch waitlist, and marketing cookies if we ever add them (we do not run advertising pixels today). Legal obligation: tax and accounting records Stripe keeps, and any lawful request we must honour.

7. Sharing

We do not sell personal information. We share with processors under contract:

  • Supabase — authentication, database, and file storage.
  • Vercel — website and API hosting.
  • Stripe — Peak payments and customer portal (independent controller of payment method data).
  • Resend — transactional email and waitlist / launch messages.
  • Apple — App Store distribution, APNs, Live Activities, Sign in with Apple if we offer it later. Peak is not an Apple In-App Purchase on this paywall.
  • Giphy — GIF search if you use GIFs in community (your query goes to Giphy).

Public posts, passports, and share URLs are visible as you configure them. We may disclose information if required by law, to protect Cobalt or other users, or in a merger where this policy still applies or you are notified.

8. Retention

Account and synced flights remain until you delete the account in Companion Settings (that removes the Auth user; related rows cascade) or we close the account for a terms violation. Stripe retains billing records as required for tax, disputes, and their services agreement. Support tickets are kept as needed to resolve them. Creator referral cookies expire after 180 days. Waitlist emails stay until you unsubscribe (the address is then kept only as unsubscribed so we do not email it again). Guest/local data is removed when you delete the app or sign in and migrate, depending on the feature.

9. Security

HTTPS to our API and site. Hashed passwords. Relay and license tokens scoped by role (telemetry vs full Peak). Bridge codes should be treated like a password. Local Bridge HTTP is only for your LAN — do not expose it to the public internet. No method of transmission is perfectly secure.

10. International transfers

Hosting and processors may be in the United States and other countries. Transfers from the EEA/UK rely on processor terms such as standard contractual clauses where they offer them.

11. Your rights

Depending on where you live you may request access, correction, deletion, export, restriction, or objection, and withdraw consent. Email reports@cobaltsim.com. You may lodge a complaint with your local authority. California: we do not sell or share personal information as those terms are defined in the CPRA, and we do not use sensitive personal information to infer characteristics. You can delete the account in Settings without emailing us.

12. Children

Cobalt is not directed at children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect their personal information. Contact us if you believe we have, and we will delete it.

13. Automated decisions

We do not make legally significant automated decisions about you. Peak access follows Stripe payment state. Abuse rate limits are automated safety measures, not credit scoring.

14. Changes

We will update this page and the in-app copy when the policy changes, and revise the date above. Material changes may also be noted in the app or by email if we have one on file.

15. Contact

Cobalt Simulations · reports@cobaltsim.com · https://cobaltsim.com/support · Terms of Use · EULA.

Cobalt

The flight simulation companion

Get notified Creators Press Support Downloads Setup Bridge Manage Privacy Terms EULA