Privacy Policy
This policy applies to the SeaMemo mobile application and to the website getseamemo.com. It explains what data is collected, what it is used for, who has access to it and how you get rid of it.
1. Who is responsible
The controller under the GDPR for data processing in the SeaMemo app and on this website is:
Kevin Baur, BSc
Hochstraß 542
3033 Klausen-Leopoldsdorf, Austria
[email protected]
No data protection officer has been appointed, as the statutory conditions for that do not apply. Full provider details are in the imprint.
2. What the app collects
SeaMemo processes the following categories of personal data in order to provide its core functionality:
Account information
Using the app requires an account. We store your email address and an encrypted password hash – never the password in plain text. Your email address is used for authentication, password recovery and essential service communications. We do not send marketing emails without your explicit consent.
Trip and logbook data
When you record a trip, SeaMemo stores GPS coordinates, route data, timestamps, weather conditions you enter, crew information you add, journal entries and any photos or voice memos you attach. This data is held on our servers so it can sync across your devices, and is associated with your account.
Photos and media
Photos and voice memos you attach to a trip are stored on our servers. They remain private to your account unless you explicitly share the trip with crew members or other users.
Crew and shared trips
If you invite crew members to view or contribute to a trip, the share links or email addresses you generate are stored to manage access permissions. Crew members you invite can see the trip content you share with them.
Uploaded documents
If you scan licences or qualification certificates into your profile, those images are transmitted encrypted and stored against your account. They are visible to you only.
3. Location data and Crew Radar
Precise location while recording. SeaMemo needs access to your device's precise location to record your sailing route. Location is collected only while a trip is actively being recorded – with no trip running, no location is collected, in the background or otherwise. Your precise location is never shared with other users. You can revoke the permission at any time in your device settings; the app's core functionality stops working then.
Crew Radar (optional). SeaMemo includes a voluntary feature that lets you connect with other users as friends and show them your approximate position. To find friends, you can search for other users by display name or email address, and other users can find you the same way. When you send or accept a friend request, the other person is notified.
Location sharing is off by default. Only if you switch it on is your position shared with your accepted friends, and only while a trip is actively being recorded. The shared position is deliberately coarse: your coordinates are rounded to roughly an 11 km grid before they leave your device, and only your single most recent position is stored – no location history is built. To display a readable place name (for example “Lisbon, Portugal”), the rounded coordinates are sent to a geocoding provider. Only friends whose requests you have accepted can see this position, and that restriction is enforced at the database level. You can turn sharing off, or remove a friend, at any time.
4. Third parties
The following service providers process data on our behalf:
- Backend hosting and database providers store your account data, trip data, photos and other content on secure servers. They process data solely on our instruction and never for their own purposes.
- Map and geocoding providers render the maps shown in the app and convert coordinates into readable place names. Your IP address may be visible to them when map tiles load, and coordinates you record – for Crew Radar, only the coarsened position – may be sent to resolve a place name.
- App stores. Apple and Google distribute the app and process download and, where applicable, billing data as controllers in their own right.
Trip content remains private to your account unless you explicitly share it through the app's sharing features, such as inviting crew or sharing your approximate location with friends. No other third parties have access to data generated through the app. We do not sell data and run no advertising networks in the app.
5. This website
Hosting and server logs. getseamemo.com is hosted on Cloudflare. Requesting a page produces technically necessary connection data (including IP address, timestamp, requested URL, browser type and country of origin). It serves secure operation and abuse prevention and is retained only briefly.
Analytics. We use Datafast, a cookieless analytics service. No cookies are set, no cross-device profiles are built and no data is passed to advertising networks. What is recorded are aggregate figures such as page views, referrer, approximate region and device type.
Language cookie. The home page is served in German or English depending on your country of origin. If you actively pick a language in the header, we store that choice in a cookie named sm_lang (lifetime: 1 year). It contains only the language code (“de” or “en”), exists purely for your convenience, and is not set unless you make an explicit choice. The routing itself uses the country of the request as provided by Cloudflare, without storing your IP address for that purpose.
Fonts. All typefaces are served from our own server. There is no connection to Google Fonts or comparable services.
6. Legal bases
Where the GDPR applies, we process personal data on the following bases:
- Art. 6(1)(b) GDPR (performance of a contract) – for your account, trip recording, syncing, crew features and exporting sea-miles certificates.
- Art. 6(1)(a) GDPR (consent) – for the optional Crew Radar, push notifications and marketing emails. You can withdraw consent at any time with effect for the future.
- Art. 6(1)(f) GDPR (legitimate interests) – for secure server operation, abuse prevention and cookieless analytics.
- Art. 6(1)(c) GDPR (legal obligation) – where statutory retention duties apply.
7. Retention and deletion
Account and trip data are retained for as long as your account exists. You can delete your account at any time inside the app: Profile → Settings → Delete account. Deletion runs immediately and covers your account, your own trips with all legs, photos, voice memos and journal entries, your contributions to other people's trips, uploaded documents, friendships and the last position you shared. Copies in encrypted backups expire automatically and are gone at the latest after 30 days. The action cannot be undone.
Trips where you were only a crew member stay intact for the remaining participants – but your own content is removed from those too. A full walkthrough is on the Delete account page.
Uninstalling the app stops any further collection on your device, but deletes neither your account nor the data stored on our servers. Use the in-app deletion or write to [email protected].
Anonymised, aggregated usage statistics without any personal reference may be retained for service improvement.
8. Your rights
Under the GDPR you have the right to access the data we hold about you (Art. 15), to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Consent you have given can be withdrawn at any time; that does not affect the lawfulness of processing carried out beforehand.
An informal email to [email protected] is enough to exercise them. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence or place of work.
9. Children
SeaMemo is not directed at children under 13 and does not knowingly collect personal data from them. We encourage parents and guardians to supervise their children's internet use. If you have reason to believe that a child has provided us with personal data, please contact [email protected] and we will delete it promptly. You must also be at least 16 years old to consent to the processing of your personal data; in some countries a parent or guardian may consent on your behalf.
10. Security
Passwords are stored as encrypted hashes, never in plain text. Data is transmitted over encrypted connections (HTTPS/TLS) and stored using industry-standard security practices; access to other people's trip data is additionally blocked at the database level. No method of transmission or storage over the internet is 100 % secure, so we cannot guarantee absolute security.
11. Changes to this policy
We may update this privacy policy from time to time, for instance when new features arrive. The current version always lives on this page, with the effective date shown at the top. Please check back occasionally – continued use of the app means the updated version applies.
12. Contact
Questions about privacy, about how your data is processed, or about exercising your rights are answered at [email protected].
Last updated: 30 June 2026 · Deutsche Fassung