Privacy Policy
Last updated: 29 September 2026
The short version
The website and the app don't collect, store, or transmit any personal data — except, if you turn on background notifications, the push address your browser creates for this site (details below). Your spots, your location and your thresholds never leave your device. (Developers who sign up for an API key: see Developer API below.)
No accounts, no tracking
- The website and the app have no sign-up, login, or user profile. Developers who want an API key sign up separately, at api.predictsea.com (see Developer API).
- We use no analytics, advertising networks, tracking pixels, or fingerprinting.
- The website and the app set no cookies.
- Everything the app loads, including buoy observations and storm tracks, is served from this site — no third-party requests are made from your browser while you use the app, with one opt-in exception below. Background notifications, if you turn them on, reach your device through your browser's own push service (see Background notifications).
Optional overlay that contacts another server
The Seamarks overlay is off by default and only loads when you switch it on: it fetches map tiles from tiles.openseamap.org (OpenSeaMap). While it is on, that provider receives the standard technical details of an image request (your IP address, the map area you are viewing). We send nothing else, and switching the overlay off stops the requests. The overlay stays on for the rest of the browser session only; a later visit starts with it off unless you switch it on again.
Sponsors
Predict Sea may show a small number of clearly labelled sponsor slots (see the Sponsors page). No sponsor code runs in your browser, nothing is loaded from a sponsor's servers, and we count neither views nor clicks. Which sponsor you see never depends on you. If you follow a sponsor link you leave this site and that site's own privacy policy applies.
What stays on your device
- Preferences (such as the Data Saver switch) are kept in your browser's local storage. They never leave your device.
- Saved and recent spots: positions you star, the last few positions you tapped on the map and any positions you import are stored only in your browser's local storage so the search box can offer them again. Nothing is uploaded; anyone using the same browser profile can see them.
- Your location: the "use my location" button asks your browser for your position once, only when you press it, and uses it only to centre the map and open a point forecast. It is never stored — not in local storage, your spots or the page address — and never transmitted. Only if you press Link or Share in that panel is the position written into the link you copy or share.
- Watch-list alerts are worked out on your device, from the same forecast files the map uses: your saved spots and thresholds are never sent anywhere. While background notifications are on, a copy of your spots, thresholds, units and time setting is also kept in your browser's IndexedDB storage so the service worker can check them when a new run arrives; turning notifications off deletes that copy.
- Settings export / import saves your spots and preferences to a file you keep; nothing is uploaded.
- Offline cache: a service worker stores recently viewed forecast data on your device so charts keep working without connectivity. You can clear it at any time via your browser's site-data settings.
Background notifications (optional)
Background notifications are off by default. You turn them on from the watch list, and your browser asks for your permission first. When a new forecast run is published, our server sends every subscribed browser the same short message: which run is out. It contains no location, no spots and nothing about you. What your device does next depends on the option you choose in the watch list:
- Just tell me when a new run is out: your device shows the message and downloads nothing. This is the option that reveals the least.
- Check my spots in the background: your device downloads the forecast files for your saved spots from this site, compares them with your thresholds and shows the result. Your spots, thresholds and results never leave your device. But each download is an ordinary request to our web server, which logs it like any visit, with your IP address (see Server logs), and the file names show the rough area of each saved spot (a square about 300 nautical miles across). These requests happen by themselves, up to four times a day, even when you do not open the app.
For each subscribed browser we store: the push address your browser created for this site (a web address at your browser maker's push service) and the two public encryption keys that come with it; a random token your browser uses to change or cancel the subscription (we keep only a one-way hash of it); how often you want messages; the day the subscription was created; which forecast run was last sent to it and the day your browser's push service last accepted a message for it (the push service does not tell us whether it reached your device); and failure counters. We do not store your IP address, your location, your spots or thresholds, or anything that names you, and there is no account.
We process the push address because you asked for notifications (your consent). Turning notifications off withdraws that consent.
The message is delivered by the push service of your browser's maker — Google (Chrome and most Android browsers), Mozilla (Firefox), Apple (Safari) or Microsoft (Edge on Windows) — which may handle it outside your country. It is encrypted end to end, so they cannot read it. They do learn that Predict Sea sends messages to your browser (our server identifies itself to them with its public key and our contact address), and when, how often and how large the messages are. Their own privacy policies cover that service.
Turning notifications off in the watch list deletes your subscription from our server at once when you are online, or at your next connection when you are not. We also delete it when your browser's push service tells us it no longer exists (for example after you clear this site's data or block notifications), and after 60 days in which the push service accepted no message for it. Copies in our server backups expire within 30 days. You can block notifications at any time in your browser's site settings.
The notification service answers at predictsea.com/push/ and runs in the same server program as our developer API, but shares nothing with it: no API key and no usage counting. Its log records the time, the route (it carries no identifier), the status and the duration of each request — never the push address, the token or your IP address. These requests pass through our own proxy and web server, which keep no access log for them.
To see or delete what we hold for your browser, turn notifications off, or write to the contact below.
A notification comes only when a new run reaches us: no notification does not mean conditions are fine. Notifications are forecast guidance, not official warnings.
Developer API (api.predictsea.com)
We run a separate, keyed API for third-party developers. The website and our apps never use it: they read the same public forecast files as before, and your position never leaves your device. This section is about developers who sign up for a key; nothing in it concerns people who only use the website or the app.
Signing up
- Before you confirm: when you ask for a key at api.predictsea.com/signup, the email address, name and intended use you type are held only in the server's memory, for up to 30 minutes, together with the one-time link we email you (of the link itself we keep only a hash). They are never written to disk: if you don't confirm, they are gone.
- What we store once you confirm: your email address as you typed it; your name or organisation; what you said you will build; the version of the API terms you accepted and the date; the key's id and a SHA-256 hash of the key — never the key itself; its limits; the dates it was issued, replaced or revoked; and whether it came from sign-up or was issued by hand.
- Abuse counters: to keep bots from using up our email budget, sign-up and manage requests are counted per keyed hash (HMAC) of your normalised email address and per IP address (an IPv6 address by its /64 network), in memory only, for at most 24 hours. These counters are never written to disk or logged. What we do write down are daily totals for the whole service (how many requests, emails and keys), which name no one.
- Block list: if we block an address or a domain for abuse, we keep a keyed hash of the address (never the address itself) or the domain's name, with a short note, until we remove the block.
- We send the confirmation link, your key and links to manage it through Amazon Web Services (Amazon SES), which handles that mail for us as our processor. AWS's own terms, including its data processing addendum, cover that processing.
- The key is emailed to you when you confirm (and the new key when you replace one). A mailbox keeps copies and can forward them, so delete that email once you have stored the key.
- If an address bounces our mail or marks it as spam, it goes on our AWS account's suppression list and stays there until we remove it: write to us if you want it removed.
- Our emails are plain text, with no tracking pixels and no tracked links.
Using a key
- Usage is counted per key, UTC day and endpoint: the number of requests and their weight. No coordinates, no query strings, no IP addresses.
- Request contents: the coordinates and other parameters of a request are used to compute the answer and are never logged or stored by the API.
- Request log: time, key id, endpoint (without its parameters), status and duration.
- IP addresses are held in memory for a few minutes to limit failed key attempts, and are never written to disk or logged.
- Developers get no cookies and no tracking.
- Our proxy's logs are as described under "Server logs" below.
Our admin page
Only our own administrator signs in to api.predictsea.com/admin, with a link emailed to them, and gets a sign-in cookie there; developers and visitors get no cookie. An audit log records our own admin actions — which of us, what was done, to which key id, and when — with no IP address and never a key. It is kept 13 months. The weekly summary we email ourselves holds counts and key ids only.
Retention and your choices
- Account details: until you delete your account, or 12 months after the key is revoked.
- Usage rows: 13 months. The admin audit log: 13 months. Copies in our server backups expire within 30 days.
- You can replace your key or delete your account at any time at api.predictsea.com/manage. Deleting it stops the key at once and deletes your details; the daily usage counts, which name only the key id, stay for their 13 months. To see, correct or delete anything else we hold, write to the contact below.
The terms for key holders are the API terms.
Server logs
Our web server and the proxy in front of it, which we run ourselves on our rented OVHcloud server in Singapore, keep standard technical logs (IP address, requested file, timestamp) for security and capacity purposes. They are rolling logs that are overwritten within about two weeks and are not archived. We do not use these logs to identify or profile visitors, and they are not shared with sponsors or anyone else. Requests to the notification service (/push/) are not in them.
Where your data is processed
The website, its forecast files, the notification service and the developer API all run on one virtual server we rent from OVHcloud, in its Singapore data centre. The forecasts are prepared on our own machine and published to that server. Email for API keys goes out through Amazon SES in AWS's US East (N. Virginia) region, in the United States (see Developer API), and background notifications travel through your browser maker's push service (see Background notifications). The controller responsible for the personal data described here is 19 Lat (see Contact below).
Legal basis
- Server logs and abuse limits (the logs above, the API's failed-key and sign-up counters): our legitimate interest in keeping the service secure, sizing its capacity and preventing abuse.
- Background notifications: your consent, which you withdraw by turning them off.
- A developer's key and account: the contract — issuing and running the key you asked for under the API terms, including the confirmation email before it exists. The abuse brakes, the block list and our admin audit log rest on our legitimate interest in preventing abuse and keeping a record of our own actions.
Contact
Questions about this policy? Contact 19 Lat at predictsea@outlook.com.
Terms & data sources · Sponsors · Forecast status · Developer API