Legal
Privacy policy
Last updated: 7 October 2026
This policy explains what personal data we process when you use sailed.at, why, who receives it, how long we keep it, and what rights you have. We keep it as short as the facts allow.
1. Who is responsible
The controller under Art. 4(7) GDPR is:
Kirill Zhukov, Konrad-Zuse-Str. 26B, 60438 Frankfurt am Main, GermanyEmail: humans [at] sailed.at
There is no data protection officer; we are not required to appoint one. Contact us at the address above for anything in this policy.
2. The short version
- You can browse, explore and generate a couple of trails without an account.
- There is no advertising, no analytics and no tracking. We only use storage that is needed to run the site (see our cookie and storage notice).
- Trails, recipes and profile details you publish are public. Everything else is private to you unless you share it.
- AI features send the text you enter to an AI provider. Do not put personal data about other people into prompts.
- Our database and file storage are in the EU (Frankfurt). Some providers we use are in the US (section 6).
3. What we process, why, and on what legal basis
Visiting the site. When you load a page, our hosting provider processes your IP address, browser type, the page requested and a timestamp in server logs. This is needed to deliver the site and keep it secure (Art. 6(1)(f) GDPR, legitimate interest). The retention period is set by the hosting provider and is short.
Maps and images. Maps are drawn in your browser from tile servers run by third parties (OpenFreeMap, OpenSeaMap, MapTiler and, for some layers, EMODnet). Some place photos load from Wikimedia Commons or Mapillary. Your browser contacts these servers directly, so they receive your IP address, browser details and the area you are viewing. We have no control over their logs. Legal basis: Art. 6(1)(f) (showing the maps you asked for).
Your account. You sign in with an email link or with Google. We process your email address and, if you use Google, the name and picture Google shares with us. We also store the profile details you choose to add (handle, name, bio, home port, avatar, sailing experience, links). Legal basis: Art. 6(1)(b) (providing the account you asked for). Your handle, and anything else you mark as public, is visible on your public profile and on your trails.
Trails, recipes, ratings and uploads. What you create is stored with your account. A draft is private. When you publish a trail or recipe it becomes public together with your handle, and you grant others the licence described in our terms. Legal basis: Art. 6(1)(b).
AI features. When you generate or refine a trail, the text you type and the trail data needed for the task are sent to our AI provider (Anthropic), which returns the result. This also applies to visitors without an account. Do not enter names, health data or other personal data of third parties. AI output can be wrong; see our terms. Legal basis: Art. 6(1)(b) for account holders and Art. 6(1)(f) for visitors.
Abuse prevention. To stop automated misuse of the free AI features we (a) count requests per day using a pseudonymous, salted hash of your IP address (for IPv6, of your network prefix); the counters are deleted after about two days, and (b) ask visitors without an account to pass a bot check by Cloudflare Turnstile before generating a trail. Turnstile runs in your browser and sends technical signals to Cloudflare; after a successful check we set a signed, one-hour cookie (sailed_pass). Legal basis: Art. 6(1)(f) (protecting the service from abuse and its cost).
Error monitoring. When the site hits an error we send a report to an error monitoring service hosted in the EU (Sentry). It contains the error message, technical stack trace and the page path with any query string or private link token removed. It does not contain your account details. Legal basis: Art. 6(1)(f) (keeping the service working).
Contact and reports. If you write to us or use the contact or report form, we process what you send us (including your email address) to answer you and to handle the matter. Legal basis: Art. 6(1)(b) or (f), and Art. 6(1)(c) where we must handle legal notices. We keep correspondence until the matter is resolved and then, for legal claims, up to three years.
Voyages (private beta). Invited skippers can plan voyages and invite crew by link. A skipper may enter crew names, contact details, dietary needs, notes and photos. The crew link needs no account; a crew member can claim a seat on their device. These details are visible to the skipper and to the crew as set in the app, and optional fields such as dietary or medical notes may reveal health information. Please enter only what is necessary. The skipper decides what to enter about crew and is responsible for informing them; we process it on the skipper's behalf to run the voyage. Crew can ask us to delete their data (section 8).
Telegram bot (private beta). If a skipper connects the First Mait Telegram bot to a crew group, messages sent to the bot and the group's identifiers are processed in Telegram and by us to run the bot. Telegram is an independent controller for its own service. Messages sent through Telegram are not confidential from Telegram.
4. AI features and how we label them
Trails, descriptions, suggestions and some images on sailed.at are produced or assisted by AI ("First Mait"). You interact with an AI system when you use First Mait. AI output can contain mistakes: check distances, hazards and facts against official sources before you rely on them. Nothing on the site is a navigation instrument or professional advice. No decision is taken about you by fully automated means that has legal or similarly significant effects (Art. 22 GDPR).
5. Who receives data (processors and others)
- Supabase (database, sign-in, file storage): hosts all account and content data in Frankfurt, Germany. It sends sign-in emails for us.
- Vercel Inc. (web hosting and delivery): processes request data and delivers the site.
- Anthropic (AI model provider): receives the text and trail data you submit to AI features.
- Cloudflare: provides DNS for our domain and the Turnstile bot check.
- Sentry (EU region): error monitoring.
- Map and image providers (OpenFreeMap, OpenSeaMap, MapTiler, EMODnet, Wikimedia Commons, Mapillary): receive your browser's requests directly when you view maps and photos.
- Place and weather data services (OpenStreetMap Nominatim/Overpass, LocationIQ, Wikidata, Open-Meteo, a marine-weather service): receive place names or coordinates from our servers, not your IP address or account.
- Google: if you choose "Continue with Google", Google is the controller for its own sign-in service and tells us who you are.
- Telegram and Firecrawl (link previews): only if you use the beta features that depend on them.
We sign data processing agreements with processors where required. We do not sell personal data and we do not share it for advertising.
6. Transfers outside the EU
Some providers above (for example Vercel, Anthropic, Cloudflare and Google) are US companies or process data in the US. Where this involves personal data, we rely on the EU-US Data Privacy Framework for certified providers or on the EU Standard Contractual Clauses (Art. 45 and 46 GDPR). A copy of the clauses can be requested from us.
7. How long we keep data
- Account, drafts, recipes and uploads: until you delete them or your account. Published trails: until you ask for them to be deleted (they stay, anonymised, after you delete your account).
- Abuse-prevention counters: about two days.
- Server logs: a short period set by the hosting provider.
- Error reports: for as long as needed to fix the problem, normally weeks.
- Contact and report correspondence: until resolved, then up to three years for legal claims.
- Voyages and crew data: until the skipper or the account holder deletes them or the account is deleted.
8. Your rights
You have the right to:
- access the data we hold about you (Art. 15) and receive a copy in a common format (Art. 20);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17) and processing restricted (Art. 18);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent at any time, without affecting earlier processing (Art. 7(3)).
Deleting your account. You can delete your account in Settings → Account. This deletes your profile, your drafts, your voyages, the files you uploaded and everything else tied to your account. Trails you have published stay available to the community under the licence in our terms, shown as by "Former member" with no link to you, and with your private notes and credit details removed. If you want them deleted too, tick the box when you delete your account, or ask us later at the contact address below (name the trail). Copies others already made or exported under the licence cannot be recalled.
Getting a copy of your data. Use Download my data in Settings → Account: you get one machine-readable (JSON) file with your profile, trails including drafts and private notes, ratings, recipes, places, messages to us, boats and voyages. Uploaded files are linked, not included. Other people's private details (such as crew contact and medical information) and ratings others gave you are not part of it. Individual trails can also be exported from their page as GPX, KML, CSV or a full-data file.
Other requests. For anything else, or if you cannot sign in, email humans [at] sailed.at from the address you signed up with. We answer within one month. Crew members without an account can email us as well.
Complaints. You can complain to a data protection supervisory authority. For us this is The Hessian Commissioner for Data Protection and Freedom of Information (HBDI) (https://datenschutz.hessen.de), or the authority where you live or work.
9. Age
Accounts are for people aged 16 or over. Skippers who enter details about children aboard must have the authority to do so as a parent or guardian.
10. Security
Connections are encrypted (HTTPS). Access to data is limited by database access rules so that private content is only readable by its owner and, for voyages, by the people the skipper invites. No system is perfectly secure; if a breach affects you we will notify you and the authority as the law requires.
11. Changes
We will update this policy when the service or the law changes, and show the date at the top. If a change materially affects you we will tell you in the app or by email before it applies.