Privacy Policy

Last updated: 2026-08-07

1. Controller

BayPilot (“Service”) is operated by the owner of the baypilot.app domain. For privacy inquiries, contact: support@baypilot.app.

2. Key points at a glance

  • We process account data, OAuth login data, GPS location (if you enable that feature), remote Anchor Alarm data, and technical logs.
  • We do this to enable login, app functionality, security, and map, weather, and route features.
  • Data may be shared with login providers (Google/Facebook), map and weather providers, and hosting/infrastructure providers.
  • We keep the account until deletion, logs for a reasonable technical period, and tokens or access links for short periods.
  • You have the right to access, correct, and delete your data.

3. Data we process

BayPilot processes only the minimum amount of data necessary to operate the user account, authentication, maps, weather, route features, and service security.

  • Account data: email and password (stored as a hash), optional first/last name and language preference.
  • Device identifier (device_id) used for trial and anti-abuse limits.
  • Technical data: IP address, request headers, error/security logs.
  • App usage data required to provide features: route/planner/weather points and compute parameters sent to the API.
  • Cookies: e.g. “lang” to remember language choice.

4. Purposes

  • Provide the Service (maps, routes, planner, weather).
  • Authentication, security and anti-abuse (trial, rate limits, CAPTCHA).
  • Support, diagnostics and quality improvements.

4a. Legal bases for processing

We process personal data only when we have an appropriate legal basis. Depending on the situation, this may be:

  • performance of a contract or taking steps prior to entering into a contract — for account operation, login, app functionality, and route planning, map, and weather features;
  • our legitimate interest — for security, abuse prevention, error diagnostics, service stability, and development;
  • the user’s consent — where required, for example for selected device features or specific technologies;
  • a legal obligation — where the law requires us to retain or disclose specific data.

5. GPS location

BayPilot may use device location only when the user enables the map position feature or a navigation-related feature. Location is used to show the user’s current position, plan routes, calculate distance, duration, and provide boating-related functionality.

BayPilot does not perform hidden tracking. After the user deliberately starts Navigation or the Anchor Alarm, location may continue to be read with the screen locked by a visible Android foreground service until the user stops the feature. BayPilot does not sell location data.

5a. Anchor Alarm and remote notifications

The local Anchor Alarm runs on the device and does not require an account or Internet connection. Only after a signed-in user separately enables remote notifications does BayPilot send the precise boat and anchor positions, zone geometry, distance, GPS quality, alarm state, track, available battery state, and monitoring-device connection state to the server.

Active-session data is available only to devices selected by the owner: devices on the same account or one specific device on another account explicitly paired with a one-time code. A receiver has read-only access, cannot control the local alarm, and can stop receiving at any time. A push message does not contain precise coordinates; they are retrieved from the API only after device authentication and authorization.

Android uses Firebase Cloud Messaging. A supported browser uses Web Push and a dedicated service worker that can display a system notification after the tab is closed. BayPilot stores an encrypted FCM identifier or encrypted Web Push endpoint and subscription keys while the device registration is active. A receiving device does not submit its own location merely by receiving an alarm.

FCM and Web Push do not guarantee delivery time. A powered-off or sleeping device, loss of Internet access, power-saving settings, or browser restrictions may delay an alert until reconnection. Remote notifications are an additional safeguard, not a guaranteed rescue or emergency system.

6. Sharing

We may share data with technical providers only as necessary to run the Service, for example:

  • External login providers (Google/Facebook) — if you use OAuth sign-in.
  • Cloudflare Turnstile — bot protection for registration.
  • Map/geoservices and weather data providers (e.g. MapTiler/OSM, Open‑Meteo, Windy) — for requests performed by the app.
  • Google Firebase Cloud Messaging and the push service selected by the browser — to deliver remote notifications enabled by the user.

To the extent necessary for individual features to work, data may also be processed by providers of server infrastructure, security services, transactional email, error analysis, and other technical services used by BayPilot.

7. Technical data and third-party providers

BayPilot may process technical data such as IP address, device type, browser, operating system, server logs, and basic diagnostic information.

Some BayPilot features may rely on third-party service providers, such as map providers, weather forecast providers, login providers, or server infrastructure providers. Data shared with such providers is limited to what is necessary for the relevant feature to work.

7a. Cookies and local storage

BayPilot may use cookies and browser local storage (local storage / session storage) to remember user settings, maintain sessions, support security, ensure the correct operation of the interface, and limit abuse. For remote notifications, the browser also uses IndexedDB for the profile identity, short offline queue and subscription state, and Cache API to run the service worker. These data are not used to sell information about the user.

7b. Data security

BayPilot applies appropriate technical and organizational measures to protect user data against unauthorized access, loss, destruction, disclosure, or unlawful modification.

The user’s connection with the Service is protected using SSL/TLS encryption where required by the function and technical configuration of the relevant service. We also implement measures for account security, data transmission, server infrastructure, and abuse prevention.

Despite using appropriate safeguards, no method of Internet transmission or electronic storage can guarantee complete security.

8. Retention

  • Account: until deleted by the user or admin.
  • Unverified accounts: automatically removed after up to 24h.
  • Tokens (email verification, password reset, account deletion): expire after ~1h.
  • Active Anchor Alarm telemetry and track: for the duration of the session.
  • Ended remote Anchor Alarm session and precise track: up to 7 days.
  • Technical notification-delivery records without coordinates: deleted with the related session, no later than 7 days.
  • FCM or Web Push registration: for the duration of the device consent; removed when consent is withdrawn, the device or account is deleted, or the provider reports a permanent error.
  • Technical logs: retained as needed for security and diagnostics.

9. Account and data deletion

You may delete your account and related data in the app under Account → Security → Delete account or by contacting us at support@baypilot.app.

After account deletion, Anchor Alarm devices, links, consents, sessions, tracks and FCM/Web Push registrations are deleted, and remaining user data is deleted or anonymized unless further retention is required by law or necessary to protect legitimate claims.

10. Your rights

You can access, correct, or delete your data. Delete your account in the app: /app → Account → Security → Delete account.

10a. Right to lodge a complaint

If you believe that the processing of your data violates data protection laws, you have the right to lodge a complaint with the competent supervisory authority, in particular in the country of your habitual residence, place of work, or the place of the alleged infringement.

10b. Transfers outside the EEA

Some service providers used by BayPilot may process data outside the European Economic Area. In such cases, we ensure that appropriate legal safeguards required by data protection laws are applied.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, in particular in the event of legal, technical, or organizational changes affecting the operation of BayPilot. The current version of the Privacy Policy is always available on the BayPilot website and may be read, saved, or printed by the user at any time.

BayPilot – privacy policy for the sailing app | BayPilot