Navigate Boats is a free, non-commercial personal project run by Blaz Umek, Slovenia, who is the data controller under the EU General Data Protection Regulation (GDPR). This policy covers both ways to use it: the website navigate.boats and the Navigate Boats iPhone app. Contact for anything privacy-related: contact@navigate.boats.
You can use every weather and trip-planning feature without signing up, on the website and in the iPhone app. In that case we collect no personal data on a server. No analytics, no advertising, no tracking cookies. Saving trips to “My trips” is the one feature that needs an account (§3).
On the website, your setup (language, home location, boat type and size, whether kids are aboard), your saved spots, mooring corrections, dropped map pins, map-layer choices and whether you have dismissed the sign-in offer are kept only in your own browser's local storage and never sent to us. To show forecasts and maps, your browser contacts Open-Meteo and the map tile services in §5 directly, and DHMZ through our own host. Like any website, the services it contacts see your IP address and the map area or coordinates being requested.
In the iPhone app, these stay on your phone and are never sent to us, except inside a trip you save to your account (below):
These are also in the phone's backups. Saving a trip to your account sends its base and its stops (§3), so a trip you plan from Where I am sends your phone's position as its base.
The iPhone app calls Apple Maps and Open-Meteo directly from the phone, not through navigate.boats, and sends them no account data (§5). It has no analytics, advertising or crash-reporting code.
Signing in (with Google, Apple, or a one-time link sent to your email) gives you one account for the website and the iPhone app. On the website it syncs your setup across devices, and your trips show on both. Then we store:
We do not collect phone numbers, addresses or payment details, and we do not track your location: your position and the trips the iPhone app records stay on the phone (§2), apart from the base of a trip you save from Where I am. Dropped map pins, map-layer choices and the dismissed sign-in offer stay in your browser even when you are signed in. The website keeps a sign-in session token in your browser's local storage, and the iPhone app keeps its own in the phone's keychain. This is strictly necessary to keep you signed in, so it is not used for tracking and needs no consent.
Accounts are for people aged 16 or older.
Your data is never sold, shared for marketing, or used for profiling or automated decisions.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase Inc. | Database and sign-in | Account data, setup, trips, security logs | EU (Frankfurt, Germany) |
| Resend | Delivering sign-in emails | Your email address and the sign-in email | EU (Ireland) |
| Google LLC | “Sign in with Google”, only if you choose it | Google account identifiers | USA (EU–US Data Privacy Framework) |
| Apple | “Sign in with Apple”, only if you choose it | Apple account identifier, email or private relay address | EU (Ireland) / USA (EU–US Data Privacy Framework) |
| Apple (Apple Maps) | The charts on Plan and Navigate in the iPhone app (MapKit), loaded from the phone | IP address, the map area shown (on Navigate usually around your boat, and on Plan around a trip that can start where you are), no account data | EU (Ireland) / USA (EU–US Data Privacy Framework) |
| Cloudflare, Inc. | Website hosting, DNS and the DHMZ proxy | IP address, request logs | USA / global CDN (EU–US Data Privacy Framework, SCCs) |
| Open-Meteo | Weather and sea forecasts and place search, called directly from your browser or the iPhone app | IP address, the coordinates of the places you see weather for (the iPhone app never sends your phone's own position), the text you type in a place search, no account data | EU / various |
| DHMZ (Croatian Meteorological and Hydrological Service) | Croatian marine observations on the website | Fetched through our own host (Cloudflare), not by your browser: no account data | EU (Croatia) |
| Esri, CARTO, OpenStreetMap, OpenTopoMap, OpenSeaMap | Map tiles on the website | IP address, map area, no account data | Various |
The website's “Buy me coffee” link opens Ko-fi only if you click it. Ko-fi's own privacy policy applies there.
Account data, setup and trips are kept until you delete your account. Spots you delete are marked deleted so the deletion reaches your other devices, and are erased together with your account. Trips you delete are marked deleted the same way and erased completely by a weekly clean-up once they are 90 days old, so within 97 days. When you sign out, the copy of your trips in that browser is removed. The Navigate Boats iPhone app keeps a copy of your trips on the phone while you're signed in, so they show without a connection. That copy is left out of the phone's backups and deleted when you sign out. The sign-in session is kept until you sign out. The iPhone app's session stays in the phone's keychain even when the iPhone app is deleted, so sign out first. Security logs are kept only for the short period set by our providers. Deleted data can remain in provider backups for a limited time until they rotate out.
In the iPhone app, a trip you plan while signed out, or one not sent yet, waits on the phone. It stays there when you sign out, and is sent to the next account that signs in on that phone. Your places, the destination and the place you leave from stay until you remove or replace them, and recorded trips, your boat and your settings until you delete the iPhone app.
You can at any time:
For anything the website or the iPhone app doesn't cover, email contact@navigate.boats. We reply within one month. You also have the right to complain to a supervisory authority, in Slovenia the Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si, or the authority where you live.
Data is encrypted in transit (HTTPS) and at rest by our database provider. Database access rules make each account's data readable and writable only by that account. If a breach ever risks your rights, we notify the supervisory authority within 72 hours and affected users without undue delay.
If this policy changes in a meaningful way, we update the date above and show a notice on the website before the change takes effect, and in the next version of the iPhone app.