← Navigate Boats

Privacy Policy

Last updated 17 September 2026 · The website's privacy notice links a short summary in its nine languages.

1. Who is responsible

Navigate Boats is a free, non-commercial personal project run by Blaz Umek, Slovenia, who is the data controller under the EU General Data Protection Regulation (GDPR). This policy covers both ways to use it: the website navigate.boats and the Navigate Boats iPhone app. Contact for anything privacy-related: contact@navigate.boats.

2. Using Navigate Boats without an account

You can use every weather and trip-planning feature without signing up, on the website and in the iPhone app. In that case we collect no personal data on a server. No analytics, no advertising, no tracking cookies. Saving trips to “My trips” is the one feature that needs an account (§3).

On the website, your setup (language, home location, boat type and size, whether kids are aboard), your saved spots, mooring corrections, dropped map pins, map-layer choices and whether you have dismissed the sign-in offer are kept only in your own browser's local storage and never sent to us. To show forecasts and maps, your browser contacts Open-Meteo and the map tile services in §5 directly, and DHMZ through our own host. Like any website, the services it contacts see your IP address and the map area or coordinates being requested.

In the iPhone app, these stay on your phone and are never sent to us, except inside a trip you save to your account (below):

These are also in the phone's backups. Saving a trip to your account sends its base and its stops (§3), so a trip you plan from Where I am sends your phone's position as its base.

The iPhone app calls Apple Maps and Open-Meteo directly from the phone, not through navigate.boats, and sends them no account data (§5). It has no analytics, advertising or crash-reporting code.

3. If you create an optional account

Signing in (with Google, Apple, or a one-time link sent to your email) gives you one account for the website and the iPhone app. On the website it syncs your setup across devices, and your trips show on both. Then we store:

We do not collect phone numbers, addresses or payment details, and we do not track your location: your position and the trips the iPhone app records stay on the phone (§2), apart from the base of a trip you save from Where I am. Dropped map pins, map-layer choices and the dismissed sign-in offer stay in your browser even when you are signed in. The website keeps a sign-in session token in your browser's local storage, and the iPhone app keeps its own in the phone's keychain. This is strictly necessary to keep you signed in, so it is not used for tracking and needs no consent.

Accounts are for people aged 16 or older.

4. Why we process it (legal basis)

Your data is never sold, shared for marketing, or used for profiling or automated decisions.

5. Service providers (processors and third parties)

ProviderPurposeDataLocation
Supabase Inc.Database and sign-inAccount data, setup, trips, security logsEU (Frankfurt, Germany)
ResendDelivering sign-in emailsYour email address and the sign-in emailEU (Ireland)
Google LLC“Sign in with Google”, only if you choose itGoogle account identifiersUSA (EU–US Data Privacy Framework)
Apple“Sign in with Apple”, only if you choose itApple account identifier, email or private relay addressEU (Ireland) / USA (EU–US Data Privacy Framework)
Apple (Apple Maps)The charts on Plan and Navigate in the iPhone app (MapKit), loaded from the phoneIP address, the map area shown (on Navigate usually around your boat, and on Plan around a trip that can start where you are), no account dataEU (Ireland) / USA (EU–US Data Privacy Framework)
Cloudflare, Inc.Website hosting, DNS and the DHMZ proxyIP address, request logsUSA / global CDN (EU–US Data Privacy Framework, SCCs)
Open-MeteoWeather and sea forecasts and place search, called directly from your browser or the iPhone appIP address, the coordinates of the places you see weather for (the iPhone app never sends your phone's own position), the text you type in a place search, no account dataEU / various
DHMZ (Croatian Meteorological and Hydrological Service)Croatian marine observations on the websiteFetched through our own host (Cloudflare), not by your browser: no account dataEU (Croatia)
Esri, CARTO, OpenStreetMap, OpenTopoMap, OpenSeaMapMap tiles on the websiteIP address, map area, no account dataVarious

The website's “Buy me coffee” link opens Ko-fi only if you click it. Ko-fi's own privacy policy applies there.

6. How long we keep it

Account data, setup and trips are kept until you delete your account. Spots you delete are marked deleted so the deletion reaches your other devices, and are erased together with your account. Trips you delete are marked deleted the same way and erased completely by a weekly clean-up once they are 90 days old, so within 97 days. When you sign out, the copy of your trips in that browser is removed. The Navigate Boats iPhone app keeps a copy of your trips on the phone while you're signed in, so they show without a connection. That copy is left out of the phone's backups and deleted when you sign out. The sign-in session is kept until you sign out. The iPhone app's session stays in the phone's keychain even when the iPhone app is deleted, so sign out first. Security logs are kept only for the short period set by our providers. Deleted data can remain in provider backups for a limited time until they rotate out.

In the iPhone app, a trip you plan while signed out, or one not sent yet, waits on the phone. It stays there when you sign out, and is sent to the next account that signs in on that phone. Your places, the destination and the place you leave from stay until you remove or replace them, and recorded trips, your boat and your settings until you delete the iPhone app.

7. Your rights

You can at any time:

For anything the website or the iPhone app doesn't cover, email contact@navigate.boats. We reply within one month. You also have the right to complain to a supervisory authority, in Slovenia the Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si, or the authority where you live.

8. Security

Data is encrypted in transit (HTTPS) and at rest by our database provider. Database access rules make each account's data readable and writable only by that account. If a breach ever risks your rights, we notify the supervisory authority within 72 hours and affected users without undue delay.

9. Changes

If this policy changes in a meaningful way, we update the date above and show a notice on the website before the change takes effect, and in the next version of the iPhone app.