Hangar
Privacy Policy
Last updated 29 August 2026. Hangar is a control surface for webhooks you already own. This policy explains what leaves your iPhone and what does not.
What we collect
- Account record — the email address and callsign you sign up with, or the email Apple relays when you use Sign in with Apple. Stored in Firebase Authentication.
- Hangar contents — the services, commands, and flows you create, including the webhook URLs, HTTP methods, headers, and request bodies you enter.
- Run log — the label, service, status code, duration, and any error message for each command you fire, so the Console can show a history.
- Purchase state — RevenueCat tells us whether your premium entitlement is active. We never see your payment details; Apple handles the transaction.
- Diagnostics — Firebase Analytics collects standard app usage events such as launches and crashes.
What we do not collect
We do not collect your contacts, photos, location, health data, or advertising identifiers. Hangar contains no third-party advertising or tracking SDKs, and we do not sell or share your data with data brokers.
Webhook URLs and secrets
Webhook URLs, headers and request bodies are the sensitive part of your hangar. When our backend is reachable they are encrypted with AES-GCM before they are stored, and decrypted only at the moment a command fires — anyone reading the raw database sees ciphertext.
If the backend cannot be reached, the command is still saved so the app keeps working. In that case the URL is stored as you entered it, readable only by your own account under our access rules. The app shows whether a command is stored encrypted.
When a command fires in on-device mode, the request goes straight from your iPhone to the endpoint you configured. We are not in the path and never see the response body — only the status code and duration recorded in your activity log.
Where it is stored
Data lives in Google Firebase (Authentication, Cloud Firestore, and Cloud Functions) under our project, and in RevenueCat for entitlement state. Both are processors acting on our instructions. A copy of your most recent run and your service layout is cached in an App Group container on your device so widgets, Siri, and Lock Screen controls work.
How long we keep it
Your hangar stays until you delete it. Deleting a service or command removes it and its stored secret. Deleting your account removes your profile, services, commands, flows, run log, invites, and authentication record. Backups and logs age out within 30 days.
Your controls
- Edit or remove any service, command, or flow at any time.
- Delete your account from Hangar → Profile → Delete account. This is immediate and cannot be undone.
- Request a copy of your data, or ask a question about this policy, by writing to hibaabbas1306@gmail.com.
Depending on where you live you may have additional rights under the GDPR or CCPA, including access, correction, portability, and erasure. Deleting your account satisfies an erasure request; email us for anything else.
Children
Hangar is a developer tool and is not directed to children under 13. We do not knowingly collect data from them. If you believe a child has created an account, email us and we will remove it.
Changes and contact
If this policy changes in a way that affects you, we will note it in the app before the change takes effect. Questions go to hibaabbas1306@gmail.com.