Privacy

Your data stays yours.

Skiffcast does not sell, rent, trade, or share your personal information with third parties for marketing, advertising, or any other commercial purpose. Period.

Last updated: August 20, 2026.

The headline

No sell. No share. No third-party marketing.

That answer is the whole policy. The sections below name exactly what is collected, what is not done with it, how long it is held, and the controls you have over it. If anything here changes, we will update this page, bump the “last updated” date at the top, and call it out on /about so the harbor-neighbor voice matches the policy.

What we collect

Six categories, plainly named.

For each category: what is collected, and the sole purpose the app holds it for. None of this leaves Skiffcast unless the policy below says it does.

Account data

Email + password hash (managed by the auth provider, better-auth) when you sign up to save spots.

Solely to authenticate you on later visits. We do not use your email for marketing, newsletters, or any outbound campaign.

Saved spots

The waterways, ramps, and meeting points you bookmark in the saved-spots feature.

To render your "My Day on the Water" brief and to power the shareable saved-spots links.

My Day on the Water brief

An offline-cached snap of tide, wind, solunar, and water-temp for the spots you have saved.

To keep the read on screen when you clear cellular. The brief lives in your browser localStorage only — we never see it server-side.

Community reports

Short harbor-condition notes you submit from a waterway page — the body you write, plus the waterway you attached it to and the timestamp.

To display your contribution alongside other community reports on the same waterway. Never used to identify you elsewhere.

Contact form submissions

The name, email, and message body you send through /contact.

To route a reply to your inbox and keep an in-app record of the thread. Retained per standard inbox retention; never shared.

Automatic server logs

Standard server access logs — IP, user agent, request path, response status, request time.

Briefly retained for debugging abuse and traffic spikes. Not joined to your identity, not used to profile you.

What we don’t do

Four lines we will not cross.

The legal-protection core of the page — restated so the policy is unambiguous.

  • No selling to data brokers.
  • No sharing with advertisers, social platforms, or analytics resellers.
  • No third-party retargeting pixels on the public pages.
  • No account data ever leaves Skiffcast except at your explicit request (account export or delete).

How long we hold data

Until you ask us to stop.

Account data: while your account is open. Closed on request.

Saved spots + community reports: until you delete them individually or delete your account.

My Day brief: browser-local only, mirrored at skiffcast:<waterway>:conditions|v1. We never see it server-side; clearing site data clears the cache.

Contact submissions: routed to a Polsia-managed inbox; retained per standard inbox retention.

Server logs: short retention window; not joined to identity.

Your controls

Edit, delete, export — you hold the keys.

Every category above has a user-facing handle. Use it.

Edit or delete saved spots from the saved-spots page.

Delete community reports or saved spots individually from the same surfaces.

Export or delete your account on request — send a note through /contact and we will route the request.

Account export and account delete both run server-side. Export delivers a JSON bundle of your saved spots and community reports; delete purges the same set and your auth record, then emails confirmation.

Questions or a request

Ask, or read the sources sidecar.

Drop us a line through the contact page — the same channel runs export and delete requests. The /about page names every public feed that backs the briefing, so you can see exactly which agency each signal on the glance card comes from.