Privacy Policy

Boat Create Strong

Effective date: 2026-10-04

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Boat Create Strong stores the project information you enter on your iPhone using SwiftData: craft names, types and dimensions, plans, build stages and time, material quantities and prices, suppliers, purchase status, build diary and test records, measurements, decisions, launch dates, text addresses, participants, equipment, rules and change history. Photos and PDF or image documents are stored as local files. Language, currency, unit and synchronization preferences are stored locally. A randomly generated installation secret is stored in the iOS Keychain and is not a user account. If you enable optional synchronization, project records and attachments are sent to our backend. The server stores a hash of the installation secret to separate installations. Requests to the API and this public website also expose connection information such as IP addresses, request times, paths and technical error information to the hosting infrastructure. We do not request an email address, password, geographic location or contacts.

How we use information

Local processing lets you plan, record and revisit boatbuilding work offline, calculate purchase totals, search your notes and review documents. Optional server processing synchronizes this installation and stores your records and attachments for the same installation. The installation secret authorizes access to those private records. A launch reminder is scheduled on your device when you request it and grant notification permission. Technical request and error information supports delivery, security and troubleshooting. The app does not provide engineering certification or navigation.

Service providers and sharing

The backend and public privacy page are hosted by Railway, which processes network requests and stores the service database and attachment files on a persistent Railway volume. Railway and its infrastructure providers may receive technical connection and operational information needed to host the service. The application includes no third-party advertising, analytics, social sign-in, email delivery or map SDKs. Apple system photo selection, camera, file selection, document preview, Keychain and local notifications operate as device platform features. If you export records using the system file interface, the destination you choose may receive the export. We do not sell personal project data or publish private projects. Disclosure may be required to meet applicable legal obligations.

Data retention

Local records remain until you delete them or remove the application; device backup behavior is controlled by iOS and your own backup settings. Server records remain until you delete them or request deletion of all data. Project deletion uses a timestamped tombstone to prevent older offline edits from restoring a deleted project; the tombstone may retain the prior project payload until all installation data is deleted. Attachments removed from a project are deleted from active server storage when no remaining project references them. Files uploaded before an interrupted project save may remain unreferenced until all installation data is deleted. This deployment does not configure scheduled application backups. Hosting operational logs and any infrastructure backup copies are governed by Railway and its infrastructure practices; we do not claim a fixed retention or immediate purge duration for those systems. Local attachment cache files, including files from cancelled edits or removed references, may remain until you choose Delete all data or remove the app.

Deleting your information

You can remove records and attachment references in the app. Delete all data in Settings removes local records and files and queues a request to delete this installation’s server project records and attachments. If the device is offline, server deletion remains pending and is retried when connectivity returns, even if ordinary synchronization is switched off. Until that request succeeds, server data remains stored. The installation secret is kept so the queued deletion can be authorized. Removing the app alone does not send a server deletion request. We cannot promise recovery or access on another device after the installation secret is lost. Deletion from active application storage does not necessarily remove independent device backups, exported copies or hosting infrastructure copies immediately.

Permissions and your choices

The app uses the system photo picker only for images you select; it does not scan your photo library. Camera access is requested when you choose to take a photo. Files are accessed when you select a document using the system file picker. Notification permission is requested when you enable a local reminder for 24 hours before a planned launch. You can withdraw camera and notification permission in iOS Settings. Denial leaves the other notebook functions usable; a launch plan remains saved without a reminder. The app does not request location, contacts or microphone permission. Optional server synchronization can be switched off in app Settings; switching it off stops future routine synchronization but does not by itself delete already stored server data.

Your privacy rights

You can view and edit your records, export project records as JSON, remove individual records or request deletion of all installation data through Settings. JSON exports contain attachment references, not the separate original binary files. Depending on where you live, you may have legal rights to access, correct, erase, restrict or object to processing, request portability, or complain to a data protection authority. Contact el.frida.chidlow@icloud.com with privacy questions or requests. This address is a public privacy contact, not an app account or email delivery feature. Please do not send your installation secret; we may need an appropriate way to verify a request without exposing other installations.

Security

The application uses HTTPS for deployed API requests, an automatically generated random secret held in the iOS Keychain, and server-side installation authorization for private project and attachment routes. The server stores a SHA-256 hash instead of the plaintext secret. SQLite transactions, timestamp-based conflict handling and atomic attachment writes help protect data integrity. Secrets and project contents are not intentionally written to application logs. Access depends on keeping the device and installation secret secure. No system is completely secure, and we do not claim end-to-end encryption, security certification or guaranteed recovery.

Children’s privacy

Boat Create Strong is a practical project notebook intended for adult DIY builders and people able to work responsibly with tools and watercraft. It is not directed to young children and is not a substitute for qualified safety supervision. We do not knowingly ask children for personal information. If you believe a child has supplied personal information through this service, contact el.frida.chidlow@icloud.com so the concern can be assessed.

Changes to this policy

We may update this policy when the application’s processing or hosting changes. The current policy will be published at this page with an updated effective date. Material changes should be reviewed before continuing optional synchronization. Privacy questions can be sent to el.frida.chidlow@icloud.com.