Privacy Policy
Last updated: August 24, 2026
Overview
Beachable ("the app") is a coastal activity conditions app for iOS and Android. This policy explains what data we collect, how we use it, and your rights. We collect only what is necessary to provide the app's features and do not sell your data to third parties.
Data We Collect
1. Home Location (Coarse Location)
When you set a home beach during onboarding or in Settings, you search for and select a named location. We store the name and coordinates of that place to fetch tide, wave, and weather data relevant to your area. This is a location you consciously choose, and it is the only location the app stores.
Your home location is stored on your device and, if you create condition alerts, is also sent to our servers (Firebase/Google Cloud) to power those alerts.
2. Device Location (Optional, Never Stored)
The app can use your device's location, with your permission, for three optional conveniences: finding the nearest coastal area during onboarding, showing a "you are here" dot on spot maps, and sorting a list of spots by distance from you. Location is requested only while you are using the app ("When In Use"), and only at the moment one of those features runs.
If you decline, every one of those features degrades to the manual equivalent and the rest of the app is unaffected. Nothing about the app requires your location.
Your device's coordinates are never written to storage and never sent to our servers. A position is held in memory only long enough to answer the question at hand (which saved area is closest, or how to order a list) and is then discarded. When the app fetches conditions, it sends the coordinates of a saved area you chose, not your device's position.
3. Device Identifier
When you enable push notifications, your device's Firebase Cloud Messaging (FCM) token is stored. This token identifies your device for the purpose of delivering alerts you create. It is not linked to your name, Apple ID, or any other personal account.
If you create a condition alert (swell, visibility, or beach window alert), your FCM token is stored alongside the alert's location and threshold in our database so we can send you the notification when conditions are met.
4. App Usage and Analytics
We use Firebase Analytics to understand how the app is used. For example, which tabs are visited, whether onboarding is completed, and whether paywalled features are viewed. We also collect your subscription status (free or Pro) as an anonymous property.
No analytics data is linked to your identity. Firebase Analytics uses an anonymous device-level identifier.
Firebase Analytics also automatically collects diagnostic information including device model, OS version, app version, and session data.
5. Crash Reports
We use Firebase Crashlytics to capture crash reports. These reports include device model, OS version, and a stack trace of the crash. They do not include any personal information and are used solely to identify and fix bugs.
6. Purchase History
If you subscribe to Beachable Pro, your subscription status (active, expired) is stored locally on your device and logged anonymously to Firebase Analytics for aggregate revenue tracking. We do not store your payment details. All billing is handled by Apple.
7. Feedback You Choose to Send
If you use Settings → Feedback to suggest a spot or report a bug, we receive what you typed (a spot name, notes, or a bug description), and, for a spot suggestion, the map location you picked. Bug reports may include a screenshot you attach, which is stored in Google Cloud Storage. Only what you attach is sent; the app never captures your screen on its own.
Each submission also carries basic technical context so a report is actionable: platform, app version and build, OS version, device model, language, and the name of your saved home area. It is linked to the same anonymous device identifier described above, never to a personal account.
Data We Do Not Collect
- Your name, email address, or any contact information
- Any stored record of your device's location (see section 2)
- Your Apple ID or any account credentials
- Health or fitness data
- Information from your contacts or calendar (beyond what EventKit requires to add a calendar event you explicitly request)
- Advertising identifiers (IDFA)
Third-Party Services
The app uses the following third-party services that may process data as described above:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Firebase Analytics | App usage analytics | google.com/policies/privacy |
| Firebase Crashlytics | Crash reporting | google.com/policies/privacy |
| Firebase Cloud Messaging | Push notifications | google.com/policies/privacy |
| Google Cloud Firestore | Alert data storage | google.com/policies/privacy |
| WorldTides API | Tide data | worldtides.info |
| NOAA NDBC | Wave/buoy data | Public government data, no personal data sent |
| Open-Meteo | Marine weather forecast | open-meteo.com |
| Google Cloud Storage | Screenshots you attach to a bug report | google.com/policies/privacy |
Amazon Web Services (api.beachable.app) | Our conditions API, receives saved-area coordinates | aws.amazon.com/privacy |
| NOAA CoastWatch | Satellite water clarity and sea-surface temperature | Public government data, no personal data sent |
| CDIP (Scripps) | Nearshore wave model data | Public research data, no personal data sent |
| sunrisesunset.io | Sunrise and sunset times | Public API, no personal data sent |
Data Retention
- On-device data (home location, preferences, cached tide data): retained until you delete the app.
- Alert data in Firestore (FCM token + alert coordinates): retained until you delete the alert in the app. Alerts with invalid or stale device tokens are automatically disabled, and we periodically delete alert records whose device can no longer receive notifications. Note that uninstalling the app does not by itself delete these records, because the app has no way to tell our servers it is being removed. Delete your alerts before uninstalling, or email us and we will remove them.
- Analytics and crash data: retained per Google/Firebase's standard retention policies (up to 14 months for Analytics). You can turn this collection off entirely in Settings → Privacy → Share Usage Data, which stops both usage analytics and crash reporting.
Your Choices and Rights
Turning collection off. Analytics and crash reporting can be switched off in the app at Settings → Privacy → Share Usage Data. Push notifications and alerts can be switched off in Settings → Notifications. Location is requested only when you use one of the three optional features described in section 2, and declining leaves the rest of the app unaffected.
Who is responsible. Beachable is operated by Scott Bishop, who is the data controller for the purposes of the UK and EU GDPR. Contact: support@beachable.app.
Why we are allowed to process this data. Where the UK or EU GDPR applies:
- Your saved home location, saved spots and alert records are processed to perform the service you asked for (Article 6(1)(b)). The app cannot show conditions for an area you have not chosen, or send an alert without storing the alert.
- Usage analytics and crash reporting are processed with your consent (Article 6(1)(a)), which you give or withdraw with the Share Usage Data switch. Withdrawing it does not affect anything else in the app.
- Feedback you send is processed to respond to and act on it (Article 6(1)(b) and our legitimate interest in fixing our own bugs, Article 6(1)(f)).
Your rights. Where the UK or EU GDPR applies you have the right to access the data we hold about you, to have it corrected, to have it deleted, to restrict or object to its processing, to withdraw consent, and to receive it in a portable form. California residents have parallel rights under the CCPA/CPRA, including the right to know and the right to delete. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
How to exercise them. Most of it you can do yourself, immediately, in the app: deleting an alert deletes its record, and deleting the app removes everything stored on your device. For anything else, including a copy of what we hold or deletion of alert records left behind by an uninstall, email support@beachable.app. We will respond within 30 days.
One honest limitation. We deliberately do not have accounts, and we do not collect your name or email address. Alert records are keyed to an anonymous device notification token, so to find your data we need that token or enough detail to identify the records (for example the spot names and approximate dates). If you have already uninstalled the app, that token is gone from your device and we may not be able to locate your records, which is also why there is very little to find.
Children's Privacy
Beachable is not directed at children under 13. We do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top will reflect any changes. Continued use of the app after changes constitutes acceptance of the updated policy.
Contact
If you have questions about this privacy policy, contact:
Scott Bishop support@beachable.app