Beta Pacific · BoatPlay

Privacy and data retention policy

Written for boat owners, in plain language. What BoatPlay records about you and your boat, who can see it, how long it is kept, and how to get a copy or have it deleted.

Effective September 5, 2026 Applies to the BoatPlay app, BoatPlay OS aboard your boat, and the BoatPlay cloud service Contact hello@betapacific.com

The short version

  • Your boat's computer records your boat's telemetry (position, battery, motor, and similar signals) and keeps the detailed history on the boat.
  • When your boat has internet, it uploads that telemetry to our cloud server so you can see it in the phone app and so we can help you with support.
  • You can see all of your own boat's data. Our support staff can look at your boat's data to help you, and every single look is recorded where you can see it. Anyone you share a trip link with can see that one trip, until the link expires or you revoke it. Nobody else, not other boat owners, the public, or advertisers, can see your data. We do not sell data and we do not share it with third parties for their own purposes.
  • Detailed data on the boat is deleted automatically after 7 days; hourly summaries are kept for a season (180 days). In the cloud, raw telemetry is deleted automatically after 90 days and hourly summaries are kept. See the retention table.
  • If your boat has cameras, the boat's computer records video on the boat only, kept for 48 hours and then automatically deleted. You can view a bandwidth-limited live still feed from the phone app, and every remote view is logged. Recorded video never leaves the boat.
  • There are no user accounts, no names, no email addresses and no payment data in the BoatPlay system. The app identifies your boat with a per-boat credential, not a login.
  • You can ask for a copy of your data, or for it to be deleted. The exact procedure is below.

What data is collected

The onboard recorder polls the boat's instrument network once per second and stores numeric values. These are the data types:

Data typeExamplesWhere it lives
Position and trackLatitude and longitude, speed over groundBoat, then cloud
Boat telemetryHouse battery voltage, current, charge and temperature; motor rpm, temperature and derating; solar and shore charging; battery model estimates; wind; depthBoat, then cloud
Connectivity healthSatellite link state, latency, throughput, packet loss, obstruction; internet data-usage counters against the data plan (total bytes per billing cycle, never per device or per site)Boat, then cloud
Boat and credential dataBoat name, MMSI, vessel identifier; API credentials, stored only as one-way hashes, never the tokens themselvesCloud
Support access eventsOne record every time a support operator views your boat: who, when, why, and exactly what they looked atCloud
Share linksWhich trip was shared, when, when the link expires, whether it was revoked; the share token itself is stored only as a hashCloud
Video segmentsTimestamped 60-second video files per camera, recorded at 1280×720, 15 frames per second, with no audioBoat only, never uploaded
Camera stillsStill frames captured on demand or for the remote-view feedBoat; the latest frame per camera only is also in the cloud
Camera view eventsOne record every time the remote camera feed is viewed: who, when, which camera, how many bytesCloud
Push notification subscriptionsThe push endpoint and its encryption keys, a device label, when it was last used; your alert on/off choices; and the keys of alert events already sent, so a retried upload never notifies twiceCloud
Geofence configurationThe fences you set: name, centre position, radius, on or off. Also cached on the boat, which enforces the last known fence when it has no internetCloud, cached on boat
Immobilise requestsEach request you file: reason, which credential filed it, its status and timestamps; every status change is recorded permanently. These are requests to support, recorded for accountability. No command is ever sent to your boatCloud

A note on position recording. The system is built to record your position; the trip history, share links and support track view all depend on it. This policy treats position as collected data because that is the conservative way to write a privacy policy, even where the exact position feed is still being finalised.

What is not collected

  • No user accounts, no names, no email addresses, no payment data. The phone app identifies your boat with a per-boat credential, not a login.
  • No audio. The telemetry recorder stores numbers only. The camera recorder records video without audio, on the boat, under the retention windows below.
  • No video history in the cloud. Recorded video segments never leave the boat. The only camera data in the cloud is the single latest low-resolution still frame per camera, refreshed by the boat so the phone app can show a live view. Each frame replaces the previous one; the cloud keeps no frame history.
  • No guest WiFi data. The guest WiFi network on the boat collects nothing about guest devices: no device identifiers, no traffic metadata, no DNS logs. The only guest-related number anywhere is the router's total data counter, which is shared boat telemetry. The guest passphrase never leaves the boat.
  • No advertising identifiers, no analytics trackers, no third-party SDKs that profile you. Software-update data (release versions and rollout state) is fleet configuration, not data about you.

The phone app

The BoatPlay app for iPhone and iPad is a window onto your boat. It has no accounts and no sign-in. It talks to your boat directly over the boat's WiFi when you are aboard, and to the BoatPlay cloud service when you are away.

  • Boat credential. The app stores your per-boat credential on the device so it can reach your boat. It is never sent anywhere except your boat and our cloud service.
  • Location. The app uses your phone's location only to show your own position on the chart alongside the boat. It is not uploaded and not stored by us. You can decline the permission and the app keeps working.
  • Notifications. If you turn on alerts, the app registers with Apple's push notification service so your boat's alerts (for example "house battery low" or a geofence breach) reach your phone. The registration is described in the table above and is removed when you turn alerts off.
  • Charts and map tiles. The chart is drawn from OpenStreetMap and OpenSeaMap data. Tiles are fetched from those projects' servers, which see the ordinary technical information any web request carries (your IP address and the tiles requested). Charts in the app are not official nautical charts and are not for navigation.
  • Demo mode. The built-in demo boat is a bundled dataset replayed on the phone. In demo mode nothing is sent to any server.
  • No tracking. The app contains no advertising, no analytics and no tracking across apps or websites.

What leaves the boat

Only the telemetry above leaves the boat, and only when cloud sync is configured. The boat copies new recorded points into a durable on-boat queue and uploads them in batches, oldest first, over an encrypted connection to our ingest service. Points are removed from the queue only after the cloud confirms it stored them; if the link is down, the queue simply grows, bounded so that the oldest queued points are dropped after roughly 11 hours, because the boat's own 7-day local history still holds them.

If cameras are configured, one more thing leaves the boat: the latest still frame per camera, a small image refreshed every few seconds so the phone app can show a live view. Recorded video segments and older frames do not leave the boat.

If you enable push alerts, alert events leave the boat: a title, a short text and an identifier, with no other content, queued on the boat until the cloud confirms receipt so no alert is lost when the connection drops.

In the other direction, the boat downloads your geofence configuration from the cloud and caches it on board so it keeps enforcing your fence when offline. Nothing about immobilise requests travels to or runs on the boat: those are cloud records for you and support staff only.

If no cloud service is configured, nothing leaves the boat at all.

Who can see your data

WhoWhat they can seeHow it is controlled
You, the ownerEverything about your own boat: live status, trips, share links, the support-access audit trail, and the camera feed (bandwidth-limited; every view is logged)Per-boat credential. The phone app uses a read-only scope that cannot write telemetry.
Our operators (fleet dashboard)Every boat's latest position, key readings, and online or degraded stateA single operator credential; the service refuses to start without one.
Our support staffYour boat's live state, signal history and recent track, read-only. Every access is recorded (who, when, why, what they viewed) before any data is shown; if the record cannot be written, the view fails and no data is served. They also see your pending immobilise requests and can acknowledge one, which is a recorded note on a cloud record, never a command to your boat.You can see the same audit trail yourself in the app.
People you send a share link toExactly one trip: its track and stats (distance, duration, energy). Nothing live, nothing else, nothing writable. No account needed.Unguessable token, expires after 30 days, revocable by you at any time; search engines are told to stay out and the link never leaks as a referrer.
Other boat ownersNothing of yours.Enforced twice: the credential check at the service, and row-level security inside the database, so one boat's credential physically cannot read another boat's rows.
The public, advertisers, data brokersNothing. We do not sell or share data.

Support staff cannot change anything on your boat through this system; the support view has no write path at all. Because credentials and share tokens are stored only as hashes, even a copy of the database would not hand anyone a working token.

Remote camera viewing

Only you can view your boat's camera feed. The feed is a small still frame refreshed by the boat, served under a per-boat bandwidth cap so viewing can never starve telemetry on the satellite link. Every view is recorded (who, when, which camera, how many bytes) in the same transaction that serves the frame; if the log record cannot be written, no frame is served. The support view does not include the camera feed. Recorded video segments stay on the boat and are never viewable remotely.

How long we keep it

DataWhereKept for
Raw telemetry (1-second points)On the boat7 days, then automatically deleted
Hourly summariesOn the boat180 days (a full cruising season), then automatically deleted
Sync queue (points awaiting upload)On the boatUntil the cloud confirms receipt; capped at about 11 hours of data, oldest dropped first
Raw telemetryIn the cloud90 days, then automatically deleted, and only once the hour containing them has been summarised
Hourly summariesIn the cloudKept indefinitely; recomputed from the raw points before any raw point is deleted
Share linksCloudThe link works for 30 days, then answers "gone"; you can revoke sooner. The record that a link existed, and when it expired or was revoked, is kept as an audit trail
Support access eventsCloud2 years (730 days), then automatically deleted. They are the accountability record for access to your data, so they outlive the telemetry they describe without being kept forever
Camera view eventsCloud2 years (730 days), the same window as support access events
Video segmentsOn the boat48 hours rolling, then automatically deleted; a hard 20 GB disk budget additionally drops the oldest footage first
Camera stillsOn the boat24 hours, then automatically deleted
Latest camera frame (remote view)CloudOnly the newest frame per camera is kept; each upload replaces the previous one
Push notification subscriptionsCloudUntil you turn off alerts on that device, or the subscription stops working; a dead endpoint is deleted automatically on the next send
Alert preferencesCloudUntil you change them. Critical alert types (alarm raised, geofence breach) cannot be turned off
Alert de-duplication keysCloud90 days, the same window as raw telemetry
Geofence configurationCloud, cached on the boatUntil you delete or change the fence; the on-boat cache is overwritten by the next configuration pull
Immobilise requests and their audit trailCloudKept indefinitely as the accountability record for a security request, unless you ask for deletion (below)
CredentialsCloudActive until revoked; revoked credentials are kept as inactive rows (hashes only, never usable tokens)
Boat record (name, MMSI, identifier)CloudUntil you ask us to delete it

These windows are enforced by scheduled jobs on the boat and in the cloud, not by hand.

Getting a copy of your data

You can read your live status, trips and support-access audit trail in the phone app at any time. For a full export:

  1. Email hello@betapacific.com from the credential holder for your boat.
  2. We verify the request against your boat's credential.
  3. We produce an export of everything we hold for your boat as CSV and JSON files: all raw telemetry and hourly summaries; your boat record; your share-link records (never the tokens); your support-access and camera-view audit trails; your credential list (names, scopes, issue and revocation dates, never the tokens, which we do not store); your push-notification subscriptions and alert preferences; your geofence configuration; and your immobilise requests with their audit trail.

There is no self-serve export button yet. The procedure above is the committed path until one exists.

Deleting your data

On your verified request, we will, in order:

  1. Revoke every credential for your boat, so the phone app and the boat itself lose access.
  2. Revoke every share link for your boat, so all shared trips immediately answer "gone".
  3. Delete all telemetry, every raw point and hourly summary stored under your boat, cloud-side.
  4. Delete your push subscriptions and alert preferences, so no notification can be sent to any of your devices again.
  5. Delete your geofence configuration, immobilise requests and their audit trail.
  6. Delete your boat record (name, MMSI, identifier).

What deletion cannot do, honestly:

  • The copy on your boat. The onboard computer holds its own 7-day raw and 180-day summary history plus the 48-hour video and 24-hour stills windows. That hardware is yours; wiping it is something you do on the boat, or we can talk you through it. We have no remote-delete capability for it.
  • Copies other people already made. If you shared a trip link, a recipient may have saved or screenshotted the page. Revoking the link stops future access; it cannot recall copies that already exist.
  • Backups. Our cloud backups are overwritten on their normal rotation; a deletion takes effect in the live system immediately and disappears from backups as they rotate.
  • Support-access audit records. We keep these, stripped to the minimum needed, for their 2-year window, because they are the record of who looked at your data and when, which protects you.

Children

BoatPlay is made for boat owners and is not directed at children. There are no accounts, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, contact us and we will delete it.

Changes and contact

If this policy changes, the new version is published here with a new effective date and the change is called out in the app's release notes. Questions, export requests and deletion requests go to hello@betapacific.com.

Beta Pacific, 12 Channel Street, Boston, MA 02210, United States.