Privacy Policy
I'm Sailor — Maritime Management & Community Platform
I'm Sailor, Inc. ("we," "us," or "our") operates the I'm Sailor platform (the "Service"), available as a web and mobile application. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our Service.
We are committed to protecting your privacy and handling your data transparently. This policy is written in plain language so that you — whether you're onboard a vessel or ashore — can understand how your information is treated.
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
1. Information We Collect
We collect information in three categories: information you provide directly, information generated through your use of the Service, and information received from third parties.
1.1 Information You Provide
- Account Information. When you register, we collect your name, email address, password, and optionally a profile photo and professional credentials (such as certifications, rank, or maritime qualifications).
- Assignment and Work Data. Information you enter about your maritime assignments, including dates, schedules, vessel names and details, port locations, departure and arrival points, logbook entries, incidents, and events.
- User-Generated Content. Posts, comments, reviews, images, and videos you submit to the community feed, the Maritime Explorer, or other public areas of the Service.
- Messages. Content of direct and group messages you send and receive through the in-app messenger.
- AI Copilot Interactions. Questions, prompts, and conversational data you exchange with our AI Copilot feature.
- Reviews and Ratings. Reviews, ratings, and comments you leave on ships, ports, airports, maritime companies, or other entities within the Maritime Explorer.
- Payment and Donation Information. When you make a voluntary donation through our "Support Us" feature, your card details are entered directly with our payment processor (Stripe) — we never receive or store your full card number. We retain a record of the donation amount, currency, status, timestamp, and a Stripe customer and payment identifier linked to your account. See Section 4 for details on our payment processor.
- Support Communications. Information you provide when contacting our support team.
1.2 Information Collected Automatically
- Usage Data. Pages visited, features used, actions taken (such as likes, comments, and searches), timestamps, and interaction patterns.
- Device and Browser Information. Device type, operating system, browser type and version, screen resolution, and language preferences.
- Log Data. IP address, access times, referring URLs, and error logs.
- Product Analytics and Session Recordings. With your consent (see Section 10), our analytics provider (PostHog) records product analytics events — such as clicks, navigation, and feature usage — and may capture session recordings, which are replays of your interactions with the interface (including browser console logs). Password fields are masked; other text you enter may be captured unless specifically masked. These analytics may be linked to your account. Analytics and session recording are turned off by default and only enabled if you accept analytics cookies.
- Cookies and Similar Technologies. See Section 10 for details.
1.3 Information from Third Parties
- Authentication Providers. If you sign in using a social login (such as Google or Apple), we receive basic profile information (name, email, profile picture) as authorized by you through that provider.
- Public Maritime Data. We may supplement platform data with publicly available maritime information (vessel registries, port databases) that is not linked to your personal account.
1.4 Information We Do Not Collect
- Real-Time Location Tracking. We do not track your GPS location in real time. Location-related data on the platform (ports, airports, assignment locations) is entered by you manually or selected from our database.
- Full Payment Card Numbers. Donations are processed by Stripe. Your full card number, CVC, and expiry are entered directly with Stripe and are never received or stored on our servers. We only retain the limited donation record described in Section 1.1.
2. How We Use Your Information
2.1 Providing and Operating the Service
- Creating and managing your account.
- Enabling you to record, view, and manage your maritime assignments, logbook entries, and events.
- Powering the Maritime Explorer with community-contributed data.
- Delivering the community feed, comments, reviews, and social features.
- Facilitating messaging between users.
- Operating the gamification system (points, badges, and reputation).
- Processing voluntary donations and maintaining donation records for receipts, accounting, and dispute resolution.
2.2 AI Copilot Features
- Processing your queries through the AI Copilot to provide contextual, relevant answers about your assignments, vessels, maritime data, and more.
- Using vector embeddings of platform data to improve the accuracy and relevance of AI-generated responses.
- See Section 3 for detailed information about AI data processing.
2.3 Communication
- Sending you notifications about your assignments (upcoming schedules, reminders).
- Delivering system notifications (account security, policy updates, feature announcements).
- Responding to your support requests.
2.4 Improvement and Analytics
- Analyzing usage patterns — including product analytics events and, where you have consented, session recordings — to improve the Service's features, performance, and user experience. These analytics may be linked to your account.
- Identifying and fixing technical issues.
- Conducting research on platform usage trends, in aggregated or anonymized form where practical.
2.5 Safety and Legal Compliance
- Detecting and preventing fraud, abuse, and violations of our Terms of Service.
- Enforcing our policies and complying with applicable legal obligations.
- Protecting the rights, safety, and property of our users and the public.
2.6 Legal Basis for Processing (EEA/UK Users)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing the Service, account management | Performance of a contract with you |
| AI Copilot processing | Your consent and legitimate interest |
| Processing donations | Performance of a contract with you; compliance with financial record-keeping obligations |
| Product analytics and session recording | Your consent |
| Service improvement and diagnostics | Legitimate interest |
| Safety and fraud prevention | Legitimate interest |
| Legal compliance | Legal obligation |
| Marketing communications (if any) | Your consent |
You may withdraw your consent at any time where consent is the legal basis for processing. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
3. AI Data Processing
The I'm Sailor platform includes an AI Copilot feature, along with automated content-moderation and search capabilities, powered by third-party artificial intelligence services accessed through OpenRouter, an AI model gateway. Through OpenRouter, your queries are processed by large language models operated by providers including Google (Gemini models) and Meta (Llama models), and we use an OpenAI text-embedding model to power contextual search. This section explains how your data interacts with AI processing.
3.1 What Data Is Sent to the AI Providers
When you use the AI Copilot, the following data may be sent through OpenRouter to the relevant AI provider for processing:
- Your conversational messages (questions and prompts you type).
- Contextual information necessary to generate a relevant response, which may include:
- Assignment details (vessel names, dates, port names, event summaries).
- Relevant maritime data from the platform (ship details, port information).
- Conversation history within your current AI session.
We use vector embeddings (mathematical representations of text) to find relevant context. Generating these embeddings involves sending the underlying text to the embedding provider via OpenRouter; the resulting embeddings are stored in our database. The data sent to the AI providers is limited to what is necessary to answer your specific query.
Separately, content you post to public areas of the Service may be processed by these AI providers for automated safety and moderation checks. Your private direct messages are not sent to AI providers (see Section 6).
3.2 What Data Is Not Sent
- Your password or authentication credentials are never sent to AI providers.
- Private messages between you and other users are not sent to AI providers.
- Your full account data is not sent in bulk — only the specific context relevant to your query.
3.3 How the AI Providers Use Your Data
We access these models through OpenRouter's API. Under OpenRouter's and the underlying providers' standard API terms, data submitted via the API is not used to train their models, and providers may retain API inputs and outputs for a limited period for abuse and misuse monitoring before deletion. These terms are set by OpenRouter and the model providers and may change; we do not control their data-handling practices.
We encourage you to review OpenRouter's Privacy Policy and the policies of the underlying providers (such as Google and Meta) for the most current information.
3.4 Your Control Over AI Data
- Opt-out. You may choose not to use the AI Copilot feature. Not using it means no data is sent to AI providers on your behalf.
- Deletion. You can request deletion of your AI conversation history at any time (see Section 8).
- Transparency. AI-generated responses are clearly identified within the platform so you can distinguish them from human-authored content.
3.5 AI Limitations
AI-generated responses are provided for informational and convenience purposes only. They should not be relied upon as professional, legal, or safety-critical advice. Always verify important information through official maritime authorities and documentation.
4. How We Share Your Information
We do not sell, rent, or trade your personal information. We share your data only in the limited circumstances described below.
4.1 Third-Party Service Providers
We use the following categories of service providers to operate the Service. These providers process your data on our behalf and under our instructions:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Authentication, database hosting, file storage | Account data, assignment data, messages, user content |
| Railway | Backend application hosting | All data processed by our API; IP addresses, request logs |
| Vercel | Frontend hosting and delivery | Usage data, IP addresses, request logs |
| Cloudflare | Image and file storage and delivery | Uploaded images and documents |
| Mux | Video hosting, encoding, and streaming | Uploaded videos |
| OpenRouter (and underlying model providers, including Google and Meta) | AI Copilot, content moderation, and embeddings | AI prompts and contextual assignment/maritime data (see Section 3) |
| Stripe | Payment processing for donations | Name, email, payment card data (entered directly with Stripe), donation amount and currency |
| Resend | Transactional and invitation emails | Email address and recipient name |
| PostHog | Product analytics and session recording (with consent) | Usage events, device/browser information, IP address, session recordings, account identifiers |
| Sentry | Error monitoring and diagnostics | IP address, device/browser information, technical error context |
| LocationIQ | Location search and autocomplete | Location search queries and IP address |
Each provider is contractually obligated to protect your data and use it only for the purposes we specify. We select providers that maintain appropriate security standards and, where applicable, offer data processing agreements compliant with GDPR and other applicable laws.
4.2 Public Content
Content you post to public areas of the Service — such as the community feed, Maritime Explorer reviews, and comments — is visible to other users and may be indexed by search engines. See Section 5 for details.
4.3 Other Users
- Your profile information (name, profile photo, credentials) is visible to other registered users.
- Messages you send are visible to their recipients.
- Your contributions to the Maritime Explorer (images, reviews, comments) are attributed to your username.
4.4 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation.
- Protect and defend our rights or property.
- Prevent fraud or address security issues.
- Protect the personal safety of users or the public.
4.5 Business Transfers
If we are involved in a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your data.
5. User-Generated Content and Community Data
5.1 Public Content
The following content is considered public and is visible to all registered users of the Service:
- Community feed posts (text, images, videos).
- Comments on posts and Maritime Explorer entities.
- Reviews and ratings of ships, ports, airports, and companies.
- Images submitted to the Maritime Explorer.
- Your profile name, photo, and professional credentials displayed alongside your contributions.
Please exercise care when posting. Public content cannot be made fully private after publication, as other users may have already viewed or interacted with it. While you can delete your own content, copies or references may persist in other users' feeds or notifications.
5.2 Private Content
The following content is private and not visible to other users unless you choose to share it:
- Your assignment and work data (schedules, logbook entries, events, incidents).
- Your AI Copilot conversations.
- Your direct messages (visible only to conversation participants).
5.3 Community Contributions and Attribution
When you contribute to the Maritime Explorer (submitting images, facts, or reviews), your contribution is attributed to your username. This attribution remains even if you later delete your account, though we will anonymize it upon request (see Section 9).
5.4 Content Moderation
We reserve the right to review, remove, or restrict content that violates our Terms of Service, community guidelines, or applicable law. Automated and manual moderation processes may be used.
6. Messaging Privacy
6.1 Message Content
Messages sent through the in-app messenger are stored on our servers to deliver them to recipients and maintain conversation history. Messages are visible only to the participants in a conversation (direct or group).
6.2 Message Security
Messages are transmitted using encrypted connections (TLS/SSL in transit). Messages are stored in our database with access controls restricting visibility to conversation participants.
6.3 What We Do Not Do with Messages
- We do not read or monitor the content of your private messages for advertising purposes.
- We do not use private message content to train AI models.
- We do not share message content with third parties except as required by law (see Section 4.4).
6.4 Message Retention
Messages are retained for as long as your account is active or as needed to provide the messaging service. You may delete individual messages or entire conversations. See Section 8 for account deletion details.
7. Data Storage and Security
7.1 Where Your Data Is Stored
Your data is stored and processed by our infrastructure providers, primarily Supabase (database, authentication, and file storage), Railway (backend application), Vercel (frontend), Cloudflare (images and files), and Mux (video). These servers may be located in the United States, European Union, or other regions depending on provider infrastructure. See Section 12 for information on cross-border data transfers.
7.2 Security Measures
We implement a range of technical and organizational measures to protect your data, including:
- Encryption in Transit. All data transmitted between your device and our servers is encrypted using TLS/SSL.
- Encryption at Rest. Databases and file storage systems use encryption at rest.
- Access Controls. Access to personal data is restricted to authorized personnel on a need-to-know basis.
- Authentication Security. Passwords are hashed and salted; we never store plaintext passwords. Authentication is managed through Supabase Auth with industry-standard protocols.
- Infrastructure Security. Our key infrastructure and payment providers (such as Supabase, Railway, Vercel, Cloudflare, Mux, and Stripe) maintain SOC 2, ISO 27001, PCI DSS (for payment processing), or equivalent security certifications.
- Regular Reviews. We periodically review our security practices and update them as needed.
7.3 Security Limitations
No system is perfectly secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for any activity under your account.
If you believe your account has been compromised, contact us immediately at info@imsailor.com.
8. Data Retention and Deletion
8.1 Retention Periods
We retain your personal data only as long as necessary for the purposes described in this policy, or as required by law.
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 30 days after deletion request |
| Assignment and work data | Duration of account; deleted upon account deletion |
| User-generated content | Community contributions (posts, comments, stories, reviews) are retained but anonymized (un-linked from your profile) upon account deletion |
| Messages | Duration of account; deleted upon account deletion |
| AI conversation history | Duration of account; deletable on request |
| Donation records | Retained as required for financial, tax, and dispute-resolution purposes (typically up to 7 years), even after account deletion |
| Usage analytics and session recordings | Up to 12 months, then deleted or aggregated |
| Server logs | 90 days |
8.2 Account Deletion
You may request deletion of your account and associated personal data at any time by:
- Using the account deletion option in your account settings.
- Contacting us at info@imsailor.com.
Upon receiving a valid deletion request, we will:
- Delete or anonymize your personal data within 30 days.
- Remove your assignment data, messages, and AI conversation history.
- Retain your community contributions (posts, comments, stories, and reviews) but anonymize them, permanently un-linking them from your profile so they are no longer attributed to you.
- Delete your likes, votes, reactions, follows, and connections.
- Retain only data that we are legally required to keep (such as records needed for legal compliance, dispute resolution, or fraud prevention).
8.3 Data Portability
You have the right to receive a copy of your personal data in a structured, commonly used, machine-readable format. See Section 9.
9. Your Rights
Depending on your location, you may have some or all of the following rights regarding your personal data. We honor these rights for all users regardless of location as a matter of good practice, though certain rights are specifically guaranteed under laws like the GDPR (EU/EEA/UK) and the CCPA/CPRA (California, USA).
9.1 Right of Access
You have the right to request a copy of the personal data we hold about you and information about how it is processed.
9.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data. You can update most of your information directly through your account settings.
9.3 Right to Erasure ("Right to Be Forgotten")
You have the right to request deletion of your personal data, subject to certain exceptions (such as data we are legally required to retain). See Section 8.2.
9.4 Right to Restrict Processing
You have the right to request that we limit the processing of your personal data in certain circumstances — for example, while we verify the accuracy of your data following a correction request.
9.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV) and to transmit it to another service provider.
9.6 Right to Object
You have the right to object to the processing of your personal data where we rely on legitimate interest as the legal basis. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
9.7 Right to Withdraw Consent
Where processing is based on your consent (such as AI Copilot usage), you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
9.8 Right to Lodge a Complaint
If you believe we have violated your data protection rights, you have the right to lodge a complaint with your local data protection supervisory authority.
9.9 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to Know. You may request details about the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom it is shared.
- Right to Delete. You may request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale. We do not sell your personal information. If this changes, we will provide a clear opt-out mechanism.
- Non-Discrimination. We will not discriminate against you for exercising your privacy rights.
9.10 Exercising Your Rights
To exercise any of these rights, contact us at info@imsailor.com. We will respond to verified requests within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before fulfilling a request.
10. Cookies and Tracking Technologies
10.1 What We Use
| Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Authentication, session management, security | Session / persistent |
| Functional Cookies | Language preferences, user settings | Persistent |
| Analytics Cookies | Understanding usage patterns, improving the Service | Persistent (up to 12 months) |
10.2 Third-Party Cookies and Analytics
We use PostHog for product analytics and session recording. PostHog sets cookies and uses your browser's local storage to measure how you use the Service and, with your consent, to record sessions (see Section 1.2). Analytics and session recording are disabled by default and are only enabled if you choose "Accept All" on our consent banner.
10.3 Your Cookie Choices
- Browser Settings. You can configure your browser to block or delete cookies. Note that blocking essential cookies may prevent the Service from functioning properly.
- Consent Banner. Analytics and session-recording technologies are off by default. On your first visit we display a consent banner; analytics are enabled only if you select "Accept All" (choosing "Essential Only" keeps them off). To withdraw consent after enabling it, clear this site's cookies and local storage in your browser settings, or contact us at info@imsailor.com.
11. Children's Privacy
The Service is not intended for individuals under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children under 16.
If we discover that we have inadvertently collected personal data from a child under 16, we will take prompt steps to delete that data. If you believe a child under 16 has provided us with personal information, please contact us at info@imsailor.com.
12. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence, including the United States, where some of our service providers are located. These countries may have data protection laws that differ from those in your jurisdiction.
When we transfer personal data outside the European Economic Area (EEA), United Kingdom, or Switzerland, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Reliance on the recipient's participation in recognized frameworks (such as the EU-U.S. Data Privacy Framework, where applicable).
- Other legally recognized transfer mechanisms.
You may request information about the specific safeguards applied to your data transfers by contacting us at info@imsailor.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.
When we make changes:
- We will update the "Last Updated" date at the top of this policy.
- For material changes, we will notify you through the Service (such as an in-app notification or email) at least 14 days before the changes take effect.
- Your continued use of the Service after the updated policy takes effect constitutes your acknowledgment of the changes.
We encourage you to review this policy periodically.
14. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
I'm Sailor, Inc.
16192 Coastal Highway
Lewes, Delaware, 19958, United States
Email: info@imsailor.com
Data Protection Officer: info@imsailor.com
For users in the EEA/UK, our EU representative can be contacted at:
Arturs Vanags
Bralu Kaudzisu iela 44 - 12, Riga, Latvia, LV-1021
Email: art.v@imsailor.com