CoSkipper
EN DE

Privacy Policy

Last updated: 29 July 2026 · Applies to the CoSkipper app and the coskipper.app website

This policy is available in English and German. The app itself is available in further languages; if you are addressed in German, the German version applies — otherwise this English version does.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

Kamil van der Linde
Heiglhofstrasse 17
81377 München
Germany

Phone: +49 1575 5562929
Email: info@coskipper.app

No data protection officer has been appointed, as the statutory conditions for doing so are not met.

2. Our principle

CoSkipper is an app for planning and documenting sailing voyages together with a crew. The data you enter is used solely to provide those functions to you and to your crew. We do not sell data, we run no advertising, no cross-service tracking, and we build no user profiles for advertising purposes.

Some of your data is by nature visible to other crew members — that is the point of the app. Section 8 explains exactly what that means.

3. The coskipper.app website

3.1 Hosting and server logs

The website is delivered via Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). When a page is requested, technically necessary access data is processed: IP address, date and time, page requested, volume of data transferred, referrer and browser identification. This serves delivery, operational security and defence against attacks.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning website).

3.2 Fonts (Google Fonts)

The website loads the "Urbanist" typeface from Google Fonts (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Your IP address is transmitted to Google in the process. Legal basis: Art. 6(1)(f) GDPR (consistent presentation of the website).

3.3 No cookies, no analytics

The website sets no cookies, uses no analytics or tracking tools and embeds no advertising networks. A cookie banner is therefore not required.

4. The app

4.1 Account and sign-in

An account is required to use the app. Depending on the method you choose, we process:

  • Email sign-in: your email address. Sign-in uses a one-time numeric code that we send to you by email.
  • Sign in with Apple: the user identifier supplied by Apple and your email address (or the relay address Apple generates if you choose "Hide My Email").
  • Sign in with Google: the user identifier supplied by Google, your email address and, where provided, your display name.

We additionally store technical account data (registration time, last sign-in, authentication logs). Your session is stored on your device in the protected system store (iOS Keychain / Android Keystore).

Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement).

4.2 Profile and crew-list data

Your profile can hold details needed for voyage planning and for check-in with charter companies: first and last name, date of birth, place and country of birth, nationality, address and country of residence, phone number, identity document type and number, profile picture, and the name, phone number and relationship of an emergency contact.

All of these fields are optional. They are collected only if you enter them yourself, and are used solely to make them available to you and — if you join a voyage — to that voyage's skipper for the crew list. We do not transmit them to charter companies or authorities.

Legal basis: Art. 6(1)(b) GDPR. Where you enter details about a third party (emergency contact), we rely on Art. 6(1)(f) GDPR (legitimate interest in safety on board). Please inform that person.

4.3 Voyage data

To provide the app's functions we process the content you create: voyages (name, dates, boat and charter details, meeting point), route and day planning including places and coordinates, activities, checklists, packing lists, safety briefings and their acknowledgments, logbook entries, sea-mile records and uploaded files.

Legal basis: Art. 6(1)(b) GDPR.

4.4 Photos, documents and files

When you upload a profile picture, a voyage image or a document, the app accesses your device's camera or photo library — only after you have granted that permission at operating-system level. Only the file you select is transferred. Files are stored on our EU-based storage and are accessible within the app only to you and, depending on context, to the crew of the relevant voyage. Embedded metadata (for example a photo's EXIF location) is not evaluated, but is not automatically stripped either.

Legal basis: Art. 6(1)(b) GDPR.

4.5 Location data

For features such as setting your current position, recording logbook entries and the map view, the app may access your device location. Access happens only with your operating-system permission, only while you are actively using the app, and only when you trigger the relevant function. There is no background location tracking and no continuous position recording. A location is stored only if you deliberately add it to an entry.

Legal basis: Art. 6(1)(b) GDPR; the system-level permission additionally rests on your consent, which you can withdraw at any time in your device settings.

4.6 Maps, harbours and place search

Map tiles are loaded from MapTiler AG (Höfnerstrasse 98, 6314 Unterägeri, Switzerland). Place search uses Google's Places interface (Google Ireland Limited, Dublin, Ireland). When a map is loaded or a search is run, the technically necessary data is transmitted to the respective provider — in particular your IP address and the map section displayed or the search term you entered. Your account data is not transmitted.

Marina and harbour data additionally comes from OpenStreetMap and is cached on our server; no personal data is involved in that caching.

Legal basis: Art. 6(1)(b) GDPR.

4.7 Crew invitations

When you invite a crew member to a voyage, you enter their email address. We use that address solely to send the invitation and to match the person when they join. You confirm that you are entitled to share that address. Invitations that are never accepted are deleted at the latest as part of the archiving described in section 7.

Legal basis: Art. 6(1)(b) and (f) GDPR (carrying out the invitation you initiated).

4.8 Ship's kitty

The ship's kitty is purely a record-keeping tool. We process the amounts, descriptions and crew allocations you enter. No payments are processed; no payment details such as bank accounts are collected.

4.9 Sending email

Sign-in codes, invitations and system notifications are sent via mailbox.org (Heinlein Hosting GmbH, Schwedter Str. 8/9b, 10119 Berlin, Germany). We send no marketing email and no newsletter.

4.10 Diagnostics and crash reports

To keep the app stable we use Sentry (Functional Software, Inc. d/b/a Sentry, San Francisco, USA), with processing in the provider's EU region (data centres in Germany). When an error occurs, technical data is transmitted: error message and stack trace, device type, operating-system version, app version and a pseudonymous identifier for your account so that recurring errors can be correlated. Your voyage content is not transmitted; the app strips credentials, tokens, email addresses and query parameters before a report leaves the device. Error reporting is disabled in the development environment.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functioning, secure app).

4.11 Data that stays on your device

Some data never leaves your device: display settings (theme, language), your onboarding progress and your personal journal entries. These are stored locally only and are deleted when you uninstall the app — they are therefore also not part of a data subject access request.

5. Recipients and processors

We use carefully selected service providers, with data processing agreements under Art. 28 GDPR in place where required:

ServiceProviderPurposePlace of processing
SupabaseSupabase, Inc., USADatabase, authentication, file storageAWS region eu-central-1, Frankfurt, Germany
SentryFunctional Software, Inc., USACrash and error reportsProvider's EU region (Germany)
mailbox.orgHeinlein Hosting GmbH, BerlinSending emailGermany
MapTilerMapTiler AG, SwitzerlandMap tilesSwitzerland / EU
Google PlacesGoogle Ireland Limited, IrelandPlace searchEU / USA
CloudflareCloudflare, Inc., USAWebsite deliveryGlobal edge network
Apple / GoogleApple Distribution International Ltd. / Google Ireland Ltd.App distribution, sign-inEU / USA

6. Transfers to third countries

Your voyage and account data is processed within the European Union. Some of the providers listed above are based in the USA and may gain access in the course of support and operations. We base those transfers on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where the provider is certified, on the adequacy decision for the EU–U.S. Data Privacy Framework (Art. 45 GDPR). An adequacy decision also exists for Switzerland.

7. Retention and deletion

7.1 Automatic archiving after a voyage ends

30 days after a voyage's end date, data that is no longer needed once the voyage is over is deleted automatically and permanently — in particular open invitations and the email addresses used for them, the ship's kitty ledger, packing-list allocations, all checklists, the safety briefing including its acknowledgments, and the activity plan. Planning-only details (charter, meeting point and check-in fields) are removed as well.

What remains is the record with evidentiary value: the complete logbook, sea-mile records, the route, the voyage name, boat and charter company details, and the list of crew members who were actually aboard.

7.2 Deleting your account

You can delete your account at any time in the app (Profile → Delete account). This deletes your sign-in account, your profile, your uploaded files and the data you created; if you signed in with Apple, the link to your Apple ID is also revoked. Deletion is immediate and irreversible.

One exception concerns completed voyages with other crew: so that the other participants do not lose their logbook, sea-mile records and safety briefing, such a voyage is handed over to another crew member when you delete your account, rather than being deleted. Your personal profile data is no longer contained in it; what remains is the fact that you were part of the crew. If no other crew member took part, the voyage is deleted in full.

7.3 Other periods

  • Authentication logs: up to 90 days.
  • Crash and error reports: up to 90 days.
  • Website access logs: short-term, as part of operational security.
  • Email correspondence with us: until your enquiry has been fully dealt with, unless statutory retention obligations apply.

8. What other crew members can see

CoSkipper is a shared app. When you join a voyage or invite people to your own:

  • Your name and profile picture are visible to the other crew members of that voyage.
  • Your crew-list details (section 4.2) are visible to that voyage's skipper insofar as you have entered them — this is what those fields are for.
  • Content you create, such as logbook entries, checklist status, packing lists and kitty entries, is visible within the voyage.
  • Your other voyages, your journal and your non-voyage documents are not visible to other users.

If you leave a voyage or delete your account, content that other crew members need as part of their own records (for example a shared logbook entry) may remain with them.

9. Your rights

In respect of personal data concerning you, you have the right to:

  • access (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • withdraw consent with effect for the future

An informal message to info@coskipper.app is enough. You can also delete your account yourself in the app at any time.

10. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach, Germany
www.lda.bayern.de

11. Data security

All traffic between the app and the server is TLS-encrypted. Access to data is restricted per record at database level to the accounts entitled to it (row level security). Your session is held in the device's protected system store. Log data is stripped of credentials, tokens and email addresses before it is stored.

12. Children

The app is not directed at children. You must be at least 16 years old to create an account. If we learn that an account was created by a younger person without the consent of their guardian, we will delete it.

13. No automated decision-making

We do not carry out automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

14. Changes to this policy

We update this policy when the app, the services we use or the legal situation change. The version published on this page applies; the date above shows its status. We will additionally notify you in the app of any material change.

← Back to home Terms of Use Imprint
CoSkipper
Privacy Terms Imprint Deutsch

© 2026 Kamil van der Linde