Privacy Policy

SurfCap Vibes

Effective date: 2026-09-26

This policy explains how this application handles information and how to contact us about privacy.

Information we process

SurfCap Vibes works without an account. On your iPhone it stores the surf spots you add (names, text addresses and coordinates), preferences, practiced-technique marks, session records (date, duration, rating, notes and any attached conditions), and the last forecast. A random installation secret is kept in Keychain. If you choose Use current location, iOS supplies your current coordinates for the spot you save; the app does not track your location in the background. When online, the app sends the installation secret with forecast and session requests to our Railway-hosted service. The service stores a hash of that secret and the session records you back up. It temporarily caches forecast results by requested coordinates. The service and its hosting infrastructure necessarily receive request metadata such as IP address, time, path and status; application logs contain request IDs, method, path without query parameters, status and duration, but not the installation secret. We do not collect an email address through the app.

How we use information

We use saved spot coordinates to request marine conditions and show the GO, WAIT or NO outlook, hourly forecast and conditions attached to a session. We use session records to display and edit your log and calculate progress summaries. The installation secret authorizes access to your own server backup. Local preferences adjust the outlook, units and reminder; practiced marks track your progress through offline lessons. Request metadata supports operation, reliability and diagnosis of the service.

Service providers and sharing

The app backend and PostgreSQL storage run on Railway, which processes service traffic and infrastructure logs for hosting. For a forecast request, our backend sends the requested coordinates to Open-Meteo Marine and Open-Meteo Weather; those providers also receive the backend's network request metadata. We do not send your session notes or installation secret to Open-Meteo. We do not use advertising, analytics, email-delivery or social-sign-in services. We do not sell personal data.

Data retention

Session backups and the hash of an installation secret remain on the server until you delete all data for that installation, subject to any provider-operated backups and infrastructure retention outside the live database. Forecast responses are cached on the server for up to 30 minutes and the latest forecast remains on your iPhone until replaced or deleted. Local spots, sessions, preferences and practiced marks remain until you remove them or delete app data. Railway controls infrastructure logs and backups; we do not assert a fixed retention period for those systems because none is configured by this app. A lost installation secret cannot be used to locate or recover its server records.

Deleting your information

In Settings, Delete all data first asks the server to erase sessions tied to this installation secret, then removes the local log, spots, forecast cache, preferences, practiced marks and Keychain secret. This action requires an internet connection; if server deletion fails, the app keeps the local data and explains that you should retry. You can delete individual sessions from the log; their server deletion is retried when connectivity returns. Data in Railway-managed backups or infrastructure logs may persist according to Railway's own processes after deletion from the live database. For a privacy request, contact Voitenkosemen947@gmail.com; without the installation secret, we may be unable to identify a particular backup.

Permissions and your choices

Current location is optional and requested only if you tap Use current location while adding a spot; you may instead type coordinates. Daily notifications are optional and are scheduled on the iPhone using the last loaded outlook. You can withdraw either permission in iPhone Settings and turn off reminders in the app. The app does not request photos, contacts, camera, microphone or background location.

Your privacy rights

You can view, edit and delete your sessions in the app, remove saved spots, and use Delete all data to erase the live server copy associated with this installation. To ask about access, correction or privacy, email Voitenkosemen947@gmail.com. The app has no account or email-based recovery; requests concerning server records may require the installation secret to establish which records are yours. Rights available under local law may vary by location.

Security

Private API requests use HTTPS and a cryptographically random installation-scoped secret stored in iOS Keychain. The server checks that secret for every private request and stores only its SHA-256 hash to separate installations. PostgreSQL holds session backups. These measures reduce unauthorized access but cannot guarantee absolute security; anyone who obtains an installation secret may access that installation's backup. Protect access to your device and its backups.

Children’s privacy

SurfCap Vibes is intended for surfers aged 16 and older and is not designed for children under 16. The app does not ask users to state their age or create an account. If you believe a child's data was stored, contact Voitenkosemen947@gmail.com and use the in-app deletion option when you have the installation.

Changes to this policy

We may update this policy when the app, backend or processing changes. The effective date at the top of this page will be updated, and the current policy will remain available at this address. Material changes will be described in an app update or on this page. Questions can be sent to Voitenkosemen947@gmail.com.