1. Who we are
FirstSolo (“we”, “us”) is a service of Average Quality, LLC, a Texas limited liability company, which operates the website and service at firstsolo.ai and is the controller of the personal data described here. We are an independent study tool and are not affiliated with or endorsed by the Federal Aviation Administration. You can reach us at [email protected].
2. What we collect
Account information. Your email address (used to sign you in with one-time codes) and the display name you choose. If you continue with Google or Apple instead, we keep the address, the name if you share it, and the account identifier that provider gives us — nothing else; with Apple’s Hide My Email the address is a private relay that forwards to yours. We do not store passwords; there are none.
Study activity. The sessions you start, the questions served to you, the answers you give — including free-text answers and messages you exchange with the AI examiner — your scores, mastery estimates and the timing of your work. This is the product: it is what makes the next question fit you.
Voice input. If you answer by voice, your browser records the answer only while the microphone button is on and sends the recording to us to be turned into text. We pass it to OpenAI for transcription and do not keep the recording: what stays is the text, and only once you choose to send it.
Credits and billing records. Your credit balance, every credit charged or added and what it was for, and — only for the purpose of checking our own prices against costs — the size, in tokens, of each request the service made to an AI model on your behalf, and the length of each voice recording transcribed. We do not store payment card details; when paid credit packs launch, payment will be handled by a payment processor and this policy will be updated first.
Technical data. Server logs that record requests to the service with the time, the page or endpoint, the response status, a short account identifier and the network address they came from. These logs exist to keep the service running and secure and are not used for profiling.
Messages you send us. If you use the support form or email us, we keep the message and your address so we can reply.
3. Payments
When you buy credits, the payment is taken by Stripe on its own payment page. Your card number never reaches our servers and we never store it. Stripe collects what it needs to take the payment and to meet its own legal obligations — your card details, your billing address, and your email address — and acts as its own controller for fraud prevention and financial reporting. Its privacy policy is at stripe.com/privacy.
What we keep is the record of the purchase: which pack, how many credits, the amount and currency, any tax, the date, and Stripe’s reference for the payment. We need it to put the credits in your account, to answer questions about a charge, and to keep the accounts that tax law requires us to keep.
4. What we do not collect or do
- We do not sell, rent or trade personal information — to anyone, for any purpose.
- We do not share your information with third parties for their own marketing or any other purpose of their own.
- We do not use your answers, messages or any other data of yours to train AI models, ours or anyone else’s.
- We do not show advertising and do not use advertising or cross-site tracking technologies.
- We do not collect precise location, contacts, or anything from your device beyond what a web browser sends.
5. How we use it
- To provide the service: sign you in, write and grade questions, track your mastery, keep your credit ledger.
- To keep the service working and safe: diagnose failures, prevent abuse, verify that charges match usage.
- To improve the service in aggregate — for example, which subtopics students find hardest, or how often a generated question is rejected by verification — without singling anyone out.
- To answer you when you write to us.
6. Service providers who process data for us
We run the service on infrastructure and services operated by other companies. They process data only to provide their service to us, under their own terms, and not for their own purposes:
- OpenAI — generates and verifies questions, grades free-text answers and transcribes answers given by voice. The question, the reference notes, your answers and messages in a session, and any voice recording are sent to OpenAI’s API to produce the response. We send text requests with storage disabled, and under OpenAI’s API terms none of this data is used to train its models.
- Stripe — takes payments for credits and holds the payment records, as described above.
- Emailit — delivers sign-in codes and messages from the support form.
- DigitalOcean — hosts the application, the database and the file storage (illustrations, figures and reference documents).
- Google Analytics — see “Cookies and analytics” below.
We may also disclose information if the law requires it, to protect our rights or the safety of others, or as part of a merger or sale of the service — in which case this policy would continue to apply to your data.
7. Cookies and analytics
Strictly necessary cookies. Signing in sets a small number of cookies that identify your session (“fs_access”, “fs_refresh”, “fs_session”). They contain no personal information beyond an account reference, are not readable by other sites, and are deleted when you sign out. The service cannot work without them.
Preferences. Your browser may store a few conveniences locally (for example the zoom level of the reference viewer, or recent searches). These never leave your device.
Google Analytics. We use Google Analytics to understand, in aggregate, how the public site and the service are used — which pages are visited, roughly where visitors come from, which features are used. Google Analytics sets its own cookies (“_ga” and similar) and processes data under Google’s privacy policy. We do not send it your email, your name or the content of your study. You can opt out with Google’s browser add-on or by blocking its cookies.
How you found us. If you arrive from an advertisement, a link on another site or an instructor’s referral link, we keep what that link said about where it came from — the campaign tags in the address, the advertising network’s click identifier, the name of the site that linked to you, and any referral code — in a cookie (“fs_attr”) for up to 90 days. If you open an account in that time, it is copied onto your account so we can tell which of our own efforts actually help people find us. It is first-party: it stays on our servers, is never sold or shared, is not combined with anything bought from a data broker, and is not used to build a profile of you or to target advertising back at you. We record the name of the referring site, never the full address of the page you came from. It is deleted with your account. Blocking cookies, or deleting this one, costs you nothing — the service works exactly the same.
We use no other analytics or tracking tools.
8. How long we keep it
Your account information, study activity and credit ledger are kept for as long as your account exists. Server logs are kept for a limited time for operations and security and then discarded. Messages you send us are kept as long as needed to handle them.
Payments are different. Stripe keeps its record of every payment — the amount, the date, the card’s last digits and the billing address — for as long as financial and tax law requires, which is typically several years, and it does so whether or not you still have an account with us. That record is what a refund, a chargeback or an audit is settled from.
The account history. Every new account starts with free credits, once per person. To keep it that way we keep a short record of each account opened and deleted: when it happened, whether you signed up with an email code, Google or Apple, and whether the free credits were given. The record does not hold your address. It holds a one-way fingerprint of it, and of the Google or Apple account identifier where you used one: we can check whether an address someone gives us has had an account before, but we cannot turn the fingerprint back into an address. This record is kept after an account is deleted; if an address that had an account signs up again, the new account works as usual but starts without free credits.
9. Deleting your account and data
You can delete your account yourself at any time from the account page. Deletion is immediate and complete: your account, sessions, answers, mastery record, credit ledger and any remaining balance are removed and cannot be recovered. Copies in routine backups expire on their own schedule shortly after. You can also ask us to delete your data by email; we will confirm when it is done.
Three things survive it, and we would rather say so than surprise you. Payments you have made stay in Stripe’s records, as described above, because the law requires a business to keep its accounts. The account history keeps its fingerprint of your address and the dates the account was opened and deleted, so the free credits are not given to the same person twice. And deleting the account does not refund an unused balance — if you want the unused part of a recent purchase back, ask us before you delete, while there is still a balance to measure it against.
10. Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal information, to object to or restrict certain processing, and to complain to a supervisory authority. You can exercise the first four directly: your study record is visible in the app, your name is editable on the account page, and deletion is described above. For anything else, email us and we will respond within 30 days.
11. Security
Sign-in uses one-time codes sent to your email, or your Google or Apple account, so we hold no password to lose. Data is encrypted in transit. Access to the production systems is limited to the people who operate the service. No system is perfectly secure; if we learn of a breach affecting your data we will tell you.
12. Children
The service is intended for people preparing for an FAA pilot certificate and is not directed to children under 13. We do not knowingly collect information from children under 13; if you believe a child has created an account, contact us and we will delete it.
13. Changes to this policy
We will update this page when our practices change and revise the effective date at the top. For material changes — for example a new category of data or a new service provider — we will also let signed-in users know in the app or by email.
14. Contact
Questions about privacy: [email protected], or the form on our support page.