Your vessel record remains yours
Privacy Policy
This policy explains how Neptivum handles account, vessel, voyage and crew information while keeping the logbook useful offline.
Last updated 8 October 2026
1. Controller
Neptivum is operated by SIA CrowFoundry, registration No. 50203733521, VAT No. LV50203733521, Mednieku iela 17, Sigulda, Siguldas novads, LV-2150, Latvia. For privacy matters, contact privacy@neptivum.com.
2. Data we process
| Data | Purpose | GDPR basis |
|---|---|---|
| Email, password hash, locale, session and Apple/Google provider identifiers; identity tokens processed transiently for requested sign-in; terms version, agreement time and 18+ self-declaration time for new registrations that provide the current declarations | Create, secure and synchronize your account. | Contract |
| Vessels, voyages, precise GPS track points, log entries, plans, port calls, costs and maintenance records | Provide the logbook, offline synchronization, backup and export functions you request. | Contract |
| Crew names, roles, watch events and optional contact or emergency information | Maintain the private crew and watch record that you enter. | User-directed vessel operations; assess the applicable contract or legitimate-interest basis and inform the people whose data you enter. Permission to use the app is not consent on behalf of crew. |
| Documents, photos and audio notes | Attach evidence and notes to your private vessel record and cloud backup. | Contract |
| Apple, Google or Stripe product, customer, invoice and transaction identifiers, entitlement state, expiry and revocation status | Verify Pro access, restore purchases, provide invoices, manage subscriptions and prevent duplicate grants. | Contract; legal and accounting obligations where applicable |
| Device platform, install identifier, IP address and minimal security or service logs | Synchronize safely, diagnose faults and prevent abuse. | Contract; legitimate interests |
| Technical crash diagnostics, application release, error types and sanitized code locations | Detect crashes, hangs and technical faults. Crash reports default on only after agreement to the current terms and a separate declaration that you are 18 or older, and only in a release for which the operational privacy assessment and processor controls have been completed. Agreement to terms is not consent to diagnostics. You can object and turn reporting off at any time in More → Settings without losing any feature; existing opt-outs are preserved. Precise vessel positions, logbook content, crew data, screenshots, request content, exception text, source snippets and local variables are excluded. | Legitimate interests in maintaining service reliability and security |
| Sampled feature duration and success or failure results | Improve performance using fixed feature categories, without URLs, record identifiers or request contents. Performance diagnostics are off by default and require a separate explicit choice in More → Settings after an 18+ declaration and the operational privacy checks. You can withdraw that choice at any time without losing any feature. | Consent |
Payment card details are handled by Apple, Google or Stripe. Neptivum does not receive or store full card numbers.
App versions. The new diagnostic eligibility, minimisation and queue controls described here apply to version 1.0.5 (build 58) and later. The prepared 1.0.5 release currently keeps actual diagnostic sending off behind its operational privacy-readiness gate, even though the crash-reporting preference defaults on. These controls do not retrofit earlier installed versions. Earlier SDK startup, payloads and persistent queues can differ and can include device or installation identifiers, native stacks and exception or context content before the new terms or age gate. Use the diagnostic setting where available in an older version, and update when the new release is available; that setting is not represented here as purging its old native queues. The registration transition below preserves older account-creation requests only until the updated store releases are available.
3. Offline and cloud operation
The logbook is designed to work locally without a connection. Data is sent to Neptivum’s API when you sign in and use synchronization or cloud-backup functions. Precise location is recorded only for an active voyage when you enable a tracking mode. Background location is not used for advertising or cross-app tracking.
4. Processors and transfers
- Hetzner Online: EU-hosted Kubernetes, PostgreSQL and private object storage.
- Cloudflare: DNS, TLS edge and security delivery.
- Brevo: transactional email.
- Stripe: direct web checkout, tax calculation, subscription management, fraud prevention and PDF invoices.
- Apple and Google: app distribution, the optional sign-in you request, in-app purchases and purchase verification. Google’s web identity SDK is loaded only after the account eligibility/rules gate, rather than during local app startup.
- Sentry (Functional Software, Inc.): EU-region scrubbed Dart error reporting and optional fixed feature-duration reporting when enabled and operational privacy checks are complete. The app excludes account, user, device and installation identities, location, arbitrary device context, network requests, crew/vessel/logbook content, private filenames and paths, exception text, local variables, screenshots, replay and attachments. Native crash and raw-memory reporting are disabled. Connection IP is processed to serve a request; reports are not represented as anonymous. Reporting has no persistent disk queue in this version. Before activation, we require the processor agreement, retention and transfer assessment, server IP-storage prevention, geography scrubbing and actual received-payload verification. Diagnostic retention is limited to the recorded project schedule, at most 90 days.
- AISStream and Fintraffic / Digitraffic: the requested MMSI is sent through our API for a manual lookup or automatic reception while a Pro voyage with a saved MMSI is active and the app is open. No account email or phone GPS is sent to these AIS feeds. Received positions retain their provider and observation time. Digitraffic data is provided under CC BY 4.0; Fintraffic / Digitraffic is a regional supplement, not guaranteed worldwide coverage.
- MET Norway: a location rounded to approximately one kilometre is sent through Neptivum's server only when an eligible signed-in user requests live voyage weather. MET Norway does not receive the user's device IP address from the app.
Where a processor involves an international transfer, applicable safeguards such as adequacy decisions or Standard Contractual Clauses apply.
5. Retention and deletion
Active account data remains until you delete it or the service must remove it under these Terms. The in-app Delete account action removes the live account database records, synchronized vessel data and backed-up attachment objects. Encrypted disaster-recovery database backups expire under the operational retention schedule, currently no longer than 14 days, and are isolated from ordinary product use.
Transaction, invoice or accounting evidence may be retained separately where Stripe, Apple, Google, Latvian or EU law requires it. Deleting a Neptivum account does not automatically cancel a subscription. Cancel a web subscription in the Stripe billing portal or a store subscription in the relevant store.
6. Your rights
Subject to the GDPR, you may request access, correction, erasure, restriction, objection and portability. We respond normally within one month and explain any lawful extension. You can object to operational diagnostics in More → Settings; this stops future reporting and removes the dedicated legacy diagnostic cache, without deleting your logbook. The app makes no advertising profiles or automated decisions with legal or similarly significant effects. Neptivum also provides PDF, XLSX, CSV, GPX and JSON exports. Contact privacy@neptivum.com. You may complain to the Latvian Data State Inspectorate or your local supervisory authority.
7. Security and responsibility
Transport is encrypted with TLS, credentials are hashed or stored in platform secure storage, and attachment downloads use short-lived signed URLs. You are responsible for having a lawful basis to record another person’s contact, emergency or crew information and for limiting sensitive material to what the logbook genuinely needs.
8. Children, cookies and changes
Neptivum is a general-audience marine recordkeeping app and is not directed to children. New registration screens require an initially unchecked 18+ self-declaration and current-rules agreement before email or social account creation; no date of birth or identity document is requested. These choices are stored locally and sent for new-account creation; the server records the terms version and receipt times. During the native-release transition, older installed clients can still register without the new fields; no adult or current-version receipt is inferred for them. The server check becomes mandatory when the updated store releases are available. Existing server accounts retain sign-in, recovery and deletion access. Technical reporting requires a separate 18+ declaration. Local recordkeeping remains available without these age declarations. These declarations are not verified age assurance. If we learn that a child below the account minimum has provided personal data, contact privacy@neptivum.com so we can restrict processing and address deletion and applicable parental rights. Do not enter children’s contact or emergency information without a lawful basis and the necessary notice or authority. The public website does not use advertising cookies. Material policy changes will be posted here with a new effective date and communicated when legally required.
Website statistics and storage
Optional website statistics use our self-hosted Matomo service only after you accept statistics in the privacy notice. Rejection is equally available. No analytics script or event request is sent before that choice. Withdraw or change it at any time in Privacy settings; prior opt-outs and browser Do Not Track or Global Privacy Control signals are respected. Analytics cookies are disabled. Statistics include page paths, page titles, referring websites and coarse device and location information. Query details and fragments are excluded. Your choice is saved in this browser for 180 days and can be changed through Privacy settings. This does not collect data from the app. Cloudflare delivers and protects the website and may use essential security cookies. Contact info@crowfoundry.com about your data.