Effective date: 29 March 2026 Last reviewed: 17 July 2026
1. Who we are
The mySailing mobile and web applications (the “Services”) are provided by
Piotr Gawroński, a private developer based in Łódź, Poland.
Email: app@mysailing.app
As a private individual, we are not required to appoint a Data Protection Officer.
2. Scope
This notice covers:
- The public website located at
https://mysailing.app. - The mySailing mobile, desktop, and web applications.
- Customer support interactions, beta programs, and community surveys.
3. How we process personal data
We only collect data that is necessary for the functionality being used. The table below summarises the processing activities, categories of data, purposes, lawful bases under Article 6 GDPR, retention periods, and typical recipients.
| Context | Data categories | Purpose | Lawful basis | Retention | Recipients |
|---|---|---|---|---|---|
| Account creation & authentication | Name, email, hashed password, profile image | Create and manage user accounts, enable sync, allow password resets | Contract (Art. 6(1)(b) GDPR) | Active account + 30 days after closure | Stored on user device only (sync disabled); future EU cloud provider to be named |
| In-app logbook & crew management | Vessel name, voyage details, crew rosters, uploaded files | Provide sailing log features, generate analytics for the user | Contract; optional guests rely on legitimate interest with opt-out | Stored locally on device until you delete; once cloud sync launches, retained until user deletes voyage or 24 months of inactivity | Stored on user device only (sync disabled); future EU cloud provider to be named |
| Device telemetry & diagnostics | Device model, OS version, anonymised crash logs, feature usage events | Maintain stability, debug crashes, plan improvements | Legitimate interest (Art. 6(1)(f)); users can disable analytics in settings | 12 months rolling window | Firebase Crashlytics (Google’s standard terms) |
| Support & feedback | Contact info, support ticket content, attachments | Respond to support requests, resolve issues | Legitimate interest | Until resolved unless you request deletion | Email (mydevil.net) |
Future hosted storage
Right now, mySailing keeps voyage data on your device only. We plan to launch secure cloud synchronisation hosted in the EU (targeting AWS eu-central-1 or an equivalent ISO 27001 provider). Before enabling sync we will (a) update this document with the final processor list and retention defaults, (b) sign the provider’s GDPR-compliant data-processing terms (or SCCs if outside the EEA), and © release an opt-in UI explaining what data leaves the device and how to disable syncing at any time.
Online Sailor Profile
When you create an online sailor profile (optional, currently in beta), the following data is stored on our servers hosted at MyDevil (Poland, EU):
Required (contractual basis — Art. 6(1)(b) GDPR):
- Display name, email address, phone number
- Sailing qualifications: certificate type, STCW, radio operator certificate
- Professional role and experience description
Optional (consent basis — Art. 6(1)(a) GDPR):
- Date of birth, place of birth, nationality
- Emergency contact information
- Personal identification details
Optional personal data is collected only with your explicit, separate consent (presented as an unchecked-by-default checkbox during registration). It is used exclusively to populate crew lists when you join a trip registered online.
You may join any trip without sharing optional personal data — in that case only your display name and role appear on the crew list.
Consent audit trail: We record when you gave consent, the policy version you agreed to, your IP address, and the scope of your consent (GDPR Art. 7(1) compliance). You may withdraw consent at any time; upon withdrawal, optional personal data is immediately cleared from our servers and all active consents are revoked.
Auto-deletion from trips: When optional personal data is added to a trip crew list, it is automatically removed from that trip’s record 30 days after the trip’s end date. You may request earlier deletion at any time.
Profile deletion: You may delete your online profile at any time from the app. All server-side data is permanently deleted within 30 days. Data included in shared trip records (crew lists) is retained for the trip’s duration plus 30 days, then anonymised. All consent records are retained for the legally required period.
4. Cookies and similar technologies
Our website is built on WordPress and uses strictly necessary cookies for session management and security. We do not use analytics cookies or third-party tracking; if this changes we will deploy a consent banner and update this notice before any optional cookies load.
The app itself does not use third-party advertising SDKs. Crash and performance telemetry respects your operating system’s privacy settings (you can opt out in settings).
5. How we share data
We never sell personal data. Today we rely on:
- Local device storage — account, logbook, and crew data stay on the device unless you opt into future sync.
- Firebase Crashlytics — crash logs and performance metrics processed under Google’s Data Processing and Security Terms (includes SCCs for US transfers).
- mydevil.net email — support replies and attachment handling within the EU.
If we add another processor, we will update this list before data flows to that vendor.
6. Security
We implement technical and organisational measures that include:
- Encryption in transit (TLS 1.2+) and at rest (AES-256 for future cloud sync).
- Device-keystore storage of authentication tokens.
- Role-based access control for internal tooling.
- Secure development lifecycle, dependency review, and third-party penetration tests before major releases.
- Regular backups stored in the EU with separate encryption keys.
No method of transmission is perfectly secure, but we continuously monitor for vulnerabilities and remediate issues promptly.
7. Retention
We keep data only as long as needed for the purposes set out in Section 3 or to comply with legal obligations. When retention expires we delete or irreversibly anonymise the data. Users can delete logbooks, crew entries, or documents at any time from within the app; deleting an account removes associated sync data once server-side sync is available.
8. Your rights
Under GDPR you may:
- Request access to a copy of your personal data.
- Ask us to correct inaccurate or incomplete data.
- Request deletion where data is no longer needed or consent is withdrawn.
- Restrict or object to processing, including telemetry collected under legitimate interests.
- Receive your data in a portable format (CSV/JSON) for information stored in electronic form.
- Withdraw consent at any time without affecting past lawful processing.
- Lodge a complaint with a supervisory authority.
Please email app@mysailing.app to exercise these rights. We respond within
one month (extendable by two months for complex cases) and may request
verification to protect your data.
Supervisory authority
You can lodge complaints with the Polish Data Protection Authority (UODO),
ul. Stawki 2, 00-193 Warsaw, Poland (https://uodo.gov.pl), or with your local
authority if you reside in the EEA/UK.
9. Children
mySailing is not directed at children under 16. We do not knowingly collect children’s personal data. If you believe a child has provided data, contact us so we can delete it.
10. Automated decision-making
We do not engage in profiling or automated decisions that produce legal or significant effects on individuals.
11. Changes to this policy
We review this policy at least annually and whenever we add new processing activities. Material updates will be announced via in-app notification or email before they take effect. Continuing to use the Services after an update takes effect constitutes acceptance of the revised policy.

