Privacy Policy

Last updated 6 August 2026

Draft, pending legal review. skipper.id is in a private pilot. What follows describes how the service actually handles data today — it is accurate to the system, but it has not been reviewed by a lawyer and is not yet a binding legal document. Questions in the meantime: reach the founder directly.

skipper.id is a document vault for yacht skippers. You upload your own certificates and identity documents, we keep them safe, and you decide which charter company sees what — through a link you create and can revoke.

What we store

  • Your account: name, email address, and whether that address has been confirmed. If you sign in with Google, we receive your name and email address from Google — nothing else.
  • Your profile: display name, country, languages, and the sailing CV you write yourself.
  • Your documents: the files you upload, plus their type, title and expiry dates. When you upload a photo or scan (JPEG, PNG or WebP) through this site, we remove the hidden metadata a camera writes into it — including the coordinates of the place it was taken — before the file is stored. The picture itself is not altered. A PDF is stored exactly as you sent it: we do not open it, because flattening it would destroy the pages and text inside — which means a PDF keeps whatever its author, scanner or phone wrote into it, and any photographs inside it keep theirs. Both of these happen in your browser, so they cover files uploaded through our pages.
  • Identity records: passport and national ID numbers, if you choose to add them. These are encrypted before they are written down, kept apart from everything else, and never included in a share link or shown to a charter company.
  • Citizenship, residence, permits and visas: the countries whose citizenship you hold (or a statement that you hold none), where you live, and the residence permits and visas you tell us about, with their dates. Encrypted and kept in the same place as the identity records above, on the same terms. Two things about this section are deliberate. Nationality — what you call yourself — is optional, is never taken from a document, and no conclusion anywhere on this site is drawn from it: under EU law it can reveal ethnic origin, which is a category we do not reason about. And we make one statement of our own from this data, that a citizen of an EU/EEA state moves freely within the EU/EEA — a right, not a lookup. Everything else here is your word, shown as your word.
  • Access records: which document was opened, through which link, and when. For a share link we also keep each attempt to enter its PIN, whether it succeeded, and what the browser said about itself. We do not record who the reader is: a share link needs no account, so there is no name to record. Your IP address is stored as a one-way hash, never as the address itself.

Where it lives

On our own servers in Estonia — the files in our own storage, the database on the same machine. We do not put your documents in an external cloud.

Text recognition runs on our own hardware. When you upload a document we read the dates and numbers off it to fill the form for you. That happens in a process on the same machine: the file is not sent to any AI service or outside company. The result is only a suggestion — you confirm or correct every field before it is saved.

When you report a problem.The button in your account sends us what you wrote, plus the context we would otherwise have to ask you for: the page you were on, the document it concerned if it concerned one, the version of the app, your browser’s identification string, window size, language and time zone, your account’s email address, the last few errors the page recorded, and the time we received it. For those errors we keep the kind of failure and where in our codeit happened — not the error’s wording. That wording is the one part that can quote what you had typed: an error about an unreadable document can carry the document number inside it. So it is dropped before the report leaves your browser, and never what you had typed, never anything from another person’s account. It becomes a support ticket in our own tracker and is stored nowhere else — there is no table of reports. If you were on a page whose address carries a sharing link, the link itself is stripped out before the report leaves.

The address of that page also becomes the ticket’s title, so it is visible in the list of open tickets and not only inside your own. Nothing else you send appears there.

The report reaches us through a receiving service shared with the other sites of the same owner. Your browser never contacts it — our own server passes the report on — and what it is told about you is your account’s identifier, not your email address and not your name. Your IP address is not passed on at all.

When you write to us without an account. The support form at /support sends us what you wrote, what you said it was about, and — only if you ask for a reply — the address or handle you gave and the time we received it. Choosing “No reply needed” means exactly that: no contact detail is kept and none is sent on. We do not put your IP address or your browser into that message; for a stranger who wrote to us once, they would be personal data with no use that justifies it.

That page sets one cookie, and only so that the limit on how often the form can be used counts you rather than your whole office — behind a shared connection, one person’s messages would otherwise use up everyone’s. It holds sixteen random bytes and nothing else: no name, no account, no history. Scripts cannot read it, it is not used for analytics or advertising, it never reaches the message we send, and it expires after 30 days.

That tracker is private: it has no outside collaborators and no deploy keys, and exactly two people can read it — the founder and our operations account. The bridge that files your report holds a key that can do one thing, create a ticket. Whoever can open a ticket can also open anything attached to it; that circle is the same two people.

Who else is involved

  • Google — only if you choose to sign in with Google. Google tells us your name and email address so we can create your account.
  • The charter company you share with — sees only what your share link exposes, and only until you revoke it or it expires.

We do not sell your data, we do not use it for advertising, and we do not send your documents to anyone you have not shared them with.

How long we keep it

  • While your account exists: your profile, documents and identity records stay until you delete them.
  • Deleted documents: hidden immediately, then permanently erased — file and record — after 30 days. That window exists so an accidental deletion can be undone.
  • Expired share links: removed automatically.
  • Problem reports: your message goes to our mailbox and to our ticket tracker; the technical copy on the receiving server lives 30 days and is then deleted automatically. Ask us to delete it sooner and we will. For the mailbox and the ticket we do not print a number here yet: we would only be repeating one we cannot show a mechanism for, and a date with nothing behind it is worse than saying nothing. It is named as soon as there is a job that enforces it.
  • Backups: kept 14 days, then deleted. A document you erase may survive in a backup until that window passes.

Your rights

Under the GDPR you can ask for a copy of your data, correct it, or have it erased. Two of those are buttons rather than requests:

  • Export — download everything we hold about you, including your files.
  • Delete your account — removes your profile, documents, identity records and share links.

You can also object to how we handle your data, or complain to the Estonian Data Protection Inspectorate.

Contact

skipper.id is run from Estonia. During the pilot, reach the founder directly — the operating entity, its registered address and a data-protection contact will be named here before public launch.