Privacy — Chart
chart.boating.systems · last updated 30 September 2026
Chart runs on your device. Signed out, your position and your tracks stay on the phone. Signed in, your outings and your current position are saved to your own private account. Nothing you record is visible to anyone else unless you share it yourself.
This is Chart's own policy, kept here for the app stores. The boating.systems privacy policy covers every app in the family, including your rights and where data is stored.
Who we are
Chart is part of boating.systems, run by Progressable LLC, 69 E. Pearl Street, New Haven, Connecticut, USA. Questions, corrections, or a request to delete your data: info@boating.systems.
Location
Chart asks for location so it can show where your boat is on the chart, report your speed and course, and colour the water against your draft. While you are recording an outing, Chart keeps recording with the screen off or the app in the background. On Android this runs as a location foreground service with a visible "Recording your outing" notification; Chart does not request Android's separate background-location permission. On iPhone, Chart asks for "Always" location permission when you start recording. When nothing is recording, Chart does not track you in the background.
- On the device. Your track — the line behind the boat — is held on the phone. Depending on your settings it either fades after about 45 minutes or is saved to the app's local storage so you can look at the outing later.
- Sent to us only if you sign in. When you are signed in, a finished outing is uploaded to your own private account so it appears in the Log app on your other devices. Signed out, no track ever leaves the phone.
- Your current position, if you sign in. While location is on, Chart saves your current position, speed, course, active route and chosen boat to your account about every 30 seconds, whether or not you are recording, so your other devices can show where you are. Only you can read it. If you have chosen a boat, people with access to that boat in our apps can see the same position. Signed out, nothing is saved.
- Optional tester area. A signed-in person may choose to share an approximate area from the account sheet. The device reduces its current location to a roughly 55 km cell before sending it. We use counts of consenting accounts on a private operations map, and you can remove your area from the same sheet. It is never required for using Chart or signing in.
- Sent to weather services. To fetch a wind forecast, Chart asks the US National Weather Service for the forecast grid covering your position, which means your position is sent to weather.gov. Weather alerts are requested for a position rounded to about 5 km. Tide and current predictions are fetched by station identifier, not by your position.
- Visible to map servers. Chart requests charts and map tiles for the area you are looking at from our servers and, for the optional NOAA chart, radar and aerial-photo layers, from NOAA and Esri. Like any web request, that reveals the area being viewed and your IP address to the server answering it. Offline chart downloads come from our servers and are stored on the phone.
What we store when you sign in
Signing in is optional. Chart works fully without an account; signing in is what lets your boats, settings and outings follow you to another device.
| Data | Why | Who can see it |
|---|---|---|
| Your Google or Apple account identifier, email address and name | To recognise you across devices and apps | You and the operator |
| Your boats (name, draft, air draft) | To colour depths against your keel | You |
| App settings (units, safety margin, display mode) | To keep the app set up the way you left it | You |
| Your current position, speed, course, route and boat (overwritten about every 30 seconds) | So your other devices can show where you are | You, and people with access to the boat you chose |
| Outings — track points, times, speeds, and the boat they belong to, plus photos and voice notes you add | So the Log app can show them | You, unless you publish one — see How we use what you record |
Trips are private when created. Publishing one is a separate, deliberate act that makes that trip readable by anyone who has its link — it is never listed or searchable, and unpublishing closes access again immediately.
How we use what you record
Beyond showing your outings back to you, we study recorded data to make the service better. Where that work does not need to know whose track it is — and it usually does not — we use it aggregated and stripped of account, person, vessel and trip identifiers. The purposes are:
- Finding real places — where boats repeatedly arrive, stop, moor, launch or land can nominate an anchorage, landing, channel or ramp the Guide does not yet know about. It only ever creates a private candidate; a person decides what gets published.
- Checking charts against reality — a boat that floated somewhere proves the water was at least as deep as its draft. Corrected for tide and pooled across many boats, that can show where a survey looks stale, or where the chart has no data at all.
- Depth data, if you connect an instrument — if you connect a depth sounder or an onboard system that reports depth, we may use those soundings for the same purpose, and may work out your instrument's offset by comparing it against well-surveyed water. Sharing soundings with public hydrographic programmes is a separate choice we would ask you for.
- Conditions and seasonality — when places and routes are busy, by season, broad time of day, conditions and class of craft.
- Making the apps work better — diagnosing faults, and improving the algorithms that colour tracks, trim the drive home, estimate speed and assess depth ahead.
Three things this never means. It is never what makes a trip public: sharing is yours to choose. A trip is private when it is created, becomes readable by other people only when you share it, and stops being readable the moment you unshare it. Anchor Watch data is never an input to any of it — safety data lives in a separate database and is not repurposed. And we do not sell your data.
Nothing derived this way is a navigation claim. Evidence that boats pass somewhere may flag a chart as possibly stale; it never raises a charted depth, clears a hazard, or quiets a warning in the app.
You may opt out of having your uploaded outings used for these community insights by emailing info@boating.systems. We will also provide this as an account setting before publishing a community heat map, depth-confidence layer or other aggregate product. Opting out does not remove your private outings from Log; you can delete those separately. The full statement of what we may and may not do with recorded data is in the terms of use.
What we do not do
- No advertising, and no ad identifiers.
- No analytics or tracking SDKs. Chart ships with none.
- No selling or sharing of personal data with third parties for their own purposes.
- No account required to use the app.
Feedback you send
If you send feedback from Chart, it carries what you write plus what the app knew at that moment, so we can find the problem: your position rounded to about 100 m and the area on screen, the page address, browser and device type, screen size, recent error messages, your settings and boat, the tide shown, and how much battery Chart was using. Only staff can read it. If you are signed out, sending feedback creates an anonymous session (a random account with no name or email) to file it under. Written feedback has no automatic expiry; ask us to delete it.
Basic problem reports
Chart sends basic failure reports to help us fix sign-in, recording, sync and startup problems, including when you are signed out. They contain a fixed error category, the app build, platform, Android build/API numbers, device brand category, occurrence time and whether the device was online. They do not contain raw error messages, tracks, coordinates, account identifiers or URLs. A random identifier identifies each report for retry deduplication; it is not a device ID. Up to 20 reports wait locally for at most seven days and are retried when online. Server reports expire after 14 days (deletion may take an additional day). Turn off “Send basic problem reports” in Chart settings to stop sending and clear unsent reports. The service provider also processes ordinary request metadata such as IP address in access logs; our application reports do not store it.
Processors
We use Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions and Hosting) to run the service and store the data described above on our behalf. See Firebase's privacy documentation. Chart also reads public forecast, chart and radar data from NOAA and the US National Weather Service, and optional aerial imagery from Esri.
Keeping and deleting your data
Data on your device is removed when you uninstall the app or clear its storage. Outings you have uploaded are kept until you delete them: each trip can be deleted from the Log app. Deleting a trip removes it, its notes, photos and voice notes at once; the stored copy of its track is not yet removed automatically, so email us and we will remove it. To request deletion of your account and everything attached to it, use Delete my account in Chart’s information panel or visit our account deletion page. Requests are normally completed within 30 days (each request is carried out by hand); records subject to a legal retention requirement are anonymized and retained only for that period.
Children
Chart is for people aged 13 and over. It is not directed at children, and we do not knowingly collect data from children under 13. If you believe a child has given us data, email us and we will delete it.
Changes
If this policy changes materially we will update the date at the top and, for anything that affects what leaves your device, say so in the app's release notes.
Safety
Chart is not a certified navigation system and must not be used as your primary means of navigation. Charted data may be incomplete, out of date, or wrong, and predictions are predictions. Carry official charts and keep a proper lookout.