Privacy Policy

Keeldragger Offshore Toolkit — web edition · Last updated 29 August 2026

Your boat stays on your device unless you choose otherwise. The web app stores everything in your browser and works fully offline. Two sync options exist, both off until you switch one on: your own iCloud (which never reaches us at all), or a Keeldragger account, where your data is encrypted on your device before it is sent, so what we hold is ciphertext we cannot read.

This policy covers the web app at app.offshore.keeldragger.com. The iPhone, iPad and Mac apps are covered by their own policy; they do not use the Keeldragger account described below.

Our commitments

Where your data lives

1. On this device — always

Everything you enter — checklist dispositions and notes, vessel details and boat systems, your float plan (including crew details, itinerary and photos), and your emergency cards — is saved in your browser's local storage on the device you are using. In this default mode nothing is transmitted anywhere, and the app works with no connection at all.

Because it lives in the browser, clearing your site data deletes it. Exporting a backup file is the way to keep a copy, and that file is yours alone — we never see it.

2. Your own iCloud — optional

If you also use the iPhone, iPad or Mac app, you can sign in with your Apple Account to sync through your own private iCloud database. That exchange is between you and Apple: your data does not pass through Keeldragger, and we have no access to it and no record of it. It is governed by Apple's privacy policy. Signing in places a cookie from Apple's CloudKit service in your browser to keep that session.

This route currently runs one way — it brings your boat into the browser. Apple does not accept uploads from web browsers, so changes made in the browser travel back to your devices via a backup file.

3. A Keeldragger account — optional

An account syncs any browser or device in both directions, through servers we operate on Amazon Web Services. Before anything is sent, your data is encrypted on your device using a key derived from a sync passphrase that only you know (AES-256-GCM, with the key wrapped using PBKDF2-HMAC-SHA256). Your passphrase is never transmitted to us and we have no copy of it.

What we hold, and can see:

ItemWhy
Your email addressTo create the account, verify it, and let you sign in or reset your password.
Encrypted blocks of dataThe sync itself. We can see how large they are and when they changed, but not what is in them.
Version numbers and timestampsTo decide which device has the newer copy without relying on device clocks.
Photo filenames and sizesFilenames are random identifiers that reveal nothing about the image, which is itself encrypted.
Your wrapped encryption keySo another one of your devices can unlock the account with your passphrase. It is useless without it.
Sign-in times and IP addressesRecorded by the sign-in service and in server error logs, as a normal part of operating and securing a service. Kept briefly.

What we never see: the contents of your checklist, vessel record, float plan, emergency cards or photos — including crew names, ages, passport numbers, and medical information. Nor which of your devices made a change: the device label used to explain sync conflicts to you travels inside the encrypted data, not alongside it. All of this is encrypted before it leaves your device, and would be equally unreadable to anyone who obtained the stored files, whether by breach or by legal demand.

One limitation, stated plainly. This app's code is delivered by our server each time you load the page. End-to-end encryption in a web browser therefore depends on us continuing to ship honest code. This design removes our ability to read your data at rest and makes a breach of our storage worthless to an attacker, but no web app can protect you from an operator who deliberately ships malicious code — a limit shared by every browser-based encrypted service. The App Store apps, which are reviewed and signed, are not subject to it.

Your sync passphrase

Your passphrase is deliberately separate from your account password. We never receive it and cannot reset, recover or bypass it. If you forget it, nothing is lost: every device you have already set up keeps a complete local copy of your boat, and your backup files still work. You would reset sync — creating a fresh key and uploading again from a device that has your data.

Information about other people

A float plan can include details about your crew, including health information, passport numbers, and in some cases children. Enter only what your passage genuinely requires, and only with the agreement of the people concerned. If you use a Keeldragger account, this information is encrypted and unreadable to us; in the default mode, it never leaves your device at all.

Keeping and deleting your data

We keep no backups of your encrypted data beyond what the deletion above removes. Routine server error logs, which contain request metadata such as IP addresses but never your content, age out on their own within about two weeks.

Your rights

Depending on where you live, you may have rights to access, correct, export or delete your personal information, and to object to its processing. Three of these are built into the app rather than left to a request: you already hold a complete copy of your data, Export backup gives it to you in a portable file at any time, and Delete account erases everything we hold, on the spot. For anything else, contact us at the address below. We do not discriminate against anyone for exercising these rights.

Where a Keeldragger account is used, we process your email address and the encrypted data to provide the sync service you asked for, and to keep that service secure and working.

Service providers

We use no other processors, and no advertising or analytics providers of any kind.

Cookies and browser storage

We set no tracking or advertising cookies. The app uses your browser's own storage to hold your boat data and your preferences; a Keeldragger account additionally stores a sign-in token so you are not asked to sign in every visit, and iCloud sync stores a session cookie set by Apple. All of it is first-party and used only to make the app work.

Children

The app is intended for adults responsible for a vessel and is not directed at children. We do not knowingly collect personal information from children; with a Keeldragger account we cannot read any of the content you store in any case.

Changes to this policy

If this policy changes, the date at the top changes with it, and any change that affects what we can see or hold will be described here before the feature that causes it becomes available.