Privacy policy
Last updated 7 September 2026
The short version
Your logbook never leaves your device. There is no account to create and no server of ours to sign in to. Nothing in the app reads your trips, hours, fuel, maintenance, crew or documents and sends them anywhere — there is nowhere for them to go.
Every network call the app makes
Worth being exact rather than sweeping. This is the complete list, and not one entry carries anything out of your logbook.
| Who is contacted | What is sent |
|---|---|
| RevenueCat, for your subscription | A purchase record and an anonymous identifier for the install. Nothing about your boat or your log. |
| Apple, for the purchase itself | StoreKit handles payment. We never see a card, a name or an Apple Account email. |
| Apple iCloud, only if you switch sync on | Your logbook, into your own private database. See below — we cannot read it. |
| NOAA, for tide predictions | A tide station number and a date range. The station list is bundled in the app, so your position is never sent — the nearest station is worked out on the device. |
| Apple Maps, when you search for a dock | The text you type into the search field, as any search box in any app does. No log, no vessel, no recorded position. |
| Apple Maps, for tiles on the trip map | The area you are looking at, when you open a finished trip ashore. Recording a passage draws on ruled paper and needs no tiles at all. |
Everything else in the app — recording a trip, the dual clock, reports, exports, reminders, search, the anchor watch — runs with the aerial down.
What the app stores, and where
Everything below is stored on your device, inside the app’s own container, protected by your device passcode and iOS file protection.
| What | Why it exists |
|---|---|
| Vessel details | The record a surveyor, broker or insurer asks for |
| Trips, crew aboard, conditions | The logbook |
| Position while a trip is under way | To draw the track and compute distance |
| Engine hour readings | To run maintenance intervals on hours as well as dates |
| Fuel fill-ups | Consumption figures |
| Maintenance, service records, parts and costs | The service history |
| Scanned documents and photographs | Registration, insurance, the survey |
| Crew names and phone numbers, if you add them | So a float plan and a crew list can name people |
| Marks — anchorages and places you save | So a spot worth remembering is still there next season |
| The anchor watch circle, while one is set | Where you dropped the hook, and how far the boat may swing |
| Downloaded tide tables | So the table still reads with no signal, once it has been fetched |
| App preferences | To keep the app set up the way you left it |
Location
Logline asks for location access only while you are using the app, and only when you ask for something that needs it. It is used to record where a trip went and how far it travelled. Automatic trip detection is armed by setting a home dock and by nothing else, so the app does not watch for departures from anyone who has not asked it to.
With the app’s background location mode, a passage keeps recording while your screen is off — this is the point of the feature, since a phone in a pocket is where most passages are logged. iOS shows its own indicator while this is happening.
The anchor watch is the second thing that reads your position: while one is set, the app checks whether the boat has left the circle you drew. That happens on the device and wakes nothing but the alarm.
Your position never leaves the device. Logline does not request “Always” location access, and it reads your position only while a trip is recording or an anchor watch is set. If you decline location access, the app works normally and trips are logged by hand.
Two screens do send something, and neither sends where you are. Searching for a dock sends the words you type to Apple, the way any search field does. Tide predictions are asked for by station number, chosen from a list bundled inside the app, so your coordinates are not part of the question. Both are in the table above.
Camera and photographs
The camera is used only to scan the boat’s papers into the on-device document wallet. Text recognition runs on the device, using Apple’s Vision framework. No image and no recognised text is uploaded.
Photographs you attach are selected through Apple’s system photo picker, which runs outside the app — Logline receives only the specific images you pick and never has access to your photo library.
iCloud sync — off unless you turn it on
Logline can back the same local database with your own iCloud account. It is off by default and switching it on or off never moves or deletes your records.
When it is on, your logbook syncs through Apple’s CloudKit into your personal private database. That data belongs to your Apple Account. The developer has no access to it and no ability to read it, and there is no server involved on our side. Apple’s own privacy policy governs iCloud.
Purchases
Logline requires a subscription. Purchases are handled by Apple through the App Store, and subscription status is managed for us by RevenueCat, which receives the purchase record and an anonymous identifier for the install so the app can tell whether a subscription is active. It never sees your payment details, your Apple Account email, or your name, and it is never given anything from your logbook.
Analytics, stated exactly
Nothing measures how you use the app. No screen you open, no button you press, no trip you log and no figure you enter is counted, timed or reported. There is no analytics SDK, no telemetry and no crash reporting in Logline.
One thing is nevertheless declared as analytics on the App Store privacy label, and it should be said here rather than left as a discrepancy for you to find: the subscription record RevenueCat already holds — the purchase, the anonymous install identifier — also appears on RevenueCat’s own dashboard as revenue figures. Apple counts that as analytics, so we declare it as analytics. It is the same data described under Purchases above, put to no additional use, and it contains nothing from your logbook.
What we do not do
- No accounts, no login, no email address collected
- No measurement of how the app is used, no telemetry, no crash reporting — see above for the one thing Apple’s label counts as analytics
- No advertising, no advertising identifier, and no tracking across apps or websites — the App Tracking Transparency prompt is not shown because there is nothing to ask about
- No data sold or disclosed to anyone
Deleting your data
Everything is on your device, so you control all of it.
- Settings → Erase everything removes the boat, every trip, every service record and every scanned file. It is immediate and cannot be undone. Back up first if you want a copy — the app offers a single-file export.
- Deleting the app removes its container and everything in it.
- If iCloud sync was on, turning it off stops syncing; removing the data from iCloud is done in iOS Settings → your name → iCloud → Manage Account Storage.
Children
Logline is not directed at children and collects no information from anyone, including children.
Contact
Questions about this policy: steadyhabit.support@gmail.com