The short version
- Your boat's computer records your boat's telemetry (position, battery, motor, and similar signals) and keeps the detailed history on the boat.
- When your boat has internet, it uploads that telemetry to our cloud server so you can see it in the phone app and so we can help you with support.
- You can see all of your own boat's data. Our support staff can look at your boat's data to help you, and every single look is recorded where you can see it. Anyone you share a trip link with can see that one trip, until the link expires or you revoke it. Nobody else, not other boat owners, the public, or advertisers, can see your data. We do not sell data and we do not share it with third parties for their own purposes.
- Detailed data on the boat is deleted automatically after 7 days; hourly summaries are kept for a season (180 days). In the cloud, raw telemetry is deleted automatically after 90 days and hourly summaries are kept. See the retention table.
- If your boat has cameras, the boat's computer records video on the boat only, kept for 48 hours and then automatically deleted. You can view a bandwidth-limited live still feed from the phone app, and every remote view is logged. Recorded video never leaves the boat.
- There are no user accounts, no names, no email addresses and no payment data in the BoatPlay system. The app identifies your boat with a per-boat credential, not a login.
- You can ask for a copy of your data, or for it to be deleted. The exact procedure is below.
What data is collected
The onboard recorder polls the boat's instrument network once per second and stores numeric values. These are the data types:
| Data type | Examples | Where it lives |
|---|---|---|
| Position and track | Latitude and longitude, speed over ground | Boat, then cloud |
| Boat telemetry | House battery voltage, current, charge and temperature; motor rpm, temperature and derating; solar and shore charging; battery model estimates; wind; depth | Boat, then cloud |
| Connectivity health | Satellite link state, latency, throughput, packet loss, obstruction; internet data-usage counters against the data plan (total bytes per billing cycle, never per device or per site) | Boat, then cloud |
| Boat and credential data | Boat name, MMSI, vessel identifier; API credentials, stored only as one-way hashes, never the tokens themselves | Cloud |
| Support access events | One record every time a support operator views your boat: who, when, why, and exactly what they looked at | Cloud |
| Share links | Which trip was shared, when, when the link expires, whether it was revoked; the share token itself is stored only as a hash | Cloud |
| Video segments | Timestamped 60-second video files per camera, recorded at 1280×720, 15 frames per second, with no audio | Boat only, never uploaded |
| Camera stills | Still frames captured on demand or for the remote-view feed | Boat; the latest frame per camera only is also in the cloud |
| Camera view events | One record every time the remote camera feed is viewed: who, when, which camera, how many bytes | Cloud |
| Push notification subscriptions | The push endpoint and its encryption keys, a device label, when it was last used; your alert on/off choices; and the keys of alert events already sent, so a retried upload never notifies twice | Cloud |
| Geofence configuration | The fences you set: name, centre position, radius, on or off. Also cached on the boat, which enforces the last known fence when it has no internet | Cloud, cached on boat |
| Immobilise requests | Each request you file: reason, which credential filed it, its status and timestamps; every status change is recorded permanently. These are requests to support, recorded for accountability. No command is ever sent to your boat | Cloud |
A note on position recording. The system is built to record your position; the trip history, share links and support track view all depend on it. This policy treats position as collected data because that is the conservative way to write a privacy policy, even where the exact position feed is still being finalised.
What is not collected
- No user accounts, no names, no email addresses, no payment data. The phone app identifies your boat with a per-boat credential, not a login.
- No audio. The telemetry recorder stores numbers only. The camera recorder records video without audio, on the boat, under the retention windows below.
- No video history in the cloud. Recorded video segments never leave the boat. The only camera data in the cloud is the single latest low-resolution still frame per camera, refreshed by the boat so the phone app can show a live view. Each frame replaces the previous one; the cloud keeps no frame history.
- No guest WiFi data. The guest WiFi network on the boat collects nothing about guest devices: no device identifiers, no traffic metadata, no DNS logs. The only guest-related number anywhere is the router's total data counter, which is shared boat telemetry. The guest passphrase never leaves the boat.
- No advertising identifiers, no analytics trackers, no third-party SDKs that profile you. Software-update data (release versions and rollout state) is fleet configuration, not data about you.
The phone app
The BoatPlay app for iPhone and iPad is a window onto your boat. It has no accounts and no sign-in. It talks to your boat directly over the boat's WiFi when you are aboard, and to the BoatPlay cloud service when you are away.
- Boat credential. The app stores your per-boat credential on the device so it can reach your boat. It is never sent anywhere except your boat and our cloud service.
- Location. The app uses your phone's location only to show your own position on the chart alongside the boat. It is not uploaded and not stored by us. You can decline the permission and the app keeps working.
- Notifications. If you turn on alerts, the app registers with Apple's push notification service so your boat's alerts (for example "house battery low" or a geofence breach) reach your phone. The registration is described in the table above and is removed when you turn alerts off.
- Charts and map tiles. The chart is drawn from OpenStreetMap and OpenSeaMap data. Tiles are fetched from those projects' servers, which see the ordinary technical information any web request carries (your IP address and the tiles requested). Charts in the app are not official nautical charts and are not for navigation.
- Demo mode. The built-in demo boat is a bundled dataset replayed on the phone. In demo mode nothing is sent to any server.
- No tracking. The app contains no advertising, no analytics and no tracking across apps or websites.
What leaves the boat
Only the telemetry above leaves the boat, and only when cloud sync is configured. The boat copies new recorded points into a durable on-boat queue and uploads them in batches, oldest first, over an encrypted connection to our ingest service. Points are removed from the queue only after the cloud confirms it stored them; if the link is down, the queue simply grows, bounded so that the oldest queued points are dropped after roughly 11 hours, because the boat's own 7-day local history still holds them.
If cameras are configured, one more thing leaves the boat: the latest still frame per camera, a small image refreshed every few seconds so the phone app can show a live view. Recorded video segments and older frames do not leave the boat.
If you enable push alerts, alert events leave the boat: a title, a short text and an identifier, with no other content, queued on the boat until the cloud confirms receipt so no alert is lost when the connection drops.
In the other direction, the boat downloads your geofence configuration from the cloud and caches it on board so it keeps enforcing your fence when offline. Nothing about immobilise requests travels to or runs on the boat: those are cloud records for you and support staff only.
If no cloud service is configured, nothing leaves the boat at all.
Who can see your data
| Who | What they can see | How it is controlled |
|---|---|---|
| You, the owner | Everything about your own boat: live status, trips, share links, the support-access audit trail, and the camera feed (bandwidth-limited; every view is logged) | Per-boat credential. The phone app uses a read-only scope that cannot write telemetry. |
| Our operators (fleet dashboard) | Every boat's latest position, key readings, and online or degraded state | A single operator credential; the service refuses to start without one. |
| Our support staff | Your boat's live state, signal history and recent track, read-only. Every access is recorded (who, when, why, what they viewed) before any data is shown; if the record cannot be written, the view fails and no data is served. They also see your pending immobilise requests and can acknowledge one, which is a recorded note on a cloud record, never a command to your boat. | You can see the same audit trail yourself in the app. |
| People you send a share link to | Exactly one trip: its track and stats (distance, duration, energy). Nothing live, nothing else, nothing writable. No account needed. | Unguessable token, expires after 30 days, revocable by you at any time; search engines are told to stay out and the link never leaks as a referrer. |
| Other boat owners | Nothing of yours. | Enforced twice: the credential check at the service, and row-level security inside the database, so one boat's credential physically cannot read another boat's rows. |
| The public, advertisers, data brokers | Nothing. We do not sell or share data. | — |
Support staff cannot change anything on your boat through this system; the support view has no write path at all. Because credentials and share tokens are stored only as hashes, even a copy of the database would not hand anyone a working token.
Remote camera viewing
Only you can view your boat's camera feed. The feed is a small still frame refreshed by the boat, served under a per-boat bandwidth cap so viewing can never starve telemetry on the satellite link. Every view is recorded (who, when, which camera, how many bytes) in the same transaction that serves the frame; if the log record cannot be written, no frame is served. The support view does not include the camera feed. Recorded video segments stay on the boat and are never viewable remotely.
How long we keep it
| Data | Where | Kept for |
|---|---|---|
| Raw telemetry (1-second points) | On the boat | 7 days, then automatically deleted |
| Hourly summaries | On the boat | 180 days (a full cruising season), then automatically deleted |
| Sync queue (points awaiting upload) | On the boat | Until the cloud confirms receipt; capped at about 11 hours of data, oldest dropped first |
| Raw telemetry | In the cloud | 90 days, then automatically deleted, and only once the hour containing them has been summarised |
| Hourly summaries | In the cloud | Kept indefinitely; recomputed from the raw points before any raw point is deleted |
| Share links | Cloud | The link works for 30 days, then answers "gone"; you can revoke sooner. The record that a link existed, and when it expired or was revoked, is kept as an audit trail |
| Support access events | Cloud | 2 years (730 days), then automatically deleted. They are the accountability record for access to your data, so they outlive the telemetry they describe without being kept forever |
| Camera view events | Cloud | 2 years (730 days), the same window as support access events |
| Video segments | On the boat | 48 hours rolling, then automatically deleted; a hard 20 GB disk budget additionally drops the oldest footage first |
| Camera stills | On the boat | 24 hours, then automatically deleted |
| Latest camera frame (remote view) | Cloud | Only the newest frame per camera is kept; each upload replaces the previous one |
| Push notification subscriptions | Cloud | Until you turn off alerts on that device, or the subscription stops working; a dead endpoint is deleted automatically on the next send |
| Alert preferences | Cloud | Until you change them. Critical alert types (alarm raised, geofence breach) cannot be turned off |
| Alert de-duplication keys | Cloud | 90 days, the same window as raw telemetry |
| Geofence configuration | Cloud, cached on the boat | Until you delete or change the fence; the on-boat cache is overwritten by the next configuration pull |
| Immobilise requests and their audit trail | Cloud | Kept indefinitely as the accountability record for a security request, unless you ask for deletion (below) |
| Credentials | Cloud | Active until revoked; revoked credentials are kept as inactive rows (hashes only, never usable tokens) |
| Boat record (name, MMSI, identifier) | Cloud | Until you ask us to delete it |
These windows are enforced by scheduled jobs on the boat and in the cloud, not by hand.
Legal requests
If we receive a legal request for your data, such as a court order or other valid legal process in the jurisdiction the service operates in:
- We comply with valid, binding legal process. We will not obstruct it.
- Where the law allows, we tell you about the request before we hand anything over, so you can seek your own legal advice.
- We hand over only what we actually hold and only what the request covers. Per-boat isolation means one boat's data is cleanly separable from everyone else's.
- We will say no, or ask a court to narrow it, to requests that are over-broad, for example asking for the whole fleet when it concerns one boat.
What we can hand over is bounded by what exists: telemetry history for the retention period above, your boat's record, share-link records, the support-access and camera-view audit trails, the latest camera frame per camera, and your push-notification subscriptions and alert preferences. We cannot hand over credential or share tokens (we only store their hashes), video history (it lives only on your boat and is gone after 48 hours), or data that has already been deleted.
Getting a copy of your data
You can read your live status, trips and support-access audit trail in the phone app at any time. For a full export:
- Email hello@betapacific.com from the credential holder for your boat.
- We verify the request against your boat's credential.
- We produce an export of everything we hold for your boat as CSV and JSON files: all raw telemetry and hourly summaries; your boat record; your share-link records (never the tokens); your support-access and camera-view audit trails; your credential list (names, scopes, issue and revocation dates, never the tokens, which we do not store); your push-notification subscriptions and alert preferences; your geofence configuration; and your immobilise requests with their audit trail.
There is no self-serve export button yet. The procedure above is the committed path until one exists.
Deleting your data
On your verified request, we will, in order:
- Revoke every credential for your boat, so the phone app and the boat itself lose access.
- Revoke every share link for your boat, so all shared trips immediately answer "gone".
- Delete all telemetry, every raw point and hourly summary stored under your boat, cloud-side.
- Delete your push subscriptions and alert preferences, so no notification can be sent to any of your devices again.
- Delete your geofence configuration, immobilise requests and their audit trail.
- Delete your boat record (name, MMSI, identifier).
What deletion cannot do, honestly:
- The copy on your boat. The onboard computer holds its own 7-day raw and 180-day summary history plus the 48-hour video and 24-hour stills windows. That hardware is yours; wiping it is something you do on the boat, or we can talk you through it. We have no remote-delete capability for it.
- Copies other people already made. If you shared a trip link, a recipient may have saved or screenshotted the page. Revoking the link stops future access; it cannot recall copies that already exist.
- Backups. Our cloud backups are overwritten on their normal rotation; a deletion takes effect in the live system immediately and disappears from backups as they rotate.
- Support-access audit records. We keep these, stripped to the minimum needed, for their 2-year window, because they are the record of who looked at your data and when, which protects you.
Children
BoatPlay is made for boat owners and is not directed at children. There are no accounts, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes and contact
If this policy changes, the new version is published here with a new effective date and the change is called out in the app's release notes. Questions, export requests and deletion requests go to hello@betapacific.com.
Beta Pacific, 12 Channel Street, Boston, MA 02210, United States.