Privacy Policy
Last updated 2026-09-18
Overview
MARLOG is a maritime discovery, learning and reference app for coastal mariners. We respect your privacy and collect only what the app needs to work. This page explains what we collect, why, and what control you have.
This website
Everything below describes the MARLOG app. The website at marlog.app is a static site with no server logic of its own, and it behaves differently. The contact form opens a message in your own mail app, pre-filled with what you typed, which you then choose to send or discard — so nothing reaches us unless you send it yourself. The updates-list field is different: when you submit your email there, it is stored in our database (Supabase, on EU servers) for the single purpose of emailing you when there is news about MARLOG; we send nothing else, and you can have it removed at any time by emailing support@marlog.app. If you arrive through a campaign link (a web address carrying utm_ parameters), the site keeps the campaign name and a click count in your own browser's local storage; that never leaves your device. The site runs no advertising trackers. Visit measurement works two ways. Vercel Web Analytics — run by the service that hosts the site — counts pages visited on every visit without setting any cookie, without a cross-site identifier, and without collecting anything that identifies you. Google Analytics also runs on every visit: it records the pages you visit and an approximate region, using your browser's storage, processed by Google per Google's privacy policy. A content blocker stops both, and clearing site data for marlog.app removes anything stored in your browser. Email you send to support@marlog.app is received and stored by our mail provider in the ordinary way.
What we collect
Account info: your email address (required for sign-in) and an optional display name and home port. Location: your device GPS is read while the Home, Forecast and Atlas screens are open, so we can show the weather and the places near you, and to confirm you are within 200 metres of a place when you log a visit. Your last position is cached on your device so those screens can open without waiting for a new fix; if you set a home port, its coordinates are saved to your account so sea-condition alerts know where to check. We do not keep a continuous location history. Activity: visits you log, lessons you complete, flashcards you review, articles you save and badges you earn. AI conversations: messages you send to the in-app assistant are sent to Groq’s API to generate replies, along with your approximate coordinates at the start of a conversation; when the service is saturated, your question may be processed by Google’s Gemini API instead, so the assistant keeps answering rather than telling you it is busy. We do not store a long-term archive of these messages. Usage: a handful of product events that tell us whether the app is working as intended: that it was opened, how far through the introduction people get, whether they reach the map or a lesson, whether the Supporter screen was shown and what prompted it, whether a purchase completed, and whether a session ended unexpectedly. Each carries the app version and platform. They are counted against a random identifier created on your device — not your advertising ID — and, once you are signed in, they are also linked to your account, so we can tell a completed sign-up from an abandoned one. They never leave our own servers, and we do not keep a screen-by-screen trail of where you browse or what you read.
What we do not collect
We do not collect payment details, contacts, your photo library, microphone recordings — the dictation feature returns text only, and no audio file is stored or uploaded, or any data from other apps on your device. There is no ad tracking in MARLOG.
Why we collect it
To sign you in, to verify visits at a place (the 200-metre proximity check), to power the discovery loop (badges, your map, your visit history), and to make Academy, News and the AI assistant work.
Purchases
The optional Supporter subscription is bought through Apple's App Store and processed by RevenueCat, our purchase infrastructure. RevenueCat receives your account identifier and your App Store subscription status — never your payment details, which stay with Apple. We store only whether your account has an active Supporter period.
Third parties
Supabase is our backend and stores your account, profile and activity data on EU servers. Sign in with Apple, if you use it, gives us an identifier and — only if you allow it — your name and email; we also keep one Apple token on our server solely so that deleting your account can revoke it, as Apple requires. Apple Weather powers the in-app forecast: your coordinates go to our server, which requests data from Apple's WeatherKit API on your behalf. MET Norway powers the server-side sea-condition alerts rather than the in-app forecast, and receives anonymous coordinates only. Copernicus Marine Service provides wave height, sea temperature and currents, and receives coordinates only. OBIS, the Ocean Biodiversity Information System, powers the species lists — your device queries it directly, so OBIS sees the coordinates of the point you are looking at and, as with any web request, your IP address. OpenStreetMap Nominatim and Komoot Photon resolve place searches; the text you type reaches them through our own geocoding function rather than from your device. BigDataCloud turns coordinates into a place name for the Home, Forecast and Atlas headers; it receives your approximate position and your IP address. Groq (Groq, Inc., US) powers the AI assistant, processing your messages and the coordinates sent at the start of a conversation under a services agreement that bars Groq from training on them; when Groq is saturated, questions fall back to Google Gemini, processed per Google's privacy policy. Google Cloud Text-to-Speech reads the Captain's Brief aloud and receives only that text. RevenueCat handles subscription state and receives your account identifier and your App Store subscription status. Expo routes push notifications and receives your device push token together with the notification text. Resend sends account emails and processes your email address. Sentry receives crash and performance reports tied to your account identifier and a one-way hash of your email address — never the address itself; a report may name the screen you were on, any position in it is rounded to about 11 km first, and whatever you typed into a search box is never sent, only how long it was. MapLibre, OpenFreeMap, OpenSeaMap and Esri serve map and satellite imagery through anonymous requests for the area you are viewing; the Home dashboard thumbnail asks Esri for a single image of a surrounding cell, with your position rounded to about 5 km first, so the request describes an area rather than your exact position. Only Supabase, Sign in with Apple, RevenueCat, Resend, Expo and Sentry ever receive anything tied to your account.
Your rights
You can access, export or delete your data at any time. Use Settings → Delete account in the app to request deletion, or email us. Under KVKK and GDPR and KVKK you also have the right to rectify inaccurate data and to lodge a complaint with your data protection authority.
Children
MARLOG is not directed at children under 13. We do not knowingly collect data from them.
Region
MARLOG is operated from Türkiye. We aim to handle data in line with Türkiye’s KVKK and the EU’s GDPR.
Changes
If we make significant changes to this policy, we will update the date above and notify you in the app the next time you open it.
Contact
Questions, requests or concerns: support@marlog.app