Privacy Policy
Effective 25 July 2026 · Last updated 18 August 2026
SailStats (“the app”) is a sailing-instrument and race-recording app published by Internet Marketing Solutions Limited (“we”, “us”), a company registered in New Zealand. This policy explains what data the app handles, where it goes, and your choices.
Summary
- Almost everything SailStats records — GPS tracks, boat-instrument (NMEA) data, sessions, races, dashboards and settings — is stored only on your device.
- Your location is used to record your sail and power racing calculations, and the app keeps recording in the background while a session is active.
- Data leaves your device only if you choose to use Fleet Cloud (creating or joining a shared race and uploading your track).
- We show no ads, and we do no tracking. This version of SailStats contains no analytics SDK and collects no usage statistics. We never sell your data or share it with data brokers.
- You can delete everything you have ever put in our cloud, from inside the app, at any time: Settings → Privacy & Data → Delete Account & Cloud Data.
- Signing in is optional. If you choose Sign in with Apple we receive an email address — a private relay alias if you hide yours — and nothing else. We never email you.
1. Data stored on your device
When you record a sail, SailStats stores the following locally, inside iOS’s protected app storage:
- GPS track points (latitude, longitude, timestamp, speed, course).
- Boat-instrument data received over NMEA 0183 from connected instruments (wind, boat speed, depth, heading, heel, water temperature and similar).
- Sessions, races, start-line data, dashboards, polar performance data and your app settings.
This data stays on your device. It is included in the backup file you can create via Settings → Backup & Restore → Export All Data, which you control and store wherever you choose. Deleting the app removes this data from your device.
2. Location data
SailStats uses your device’s location (via Apple’s Core Location) to:
- record your GPS track;
- calculate start-line distances, laylines and other racing and navigation values; and
- keep instrument data and recording running while your screen is locked.
To record reliably during multi-hour sails, the app requests “Always” location permission and continues to receive location updates in the background while a session, race timer or anchor watch is active. You can change or revoke this at any time in iOS Settings → Privacy & Security → Location Services → SailStats.
Your location is not transmitted off your device except through the optional Fleet Cloud feature described below.
3. Fleet Cloud (optional cloud sharing)
Fleet Cloud lets sailors share a race and compare tracks. It is optional — you only send data to our servers if you create or join a shared race and choose to upload your track.
Anonymous identity. The first time you use a cloud feature, the app creates an anonymous account with Google Firebase Authentication. This is a random identifier — it does not require or collect your name, email or phone number, and it is created only at that point: if you never create or join a shared race, no account is ever created and nothing is sent.
Optional sign-in (Sign in with Apple). You can, if you want to, link that anonymous account to your Apple ID in Settings → Account. It is entirely optional: the app — including Fleet Cloud — works fully without it, and it is never required to record, review or share a sail.
- What it is for. An anonymous account lives on one device. If that device is lost or replaced, there is no way to prove the cloud data was yours. Signing in attaches the account to you rather than the device.
- What we receive. An email address from
Apple, which will be an
@privaterelay.appleid.comforwarding alias if you choose to hide your real one, and your name, which Apple provides once at your first sign-in. The name is optional in every practical sense: it seeds a display name you can edit or clear in Settings → Account, it is only ever shown to people in races you share, and leaving it blank changes nothing. - What we do with it. The email is a login credential and an account label. We do not email you, there is no mailing list, and neither the email nor the name is shared with anyone or used for marketing.
- A private list of your races. So that a replacement device can rebuild your library, we keep a list against your account of which races it has shared or joined — race identifiers and join codes only, no track data. It is readable only by you, and it is deleted with your account.
- Signing out never deletes anything on your device.
What is uploaded when you use Fleet Cloud:
- Race details you enter (race name, start date and time, location label, series, division, host club, course marks and any sponsors).
- Your boat’s identity for that race: boat name, sail number and display colour.
- Your recorded GPS track and instrument data for that race, so other participants can view the shared replay. A privacy setting (“Track only”, “Track + SOG/COG” or “Full telemetry”) lets you indicate how much of your recorded data should be shared.
- Any course marks you suggest to a race.
- The anonymous account identifier that ties the above to your device.
- A private, account-only list of which races you have shared or joined (identifiers and join codes), so a replacement device can rebuild your library. No other user can read it.
This data is stored using Google Firebase (Cloud Firestore and Cloud Storage) and is visible to other participants of the same shared race via that race’s join code. We do not make it publicly searchable.
4. Apple HealthKit (Apple Watch)
If you use the Apple Watch app, SailStats starts a workout session during race countdowns so the timer stays live on your wrist. This writes a workout to Apple Health on your device. SailStats does not read your health data and does not transmit any health or workout data off your device — the workout session is used solely to keep the timer running.
5. Diagnostics and support
SailStats keeps an on-device diagnostics log (location fixes and background heartbeats) to help troubleshoot recording problems. This log is not collected automatically. It is only shared if you choose to export it (Settings → Diagnostics → Export Background Log) and send it to us for a support request. If you send us a diagnostics log or backup, we use it only to investigate your issue.
6. Third-party services
SailStats uses Google Firebase (Authentication, Cloud Firestore and Cloud Storage) to provide Fleet Cloud. When you use Fleet Cloud, the data described in Section 3 is processed and stored by Google on our behalf, governed by the Firebase Privacy and Security terms and the Google Privacy Policy.
This version of SailStats does not include Firebase Analytics, Crashlytics, Cloud Messaging, or any advertising or attribution SDK. If we ever add usage analytics it will be opt-in, it will never carry your location, tracks, boat name or race content, and this policy and our App Store privacy labels will be updated before any such data is collected.
7. What we do not do
- We do not display advertising.
- We do not track you across other apps or websites, and the app requests no advertising identifier.
- We do not run third-party analytics in this version, and any future analytics will be opt-in (Section 6).
- We do not sell your data or share it with data brokers.
8. Data retention and deletion
- On-device data is retained until you delete it in the app or delete the app itself.
- Fleet Cloud data: a race and its uploaded tracks stay in our cloud backend so participants can keep viewing the shared replay.
- Deleting your cloud data and account. In the app, go to Settings → Privacy & Data → Delete Account & Cloud Data. This deletes, from our servers: your boat’s entry and uploaded track in every race — whether you hosted it or joined it — any course marks you suggested, and the account itself, including any email address held against it.
- If you signed in with Apple, deletion also revokes SailStats’ access token with Apple, so the app stops appearing under your Apple ID’s sign-in list. You will be asked to sign in once more first — that is Apple and Firebase confirming it is really you before an account is destroyed.
- We delete your data, not other people’s. If a race you hosted has other boats in it, the race itself is handed to another participant rather than destroyed, so their tracks and their shared replay keep working. A race nobody else joined is deleted outright. Your own recordings on your device are not affected — they are yours and stay where they are. The action cannot be undone.
- One technical remnant survives: the six-character join code for a deleted race stays reserved so the code can never be handed out twice. It contains no personal data and no longer opens anything.
- If you can’t complete deletion in the app — for example you no longer have the device — contact us (Section 13) with your boat name and the race join code and we will remove it.
9. Children
SailStats is a boating tool intended for a general audience and is not directed at children under 13 (or the equivalent minimum age in your country). We do not knowingly collect data from children.
10. Your rights
Depending on where you live (including under the New Zealand Privacy Act 2020 and, for EU/UK users, the GDPR/UK GDPR), you may have the right to access, correct or delete personal data we hold, or to object to or restrict its processing. Because Fleet Cloud data is tied to an anonymous identifier and a boat name/sail number rather than your legal identity, please include those details so we can locate your data.
11. International data transfers
Fleet Cloud data is processed outside New Zealand. Where required, such transfers rely on appropriate safeguards.
- Race data and uploaded tracks (Cloud Firestore and Cloud Storage) are stored in the Google Cloud region australia-southeast1 (Sydney, Australia).
- Firebase Authentication — the account identifier, and the email address if you signed in with Apple — is processed by Google in the United States, which is how that service operates and is not region-configurable.
12. Security
Data in transit to and from Fleet Cloud is encrypted using standard transport security (HTTPS/TLS). Access to cloud data is restricted by security rules so a participant can only write their own race and track records. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
13. Contact
Questions or privacy requests — contact
Internet Marketing Solutions Limited, New Zealand:
contact@sailstats.com
14. Changes to this policy
We may update this policy as the app evolves. We will revise the “Last updated” date above and, for material changes, provide notice in the app or on our website.