Privacy
What stays aboard,
and what we keep.
Siparu has two halves. The plugin runs on your boat and records everything she measures onto her own storage. The hosted service lets you watch her from ashore. Almost nothing about your boat is kept ashore, and this page says, in plain words, exactly what is.
Last updated 4 September 2026
Who is responsible for this
Siparu is run by Siparu Ltd, registered in England and Wales under company number 17429552, at 128 City Road, London EC1V 2NX. The company is the controller of the personal data described on this page. Until 1 September 2026 the service was run by its founder personally; the company took it over on that date and answers for it now. Write to privacy@siparu.app about anything here, and a person answers.
What stays on the boat
Her position, speed, heading, wind, depth, her voyages and her logbook are recorded and held on board, in the Signal K server on your own network. They are not copied ashore to be stored. When you watch her live, her readings travel from her own server, through a relay that keeps none of them, to your browser, and to nobody else. The moment she goes offline there is nothing ashore to show, because nothing was kept. That is the point of the product, not a limitation of it.
Since version 0.2.0 they also travel sealed. The boat encrypts every report to the screens you have authorised, so what crosses the relay is a block it cannot open, and a boat that has authorised no screen sends nothing at all rather than sending it in the clear. Before that version the relay stored nothing either, but a report crossed it readable, which made this a promise about what we do rather than about what we can. A boat still running an older version sends her reports that way until she is updated.
What we keep ashore
An account is the only thing that lives on our side, and it holds the least a service needs to know who you are and which boat is yours:
- Your email address, and a password we never store in the clear: it reaches our authentication provider over TLS and is hashed there, so we hold the hash, not the word.
- Each boat you have paired: her name, that she is yours, and the time she last called in. That last item is a timestamp on our clock, not a position. It is how a screen can show when she was last online, without holding where she was.
- While you connect a boat, a short-lived pairing record: a hashed code that expires within the hour and is used once.
- Your membership, if you take one: which plan you are on and when it renews. Never a card number (see below).
- Your dashboard layout: which gauges you have chosen to hide. Your device seals this with a key derived from your password before it is sent, so what we store is a sealed block rather than your layout in the clear. We keep it only so your choices follow you between devices.
- Each screen you have authorised to open her reports: a device identifier that means nothing on its own, the public half of that device's key, and a note of which screen approved which. The private half never leaves the device it was made on. These are what let your boat seal her reports to your screens without letting us open them.
- Your sign-in sessions. When you sign in, our authentication provider records the session together with the address it came from and the browser string it announced. That is how a session stays valid and how one that is not yours could be told apart. We do not prune these on a schedule today, so a session record outlives the sitting it belongs to; deleting your account removes them with everything else.
One thing we keep is not about you at all: a daily tally of how many times a boat asked for a pairing code. It is how we learn whether the free half aboard leads anyone to want the shore, and it is a number rather than a record. A date and a total, with nothing in it that says which boat asked, from where, or at what hour. One boat asking twice and two boats asking once are the same entry, deliberately, because telling them apart would mean keeping something that identifies them.
What we deliberately never keep
Some things are absent by design, and their absence is the promise:
- Where your boat is. No position, no track, no last known fix sits ashore. Ever. From version 0.2.0 it cannot be read in passing either, because what crosses the relay is sealed to your own screens. On earlier versions it crossed readable, and a boat that has not been updated still sends it that way.
- What she carries. Your gauge choices would reveal which systems she runs, so your device seals them before they reach us, and we store a sealed block rather than the list in the clear.
- Your card. Payment is handled by a payment processor, and never by us.
- A phone number. Nothing here asks for one.
- A count of who installed it. The plugin on your boat sends us nothing at all until you begin pairing her, so an installation that never reaches for the shore is one we cannot see and do not try to. We would rather not know than measure you.
Payments
The Remote plan (watching a boat from ashore) is a membership, and it is not on sale yet. When it is, it is taken here on this site rather than inside an app. The software on the boat is free, and stays free whether or not you ever take a membership. We never see or hold your card: a payment processor holds it under its own terms. What reaches us is only that you have a membership and until when, recorded against your account so that signing in on a laptop finds what you took on a phone.
The contact form
If you write to us through the form, we keep what a reply needs and no more: your message, the email address to answer it, and, if you offer them, a name and a subject. The message is stored, and that store is what we read and answer from. We do not keep your IP address with the message; it is seen only at the edge, to slow a flood of automated messages, and then it is gone. Signing in is the one place an address is written down, and it is named above. The lawful basis is your consent, and you may withdraw it at the address below.
Cookies, tracking and third parties
This site sets no tracking cookies, runs no analytics, and carries no advertising or social pixels. Nothing follows you off this page.
When you are signed in, the app keeps you signed in with a token in your browser's own local storage. This site reads that one token, and nothing else, to decide whether to show you a way in or a way to your dashboard. It is not a tracking cookie and it never leaves your browser.
The typefaces and the page's animation code are served from this domain, so no font or type CDN is told that you are reading this. The one third-party script on this site is Cloudflare Turnstile, the check that the contact form is filled in by a person; Cloudflare is one of the three companies that handle data on our behalf, as processors, under contract and on our instructions only:
- Supabase holds your account, your boats and your messages. The database is in the European Union (Frankfurt).
- Cloudflare serves this site, runs the relay that carries your boat's reports, and provides the check that a form is being filled in by a person rather than a machine. It is a global network, so a request of yours is answered by whichever of its locations is nearest.
- Resend delivers the mail an account needs: a sign-up code, an invitation, a notice that a password changed.
One further request leaves your browser, and only when you open the chart from ashore. The coastline underneath your boat is drawn from OpenFreeMap, so that service is asked for the squares of map you are looking at, and a square says roughly which stretch of coast held your attention. It is run from inside the European Union, sets no cookie, and does not log addresses by default. Your boat's own position and track are not sent there: your browser draws them on top, from readings it has already unsealed. The chart is the only place this happens, and closing it ends it.
Cloudflare and Resend are established in the United States, so serving you can involve a transfer outside the European Economic Area. Both are engaged under the European Commission's standard contractual clauses, and what Cloudflare carries for your boat is sealed to your own devices before it reaches them (see above). Serving any web page leaves the usual request line (an address, a browser string); we use it to keep the service up and to rate-limit the form, not to build a picture of you.
Where it lives, and for how long
Your account, your boats and any message you send are held by Supabase, in the European Union; the live relay and this site run on Cloudflare. Both are encrypted at rest. How long each thing stays:
- Your account, and the boats and preferences attached to it, for as long as you have an account. Close it and all of it goes at once, from your own Account page.
- A message you send through the form, until the exchange is finished and in any case no longer than a year after it arrived.
- A pairing record, under an hour: it expires on its own and is used once.
- A membership, for as long as it runs and then as long as the law requires the record of a sale to be kept. Nothing here is on sale yet, so today there is nothing of this kind.
Your boat's own history is not on this list because it is not ashore at all. It is on her, and it is yours: nothing here expires it, and nothing here can produce it.
Your rights
Under the GDPR you can ask what we hold about you, ask for a copy, ask us to correct it, and ask us to delete it. Deleting is in your own hands: your Account page closes the account and takes every boat with it, and any boat can be removed from its own page, with nobody to ask. For a copy of what we hold, or a correction, write to privacy@siparu.app and we will do it, and confirm when it is done. There is little to hold, by design.
You can also object to what we do with your data, ask us to restrict it, and ask for what you gave us in a portable form. Providing it is not a legal requirement and there is no automated decision-making here: nothing about your account is decided by a machine reading your data.
The lawful basis for your account data is the contract to run the service you signed up for; for a message sent through the contact form it is your consent, which you may withdraw at the same address.
If you think we have handled your data badly, tell us first and we will put it right. You are also entitled to complain to a supervisory authority: in the United Kingdom that is the Information Commissioner's Office, and in the European Union it is the authority for the country you live or work in.
Changes
If this policy changes in a way that affects what we do with your data, the date above changes and, where the change is material, we tell you before it takes effect.