Privacy Policy for FlightDeck
1. Introduction & Core Philosophy
Kip Lawrence (“we,” “our,” or “us”) develops and maintains FlightDeck (application identifier quest.kip.flightdeck), a native macOS developer tool for Apple App Store Connect management and local Model Context Protocol (MCP) workflows, as well as the website hosted at https://kip.quest/flightdeck/.
FlightDeck is engineered from the ground up on a local-first, privacy-by-design architecture. We recognize that your App Store Connect API keys provide privileged access to your apps, builds, and developer account. FlightDeck is architected so that your sensitive credentials never leave your Mac, your API requests travel directly to Apple, and no intermediary cloud servers operated by us ever see or store your data.
Core Principle: FlightDeck operates without an intermediary cloud backend. All App Store Connect API traffic is transmitted directly from your Mac to Apple servers over encrypted HTTPS (TLS 1.3).
2. App Store Connect Credentials & Key Security
To interact with Apple’s App Store Connect API, you configure one or more connection profiles by providing your Key ID, Issuer ID, and private API key (.p8 PKCS#8 format). Here is precisely how those credentials are handled:
-
Secure macOS Keychain Storage: Your private
.p8API key material is stored exclusively in the native macOS Keychain (kSecClassGenericPassword) using Apple’s Security framework under the service identifierquest.kip.flightdeck.keys. -
Process Argument Isolation: When importing or retrieving keys, key material is streamed strictly through standard input/output using a dedicated native helper. Secrets are never passed in process command-line arguments (
argv), preventing exposure through system diagnostic tools or process inspection. - No Plaintext Key Storage: Private keys are never written to disk, application preferences, temporary directories, or application log files.
-
Local Token Generation: FlightDeck signs short-lived (15-minute maximum lifetime) JSON Web Tokens (JWTs) locally on your Mac using ECDSA P-256 (ES256). The private key itself is never transmitted over the network—not even to Apple. Only the locally signed, ephemeral token is sent in the
Authorization: Bearerheader of requests made to Apple. - Connection Profile Metadata: Non-sensitive metadata (such as profile name, Key ID, and Issuer ID) is saved locally in application preferences to maintain profile configurations across launches.
-
Immediate Deletion: When you delete a connection profile in FlightDeck, the private key is immediately and permanently removed from your macOS Keychain via
SecItemDelete.
3. Direct Communication with Apple
FlightDeck communicates directly with Apple over three specific, encrypted HTTPS channels:
| Destination Endpoint | Purpose | Authentication |
|---|---|---|
api.appstoreconnect.apple.com |
Core App Store Connect REST API operations (managing apps, versions, builds, TestFlight, and metadata) | Locally signed ES256 Bearer JWT |
itunes.apple.com |
Public storefront lookup (displaying app ratings, versions, and public customer reviews) | None (Public anonymous lookup) |
Apple Presigned Asset Endpoints (e.g., upload.itunes.apple.com) |
Uploading application build archives (.ipa, .pkg) and screenshot sets |
Presigned authorization headers provided by Apple |
No Cloud Intermediaries: We do not operate, nor does any third party operate, a relay server, proxy server, or caching server between FlightDeck and Apple. Your data travels directly from your device to Apple’s servers over TLS 1.3.
4. Model Context Protocol (MCP) Server
FlightDeck contains an embedded Model Context Protocol (MCP) server that enables local AI coding assistants (such as Claude Desktop or Cursor) to interact with App Store Connect capabilities.
-
Strict Loopback Binding: The embedded MCP HTTP server binds exclusively to the local IPv4 loopback address (
127.0.0.1). It does not bind to0.0.0.0or any external network interface. Devices on your local network (LAN) or the internet cannot connect to FlightDeck’s MCP server. - Configurable Authentication: By default, the MCP server allows connections exclusively from your local Mac without requiring a password. When password protection is enabled, inbound requests require an authentication Bearer token stored securely in your macOS Keychain. Missing or invalid credentials are rejected with HTTP 401 Unauthorized.
-
Credential Protection: MCP tools execute authorized actions internally using FlightDeck’s engine. Zero MCP tools expose or return private keys,
.p8file contents, or raw JWTs to MCP clients. - Semantic Safety & Human Approval: Mutating actions (such as submitting an app for App Review, modifying localized copy, or modifying beta groups) can be staged for manual confirmation. When staged, the operation generates an approval ticket in the FlightDeck macOS desktop UI requiring your explicit confirmation before any payload is sent to Apple.
- Developer Control: Enabling the MCP server is optional and developer-controlled. You decide which local AI clients to configure. How external AI clients process information once received by them is governed by those clients’ respective terms and privacy policies.
5. Artificial Intelligence (AI) Providers
FlightDeck contains zero direct integrations with external AI providers.
The FlightDeck application does not connect to, communicate with, or transmit data to OpenAI, Anthropic, Google Gemini, DeepSeek, or any other cloud-hosted AI service. FlightDeck operates solely as an MCP server. If you connect an external AI agent to FlightDeck via MCP, data requested by that agent flows directly between your local agent process and FlightDeck on your Mac.
6. Analytics, Telemetry & Tracking
FlightDeck does not currently use third-party analytics or usage-tracking services. Specifically:
- We do not embed analytics SDKs (no Google Analytics, Firebase, Mixpanel, Amplitude, PostHog, or Segment).
- We do not collect behavioral telemetry, track button clicks, measure session lengths, or profile user behavior.
- We do not track you across other applications or websites.
7. In-App Purchases & Subscriptions (RevenueCat)
FlightDeck offers an optional “FlightDeck Pro” auto-renewing subscription through Apple’s Mac App Store using StoreKit 2.
To manage and validate subscription entitlements across launches, FlightDeck integrates RevenueCat, Inc. (purchases_flutter) as a third-party service provider.
- Data Shared with RevenueCat: RevenueCat receives anonymous App User IDs, StoreKit product identifiers, and Apple-issued transaction receipts to verify active entitlement status.
- Data Never Shared with RevenueCat: RevenueCat never receives your App Store Connect credentials, private keys, Key IDs, Issuer IDs, Apple ID credentials, or payment card details (financial processing is handled entirely by Apple).
- For more details regarding RevenueCat’s privacy and security practices, please refer to the RevenueCat Privacy Policy.
8. Diagnostics & Crash Reporting
FlightDeck does not embed third-party crash reporting frameworks (such as Sentry, Bugsnag, or Crashlytics).
If the application encounters an unhandled exception or crash, standard macOS diagnostic reports may be collected and aggregated by Apple if you have opted into sharing crash analytics with developers in your macOS System Settings. These diagnostic logs are governed by Apple’s Privacy Policy.
9. Local Storage on Your Mac
FlightDeck stores information in four specific locations on your local Mac:
-
macOS Keychain: Securely stores
.p8private keys and your local MCP server authentication password using macOS Secure Enclave / encryption mechanisms. -
Application Preferences (
~/.asc_mcp/preferences.json): Within the application’s sandboxed container, stores non-sensitive profile identifiers (profile name, Key ID, Issuer ID), MCP port configuration, autostart preferences, and safety policy settings. -
Local Audit Event Trail (
~/Library/Application Support/asc_mcp/audit.jsonl): Stores a local, chronological record of executed App Store Connect operations and HTTP status codes for your own inspection and compliance. The audit logger automatically strips and redacts private key patterns, JWT signatures, and sensitive identifiers. The audit trail is strictly bounded to a maximum of 2,000 entries (FIFO trimmed) and never leaves your Mac. -
Local MCP Discovery Artifacts (
~/.asc_mcp/discovery/): Ephemeral JSON files containing local loopback port numbers and process IDs used by local MCP clients to detect the running server. These files are automatically cleaned up when the server stops.
10. Clipboard & File Access
- Clipboard Access: FlightDeck interacts with the macOS clipboard only when you explicitly click a “Copy” button in the user interface (e.g., copying an AI prompt template or API response). FlightDeck never reads, monitors, or inspects your clipboard.
-
File Access & App Sandbox: FlightDeck operates under the strict macOS App Sandbox (
com.apple.security.app-sandbox). File access outside the container requires explicit user action via native macOS Open and Save dialogs (such as selecting a.p8key file or choosing a build archive for upload).
11. Website Data Handling (https://kip.quest/flightdeck/)
The FlightDeck website at https://kip.quest/flightdeck/ is currently a static informational and documentation resource:
- We do not use tracking cookies, analytics cookies, or advertising pixels on this site.
- No user accounts, waitlist forms, or tracking scripts exist on the website at this time.
- Standard Web Server Logs: Like virtually all web servers, our Apache web server hosting infrastructure may automatically generate standard operational access logs containing request metadata (such as IP address, requested URL, user-agent header, and timestamp). These logs are utilized solely for server maintenance, security monitoring, and DDoS defense, and are retained on standard rotating server schedules.
12. Future Capabilities & Policy Updates
As FlightDeck evolves into a comprehensive developer hub, future phases may introduce additional developer-facing features on the website, such as developer accounts, bug reporting, community feature voting, and feedback submissions.
This Privacy Policy will be updated prior to or concurrently with the introduction of any new data collection mechanisms. We will post updates directly to this URL with a revised “Last Updated” date.
13. Contact Information
If you have any questions, concerns, or feedback regarding this Privacy Policy or FlightDeck’s data handling practices, please contact us at:
Kip Lawrence
Email: info@kip.quest
Website: https://kip.quest/flightdeck/