← Back to Predict Sea

Privacy Policy

Last updated: 29 September 2026

The short version

The website and the app don't collect, store, or transmit any personal data — except, if you turn on background notifications, the push address your browser creates for this site (details below). Your spots, your location and your thresholds never leave your device. (Developers who sign up for an API key: see Developer API below.)

No accounts, no tracking

Optional overlay that contacts another server

The Seamarks overlay is off by default and only loads when you switch it on: it fetches map tiles from tiles.openseamap.org (OpenSeaMap). While it is on, that provider receives the standard technical details of an image request (your IP address, the map area you are viewing). We send nothing else, and switching the overlay off stops the requests. The overlay stays on for the rest of the browser session only; a later visit starts with it off unless you switch it on again.

Sponsors

Predict Sea may show a small number of clearly labelled sponsor slots (see the Sponsors page). No sponsor code runs in your browser, nothing is loaded from a sponsor's servers, and we count neither views nor clicks. Which sponsor you see never depends on you. If you follow a sponsor link you leave this site and that site's own privacy policy applies.

What stays on your device

Background notifications (optional)

Background notifications are off by default. You turn them on from the watch list, and your browser asks for your permission first. When a new forecast run is published, our server sends every subscribed browser the same short message: which run is out. It contains no location, no spots and nothing about you. What your device does next depends on the option you choose in the watch list:

For each subscribed browser we store: the push address your browser created for this site (a web address at your browser maker's push service) and the two public encryption keys that come with it; a random token your browser uses to change or cancel the subscription (we keep only a one-way hash of it); how often you want messages; the day the subscription was created; which forecast run was last sent to it and the day your browser's push service last accepted a message for it (the push service does not tell us whether it reached your device); and failure counters. We do not store your IP address, your location, your spots or thresholds, or anything that names you, and there is no account.

We process the push address because you asked for notifications (your consent). Turning notifications off withdraws that consent.

The message is delivered by the push service of your browser's maker — Google (Chrome and most Android browsers), Mozilla (Firefox), Apple (Safari) or Microsoft (Edge on Windows) — which may handle it outside your country. It is encrypted end to end, so they cannot read it. They do learn that Predict Sea sends messages to your browser (our server identifies itself to them with its public key and our contact address), and when, how often and how large the messages are. Their own privacy policies cover that service.

Turning notifications off in the watch list deletes your subscription from our server at once when you are online, or at your next connection when you are not. We also delete it when your browser's push service tells us it no longer exists (for example after you clear this site's data or block notifications), and after 60 days in which the push service accepted no message for it. Copies in our server backups expire within 30 days. You can block notifications at any time in your browser's site settings.

The notification service answers at predictsea.com/push/ and runs in the same server program as our developer API, but shares nothing with it: no API key and no usage counting. Its log records the time, the route (it carries no identifier), the status and the duration of each request — never the push address, the token or your IP address. These requests pass through our own proxy and web server, which keep no access log for them.

To see or delete what we hold for your browser, turn notifications off, or write to the contact below.

A notification comes only when a new run reaches us: no notification does not mean conditions are fine. Notifications are forecast guidance, not official warnings.

Developer API (api.predictsea.com)

We run a separate, keyed API for third-party developers. The website and our apps never use it: they read the same public forecast files as before, and your position never leaves your device. This section is about developers who sign up for a key; nothing in it concerns people who only use the website or the app.

Signing up

Email

Using a key

Our admin page

Only our own administrator signs in to api.predictsea.com/admin, with a link emailed to them, and gets a sign-in cookie there; developers and visitors get no cookie. An audit log records our own admin actions — which of us, what was done, to which key id, and when — with no IP address and never a key. It is kept 13 months. The weekly summary we email ourselves holds counts and key ids only.

Retention and your choices

The terms for key holders are the API terms.

Server logs

Our web server and the proxy in front of it, which we run ourselves on our rented OVHcloud server in Singapore, keep standard technical logs (IP address, requested file, timestamp) for security and capacity purposes. They are rolling logs that are overwritten within about two weeks and are not archived. We do not use these logs to identify or profile visitors, and they are not shared with sponsors or anyone else. Requests to the notification service (/push/) are not in them.

Where your data is processed

The website, its forecast files, the notification service and the developer API all run on one virtual server we rent from OVHcloud, in its Singapore data centre. The forecasts are prepared on our own machine and published to that server. Email for API keys goes out through Amazon SES in AWS's US East (N. Virginia) region, in the United States (see Developer API), and background notifications travel through your browser maker's push service (see Background notifications). The controller responsible for the personal data described here is 19 Lat (see Contact below).

Contact

Questions about this policy? Contact 19 Lat at predictsea@outlook.com.