Privacy policy

Privacy

Draft for review, dated October 10, 2026. This page describes the app’s behavior. It is the product disclosure to check before App Store submission.

Who operates Wavy

Wavy: Water Conditions is operated by James Jobs LLC. The public site is wavy.day. The app’s bundle id is com.wavy.app.jsd. Questions and deletion requests go to [email protected].

Wavy is a conditions reader for recreational time on the Great Lakes. It is not for navigation or safety-of-life decisions. Verify conditions with official sources before heading out.

What Wavy does not collect

Wavy does not:

  • ask for your name, email, contacts, photos, or health data
  • use an advertising identifier or track you across apps and websites
  • sell personal information, or share it for cross-context advertising
  • run analytics or advertising cookies on this website
  • keep a history of your phone’s location

This website does not create an account. Visiting it does not add you to a profile.

On your devices

Favorites, boats, outings, alert rules, and unit preferences are stored on the device. Scoring and the on-device narration run locally. The narration rephrases the score. It does not send that text to Wavy.

Optional iCloud sync uses your private iCloud database in the container iCloud.com.wavy.app.jsd for favorites, boats, pairings, and preferences. That data stays in your iCloud account. It is not copied to Wavy’s servers. Sync is not a production service until that container is configured and checked, and the app will not present it as available before then.

Phone location

If you allow location while using the app, Wavy takes one foreground fix to rank harbors near you. The permission line in the app is: “Wavy uses your location once to find the harbors nearest you. No tracking, no history.” That phone fix is used on the device. It is not uploaded and it is not retained as a location history.

Wavy does not request background location, and it does not ship geofenced marina alerts.

If remote alerts are turned on

Remote push alerts are not a production service yet. The app can register an install with Wavy’s Cloudflare service when that path is used. Registration is tied to a random installation id stored on the device, not to your name. For App Store privacy answers, treat the following as collected for app functionality, not linked to your identity, and not used for tracking:

  • Device ID: the installation id, a hashed device secret, the Apple push token, platform, app version, and an optional Live Activity token
  • Other user content: the alert rules you sync, and the spot and boat pairing identifiers those rules refer to
  • Precise location: the latitude and longitude of a saved spot attached to a synced rule, so the service can evaluate conditions at that spot. This is the spot’s coordinates, not a trail of your phone
  • An entitlement expiry time if server-side subscription checks are turned on. Purchase history stays with Apple. Wavy does not receive it today

Those records live in Cloudflare D1. Push delivery itself stays off until Apple push credentials and the app capability are in place.

Apple

Purchases and restores use StoreKit. Apple processes the payment. Subscription management, if Wavy+ is offered later, is in your Apple ID settings. If you choose to share crash or diagnostic data with Apple, that is Apple’s setting, not a Wavy account.

Public sources and cameras

Conditions come from public NOAA National Data Buoy Center observations and National Weather Service forecasts and alerts. Wavy may fetch those directly or through its Cloudflare API. Allowlisted NOAA BuoyCAM images may be stored in Cloudflare R2 for 30 days so the app can show recent frames. They are public buoy images, not pictures of you.

Other cameras are deep links. Wavy does not embed, proxy, analyze, or archive them. NOAA and NWS material is used with attribution. Wavy is not a government service and does not speak for NOAA or the National Weather Service.

Operational logs

Cloudflare may keep short-lived request logs, which can include an IP address and user agent, to run and protect the API. A rate-limit table stores a hash of the caller and a route, not the raw IP, for abuse control on registration. These logs are not used to build a marketing profile.

Retention and deletion

There is no Wavy account to delete. Phone location is not kept. Public observation history and BuoyCAM images follow the service retention above and are not your personal file.

Remote alert data is kept until the install deletes it. In the app, Settings includes “Delete alert data on Wavy’s servers.” That calls an authenticated delete for this installation id and removes the device row, push token, live activity token, alert rules, and related delivery state. Boats and favorites stored only on the device are left in place.

The installation id is shown in Settings after this install has created one. It is the only key Wavy has. Email alone cannot be matched to a row, because Wavy never received your email. If you already deleted the app and still have that id, write to [email protected] and include it. If you do not have the id, there is no record Wavy can look up.

Children, Canada, and other requests

Wavy is not directed to children under 13. The Great Lakes include Canadian waters. If you use Wavy from Canada, or you want a copy of the remote alert record for an installation id you still have, use the same contact. Wavy will not sell or share personal information as those words are used in US state privacy laws.

If the data practices change, this page will change and the date at the top will move with it. The App Store privacy URL for Wavy is https://wavy.day/privacy.