Privacy Policy - modus marine
Effective date: 2026-09-22 Last updated: 2026-10-04
1. Who we are
modus marine is a maintenance and operations platform for cruising and charter yachts. It is built and run by its independent developer ("we", "us") - an individual, not a company.
The app is in private testing. Every account exists because we invited the person using it, so the route to us about anything in this policy is a direct reply to whoever gave you access. Before the app is offered publicly we will name an operating entity and a monitored contact address here, and tell you before that change takes effect (§12).
For data protection law purposes (GDPR / UK GDPR / similar regimes), we are the data controller for the personal data described below.
2. What we collect
We only collect what the app needs to do its job.
a. Account data (when you sign up)
- Email address
- Password (you set it; we never see it - Supabase hashes it before storage)
- An account picture, if you pick one: one of the app's own icons, not a photo
- If a captain gives someone a view-only login (up to five per boat), the email address the captain created it with, and the same password protection as above
b. Vessel & profile data (when you onboard)
- Vessel name, length, type (propulsion / hull configuration)
- Your role on the vessel (captain by default)
c. Operational data you enter (this is the bulk of the app)
- Equipment records (make, model, serial, location, notes, hour readings)
- Service records (intervals, completions)
- Projects (titles, progress notes, status)
- Calendar events
- Documents (manuals, certificates, ship's papers) and any files you upload
- Tasks (your weekly to-do list, including any set to repeat) and the note on each week
- Logbook and dive log entries (your device's GPS position when you tap to record it, weather and sea conditions, who was aboard, notes), and dive tank refills
- Passage plans (the route, your estimates, crew, contacts and notes you type)
- Spares and stores, including a photo of a part if you take one
- Weekly review reports: a saved copy of each week's completed and planned tasks, the projects opened and closed, and your equipment's hours, made automatically once each week has ended. The app keeps them so a report reads the same later as the day it was made, and shows them to your boat's view-only logins if you have given any. The week in progress is put together when you open it and is not kept. The app never sends a report anywhere: it is a PDF you download and share yourself.
Some of this data may relate to third parties (crew names in notes, a contractor's name on a service completion, an owner's email address). You are responsible for having a lawful basis to enter that data - see §10.
d. Technical data we receive automatically
- IP address and basic request metadata (kept by our hosting provider for security/abuse prevention)
- Session cookies set by the authentication system
- Which documents you have opened, kept per user so your own "Recently opened" order works. Nobody else can see it, the captain included.
- A count of how many times each account has used the document reader in a day, kept to enforce a limit - counts only, never the content that was read
We do not use third-party analytics, advertising trackers, or social-media pixels.
3. Why we use it (purposes and lawful bases)
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Providing the service you signed up for (auth, syncing your vessel data, projecting service due-dates, making the weekly review reports) | Performance of a contract - Art. 6(1)(b) |
| Keeping the service secure (rate limiting, abuse prevention, audit) | Legitimate interests - Art. 6(1)(f) |
| Complying with legal obligations (tax records, lawful requests) | Legal obligation - Art. 6(1)(c) |
We do not profile you, sell your data, or use your data to train AI models.
One feature does send data to an AI provider, and only when you choose to use it: when you photograph a part, a machine's plaque, a label or a packing slip, or upload photos or a PDF of an old logbook's pages or of an equipment manual's service schedule, and ask the app to read it, that file is sent to Anthropic and comes back as text you can edit (§4). A logbook page can carry the names of crew. Nothing goes there unless you use that feature, Anthropic does not train on it, and the file is not kept by them on our behalf.
4. Who else processes your data (subprocessors)
We use the following processors. Each is contractually required to protect your
data on our behalf. See subprocessors.md for the up-to-date
list and the data each receives.
- Supabase Inc. - database, authentication, file storage (region: US East). We have / will accept their Data Processing Addendum.
- Vercel Inc. - application hosting and edge / serverless compute.
- Anthropic PBC - turning a photo or PDF you upload into text, only when you use that feature. The file and the instruction go to Anthropic's API and the text comes back; it is not stored there on our behalf and is not used to train their models.
- Resend - delivering the app's account emails: the link that confirms a new account or a changed email address, or resets a password. It receives the address the email goes to and the email itself. We send no other email.
5. International transfers
The application and its data are hosted in the United States (Supabase US-East, Vercel global edge). If you are in the EEA / UK / Switzerland, your personal data will be transferred to the US. Transfers rely on Supabase's and Vercel's Standard Contractual Clauses and their supplementary technical measures (encryption at rest and in transit; row-level access enforced at the database).
6. How long we keep it
- Account data: for as long as your account exists, plus a short retention period after deletion to handle billing/legal/support follow-up.
- Operational data you enter: for as long as your account exists. Deleted
items use a soft-delete model (
deleted_atcolumn) so you can recover them - this is operational memory, not silent loss. Soft-deleted records are removed when you delete your account. - Logs and technical data: typically 30-90 days, depending on the provider.
If you ask us to delete your account (§7), we will hard-delete the data we hold about you and instruct our subprocessors to do the same.
7. Your rights
If you are in the EEA, UK, California, or another jurisdiction with similar laws, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Delete your account and personal data (the "right to be forgotten")
- Restrict or object to certain processing
- Receive your data in a portable form (export)
- Withdraw consent where processing relies on it
- Lodge a complaint with a supervisory authority (e.g. the ICO in the UK, your national DPA in the EU, or the California AG)
Deletion you can do yourself, right now, from Settings. It is a real erasure, not a hidden flag: your login, the vessel you are the only captain of, its records and the files you uploaded are removed, and on a vessel you share with another captain your work stays but stops being attributed to you.
You can download your boat's records yourself at any time from Settings (Export my data): a file of spreadsheets and a machine-readable copy. It does not include files you uploaded (documents and photos); each document's files can be downloaded from its page.
For anything else on this list, reply to whoever gave you access (§1). We will respond within 30 days.
8. Security
- Passwords are hashed by Supabase (bcrypt). We never see them.
- All connections use HTTPS / TLS. Storage is encrypted at rest.
- The database uses Row-Level Security - each piece of data is scoped to the vessel it belongs to, and access is enforced inside Postgres rather than only in application code.
- Strict security headers including a Content Security Policy are set on every page.
- A photo you send to the document reader has its embedded metadata (GPS position, device model, timestamp) stripped on our server before it leaves for the reader, whatever your phone wrote into the file.
- The Victron access token, if you connect one, is stored in a table no browser session can read at all - only our server can.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and (where required) the relevant supervisory authority within 72 hours of becoming aware, in line with GDPR Art. 33-34.
9. Cookies and local storage
We use the minimum necessary:
- Authentication cookies - set by Supabase to keep you signed in. Session duration controlled by Supabase. Essential.
mm-form-draftlocalStorage entry - if your phone closes the app in the background while you are part way through a form, what you had typed is kept here for a few hours so the form comes back as you left it. Never sent to us. Functional.mm-inventory-tablocalStorage entry - remembers which Inventory tab you last had open. Never sent to us. Optional.tzcookie - your device's timezone (for exampleAmerica/Tortola), set automatically so dates and times print correctly on documents such as the passage plan and the trip log. Sent only to our own server. Essential.
We do not use analytics or advertising cookies.
10. Data about other people (crew, owners, contractors)
If you enter data about other people (e.g. a crew member's name in a note, a contractor's name on a service completion, a boat owner's email address), you warrant that you have a lawful basis to do so - typically the employment relationship, contract, or their consent - and that you will tell them their data is being processed in this app on request.
For these third parties, you are the data controller and we act as your processor. We will only use that data to provide the service to you, and we will support requests they make to us by referring them back to you.
11. Children
The app is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to this policy
If we make material changes we will notify you (in-app or by email) at least 30 days before the change takes effect. Continued use of the app after the effective date means you accept the updated policy.
13. Contact
Questions about this policy or about your data: reply to whoever gave you access to the app (§1). A published contact address replaces this line before the app is offered publicly.