Privacy policy
What data we collect, why, and what you can do about it. Written plainly — no lawyer paragraphs unless we have to.
Last updated: 2026-07-21 — Private profile recovery preview
Who we are
FFB-Bridge is developed and published by Rohsam Inc., a software publisher based in Toronto, Ontario, Canada. Rohsam Inc. operates ffb-bridge.com and the FFB-Bridge download and update list. You can reach us about any privacy matter at supportffb-bridge.com. Publisher verification details are available at rohsam.com/legal.
What we collect
When you sign up for the download email, we store:
- Your email address — so we can send you the confirmation link and, if you consent, occasional release-related updates.
- Your IP address at signup — logged once, for abuse triage only. Never shown publicly, never shared.
- A random token we generate to authenticate your confirmation and download links. It has no link to your personal identity beyond your signup row.
- Signup, confirmation, and download timestamps — so we know when a subscriber confirmed and how many downloads they've used against their quota.
- Beta browser-access grants — after you confirm access to the beta page, your browser stores a random token and we store only its one-way SHA-256 hash, the linked subscriber-row ID, and creation and expiry times. We do not store an IP address, user-agent, device fingerprint, last-visit time, or browsing history with this grant.
When you send feedback through the feedback form, we store the report text, optional category, optional reply email, submission timestamp, user-agent string, and a keyed hash of your IP address for abuse prevention. We do not publish feedback reports.
If you attach screenshots, we store the uploaded image files so we can inspect the bug or UI state you chose to share. Screenshots may contain anything visible on your screen, so review them before sending.
If you attach or upload a support bundle, we store the ZIP and parse its allow-listed text files into structured triage data: app version, build hash, operating system, hardware identifiers, simulator connection details, active tuning values, current physical-device and renderer selection, safety ceiling, calibration and force-polarity settings, explicit control assignments, compatibility settings, Support checks, and warning/error log lines. Passwords in SimConnect config are stripped by the app before the bundle is created. See Support bundles for the full file list and limits.
Requesting a recovery sign-in link temporarily stages your encrypted email address, a keyed email lookup, a single-use login token and protected delivery record, and a keyed IP value for rate limiting. Your first confirmation may create the separate recovery account and link the verified email to an eligible Pro license. Approving a computer stores its name, platform, and session timestamps. Profile lifecycle metadata and profile JSON are stored only after you separately enable remote copies and select profiles in the desktop app.
If you choose to make an optional Support the Dev payment or buy an FFB-Bridge Pro license, checkout is hosted byStripe. Rohsam Inc. does not receive or store full card numbers. Stripe may provide us payment records such as amount, currency, payment status, Stripe session/payment identifiers, receipt email, and limited billing details needed for receipts, refunds, accounting, tax, fraud prevention, or support.
Outside that optional Stripe-hosted payment flow, for ordinary site visitors, download-email users, and core or Free desktop-app use, we do not collect names, addresses, phone numbers, credit cards, flight data, or desktop telemetry. Core force-feedback operation stays local. The app connects externally only for a feature you enable or trigger, such as the update check described below, profile sharing, or optional Pro profile recovery. It never automatically uploads flight data or hardware settings; you choose whether to attach screenshots or a support bundle to feedback. See the FAQ on the home page.
Update checks
When update checking is enabled — it is on by default and can be turned off in the app's Settings — the desktop app contacts ffb-bridge.com when it starts to fetch the current version manifest, a small public JSON file describing the latest available release. The request carries no personal data and no identifiers: no account, no license or serial number, no hardware details, and no tracking parameters. Like every request to this website, it appears in our standard web-server access logs, which are kept only as long as needed to operate and secure the site.
We count manifest responses and approved updater-file requests only as aggregate operational statistics. The labels are the Stable/Beta route, the public manifest's version and platform, the serve result, and a broad request class (likely desktop, browser, automation, known bot, or other). For these statistics we do not retain raw headers, an IP address or hash, cookies, installation identifiers, or per-request analytics events; they cannot tell us how many unique people or devices use FFB-Bridge.
First-party cookies
For visitors using the public marketing and download pages (not the optional community sign-in or invite-only translation review), this site uses at most two first-party cookies. Neither is used for advertising, cross-site tracking, analytics, or a behavioral profile.
Language choice
The website is available in multiple languages. Language pages use visible URL prefixes such as /fr-ca/, /de/, and /ja/. When you explicitly choose a language, we store one first-party preference cookie named ffb_lang for up to 180 days so the bare home page can remember that choice. The cookie contains only the selected language code, such as fr-CA. It is not a tracking ID and is not shared with anyone.
Verified beta access
If you ask to access beta downloads and confirm the link in your inbox, we store an HTTP-only, secure, same-site cookie named ffb_beta_access for up to 730 days. It lets that browser display the beta download buttons without asking you to verify again. A new browser or device, a cleared cookie, or an expired grant requires a new email confirmation.
The cookie contains only a cryptographically random bearer token. It does not contain your email address, subscriber ID, IP address, device details, or a stable analytics identifier. The database stores only the token's one-way hash and its link to your confirmed subscriber row. That link is necessary to prove confirmation, revoke access after unsubscribe or deletion, and contact beta participants about urgent force-safety changes. The grant is therefore pseudonymous rather than anonymous, but it is not read by our analytics and is never used to follow what you view. The browser sends it only on /beta paths. Unrelated pages never receive it.
Profile recovery account
Passwordless sign-in uses the necessary, functional .ffb.account secure HttpOnly SameSite cookie with a 30-day sliding lifetime. A separate protected pending-link cookie lasts no more than about five minutes while you confirm a link. Neither cookie contains profile content or is used for analytics or marketing.
Site translations are automatically generated and may contain mistakes. If you send translation corrections or language requests through the feedback form, we handle that message under the same feedback rules described on this page.
Separately, we may directly invite a very small number of specific people to review translations. This is not a public feature, is not advertised on the site, and is not visible or available unless we personally send someone an invite link. For those invited reviewers only, we store the reviewer's name, email address, review language, invite status, expiry or revocation timestamps, temporary review cookie, and any translation notes they submit. We use that information only to manage translation review and improve localized site text.
What we don't do
- We don't use third-party analytics that set cookies or track you across sites. The site uses self-hosted Umami for aggregate page-view counts, referrers, device type, and browser/OS summaries; it is cookie-free and does not profile individual visitors. Query strings and URL fragments are excluded from analytics, and browser Do Not Track is respected.
- We don't sell, rent, or share your email address with any third party for marketing. We only use service providers needed for services you request, such as email delivery and optional Stripe-hosted payment processing.
- We don't send you marketing on behalf of anyone else.
Why we collect it
Three reasons:
- Delivery of the download links you asked for — your signup is the explicit request for this service.
- Release updates (when you tick the consent box): new releases, breaking changes, and bugs we discover after you've installed. Messages are limited to important product updates; general marketing is excluded.
- Beta testing and force-safety notices (when you request beta access): beta release/testing messages and urgent notices about behavior that could cause a strong force-feedback base to move unexpectedly or produce unsafe force.
- Abuse triage, if we see a signup pattern or feedback upload pattern that looks like an attack.
- Support and debugging, when you choose to send feedback, screenshots, or a support bundle.
- Optional support payments, when you choose to contribute through Stripe, for payment processing, receipts, refunds, accounting, tax, fraud prevention, and related support.
- FFB-Bridge Pro licensing, when you buy or recover a Pro license, for license fulfillment, activation, recovery, refunds, chargebacks, fraud prevention, and support.
- Private profile recovery. When you opt in, we use the data only to authorize your computers, retain the profile versions you selected, restore or export them, enforce limits, and honour deletion.
- Language preference, when you choose a site language and ask the site to remember it on future visits.
- Persistent beta access, when you confirm a beta verification link and ask that browser to remember it.
Feedback reports are voluntary. You decide whether to include an email address, screenshots, or a support bundle.
We will never send you anything outside of those categories without separate, explicit consent.
Consent and withdrawal (CASL)
Under Canada's Anti-Spam Legislation, we only send commercial electronic messages to people who have given express consent. That's the checkbox on the signup form. You can withdraw consent at any time:
- Click the Unsubscribe link at the bottom of any email we send you. That instantly marks your row as opted out and prevents any further send.
- Or email supportffb-bridge.com from the subscribed address with "unsubscribe" in the subject. Processed within one business day, always faster than the 10-business-day CASL maximum.
Changed your mind after unsubscribing? Re-enter your email on the home page and tick the consent box again. You'll see a confirmation prompt that acknowledges the re-opt-in, then a fresh link lands in your inbox — no need to email anyone.
Community profiles and forum
Draft — pending legal review. The description of the community profile-sharing data flow below is new and is being reviewed alongside the Profile Library Terms. It accurately reflects what the software does today; the binding wording may change after review.
If you join the community (a free, passwordless account), we store only what you contribute: a display handle, any tuning profiles you share, your reviews, and your forum posts. There is no behavioural tracking — no "who viewed what", no per-user event log. Community membership is separate from the marketing list: joining never adds you to broadcast email.
If you add an image to a forum post, we accept only JPEG, PNG, or WebP, decode it on our server, correct its orientation, resize it, and create new WebP copies. We do not retain the original upload or its embedded camera, location, author, or device metadata. A staged image that you do not post expires after about 24 hours. Published images remain with the post until you remove them, a moderator removes them, or your account is erased; a reported image may be kept as private moderation evidence for up to 90 days. Forum pages never load an image from an uploader-selected remote host.
If a forum post contains a standalone YouTube link, we show a first-party placeholder that makes no request to YouTube or Google. The player loads only after you choose “Load video from YouTube”. At that point your browser connects directly to YouTube's Privacy Enhanced Mode service, which receives your IP address and request/browser information and may collect additional playback data. You can use the ordinary “Open on YouTube” link instead. Google's processing is described in the Google Privacy Policy and the YouTube Terms of Service.
Sharing a profile from the app
When you click "Share" on a tuning profile in the FFB-Bridge desktop app, the app transmits that profile to ffb-bridge.com and we hold it transiently — about 30 minutes — only so we can pre-fill the submission form for you. Profile sharing is one explicit network feature; update checks and optional Pro profile recovery are separate, user-controlled connections. A shared profile that you do not go on to Publish is automatically deleted when that short window lapses. It is held in temporary server memory only, is never made public, and is never written to our database unless you publish it.
A shared profile carries a little environment metadata to make it useful to other pilots: the force-feedback stick model it was tuned on, the aircraft it is for, and the FFB-Bridge app version that created it. Tuning profiles contain aircraft and force-feedback settings. A shared profile is designed to contain no personal information, and your email and account identity are never placed inside it. You are credited publicly only by the display handle you choose (or "Anonymous").
The act of sharing from the app happens before you sign in. To stop abuse of that anonymous upload endpoint, we process your IP address only as a keyed (hashed) value for rate-limiting — the same abuse-prevention basis described above for the feedback form. We do not store the raw address for this purpose, and it is never shown publicly or shared. This applies to anonymous requests before sign-in and to requests from signed-in members.
Private profile recovery preview
Buying or activating Pro does not create a recovery account or upload profiles. Requesting a sign-in link starts only the short-lived verification stage. The first confirmation creates the recovery account only for a verified email linked to an eligible Pro license. No profile is uploaded until you separately approve a named computer, enable remote copies, and select profiles in the desktop app.
Profile JSON is validated, compressed, deduplicated only within your account, and encrypted with a dedicated AES-256-GCM key before storage. The service manages encryption at rest and decrypts profile content only for authorized recovery functions. Profile content is excluded from analytics, recommendations, advertising, and model training.
A requested link's single-use token and protected delivery record expire within 20 minutes. If you never confirm a first request, its recovery-only email staging is eligible for normal cleanup after 72 hours. The preview then keeps up to 250 active profiles and 10 versions per profile, with account totals of 500 retained profile identities and 5,000 retained versions; retained history and 30-day recoverable trash count toward those limits, alongside a 25 MiB compressed-content cap. Portable export is capped at 256 MiB of retained plaintext plus its manifest. Computer access tokens last 15 minutes, sessions expire after 90 idle days or 365 total days, and the recovery account remains until you erase it.
FFB controller identity and selection, calibration, polarity, MOZA settings, safety acknowledgements, simulator settings, logs, support bundles, screenshots, telemetry, and public Profile Library state are not copied. The approved computer name, platform, and session metadata described above are stored.
You can pause new copies, revoke a computer, restore remote trash, or download a complete ZIP. Deleting one remote profile moves only the remote copy to recoverable trash until its displayed purge date, after which it is permanently removed. Erasing the recovery account records the erasure independently and deletes the live account and SQL data. Encrypted disaster-recovery media cannot be selectively rewritten in place; before public availability they must have a documented, bounded expiry schedule. A non-identifying keyed tombstone prevents an older restored database from recreating the account. Your download-email and marketing choices, and separate community membership, have their own controls. Local profile files are never deleted.
Deleting community data
If you ask us to delete your account, we anonymise your contributions — your handle is replaced with "[deleted member]" so threads and published shared profiles stay readable for everyone — or remove them entirely on request. Your sign-in identity (handle, login tokens, any moderator notes) is deleted outright. Images you uploaded to forum posts are deleted outright rather than anonymised.
Deletion concerns apply to published profiles only. Profiles that were shared from the app but never published are not retained — the transient staged copy is auto-deleted within about 30 minutes, so there is nothing for us to delete after that.
How long we keep it
Your subscriber row persists until one of:
- You unsubscribe — we keep the row marked opted-out so we honor your choice even if the same address re-signs up later. No further messages are sent.
- You email us asking us to delete your data — we delete the row and its beta browser grants entirely within 30 days of the request.
- You stop using the product and ask us to remove your subscriber record — we delete it within 30 days unless we need to retain an opt-out marker to honor an unsubscribe.
Beta browser grants expire after at most 730 days and are deleted with the subscriber row. Unsubscribing or suppression makes them unusable immediately. Clearing ffb_beta_access from the browser removes that browser's local access token; the unusable server-side hash is deleted after its normal expiry (the cleanup job runs every six hours) or with the subscriber's data deletion.
Feedback reports and screenshots are retained as long as needed for product support and bug history. Raw support-bundle ZIP files are retained for a short triage window, 30 days by default, so we can re-parse them if the parser improves; parsed support data may be kept with the feedback report after the raw ZIP is removed. You can ask us to delete a feedback report or bundle at any time.
Aggregate analytics are kept without cookies or visitor profiles. Server logs and abuse-prevention records are kept only as long as needed to operate and secure the site.
Optional support-payment and Pro license records are retained as long as needed for fulfillment, activation, recovery, receipts, refunds, chargeback handling, accounting, tax, fraud prevention, support, and legal obligations.
Your rights under PIPEDA
As a Canadian resident you can, at any time:
- Access the personal information we hold about you. Email us from the subscribed address and we'll reply with your row contents.
- Correct any information you believe is inaccurate.
- Delete your data. We'll remove the row within 30 days.
- Complain to the Privacy Commissioner of Canada if you're not happy with our response: priv.gc.ca.
Non-Canadian users
We welcome users from anywhere. For users outside Canada, the principles above still apply — express consent, easy unsubscribe, no third-party sharing, minimal data collection. If you are a resident of the European Economic Area, United Kingdom, or California, the corresponding rights under GDPR / UK-GDPR / CCPA are honored through the same email-based access and deletion process described above.
Changes to this policy
If we make material changes we'll update this page and notify active subscribers by email before the change takes effect. Minor wording edits are logged via the "Last updated" date at the top.
Contact
Questions, access requests, unsubscribe requests, complaints — all to supportffb-bridge.com.
Postal address:
Rohsam Inc.
2727 Steeles Ave West, Unit 103-886, Toronto, ON M3J 3G9, Canada