DeckWatch (“the app”, “we”, “us”) is a work-planning tool for ship's deck officers. This policy explains what data the app handles and how. By using DeckWatch you agree to this policy.
Offline · Guest mode
Using DeckWatch without an account
DeckWatch can be used fully offline in guest mode. In guest mode, all your data — work plans, checklists, certificates, photos, notes and similar — is stored only on your device and is never transmitted to us or any third party.
Account · Cloud sync
Account & cloud sync (optional)
If you choose to create an account or sign in (via email/password, Google Sign-In or, on iPhone, Sign in with Apple):
- Account data: your email address and, if you use Google Sign-In, the basic profile information Google provides (such as name and email). This is used only to authenticate you and to sync your data.
- Sign in with Apple: the name and email address Apple shares with us the first time you sign in. You can choose to hide your email: Apple then gives us a private relay address that forwards to you, and we never see your real one. Used only to authenticate you and to sync your data.
- Your content: the records you create (work items, inspections, certificates, defects, rest-hour logs, record books, statements of facts, watch handover notes, photos and similar) are stored in our cloud backend so they can sync across your devices.
- Shared vessels: if you invite crew members to a shared vessel, the data on that vessel is shared with those members, and entries are attributed to crew positions (e.g. “2nd Officer”).
Authentication and cloud storage are provided by Supabase, our backend provider, and protected by access controls: through the app, only you — and any crew you share a vessel with — can access your data. Other users cannot, and nothing you store is public.
As the operator of the service, we can technically reach the data stored in our cloud backend (your records, photos and cloud backups), as Supabase can as our host. We look at it only to keep the service working, to fix a problem you report, when the law requires it, or when you ask us to. We never browse it, and we never use it for anything else. Access to our backend is limited to the developer and protected by two-factor sign-in.
Attachments
Photos
Photos you attach to records are stored on your device and, if you are signed in, uploaded to your private cloud storage for sync. They are not used for any other purpose.
The app uses the camera only when you tap to take a photo, and sees only the photos you pick from your library, never the rest of it.
A company logo you add to a vessel, and the company forms you keep in the app, stay on your device (and in the backups you make). They are not uploaded.
Dictation
Voice input
The app offers optional voice dictation for remarks. When you tap the microphone button, your phone's own speech recognition turns your speech into text:
- On Android: your phone's speech service (usually Google's).
- On iPhone: Apple's speech recognition. With an internet connection, the audio is sent to Apple to be turned into text, under Apple's privacy policy; without one, it is done on the iPhone.
DeckWatch receives only the text. It does not record, store or send the audio itself.
Passage planning · Weather
Weather along the route
When the app shows the weather along a voyage (on the ETA screen and the chart), it needs to know where the ship will be, and when. The weather is for signed-in users. The app sends the positions and times along the route you planned to our Supabase backend, which fetches the forecast from Open-Meteo. If our server cannot answer, the phone asks Open-Meteo directly (but not once your weather for the day is used up).
- What is sent: the route's positions and times only: positions you typed, pasted or picked on the chart.
- What is kept: our server keeps the forecasts by half-degree square of sea, each with the one position it was fetched at, for up to two days, so other ships on the same waters can use them. It does not keep your route or its times, and the forecasts carry no account, vessel or name.
- A daily count: so that the free forecast service is shared fairly, our server counts how many forecasts each account fetched each day (a number against the account, no positions). The counts are deleted after a week, and with the account.
- Open-Meteo receives positions and dates only, and, as with any request over the internet, the address it comes from.
GMDSS · Test calls
DSC test results (optional)
The GMDSS guide lets you log your weekly DSC test calls to coast stations. Your log is kept on your device. If you are signed in and turn on Share my DSC test results (in Settings, or under the test stations), each result is also sent to our Supabase backend, so that every ship can see which coast stations are answering.
- What is sent: the coast station's MMSI, the frequency band, whether it answered, the hour of the test, and the distance to the station rounded to 50 nautical miles. For a station not on the app's list, the name you typed for it.
- What is never sent: your position, your vessel or your name. Each result is stored with your account's user ID only, so that you can see and delete your own results, get them back on a new phone, and so that limits against misuse can apply (for example, a maximum number of results a day).
- What others see: only a colour for each station and band, worked out from all ships' results together. Nobody else sees an individual result or who sent it.
- Your choice: sharing is off until you turn it on, and you can turn it off at any time. You can delete any of your results in the app (My test calls), whenever you like; deleting your account deletes all of them.
The same results can be reported from our website's DSC Test Stations page, without an account.
- What is sent: the same as from the app: the station's MMSI, the band, whether it answered, the hour of the test, and the distance to the station rounded to 50 nautical miles, worked out in your browser from the position you typed. Your position is never sent.
- The check against scripts: the form uses Cloudflare Turnstile, which checks that a person is sending it. Cloudflare processes the browser information that check needs, under its own privacy policy.
- Your address: to limit how many reports come from one place (five a day; one per station and band an hour), we keep a one-way code made from your internet address with a secret of ours. The address itself is not kept, and the code cannot be turned back into it.
- Removal: a website report has no account to delete it from. Write to us with the station, band and time and we will remove it.
Position · GPS
The phone's location (optional)
Where the app asks for the ship's position (the GMDSS test stations and messages, MARPOL, distances and suggested routes, the Passage Plan's position update, the Garbage Record Book at sea, the anchor watch), a Use my position button can take it from your phone. The app asks for location permission only when you tap it, and reads the location only then, while the app is open.
- What happens with it: the position fills in the fields, as if you had typed it. The app reads it once each time you tap, never in the background, and keeps no track.
- Where it goes: where a position you typed would go, and nowhere else. Mostly it is used on your phone (the coast stations near you, MARPOL's rules where you are, a route). It is sent only when you ask for the weather from it (see "Weather along the route"), or save it in a record that syncs (the Garbage Record Book, the anchor watch) while signed in. If you share DSC test results, only the distance to the station, rounded to 50 nautical miles, is sent.
- Your choice: refuse the permission and type the position instead. You can change it at any time in your phone's settings.
On-device alerts
Notifications & reminders
With your permission, the app schedules local reminders on your device (for example, certificate expiry, defects and tasks). These are generated locally on your device; we do not send marketing or promotional notifications.
Reference data
What the app downloads
Signed in or not, the app fetches some reference data when it has a connection:
- From our Supabase backend: the navigational warnings in force and the list of DSC test stations.
- From Google Fonts: the app's typeface, the first time it is needed.
These requests carry nothing about you, your vessel or your records, only what any request over the internet carries (your connection's address).
Our commitments
What we do not do
- We do not show advertisements.
- We do not sell or rent your data to anyone.
- We do not use third-party analytics or advertising trackers.
Retention · Deletion
Data retention & deletion
Your data is kept as long as your account is active. You can:
- Delete individual records at any time within the app.
- Delete your entire account and its associated cloud data from within the app (Settings → Account), or by contacting us at the email below and we will delete it. See also: how to delete your account.
- If you signed in with Apple, deleting your account also withdraws DeckWatch's access to your Apple ID with Apple: the app asks you to confirm with Apple once more. You can also stop using Sign in with Apple with DeckWatch at any time in your iPhone's settings (your name → Sign in with Apple).
Eligibility
Children
DeckWatch is a professional tool intended for maritime crew and is not directed at children under 13.
Revisions
Changes to this policy
We may update this policy from time to time; the “Last updated” date above will reflect any changes.