Privacy Policy for the Nautly app
In brief: Nautly is a logbook that runs on your iPhone. Your trips, your tracks, your photos and your crew records stay on your device, and we never get to see them — we operate no server, there is no account and no sign-in.
There are two things we would rather tell you here than bury further down. Nautly retrieves map and weather data from third-party services — in doing so, those services learn which part of the chart or which sea area you are currently looking at (section 7). And if you have an iPhone backup switched on, your logbook is part of that backup — so it sits with Apple, not with us (section 9).
1. Who is responsible
Controller within the meaning of the Swiss Data Protection Act (FADP) and the EU General Data Protection Regulation (GDPR):
Marcel Fischer Bahnhofplatz 2 4133 Pratteln Switzerland Email: support@nautly.ch
Nautly is published by a private individual, not by a company.
The Swiss Federal Act on Data Protection (FADP, SR 235.1) has applied in its revised version since 1 September 2023. German, French and Italian are the authoritative languages of Swiss legislation; where we refer to Swiss provisions in this English text, the German wording prevails.
2. The principle: Nautly works on your device
Nautly is built as an offline app. That is not a privacy phrase, it is how the app is made: at sea there is no network, so a logbook has to work without one.
For your data this means:
- Everything you enter or record is stored in a database on your iPhone.
- We operate no server of our own to which Nautly transmits your data. There is no user account, no sign-in, no password.
- We have no access to your trips, your positions, your photos or your crew records.
- Nautly contains no advertising, no tracking and no third-party analytics, crash-reporting or advertising libraries. There is not a single third-party software package inside the app — so there is nothing that could pass data to anyone in the background.
Even so, data does leave your device in certain situations. We list them here in full rather than scattering them through the text:
| When | What is transmitted | Described in |
|---|---|---|
| Sea marks on the chart | The section you are viewing, IP address | 7.1 |
| Weather request (happens automatically) | Rounded coordinates, IP address; the recipient is Apple | 7.2, 7.6 |
| Currency converter | Rate request without location data; position sent to Apple | 7.3, 7.6 |
| Downloading a sea area | Map section, IP address | 7.4 |
| Satellite display | Coordinates, IP address | 7.5 |
| Map, place names, port search | Section, position, search text | 7.6 |
| You tap “More on Windy.com” | Rounded coordinates, IP address; the recipient is Windyty, SE in the Czech Republic | 7.8 |
| You export or share something | Whatever the document contains | 6 |
| iPhone backup | Your entire data set | 9 |
The first two rows matter most, because they happen without any action on your part. The sea-mark layer is switched on by default and loads as soon as you look at a chart (section 7.1). And as soon as you open the chart or a weather tile, Nautly requests the weather for your current position on its own and repeats that roughly every ten minutes — a repetition that is not tied to the chart being visible on screen (section 7.2). Both can be influenced; how, is explained in the sections named.
3. What Nautly stores on your device
| Category | What that means in practice |
|---|---|
| Trip details | Trip name, boat name, port of departure and destination, times |
| Position data | Recorded GPS track with timestamps (section 4) |
| Log entries | Events, notes, courses, weather observations, engine hours — together with the position at which an entry was made |
| Photos | Images you select, together with the time they were taken (section 5) |
| Crew records | Contact, identity-document and licence details of your crew, roles, nautical miles (section 8) |
| Signatures | Your finger-drawn signature under a completed log day |
| Boat and maintenance data | Tank levels, maintenance entries, equipment lists |
| Settings | Your preferences within the app |
Where the data comes from: exclusively from you — through what you enter, the photos you select and the recording you start.
4. Position data and recording in the background
This is the most important section. Nautly records where you are — and during a trip it carries on doing so even when the app is not on screen.
4.1 What is recorded
When you start a recording, Nautly continuously stores your position (latitude and longitude), the time of the measurement and technical values alongside it, such as speed, course and the accuracy reported by the GPS receiver. Together these form your trip track.
That is a movement profile. Such a track shows not only where you were, but also when, for how long and in what order. A long track can contain many thousands of points — on a trip lasting several days, figures in the order of 26 000 measured points are realistic. We write this down explicitly, because it is the core of what Nautly does.
4.2 When recording happens — and when it does not
- Recording runs when you start it — at the beginning of a trip, or when you switch on the anchor watch.
- It continues in the background, even if you close the app or lock the screen. That is the point of it: a logbook that stops writing the moment you look out at the water would be worthless. iOS shows you in the status bar that location services are active.
- It does not run when no trip and no anchor watch are active. The receiver is switched off in that case.
- You can stop location access entirely at any time, in the iOS settings under Privacy & Security → Location Services → Nautly. Without location access, track recording, the anchor watch and the man-overboard function no longer work.
4.3 Where your position data goes
Your trip track is not transmitted to us and not to any third party. It stays in the database on your device until you delete it or export it yourself.
Individual positions still leave your device — not the track, but the point where you currently are. This happens with the weather request (section 7.2 — it runs on its own as soon as the chart or a weather tile is open), with Apple's resolution of place names and countries (sections 7.6 and 7.3), and with the satellite display (section 7.5 — only if you have set it up). In addition there is the “More on Windy.com” link on the weather tile: a position goes out there only once you tap it — and it goes through your browser, not through the app (section 7.8). What is transmitted are coordinates; your name and an account are not part of it. What an individual service receives beyond that is stated for each of them in section 7.
These coordinates are rounded before they go out — to two decimal places, a grid of roughly 1.1 kilometres. That applies to the weather request, to the place name shown with it, to determining the country you are in for the currency converter, and to the satellite display. Two things are exempt from it, and we write them down rather than saying “we round everything”: on your device the position is stored unrounded (section 4.5 — the place-name list there is the one exception, it is rounded to about a hundred metres), and the place names for a trip’s timeline are requested from Apple unrounded. The link to Windy.com sits alongside this: the position in its address is rounded as well, but to a different degree depending on your app version (section 7.8).
4.4 Precise or approximate location
iOS lets you choose whether an app receives your precise or only your approximate location (the “Precise Location” setting). Nautly needs the precise location: an anchor watch that is meant to react to a few metres of drift, and a log track that is meant to serve as a record, are not possible with a position rounded to several kilometres. If you switch “Precise Location” off, these functions will not work properly. That does not contradict the rounding described in section 4.3: Nautly works precisely on your device — what leaves it is rounded.
4.5 Further places where a position is stored
Besides the trip track, Nautly stores individual positions in several places. Listed here are the ones that do not belong to a single trip. What happens to them when you delete something differs from point to point — which is why it is stated with each of them, rather than in one sentence covering all. For as long as they exist, they stay on your device:
- Your boat’s home port. It belongs to the boat, not to a voyage, and therefore remains stored even if you delete every trip.
- The anchor position you have set, and an active waypoint. Nautly remembers where you anchored and which destination you set, so that the anchor watch and the waypoint guidance survive a restart of the app. These are single points in the present, not a recording — the next anchor position and the next waypoint overwrite them. A waypoint you have reached does not clear itself, though: it stays stored until you set a new destination or remove it.
- The position of a man-overboard alarm. If you raise the alarm, Nautly stores the position and the time so that the alarm survives a restart of the app; that entry is removed again when you end the alarm. One point does remain, however: the alarm additionally sets a waypoint at that position, named after the time of the incident — and that waypoint stays until you set a new destination or delete it. It may be information about another person on board rather than about you (section 8).
- The file of a man-overboard incident. An alarm you have raised also creates an incident file of its own — the most detailed set of positions outside your trip track. In it, Nautly records position, speed and course every minute, together with the time, a title and your note on the incident, for up to 2000 entries — that is more than 33 hours of continuous tracking. The file is kept independently of the logbook: it is created even when no trip is running, and it remains when you delete the trip on which the incident happened. You can delete it per incident: swipe the entry to the left under More → Safety → MOB incidents — the row appears there only once at least one incident exists.
- Downloaded map sections for the offline chart. These are map images, not positions of yours — but which sea areas you have downloaded does say something about what you have been interested in. For deletion, see section 10.6. They are the only data set Nautly explicitly excludes from the iPhone backup — because they are large and can be downloaded again at any time, not for a data-protection reason.
- The stored data of the satellite display. It contains the coordinates of the most recent request (section 7.5). This file is created even if you have never set the display up — the display is switched on by default, and the file is written even when, without an access key, no pass can be retrieved at all. After 10 days the data counts as out of date and is no longer used; that does not delete it. It stays until a new request overwrites it or you delete the app.
- The location of your most recent weather request. Nautly keeps the last weather report it retrieved, together with the coordinates it applied to, so that something can be shown immediately after a restart. This entry arises without any action on your part — the weather request runs on its own as soon as the chart or a weather tile is open (section 7.2). The position is stored exactly as your device reports it; only the request that goes out is rounded (section 4.3). This entry disappears when you delete your last trip — for as long as one trip is left, it stays.
- A list of the place names Nautly has resolved for you. So that a trip’s timeline does not have to ask Apple again every time you open it, Nautly remembers the place name and the date of resolution for each position already resolved. The positions are rounded to about a hundred metres for this — the request to Apple is not, it carries the position exactly as your device reports it (section 4.3). This list grows with use and has neither an upper limit nor an expiry date. It is cleared, however, as soon as you delete a trip — with every trip deletion, not only the last.
Because deletion looks different from point to point here, it is set out once more, together: the list of resolved place names is cleared with every trip deletion. The location of your most recent weather request disappears when you delete your last trip. The file of a man-overboard incident you delete per incident, in the incident list. Your boat’s home port, the anchor position you have set, a waypoint, the data of the satellite display and the downloaded map sections, by contrast, belong to no trip — they therefore do not disappear with one, and they stay until something overwrites them or you delete the app from your device (section 10.6). And an older iPhone backup can bring all of it back (section 9a-1).
Positions that belong to a trip are not in this list — the position of an individual log entry, the capture location of a photo (section 5) and the location of a stored weather observation. They are part of the trip and disappear with it (section 10.2).
4.6 Why we are allowed to do this
- Switzerland: the processing rests on the fact that you start the recording yourself and that it serves the function you have asked for. For private processing, the FADP does not require consent; it requires compliance with the processing principles and information about the processing (Art. 6 and Art. 19 FADP).
- EU: the recording is the app’s main function and is therefore necessary for the performance of the use relationship — Art. 6(1)(b) GDPR. In addition, the recording rests on your deliberate grant of location permission.
5. Photos
When you add photos to a trip, Nautly asks for access to your photo library. You choose the images yourself; Nautly does not search your library on its own.
Nautly creates a reduced-size copy of the image (longest edge no more than 2048 pixels) — it does not merely keep a reference into your library. The copy therefore remains even if you delete the original in your library.
When importing, Nautly reads the capture time from the original image data and, where present, the capture location. The time places the photo at the right point in the trip timeline; the location places it on the chart.
A photo can therefore reveal a place that your trip track does not contain — your berth, for example, or your home address if you took a picture before casting off. We write this down because it is the point at which people least expect it.
Important for what you pass on — and here the separation is clean:
- The stored image copy itself no longer contains capture data. When the image is reduced, time and location are removed from the image file. Anyone who receives the copy does not receive a location with it.
- Nautly keeps time and location separately in its own database, so that the photo can appear on the chart. These details stay on your device.
- Only the image and the date go into PDF exports, never coordinates.
Nautly also remembers the identifier of the original in your library, so as not to import the same photo twice and to offer you the option of deleting the original. iOS asks you separately about that deletion.
Your photos stay on your device. They are not transmitted to us or to any third party — unless you export or share them yourself (section 6).
6. When you export or share something
Nautly can create documents from your data: a trip log as a PDF, a daily log, a safety briefing, packing lists, a crew record, a skipper record, a CSV file of all trips, and your trip data for passing on.
What happens to such a document afterwards is entirely up to you. Nautly hands it to the iOS share sheet; you decide whether it goes into an email, a message, a cloud storage service or to a printer. From that moment on, the terms of the service you have chosen apply, and we have no influence over it.
Two things you should be aware of:
- A trip log, a crew record and the PDF of a safety briefing contain the names of the people on board — and in the case of the briefing, everything you have written in their remarks field. If you pass such a document on, you are also passing on those people’s data. Please read section 8 in this connection.
- An exported track contains your positions with timestamps. Whoever receives the file can work out where you were and when.
7. Third-party services used by Nautly
Nautly contacts four third-party services (7.1, 7.3, 7.4 and 7.5); in addition there is Apple — for the weather (7.2), for the map, place names and port search (7.6) and for purchases (7.7). None of the four third-party services receives your name, an account or an identifier of your device — they receive what is needed for the request, plus your IP address. An IP address is technically unavoidable: without it, no service can reply to you. One item in this section, by contrast, is not a service Nautly calls: the link to Windy.com (7.8) opens only when you tap it, and then in your browser — the app itself makes no connection there.
7.1 Sea marks on the chart (OpenSeaMap) — switched on by default
Nautly places a layer of nautical sea marks over the base chart. These tiles are loaded live from OpenSeaMap as soon as you look at a chart — and this switch is set to “on” by default.
What is transmitted is which section of the chart you are viewing (tile coordinates and zoom level) together with your IP address. No key, no identifier, no account.
Why we spell this out so plainly: it is one of two transmissions that take place without any action on your part — you do not have to tap anything, simply looking at the chart is enough. The second is the weather request (section 7.2). Anyone reading along with the sea marks could tell roughly which sea area you are interested in. You can switch the sea-mark layer off in the chart view; the request then no longer takes place.
7.2 Weather data (Apple’s WeatherKit)
For the weather display, Nautly obtains the data from Apple — through WeatherKit, the operating system’s weather service. We run no server of our own for it, and no further provider is involved.
What is transmitted is your position, rounded to two decimal places — a grid of roughly 1.1 kilometres (section 4.3) — together with the technical connection details of your device, in particular your IP address. We do not pass on a name, an account or anything about your trip. Nautly does not assemble this request itself: the app hands the rounded position to an interface of iOS — what else goes with it technically is for Apple to determine, not for us.
The same position goes to Apple a second time in the process — to the place-name service, so that Nautly can show you a place instead of two numbers (section 7.6). That request, too, carries the rounded position.
Apple is therefore the recipient of your weather requests and processes them under its own privacy policy. Where that happens is for Apple to determine — we cannot name the country of processing for you. And we do not name a retention period either: we do not know how long Apple keeps such a request. We would rather write that down than give you a figure we have no evidence for.
When this request happens — and here we have to be more precise than the section title suggests: Nautly does not only ask for the weather when you tap for it. As soon as you open the chart or a weather tile, the app requests the weather for your current position and repeats that roughly every ten minutes; it also requests again if you have moved more than around five kilometres. On a longer trip, this produces many individual position reports to the same recipient — more than a single location request.
This repetition is not tied, in the app, to the chart being visible on screen. Nautly keeps recording in the background during a trip, and the weather request is not switched separately from that. We therefore do not assure you that these requests stop once you take the app off screen or lock the display — whether and for how long iOS lets an app keep running in the background is decided by the operating system, not by us.
Without a network connection, no weather request takes place. If you want to prevent these requests, it is not enough to simply not use the weather display. The request requires Nautly to know your position: if you withdraw location access from Nautly (section 10.8), the app no longer receives a position — but then track recording, the anchor watch and man overboard also stop working (section 4.2). Every request is reliably stopped if you close Nautly entirely.
7.3 Currency rates (Frankfurter)
To convert amounts of money, Nautly retrieves current exchange rates from the Frankfurter service (api.frankfurter.dev). What is transmitted is only the request for the current rate table, together with your IP address. This service does not learn which currencies you are converting or which amounts you enter, and no location data goes to it.
The currency converter as a whole is not location-independent, though, and we write that down here: so that it can determine the currency of the country you are in, Nautly sends your position to Apple — rounded, as described in section 4.3 (section 7.6). This information goes to Apple, not to Frankfurter. Without location access it is not sent; Nautly still retrieves the rates in that case.
7.4 Downloading the offline chart (Geoapify)
If you download a sea area for offline use, Nautly obtains the map tiles from Geoapify (based on OpenStreetMap data).
This happens only when you start the download yourself. The downloaded base chart does not reload anything afterwards: it shows what is already on your device. The sea-mark layer from section 7.1 is not part of that — it continues to load live even in offline mode, as long as you have not switched it off. If you really want to send nothing while under way, switch off the sea marks as well.
What is transmitted is the map section, your IP address and an access key that identifies the app as a whole — not you. No cookies are set and nothing recognisable is stored.
7.5 Satellite and sky data (N2YO)
In the delivered state, nothing leaves your device here. Nautly calculates the sun, the moon, twilight and the planets entirely on your device — even without a network.
The display of International Space Station passes is the only astronomy function that goes online, and it does so only once you have entered a free access key from n2yo.com yourself (Settings → “Astro & ISS”). No key ships with the app. As long as you do not enter one, not a single item of data leaves your device for this function.
If you have entered a key, your current location — rounded to two decimal places, so accurate to roughly 1.1 kilometres (section 4.3) — is transmitted to the service N2YO in the United States with every request; it is needed to calculate when the station is visible from your position. Your key is sent along with it. No further details about your person, your device or your trip are transmitted. The result is stored on your device and used for 10 days so that a new request is not made every time you open the view; this file contains the coordinates of the most recent request, and after those 10 days it is not deleted — only no longer used (section 4.5).
This is a transfer to the United States. It takes place only if you deliberately set this function up. It is one of two places where we can name the recipient country with certainty — the other is the link to Windy.com (section 7.8). Where Apple processes the requests from sections 7.2 and 7.6, by contrast, is for Apple to determine.
7.6 Map, place names and port search (Apple)
The base chart in Nautly is displayed using Apple’s map services. When loading map material, Apple processes the details technically required for that purpose under its own privacy policy.
Apple receives more than just the map section, and we spell that out here explicitly:
- Place names for a position. So that Nautly can show you a place instead of two numbers, it passes the relevant position to Apple’s place-name service. This happens, among other things, with every weather request (section 7.2) — that is, even when only the chart is open and you have not tapped anything.
- Your country of stay in the currency converter. There too, your position is passed to Apple to determine the country and its currency from it (section 7.3).
- What you type in the port search. What you type there goes to Apple as a search query, together with the area you are searching in. Nautly makes two requests here: your text unchanged, and the same text with the word “marina” appended.
Apple is an independent company and therefore a recipient of this information, not part of Nautly. Apple processes it under its own privacy policy. We receive nothing from this and store no result ourselves.
Your weather requests also go to Apple — they are described in section 7.2, because they happen on their own and therefore deserve an explanation of their own.
7.7 Purchases (Apple)
If you buy something in Nautly, the purchase is handled entirely by Apple. Your payment details go to Apple, not to us; we never see them. From Apple we receive only aggregated sales reports with no connection to individual people. Apple’s privacy policy applies to the payment process.
7.8 The link to Windy.com — only if you tap it
The weather tile carries a link labelled “More on Windy.com”. It leads to a weather chart run by Windyty, SE, Strakonická 3363/2d, 150 00 Prague 5, Czech Republic.
Nautly never calls windy.com itself. The app only assembles the address and places it behind the link. Your browser opens the page only once you tap it — and from that moment on you are their guest and no longer in Nautly.
The address carries your position as coordinates, so that the chart opens on your sea area straight away. It is rounded — depending on your app version, to roughly a hundred metres or to roughly a kilometre. We give you a range here rather than a single figure, because older versions of the app hand over a more precise position than the newer ones. It is not the same rounding as for the weather request (section 4.3).
Because it is your browser that loads the page, the provider also learns your IP address and whatever your browser sends of its own accord. This information therefore goes to the Czech Republic — a country the Swiss Federal Council certifies as providing adequate data protection (Annex 1 no. 37 of the Data Protection Ordinance). Windyty, SE is an independent company and processes this information under its own privacy policy. We receive nothing from this, and we do not learn whether you used the link at all. We do not name a retention period either: we do not know how long the provider keeps such a visit.
If you would rather that did not happen, do not tap the link. That is the whole measure — there is nothing to switch off, because without your tap nothing goes out.
8. Information about other people — your crew
This is the section in which we explicitly place responsibility on you.
Nautly allows you to keep records about other people — and considerably more than just their names. A crew record can hold:
| Group | Fields |
|---|---|
| Person | Name, date of birth, photo |
| Address | Street address, postcode, town, country |
| Contact | Telephone numbers, email addresses, link to your iOS contacts |
| Identity document | Document number, issuing country, expiry date |
| Qualification | Licence and certificate details |
| On board | Role, nautical miles logged, ports |
From this, Nautly can produce a crew record document.
Please consider, for each of these fields, whether you really need it. Another person’s identity document number and date of birth are not a trifle: they are not sensitive personal data in the sense of the law, but they identify a human being very precisely. A field you leave empty is one you will later have neither to protect nor to delete.
How this data is handled:
- It sits on your device, like all other data. We do not receive it.
- It leaves your device only if you export or share a document (section 6).
What this means for you:
If you use Nautly purely privately — a family trip, friends, your own boat — your processing counts as a personal matter, and data protection law largely exempts you from its requirements (Art. 2(2)(c) GDPR, Art. 2(2)(a) FADP).
But as soon as you use Nautly professionally or commercially — as a charter skipper, a boating school, a training centre — you are the controller for your crew’s data, not us. In that case:
- Tell your crew that you keep these records and what for.
- Do not collect more than you need.
- As a rule, hand a crew record only to the person it concerns.
- Delete the records once you no longer need them.
We provide the tool. What you write into it, and who you pass it to, is your decision and your responsibility.
How to get rid of crew data — and what stays behind — is set out in section 10.4. Please read it before relying on a deleted crew record taking everything with it. It does not.
8.1 The safety briefing — and its remarks field
The safety briefing records who was briefed, when, and on what. To do so it stores: the name of the person conducting it, the place, the time, a list of participants’ names, the status of the 24 briefing points — and a free-text remarks field.
Nautly does not ask for health information anywhere. There is no field for allergies, medication, swimming ability, emergency contacts or anything similar, and the 24 briefing points relate without exception to equipment and procedures on board — the ship’s medical kit, not any person’s state of health.
But the remarks field is free text, and we have to point that out:
What you write under “Further remarks” is up to you. If you enter information about a person’s health there — “allergic to penicillin”, “cannot swim” — then that is sensitive personal data. Stricter rules apply to it than to a name.
What that means in practice:
- Privately, on board with your family and friends: there is nothing wrong with noting an allergy — in an emergency that is exactly the detail that counts. Tell the person that you are doing it.
- Professionally — charter skipper, boating school, training centre: then you are responsible for it, and the requirements rise considerably. Under EU law, processing such data is prohibited in principle and permitted only under narrow conditions (Art. 9(1) and (2) GDPR) — which as a rule comes down to the explicit consent of the person concerned. Under Swiss law, where consent is required for sensitive personal data, it must be explicit (Art. 6(7)(a) FADP).
- And bear the export in mind: the briefing can be shared as a PDF, and that PDF contains the participants’ names and your remarks field. A health detail that ends up in a crew group chat cannot be called back.
Our part in this: we do not collect this data, we do not ask for it, we do not evaluate it and we never see it. We provide a notes field — and tell you what can come of it.
9. Data security and iCloud
9a — Where your data is held
Your data is held in the app’s protected storage area on your iPhone. It is protected by the security mechanisms of iOS — in particular by device encryption, which is active as long as you have set a device passcode. Other apps cannot access this area.
Nautly does not synchronise your data with iCloud. There is no synchronisation you could switch on, and none running in the background.
This has a consequence you should be aware of: if you delete the app, your trips are gone, unless you have exported or backed them up beforehand.
9a-1 — Your iPhone backup: here your data does sit with Apple
This is the point at which the sentence “everything stays on your device” ends, and we therefore say so explicitly.
Nautly’s database and your photo copies are not excluded from the backup. If you have switched on a backup of your iPhone in the iOS settings — whether to iCloud or to a computer — then your trips, your position tracks, your log entries, your crew records, your photos and the other stored positions listed in section 4.5 are part of that backup — as is the rest of the app’s data. With an iCloud backup they therefore sit on Apple’s servers.
Two things about this, and they belong together:
- This is intended and in your interest. It is how you keep your logbook when you change devices. If Nautly were excluded from the backup, a new iPhone would mean losing every trip.
- It is nonetheless a transfer you should know about. Apple’s terms apply to the backup, not ours. We have no access to it and see nothing of it. Whether and how you back up is decided by you in the iOS settings — not in Nautly.
Expressly excluded from the backup are only the downloaded map sections. There is no data-protection reason for that: they are large, and they can be downloaded again at any time. Also outside the backup are the working copies of your exports (section 10.7a) — that follows from where they are stored, not from a decision on our part.
10. How long data is kept — and how you delete it
10.1 The principle
We retain nothing, because we receive nothing. Your data sits on your iPhone; how long it stays there is up to you. Nautly deletes nothing on its own, and there is no period after which anything disappears by itself.
| What | How long |
|---|---|
| Trips, tracks, photos, crew records | Until you delete them |
| Exported documents | Outside Nautly, under your own rules |
| Working copies of your exports | Until you delete the app (10.7a) |
| Weather requests to Apple | For Apple to determine; no period is known to us (7.2) |
| Your visit to windy.com | For Windyty, SE to determine; no period is known to us (7.8) |
| Technical recovery files | See section 10.7 |
Emails to support@nautly.ch | 12 months after the last contact |
10.2 Deleting a trip
In the logbook, swipe the trip row to the left, tap “Delete” and confirm the prompt.
Deletion is immediate and final. There is no recycle bin and no way to restore.
Your recorded track disappears with the trip. It is not kept separately; it is part of the trip itself — if the trip is gone, the track is gone. The positions of that trip’s log entries and the capture locations of its photos disappear as well.
Also removed with the trip are its log entries, its photos including the image files on the device, the crew assignments, the day plans, the boat checks and that trip’s nautical-mile records.
What remains — please read this before relying on it:
- Your boat’s home port remains. It belongs to the boat, not to the voyage.
- That trip’s safety briefing is retained, including the participants’ names. It merely loses its link to the trip and then appears as a document in its own right in the list — where you can delete it individually (section 10.5).
- The file of a man-overboard incident remains. It belongs to the incident, not to the trip — you can delete it per incident in the incident list (section 4.5).
- The total nautical miles of your crew members do not go down. A person’s personal tally still includes the miles from the deleted trip.
10.3 Deleting a photo
Press and hold a photo and choose “Remove from trip” — or use “Select”, mark several and remove them together.
Nautly deletes its own copy completely: the record with the caption and capture time and the image file on the device. The original in your iOS photo library is left untouched — Nautly does not touch your library when removing a photo.
Please do not confuse this: the “To delete” area in the Photos tab is not a recycle bin for Nautly’s photos. It is a shortlist of images from your iOS photo library that you marked for later deletion while reviewing them. Nautly stores only the identifiers of those images in it, not the images themselves. This list does not empty itself — it stays until you work through it.
10.4 Deleting a crew member
Swipe in the crew list, or open the details and choose “Edit” and “Delete crew member”.
What disappears completely and irrevocably: street address, postcode, town and country · telephone numbers · email addresses · date of birth · identity document number, issuing country and expiry date · licence and certificate details · the stored photo · the link to your iOS contact. The entire personal record is gone afterwards.
What remains: in the trips the person was on board for, their name, their role on board, the nautical miles logged there and the ports remain stored. Their name also remains in any safety briefing they took part in.
Why that is so: a logbook records what happened. If deleting a contact record retroactively rewrote the trips, the record would be worthless — and the person concerned would at the same time lose the evidence of their own nautical miles, which they need for their sea time.
If you also want the name removed, you have to delete the trips in which the person is listed (section 10.2). There is no other way to do it today.
Important if you use Nautly professionally: in that case you are responsible for your crew’s data (section 8). If a crew member asks for their data to be deleted, deleting the crew record is not enough on its own — you also have to delete the trips concerned.
10.5 Deleting a safety briefing
Under More → Safety → Safety Briefing you will find all briefings — including those whose trip you have deleted. Swipe the row to the left and confirm: the briefing is then irrevocably gone, including participants’ names and the remarks field.
This is the more direct route if all you want is to remove the names from a briefing — it does not cost you the whole trip.
10.6 Deleting everything
There is currently no way in the app to delete all data at once. You delete individually — trip by trip, photo by photo, crew record by crew record.
Several data sets cannot be deleted individually in the app at all:
- The downloaded map sections of the offline chart. There is no delete function for them today. They are map images, not positions of yours — but which sea areas you have downloaded does say something about what you have been interested in. They are excluded from the iOS backup and disappear together with the app.
- The anchor position you have set, and an active waypoint. Both are overwritten by the next anchor position or the next destination; there is no separate delete button.
- The working copies of your exports. See section 10.7a.
For three sets of data there is a route, and we name it because you would not expect it (section 4.5): the list of resolved place names is cleared with every trip deletion. The location of your most recent weather request disappears as soon as you delete your last trip. And the file of a man-overboard incident you delete per incident, by swiping it to the left under More → Safety → MOB incidents.
The complete route is to delete the app. Since Nautly does not synchronise your data with iCloud, it sits without exception in the app’s protected storage area on your device. If you delete Nautly from your iPhone, iOS removes that area entirely — including the database, the image files, the map sections and the technical recovery files described in section 10.7.
Two things that this does not cover:
- Documents you have already exported or shared. They sit wherever you sent them; Nautly can no longer reach them.
- A device backup. If you have an iCloud or computer backup of your iPhone switched on, it contains a copy of Nautly’s data (section 9a-1). Deleting the app does not remove that copy. A backup is your safeguard, not ours — you can only delete it where it sits: in the iOS settings or on your computer.
A “delete all data” function within the app is planned but not yet built. We write that down rather than keeping quiet about it.
10.7 Short-lived technical files
While a recording is in progress, Nautly creates three technical files outside the database — a crash safety net, a journal with one line per track point, and offloaded sections of your track. They contain position data and serve solely to make sure a crash does not cost you your recording.
If you end a trip normally, they are removed in the process. The case in which something is left behind is a narrow one: you delete a trip while it is still being recorded. The files then do not disappear with it immediately — the track sections are overwritten when the next recording starts, and the crash safety net and its journal within one day of the last entry.
In both cases: these files remain in the app’s protected storage area on your device and are never retrieved by us at any point. They are gone once the app is deleted.
One further file sits here but does not belong in this category: the stored data of the satellite display (section 7.5) contains the coordinates of the most recent request. It is not short-lived — after 10 days the data is no longer used, but it is not deleted (section 4.5).
Like the rest of the data, these files form part of an iPhone backup if you have one switched on (section 9a-1).
10.7a Working copies of your exports
When Nautly creates a document for you — a logbook PDF, a trip export, a packing list, a skipper record — it first places the file in the app’s working area and hands it from there to the iOS share sheet. This working copy is then left behind: Nautly does not delete it by itself today, and there is no way in the app to remove it individually. It contains the same content as the document you shared — depending on the document, that also means the names of your crew and your positions.
These working copies sit in the app’s protected storage area and are never retrieved by us at any point. They are not part of an iPhone backup. They are gone once you delete the app (section 10.6). Whether and when iOS clears this area on its own is up to the system; you should not rely on it.
The fact that these copies are left behind is not intended behaviour, but an open construction site. We write it down rather than keeping quiet about it.
10.8 Withdrawing permissions
You can withdraw the permissions for location, photo library and notifications at any time in the iOS settings; section 12 explains which there are and what they are for. Withdrawing a permission stops future collection — data already stored is deleted using the routes described in this section.
11. Your rights
Depending on the law that applies to you, you have the right to information about and access to your data, to rectification, to erasure or destruction, to restriction of processing, to receive your data, and to object.
For your data inside Nautly you exercise these rights directly in the app: you can see all of your data there, and you can change it, export it and delete it. You do not need us for that — and we could not help you with it either, because we do not hold your data.
If you write to us, we process the data contained in your message; that is what your rights in relation to us apply to.
References: access Art. 25 FADP / Art. 15 GDPR · rectification Art. 32(1) FADP / Art. 16 GDPR · erasure and destruction Art. 32(2)(c) FADP / Art. 17 GDPR · restriction Art. 18 GDPR · data portability Art. 28 FADP / Art. 20 GDPR · objection Art. 21 GDPR.
Supervisory authorities. In Switzerland you can report a matter to the Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch (Art. 49(1) FADP). In the EU you may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). In the United Kingdom, the Information Commissioner’s Office (ICO) is the competent authority, ico.org.uk.
Switzerland is a third country in relation to the EU and the United Kingdom. Both the European Commission and the United Kingdom recognise Switzerland as providing an adequate level of data protection, so no additional safeguards are required for the fact that the controller is established in Switzerland.
12. Permissions Nautly asks for
| Permission | What for |
|---|---|
| Location services | Track recording, anchor watch, man overboard |
| Background location | Continuing to record while the screen is locked |
| Photo library | Importing images you select |
| Notifications | Anchor watch alarm, safety notices, reminders, and questions about your voyage |
| Motion data | Clinometer — showing the boat’s heel angle |
You can withdraw each of these permissions at any time in the iOS settings. The functions that depend on them will then no longer be available.
On motion data in detail: Nautly uses the motion sensor solely for the clinometer and only while that view is open. The measured heel values are neither stored nor transmitted — they exist only while you are looking at them. Nautly does not use a step counter or an altimeter, and no motion data is collected in the background.
On notifications in detail: Nautly sends five kinds of notification — the anchor watch and man-overboard alarm, the low-battery warning, due maintenance reminders, a crew member’s birthday (their name appears in the notification), and the question about your propulsion. All of these are created on your device. Nautly does not use a push service, does not register your device with any server, and transmits nothing in order to send a notification.
The question about your propulsion only appears while a recording is running, and it rests between sunset and sunrise. In regions where the sun does not set or does not rise for weeks there is no such quiet period — there the question may also arrive at night. It arises because the app notices, from your running recording, that a voyage has begun or has come to an end. The notification itself contains no position, no time and no distance — only the question and the possible answers. You can answer directly in the notification, without opening the app. If you do not allow notifications, nothing is lost: the question then waits for you the next time you open the app.
Whether a notification shows its text while your screen is locked is up to you, under Settings → Notifications → Show Previews in iOS.
Nautly does not read your address book. If you want to create a crew member from your contacts, iOS opens its own picker. Nautly receives only the one contact you tap — never your address book — and no permission is created for it that you would later have to withdraw. What is taken over is first name, surname, telephone numbers, email addresses, postal address and birthday, and only into fields that are still empty. A later change in your address book does not find its way into Nautly by itself.
13. Children
Nautly is not directed at children and does not knowingly collect data from children. If, as a skipper, you keep records about crew members who are minors, section 8 applies — and with particular care.
14. Changes
We update this policy when the way data is processed changes. The version published here at the time applies.
Last updated: 19 September 2026
This English version is a translation of the German original. In the event of any discrepancy, the German version published at https://nautly.ch/app/datenschutz.html prevails.
15. Contact
Questions about data protection: support@nautly.ch