01Who we are
Seapurse ("the app") is an operations tool for yacht crew: a shared shopping list and an expense log. It is operated by Suon Labs. We are the data controller for the personal information you give us when you sign up and use the app.
02What we collect
When you create an account:
- Email address, required for sign-in.
- Display name, chosen by you and visible to crew on the same vessel.
- Role: captain, chef, stew, engineer, deckhand, or solo.
When you use the app:
- Shopping items you add: name, quantity, department, notes.
- Expenses you record: amount, currency, category, vendor, date, description.
- Receipt photos you upload, held in private storage and served only through short-lived signed links.
- Vessel information: name, default currency, and the flag, IMO or length if you choose to add them.
- Audit log entries: who changed what, and when.
We also collect:
- Diagnostics through Sentry: crash reports, stack traces, device model and OS version. No content from your receipts or expenses is sent to Sentry.
- Usage analytics through PostHog: which screens you open and which features you use. We do not capture text you type into forms.
We do not collect location data, contacts, browsing history, health data, or payment card numbers. Paid plans run through Apple's in-app purchases, which never hand us card details.
03Why we collect it
- To run the service. A shopping list is not possible without storing the items.
- To sync data between the crew on your vessel.
- To diagnose crashes and bugs.
- To improve the product.
- To keep an audit trail for expense disputes.
We do not sell your data. We do not use it to train AI models. We do not share it with advertisers.
04Who can see your data
- Crew on your vessel see vessel data according to their role. The captain sees every expense on the vessel; crew see the expenses they paid for themselves.
- Anyone on another vessel can never see your data. This is enforced in the database itself with row-level security, not only in the app.
- Suon Labs staff can reach your data when you ask us for support, or to investigate abuse. That access is logged.
Sub-processors:
- Supabase, for the database, sign-in and file storage. EU region.
- Sentry, for crash reporting.
- PostHog, for product analytics.
- Apple, for app distribution and in-app purchases.
05Where your data lives
Primary storage is Supabase in eu-central-1, Frankfurt, Germany. Receipt photos sit in the same region, and any backups stay in that region.
06How long we keep it
- Active data stays as long as your account is active.
- Deleted items leave primary storage immediately. Where a copy survives in a backup, it is removed as that backup ages out.
- You can delete your account in the app, under Settings. Your personal data is removed and your receipt files are erased from storage. Where a vessel has other active crew, the expenses you recorded stay on that vessel's books but your membership is de-identified, so the vessel's accounts still add up.
07Your rights
Under GDPR and comparable laws you can:
- Access what we hold about you, and export it.
- Correct anything inaccurate.
- Delete your account and your personal data.
- Object to processing.
- Port your data. Expenses export as CSV.
- Complain to your data protection authority.
Write to privacy@suonlabs.com to exercise these rights.
08Children
Seapurse is a tool for professional crew. It is not directed at children under 16 and we do not knowingly collect their data.
09Cookies
The mobile app uses no web cookies. The web version uses essential cookies for your session and theme preference, plus PostHog analytics.
10Security
- TLS on all network traffic.
- Row-level security in the database, so you can only read vessels you belong to.
- Receipt files are private and reachable only through short-lived signed links.
- Sign-in tokens are held in the operating system keychain.
- Passwords are salted and hashed. We never see them.
We are not perfect. If you find a security problem, write to security@suonlabs.com and we will answer within 48 hours.
11Changes
We may update this policy. If a change materially affects you, we will announce it in the app at least 30 days before it takes effect.