← Navigate Boats

Privacy Policy

Last updated 16 September 2026 · Summaries in all app languages are under “Privacy details” inside the app.

1. Who is responsible

Navigate Boats (navigate.boats) is a free, non-commercial personal project run by Blaz Umek, Slovenia, who is the data controller under the EU General Data Protection Regulation (GDPR). Contact for anything privacy-related: contact@navigate.boats.

2. Using the app without an account

You can use every weather and trip-planning feature without signing up. In that case we collect no personal data on a server. Your setup (language, home location, boat type and size, whether kids are aboard), your saved spots, dropped map pins, map-layer choices and whether you have dismissed the sign-in offer are kept only in your own browser's local storage and never sent to us. No analytics, no advertising, no tracking cookies. Saving trips to “My trips” is the one feature that needs an account (§3).

To show forecasts and maps, your browser contacts the third-party services listed in §5 directly. Like any website, they see your IP address and the map area or coordinates being requested.

3. If you create an optional account

Signing in (with Google, Apple, or a one-time link sent to your email) lets you sync your setup across devices. Then we store:

We do not collect phone numbers, addresses, payment details or location tracking. Dropped map pins, map-layer choices and the dismissed sign-in offer stay on your device even when signed in. Your browser also stores a sign-in session token locally. This is strictly necessary to keep you signed in, so it is not used for tracking and needs no consent.

Accounts are for people aged 16 or older.

4. Why we process it (legal basis)

Your data is never sold, shared for marketing, or used for profiling or automated decisions.

5. Service providers (processors and third parties)

ProviderPurposeDataLocation
Supabase Inc.Database and sign-inAccount + app data, security logsEU (Frankfurt, Germany)
ResendDelivering sign-in emailsYour email address and the sign-in emailEU (Ireland)
Google LLC“Sign in with Google”, only if you choose itGoogle account identifiersUSA (EU–US Data Privacy Framework)
Apple“Sign in with Apple”, only if you choose itApple account identifier, email or private relay addressEU (Ireland) / USA (EU–US Data Privacy Framework)
Cloudflare, Inc.Website hosting, DNS and the DHMZ proxyIP address, request logsUSA / global CDN (EU–US Data Privacy Framework, SCCs)
Open-Meteo, DHMZ (Croatian Meteorological and Hydrological Service), fetched through our own host (Cloudflare)Weather and sea forecastsIP address, requested coordinates, no account dataEU / various
Esri, CARTO, OpenStreetMap, OpenTopoMap, OpenSeaMapMap tilesIP address, map area, no account dataVarious

The “Buy me coffee” link opens Ko-fi only if you click it. Ko-fi's own privacy policy applies there.

6. How long we keep it

Account and app data are kept until you delete your account. Spots you delete are marked deleted so the deletion reaches your other devices, and are erased together with your account. Trips you delete are marked deleted the same way and erased completely within 90 days. When you sign out, the copy of your trips in that browser is removed. The Navigate Boats iPhone app keeps a copy of your trips on the phone while you're signed in, so they show without a connection. That copy is left out of the phone's backups and deleted when you sign out. Security logs are kept only for the short period set by our providers. Deleted data can remain in provider backups for a limited time until they rotate out.

7. Your rights

You can at any time:

For anything the app doesn't cover, email contact@navigate.boats. We reply within one month. You also have the right to complain to a supervisory authority, in Slovenia the Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si, or the authority where you live.

8. Security

Data is encrypted in transit (HTTPS) and at rest by our database provider. Database access rules make each account's data readable and writable only by that account. If a breach ever risks your rights, we notify the supervisory authority within 72 hours and affected users without undue delay.

9. Changes

If this policy changes in a meaningful way, we update the date above and show a notice in the app before the change takes effect.