SALINITY.LIVE
Privacy Policy
This Policy explains how Salinity handles information across the website, Android app, cloud dashboard, boat-data connection, support, and owner-directed sharing. Salinity is designed to keep identifiable boat activity private and show only aggregate account activity publicly.
The operator’s exact legal entity name and postal address must be inserted here and matched to the developer name shown in the applicable app-store listing. Until that information is supplied, “Salinity,” “we,” and “us” mean the owner and operator identified in your order receipt, subscription record, or app-store listing.
1. Scope and controller
This Policy applies to Salinity’s websites, mobile applications, account and authentication flows, cloud dashboard, NMEA 2000 and device integrations, support communications, field previews, and related services (the “Service”). Salinity is the controller of information it determines how to use. A mechanic, marina, vessel owner, employer, app store, equipment provider, or other third party may separately control information under its own policy.
Privacy questions and rights requests may be sent to hello@salinity.live.
2. Information we collect
Account and subscription information
Legal name, account email, date of birth, home address, account identifiers, authentication provider and login metadata, plan status, subscription and transaction references, Family Pro owner or member role, seat and membership status, masked and one-way-hashed invitation email, invitation status and dates, support history, consent version and time, acceptance method, browser description, and security events. Salinity collects the identity and address fields to establish the adult account holder and preserve evidence of who accepted which legal documents. These entries are user-provided and are not independently identity-verified unless Salinity expressly tells you otherwise. Payment-card details should be processed by the applicable app store or payment provider rather than stored directly by Salinity.
Boat, equipment, and NMEA 2000 information
Vessel names and identifiers; hull, registration, home-port, engine, gateway, chartplotter, sensor, battery, tank, and equipment details; network device identity; supported parameter-group data; readings such as engine speed, hours, fuel flow, temperature, pressure, voltage, heading, depth, wind, position, speed, gear, and alerts; learned groups; and timestamps, quality indicators, fault codes, and diagnostic-event records.
Trips, places, conditions, and maintenance
GPS and precise location, tracks, marks, routes, ramps, docks, slips, ports, anchorages, hazards, destinations, catches, notes, photos, crew information, weather and tide preferences, fuel and range records, service history, mechanics, parts, receipts, manuals, and uploaded files.
Credentials, vessel documents, and rule preferences
Personal or vessel association, credential type, issuing jurisdiction, masked license or document number, issue and expiration dates, endorsements, restrictions, reminder settings, official renewal or verification links, user-entered verification state, and images or files you choose to upload for fishing licenses, permits, merchant-mariner credentials, registrations, documentation, insurance, radio records, inspections, or similar records. Do not store Social Security numbers, complete payment-card numbers, or unrelated identity documents.
Safety and potentially sensitive information
Float plans, people aboard, emergency contacts, MMSI or radio details, safety-equipment locations, meeting points, and medical or accessibility notes you choose to store. Only provide information that is necessary and that you are authorized to provide.
Device, app, and usage information
Device and app version, operating system, device label, a one-way-hashed installation identifier, device public key, activation and replacement history, last verified time, signed-request nonces, app-integrity or key-attestation results when enabled, language, approximate network information, IP address, timestamps, session and cookie data, permissions, connection state, diagnostics, crash and performance logs, feature interactions, and one-way account-presence records used for aggregate active-user counts.
Support-assistant messages
If you use the website support assistant, Salinity receives the text you submit and a short portion of the conversation needed to answer. Do not submit passwords, payment-card details, precise location, medical information, private vessel records, or emergency details. When AI mode is enabled, Salinity sends that text from its server to the configured AI service provider to generate an answer. Guided mode uses Salinity’s curated support answers without sending the question to that AI provider.
3. Where information comes from
We receive information from you; your phone and granted permissions; connected gateways, NMEA 2000 equipment, sensors, and vessel networks; authentication, app-store, payment, hosting, and support providers; mechanics or other people you direct to share information; and public or licensed sources used for weather, tides, maps, charts, rules, or conditions.
4. How we use information
- Provide accounts, sign-in, subscriptions, synchronization, storage, backups, exports, and support.
- Bind one active phone to each account, manage Family Pro invitation tokens and seats, prevent replay, and investigate plan or device-limit evasion.
- Receive and organize vessel readings, trips, maintenance, marks, conditions, and incident records.
- Create learned operating groups and identify changes in recorded relationships.
- Deliver owner-requested alerts, exports, mechanic packages, float plans, and sharing.
- Maintain security, prevent abuse, diagnose failures, measure performance, and improve the Service.
- Communicate service, safety, legal, billing, and product notices.
- Meet legal obligations, enforce agreements, and protect users, Salinity, and others.
5. Location and background access
Trip recording, tracks, position-linked boat readings, marks, float plans, weather/tide context, and incident timelines may require precise location. If a feature records while the screen is off or another app is open, it may require background location or background processing. The app should explain what it collects, why, whether it leaves the device, and how to stop it immediately before requesting the permission.
On the public Live Tides page, choosing “Use my location” sends the coordinates supplied by your browser to Salinity’s server only to select the nearest NOAA water-level station and return station data. The Trip Planner can also send a selected waypoint to Salinity’s server to retrieve NOAA tide and regional bathymetry context. The current planner draft and worldwide display preferences are stored in that browser’s local storage unless you remove them. Signed-in worldwide preferences can also be stored in the private dashboard preference record so the website and app can use the same coordinate, unit, language, date, clock, and time-zone choices. Map tiles and chart assets are requested through Salinity’s server, which contacts the listed data provider. Public lookups do not intentionally write the precise coordinate to an account record. Network and security logs may still include ordinary request metadata as described in this Policy. You can instead search or enter a position manually.
You may decline or revoke location in device settings, but location-dependent features will not work correctly. Disabling permission does not automatically delete information previously synchronized; use the deletion controls or contact us for that.
6. Legal bases for processing
Where laws such as the GDPR or UK GDPR apply, we process information as needed to perform our contract with you; based on your consent, including certain device permissions and optional sharing; to comply with law; to protect vital interests in limited circumstances; and for legitimate interests such as securing, operating, supporting, and improving the Service where those interests are not overridden by your rights. You may withdraw consent prospectively, but prior lawful processing remains valid.
7. How we disclose information
We may disclose information to vendors that help provide authentication, hosting, databases, object storage, email, support, app distribution, payment, mapping, weather, tides, analytics, crash reporting, and security. Website subscription checkout and billing management use Stripe; iOS in-app subscriptions use Apple’s App Store and Android in-app subscriptions use Google Play. Salinity may use RevenueCat to validate store purchases and synchronize subscription entitlements. Those providers receive the account, transaction, billing, device, and payment information needed to process and protect purchases under their own terms and privacy policies. Salinity stores provider customer, subscription, entitlement, event, and invoice references but is designed not to receive or store complete payment-card numbers. Service providers may use information only for their contracted services and legally permitted purposes.
If AI support is enabled, the configured AI provider processes the support message and limited recent chat context needed to return an answer. Salinity’s server requests non-persistent API processing where the provider supports that setting, but provider security, abuse-monitoring, and legal-retention rules may still apply. Use the FAQ or email contact instead if you do not want to submit a question through AI mode.
We disclose information to mechanics, crew, contacts, or others when you direct us to create or send a share, export, mechanic package, or float plan. We may also disclose information in a business transfer; to comply with valid legal process; or when reasonably necessary to prevent fraud, abuse, security incidents, or serious harm.
Salinity does not publicly list users, boats, locations, trips, catches, engine events, or mechanics. The website may show aggregate counts such as accounts active in the last 24 hours or seven days. Those counts use a pseudonymous account key and last-seen time. Salinity does not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined. If that practice changes, this Policy and legally required choices must change first.
8. Data that remains on the device and data synchronized
Some features may operate locally or offline; others synchronize to the Salinity account so the website and app can reflect the same records. The product must identify which records are local-only, queued, synchronized, shared, or deleted. Offline or failed sync can create gaps or conflicts. Keep independent copies of records you cannot afford to lose.
9. Retention
We keep account and user-created information while the account is active and as reasonably needed to provide the Service. Expired signed-request nonces are routinely deleted; device activation, Family Pro invitation, membership-change, and replacement-limit records may remain for security, fraud prevention, and dispute periods. The legal name, acceptance-time email, date of birth, address snapshot, accepted document versions, timestamp, method, and browser description may be retained as an agreement record for the applicable limitation or dispute period even after other account content is deleted, where law permits. We may also retain billing, security, dispute, and compliance records for applicable tax, chargeback, or legal periods. Backups and logs may persist for a limited rotation period after deletion. We delete or de-identify information when it is no longer reasonably needed, subject to legal holds and lawful exceptions.
10. Your choices and rights
Depending on where you live, you may have rights to know or access information, correct it, delete it, receive a portable copy, object to or restrict certain processing, withdraw consent, opt out of certain sharing or targeted advertising, and appeal a denied request. You may also complain to your local data-protection authority.
Use available account controls or email hello@salinity.live from the account address. We may verify identity and authority before acting. We will not discriminate for exercising a privacy right. Some information may be retained when permitted or required for security, legal compliance, transactions, or legal claims.
11. Account deletion
You may request deletion from within the app or through the public account-deletion page. Before deleting account data, Salinity attempts to stop future renewal of an active website subscription. A subscription purchased through Apple’s App Store or Google Play must also be managed under that store’s cancellation rules. Deletion is intended to remove or de-identify the account’s Salinity-controlled boat records, trips, marks, locations, maintenance, safety records, files, billing mappings, and authentication identity, subject to transaction, tax, fraud, dispute, legal-retention, and backup exceptions. Payment processors may retain transaction records under their own legal duties. Deleting the app from a phone does not delete the account. Information already shared with another person may remain in that person’s possession.
12. Security
We use administrative, technical, and organizational safeguards appropriate to the nature of the information, including access controls, protected transport, scoped storage, and account authentication. No device, radio link, gateway, network, cloud service, or storage method is perfectly secure. You are responsible for device locks, current software, safe credentials, recipient selection, and promptly reporting suspected compromise.
13. International transfers
Salinity and its providers may process information in the United States and other countries where privacy laws differ. Where required, we use a lawful transfer mechanism and supplementary safeguards. Contact us to request information about applicable safeguards.
14. Children
The Service is for adults and is not directed to children under 13 or the higher minimum age required locally. We do not knowingly create accounts for children. Contact us if you believe a child provided personal information without valid authorization.
15. Essential cookies and similar storage
The website uses essential session cookies and local device storage needed for sign-in, security, password recovery, and interface operation. We do not currently describe an advertising-cookie program. If non-essential analytics or advertising technologies are added, Salinity must provide the notices and choices required in the visitor’s location before using them.
16. Changes
We may update this Policy as the Service, vendors, or law changes. The date and version appear at the top. We will provide additional notice and obtain consent when required for a material new use. Prior versions should remain available on request.
17. Contact
Email privacy questions or requests to hello@salinity.live. Do not include passwords or unnecessary medical, payment, or precise-location information in ordinary email.