Android and iOS

Underway App Privacy Policy

Effective August 28, 2026 · Last updated September 24, 2026

The short version. Underway has no user account or advertising profile. Your log, track, notes, boat profile, and most settings are stored on your device first. Recording, review, totals, notes, and GPX export work offline. Some features send information to service providers, as described below. If you choose to send a problem report, it includes a copy of your logbook and location history.

This policy explains how the Underway mobile application handles information. Underway is an automatic boat logbook for Android and iOS. The app is provided by Antoine Meunier (“Underway,” “we,” “us,” or “our”). The application identifier iscom.getskana.

This policy covers existing test builds. Underway has not launched publicly. If a feature changes what leaves your device, we will update this policy and the relevant store disclosures before that feature is released.

This policy does not cover the Underway marketing website. See the separateWebsite Privacy Policy.

1. Core privacy principles

  • Underway has no user account or advertising profile.
  • Underway does not sell your personal information and does not use your journey data for advertising.
  • Your detailed log is stored on your device first. The app does not routinely back up or send your journeys to our servers. You can choose to send a copy when reporting a problem, as described below.
  • Features that use an internet connection send information for the purposes described in this policy.

2. Information kept on your device

Depending on the features you use, Underway stores the following in the app's private storage:

  • GPS fixes, track points, journey start and end times, route totals, estimated gaps, departure and arrival positions, and the local journey date;
  • notes and summary text that you enter or that Underway drafts for you;
  • boat name and type, home-port and saved-origin positions, automatic-journey settings, and other preferences;
  • local data used to calculate nights aboard and journey statistics, and cached forecasts and tide data in earlier test builds; and
  • optional diagnostic records about whether recording worked, without coordinates, kept on the device until you explicitly export them or send a problem report.

Underway's automatic-journey and background-recording features use location in the background when you enable them. That processing is used to detect or record a journey and is performed on the device. Granting a location permission does not, by itself, upload your track.

3. Location and background access

When you enable automatic journeys or background recording, Underway can use location while the screen is off or while the app is not in the foreground. This allows the app to detect or record a journey. Automatic-journey processing is performed on the device.

Background-location disclosure. Underway uses background location to detect or record an enabled journey when the app is closed or not in use. If you decline or revoke permission, recording and location-dependent features may be unavailable or less accurate.

Underway does not send your full journey or raw track to the map service. Map requests can reveal the area you are viewing. Earlier test builds may also send weather requests, as described below.

4. Information sent off the device

Weather data in earlier test builds

Underway’s planned release is an automatic logbook without weather or conditions. Earlier installed test builds may still make the requests described here. These disclosures remain applicable to those builds.

When you request weather, Underway sends a marine-area query or an approximate point used to retrieve the relevant forecast. Environment and Climate Change Canada may therefore receive that marine area or approximate point, plus ordinary network metadata such as an IP address.

For current wind, Underway requests a forecast for the current point from Open-Meteo's GEM/HRDPS endpoint. The requested latitude and longitude are sent to Open-Meteo for that request. Underway does not send your saved journey or track to Open-Meteo.

Tide and current predictions are downloaded as a shared regional bundle from Underway's Supabase storage. The bundle is the same for every install; it does not contain your token, account, or position. The storage or delivery service may still receive ordinary request metadata.

Mapbox chart tiles

When chart tiles are enabled, Underway requests map tiles from Mapbox for the area currently visible on screen. This can reveal the approximate map area to Mapbox and ordinary network metadata to the tile service. Underway draws your track locally over the map; it does not send your track to Mapbox as part of the map display.

Warning notifications in earlier test builds

If you enable marine-warning notifications, Underway sends a push token and the name of the marine forecast area you chose to Underway's warning service. The service uses them to deliver warnings and detect a change of watched area. It does not receive your GPS position, journey track, install ID, name, or account because Underway has no account.

The warning service uses Supabase in Canada for registration tables and Expo's push service to deliver notifications through the platform push provider (FCM on Android and APNs on iOS). Turning notifications off deletes the registration and its pending delivery receipts. Inactive registrations are automatically deleted after 90 days, delivery receipts are purged after 24 hours, and invalid tokens are removed when detected.

Journey summary drafts

In builds with summary drafting enabled, the app may prepare information about a completed journey and send it to our summary service on Supabase if the journey has no written summary. This information can include the journey date, local start and end times, named places along the route, distance, time underway, average speed, estimated distance, the number of gaps in the recording, and propulsion type.

This information contains no raw latitude/longitude, raw track points, notes, boat name, or database IDs. Our summary service sends it to Anthropic to draft two to four sentences, then returns the draft to the device. Underway does not store the submitted information or draft on its servers. The app saves the draft only if the journey’s summary is still empty. It does not replace a summary you have written or edited. Anthropic may process the request under its applicable service terms and technical logging rules.

Product analytics and crash diagnostics

Production builds may use PostHog for product-quality analytics and crash diagnosis. They can send application lifecycle and release information; a limited set of results for setup permissions, journey recording and saving, GPX export, automatic-start decisions, and recording recovery; and crash or error diagnostics. They do not send screen views, touches, element trees, rendered text, settings changes, or a general clickstream. PostHog assigns a pseudonymous identifier; there is no Underway account or PostHog person profile attached to it.

Analytics exclude journey IDs, route names, exact timestamps, coordinates, place names, notes, summaries, and unapproved free text. The app also disables session replay, screen and touch autocapture, console capture, surveys, and feature flags. Network-derived geolocation is disabled in the client and the app requests IP discard from PostHog. PostHog processes this telemetry in the United States. Analytics are enabled only in configured production builds. Development and preview builds cannot send these events. Recording continues if analytics cannot be sent.

Problem reports

When you open Settings › Diagnostics › Report a problem, read the list of information to be included, and tap Send, Underway sends one report to Supabase in Canada. It contains the complete local log, including journeys, raw tracks, precise positions, notes, summaries, and the boat profile; the recent diagnostic log; up to 64 records of the phone detecting a departure from a monitored area during the previous 30 days, without coordinates; up to 20 records about recording reliability, without coordinates; the device model and OS; the app version; and the install ID.

Nothing is sent when you open Diagnostics or the report sheet. Reports are never automatic, scheduled, retried, or sent in the background. The copy is used to trace the problem you reported and is deleted when the problem is resolved. You cannot use a problem report to restore your logbook.

5. Service providers

Underway uses service providers only for the product functions described above. Providers may process limited network metadata such as an IP address as part of operating and securing their services. Underway does not use that metadata to create a journey history or advertising profile.

ProviderInformation it may receivePurpose
Environment and Climate Change CanadaMarine-area or point forecast request and network metadataMarine forecasts and warnings in earlier test builds only
Open-MeteoPoint used for current wind and network metadataCurrent wind in earlier test builds only
Underway Supabase project (Canada)Summary-drafting requests and explicit problem reports; warning registration data and tide-bundle requests in earlier test builds onlyBackend functions and storage
AnthropicJourney information used for summary drafting when enabledDraft a log summary
PostHog (United States)A limited set of app results, app lifecycle and version information, and crash diagnostics, associated with a pseudonymous identifierProduct quality and error diagnosis
MapboxVisible map-tile area and network metadataMap imagery
Expo push service and platform push providersPush token and notification payload needed for deliveryMarine-warning notifications in earlier test builds only

6. Retention and deletion

  • On-device data: remains in the app's private storage until you edit or delete it, reset the app, or uninstall it. An exported GPX or other shared file is controlled by the destination you choose, not by Underway.
  • Warning registrations in earlier test builds: are deleted when notifications are turned off, when a token is invalid, or after 90 days without an app refresh. Delivery receipts are purged after 24 hours.
  • Summary drafts: our summary service does not retain the submitted journey information or draft after returning the response. The local copy is deleted when you delete the journey; Anthropic's handling is governed by its applicable provider terms.
  • Analytics and crash data: are retained in the PostHog project for up to 12 months under the current project setting, then deleted or aggregated under that service's retention controls. We do not retain journey tracks in this path.
  • Departure-detection diagnostics: are limited to 64 records without coordinates. Records older than 30 days are excluded when read and removed from the app’s private storage the next time it detects a departure or reads the diagnostic records.
  • Problem reports: are retained only while the reported problem is being investigated, then deleted. A deletion request may need the install ID shown in Settings › Diagnostics so the maintainer can locate the report. A report is not a user backup service.

7. Your choices and privacy requests

  • decline or revoke location, background-location, and notification permissions in Underway or your operating-system settings;
  • in earlier test builds, turn off warning notifications to delete the server registration;
  • turn off automatic journeys, which stops that feature while leaving your local log available;
  • edit or delete journeys and notes in the app;
  • choose whether to send a disclosed problem report; and
  • export a journey as GPX and decide where the exported copy is shared.

Depending on where you live, you may also have rights to request access to, correction of, deletion of, or restrictions on the use of your personal information, and to withdraw consent where processing is based on consent. Send requests toa@meunier.co. We may ask for enough information to verify and locate a request. Because Underway has no account, some pseudonymous provider data may not be identifiable from a name or email alone.

If you delete the app, its local log is normally removed by the operating system. Deleting the app does not automatically delete copies you exported or information already sent to service providers. Retention periods are described above. Use the controls above or contact us to request deletion.

8. Security

Underway uses platform-private app storage, TLS for network requests, restricted backend access, and least-privilege service paths appropriate to each feature. No method of storage or transmission is completely secure. Keep your device, operating system, and exported log files protected.

9. Children

Underway is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us so we can review and delete it where appropriate.

10. Changes and contact

We may update this policy when the app, service providers, or applicable requirements change. The “Last updated” date above shows when this policy was revised.

Privacy contact

Antoine Meunier, developer of Underway
Canada
a@meunier.co

This policy is for privacy transparency and does not replace any rights or obligations that apply under the law where you live.