Privacy Policy
This Privacy Policy explains how personal data is processed when you use the App, in accordance with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG). The App is designed to be offline-first and data-minimal: most of your data never leaves your device.
1. Controller
The controller responsible for data processing under Art. 4(7) GDPR is:
Johannes Püller
Eisenhüttelgasse 79B
2380 Perchtoldsdorf, Austria
Email: info@sailorscompanion.com
A Data Protection Officer is not appointed, as it is not required under Art. 37 GDPR for this processing.
2. Principles — what stays on your device
By design, the following are stored only locally on your device (and, if you enable it, in your own iCloud — see §4.4) and are not transmitted to the controller: your logbooks, log entries, recorded GPS track, observations, statistics, and settings. The controller operates no account system and no readable central database of your voyages. Two optional features — the anchor watch and sharing a logbook by link — do place a copy on a server operated by the controller, but it is encrypted on your device before it leaves it and the controller cannot read it. §6 describes both in full.
3. Location data
With your permission, the App accesses your device location (including in the background, “Always”) to record your track and compute distance, speed and course, and to trigger movement-based reminders. This processing happens on your device. Your position is transmitted to third parties only in the limited cases described in §4 (e.g. as rounded coordinates sent to the weather service to fetch a local forecast, as coordinates sent to the geocoding service to derive readable place names, and — indirectly — as the map view you are looking at, sent to the controller's chart server that draws it for you, see §4.5). The App never shows or invents data it cannot actually know.
Legal basis: performance of the service you requested and our legitimate interest in providing core logbook functionality (Art. 6(1)(b) and (f) GDPR). You can withdraw location access at any time in iOS Settings; background recording then stops.
4. Third-party services (recipients / processors)
The App uses the following external services. Each receives only the data necessary for its function.
| Service | Provider | Data received | Purpose |
|---|---|---|---|
| Weather forecast | Open-Meteo (open-meteo.com) | Approximate coordinates (rounded to a grid) | Retrieve the local weather/marine forecast for a log entry |
| Nautical chart (map tiles & seamarks) | Produced and provided by the controller; delivered via Amazon Web Services (CloudFront) | The requested map view and your IP address | Drawing the chart and its seamarks — for the log data this produces, see §4.5 |
| Offline charts (optional) | Provided by the controller, via Amazon Web Services | The region you selected and your IP address | Producing and downloading the charts you take with you without a network |
| Place names (reverse geocoding) | Overpass API (overpass-api.de), based on OpenStreetMap data | Coordinates | Deriving human-readable place and area names |
| Map rendering (static chart image, fallback) | Apple MapKit (Apple Inc.) | Coordinates / map extent | Render the static chart image when the App’s own renderer is unavailable |
| iCloud backup (optional) | Apple Inc. | Your local App data (if you enable backup) | Back up the App database to your own iCloud account |
| App distribution, purchases & subscriptions | Apple Inc. (App Store) | Purchase/subscription data handled by Apple | Deliver the App and process in-app purchases; the controller does not receive your payment details |
| Feedback & support (optional, see §5) | Hosted by the controller on domainFactory servers in Germany | Your message text, technical metadata, and an optional reply email | Receive and process feedback/support requests |
| Anchor watch & sharing by link (optional, see §6) | Hosted by the controller on domainFactory servers in Germany | An end-to-end encrypted copy of what you chose to share — the controller holds no key and cannot read it | Serve the shared page to whoever holds the link |
| Reporting a navigation mark (optional, see §7) | OpenStreetMap Foundation (openstreetmap.org) | The reported position, your report text, the time, and either your IP address or your OpenStreetMap account | Publish your report as a public note in OpenStreetMap |
The map data comes from OpenStreetMap and OpenSeaMap. The chart itself, however, is produced and served by the controller: viewing it sends no requests to OpenStreetMap or OpenSeaMap. The attribution is shown in the App under “Legal & About”.
Where a recipient acts as a processor, an appropriate data processing agreement (Art. 28 GDPR) is in place. For transfers to providers outside the EU/EEA (e.g. Apple), processing is safeguarded by the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework as applicable. The App contains no advertising, no analytics/tracking SDKs, and no advertising identifier. The chart's delivery network answers your request from the nearest location, which may be outside the EU; Amazon Web Services acts as a processor for this. The only usage statistic is produced server-side from log data and is described in §4.5.
4.4 iCloud backup
If you enable backup, a copy of the App’s local database is stored in your own iCloud account, under your Apple ID and Apple’s terms and privacy policy. The controller has no access to your iCloud backups.
4.5 Log data of the chart server
To draw the nautical chart, the App requests the currently visible map views from a server operated by the controller. As with any web server, log data arises in the process: your IP address, the time, the requested map view and an identifier of the App. The requested view reveals which sea area you were looking at. It says nothing about where you are, what course you sailed, or what your logbook contains — all of that stays on your device (§2).
These logs serve secure operation, defence against abusive access, and an aggregated usage statistic: how many devices used the chart on a given day, and which sea areas were viewed. During evaluation your IP address is hashed with a secret random value that changes daily; only the result of the count is stored, never the address itself. Because that random value changes daily, recognising you across several days is technically impossible. The sea areas are combined into coarse fields, so that individual harbours, approaches or berths are not discernible within them.
The raw logs are deleted automatically after seven days. No user profile is created, no merging with other data takes place, and the statistic is not passed on to third parties.
Legal basis: our legitimate interest in the secure operation of the service and in understanding how and where the App is used, in order to develop it further (Art. 6(1)(f) GDPR).
5. Feedback & support
If you choose to send feedback from within the App, the following is transmitted to the controller’s own server: your free-text message, technical metadata (e.g. app version and build, iOS version, device model, language, current screen and status, coarse counts) and, only if you fill it in, a reply email address. No position data, contacts, or persistent device identifiers are attached. If you leave the email field empty, the submission is anonymous and we cannot reply.
The exact metadata is shown to you in the App before sending. Note that free text you type may itself contain personal data; please do not include more than necessary.
Legal basis: your consent and the controller’s legitimate interest in improving the App and providing support (Art. 6(1)(a) and (f) GDPR).
6. Sharing by link (anchor watch and shared logbook)
The App can publish a copy of a voyage — or, for the anchor watch, your anchorage and the boat's movement around it — to a web page that anyone holding the link can open in a browser. Nothing is published unless you start a share, and every time you do, you are the one deciding to publish.
What is transmitted. For a shared logbook: the recorded track, the times, the statistics, the places you anchored or moored resolved to their names, and the voyage's name, region and country — plus, unless you switch it off, the boat's name and type. If you leave live position on, the page also shows where the boat is now, how fast and on what course, for as long as the share runs. Notes and any other free text you have typed into log entries are never transmitted: the transfer format has no field for them. Crew names are not transmitted either.
The controller cannot read any of it. The copy is encrypted on your device (AES-256-GCM) before it is sent. The key travels in the part of the link after the “#”, which browsers never send to a server, so it reaches neither the controller's server nor its logs. What is stored there is ciphertext and the technical minimum needed to serve it.
Anyone with the link can read it. There is no password, no account and no way for the page to tell one reader from another. A link passed on works for whoever receives it. Treat it as the secret it is.
How long, and how to stop it. A shared logbook is deleted from the server 30 days after the last update, an anchor watch 48 hours after it; the page states its own expiry date. Stopping a share freezes the page — it stays readable until that period runs out. Replacing the link deletes the published copy from the server straight away and issues a new link; the old one stops working at once. Deleting the voyage in the App, or uninstalling the App, does not by itself remove a copy that is already published — stop or replace the share first.
If other people were aboard. A track shows where the boat was and when, and if others were sailing with you that is information about them too. Publishing it is your decision, not the App's — please make it with the people concerned rather than for them.
Legal basis: your consent, given by creating the link (Art. 6(1)(a) GDPR); you can withdraw it at any time by stopping or replacing the share. What a shared page contains, who receives the link and how long it stays up are your decisions; for that publication you are the responsible party, and the controller of the App only relays a copy it cannot read.
6.1 If you are reading a shared page
You need no App, no account and no login to open a shared page, and you are not asked to agree to anything. When you open one, the controller's server processes your IP address for one purpose only — limiting the rate of abusive requests. It is hashed with a secret salt on arrival and only the hash is kept, for the length of the rate-limit window; the raw address is not stored by the service. The legal basis is the controller's legitimate interest in keeping the service available (Art. 6(1)(f) GDPR). The page saves the decryption key from your link in your browser's local storage so that reloading still works; nothing else is stored on your device, and there are no cookies, no analytics and no tracking. What you are looking at was published by the person who sent you the link: that person, not the controller, decides what it shows and how long it stays up, so ask them to take it down. Your rights under §10 and your right to complain under §11 apply to you as well.
7. Reporting a navigation mark to OpenStreetMap
The App lets you report a navigation mark — a buoy, a beacon or a light — that you have yourself observed to be missing, wrongly positioned or no longer there. If you send such a report, it is transmitted as a public note to OpenStreetMap, an open mapping project of the OpenStreetMap Foundation (OSMF), a non-profit organisation registered in the United Kingdom. It goes directly from your device to OpenStreetMap: it passes through no server of the controller, and the controller receives and stores no copy of it. Nothing is sent unless you write a report and send it.
What is transmitted. The position you are reporting, the text of your report and the time it arrives. If you sign in with an OpenStreetMap account, the report is tied to that account and its user name is shown publicly. If you do not sign in, OpenStreetMap records your IP address with the report instead. Either way, position, text and time are publicly visible worldwide from the moment they arrive. Note that free text you type may itself contain personal data; please write only what an unknown reader needs in order to understand the observation.
OpenStreetMap is a controller in its own right. What happens to your report afterwards — publication, storage, moderation, further distribution of the data — is decided by the OpenStreetMap Foundation on its own responsibility and under its own privacy policy, available at osmfoundation.org/wiki/Privacy_Policy.
A report cannot be taken back. You cannot delete a report once sent; only a moderator at OpenStreetMap can hide it, and it remains in the project's history and in the copies of the data that others have already downloaded. Withdrawing consent therefore takes effect for the future only: it prevents further reports, it does not remove one already sent.
Legal basis: your consent, given by sending the report (Art. 6(1)(a) GDPR). Reporting is voluntary; no other function of the App depends on it.
8. Permissions used
| Permission | Why |
|---|---|
| Location (While Using / Always) | Track recording, distance/speed/course, movement reminders. “Always” enables background recording; the App still works (foreground only) if you choose “While Using”. |
| Notifications | Reminders (e.g. log a position, check the forecast). The App remains usable if declined. |
| iCloud | Optional backup of your data to your own iCloud. |
9. Retention
Data on your device is kept until you delete it (entries, logbooks, track) or uninstall the App. Feedback submissions are retained only as long as needed to handle and analyse them, and are deleted after 24 months at the latest (or earlier on request). Data published through the anchor watch or a share link is deleted from the server automatically — 48 hours and 30 days respectively after the last update (§6).
10. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object (Art. 21) to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time with effect for the future. To exercise these rights, contact us at info@sailorscompanion.com. Because most data is stored only on your device, you can also exercise many of these rights directly in the App (edit/delete entries, disable backup, revoke permissions).
11. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. The competent authority in Austria is the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria — www.dsb.gv.at.
12. Children
The App is not directed at children and does not knowingly collect personal data from children.
13. Changes to this policy
We may update this Privacy Policy to reflect changes to the App or legal requirements. The current version is always available at https://www.sailorscompanion.com/privacy.html; the “Last updated” date above indicates the latest revision.