Kurshalter privacy policy
Last updated: 19 September 2026
This policy covers kurshalter.com, including its chart demo, email contact and public share viewer, and the associated app. Sections 1.1 to 1.4 cover the website; sections 2 to 7 explain app features. Deutsche Fassung.
At a glance
- The website uses no analytics or advertising services and sets no cookies itself. Hosting and chart requests still involve IP addresses and technical request data.
- The website does not request your device location. The homepage demo uses a prepared voyage. The share viewer shows the position of the person who created the link.
- Kurshalter has no user accounts. The current Free/Plus app does not show advertising.
- The app includes Google AdMob and its consent manager for optional banners. While advertising is disabled, the app does not initialize advertising or request ads.
- We do not sell your navigation data or send your routes, tracks or precise GPS position to advertising providers. Advertising, if enabled, is described in section 2.
- Your routes, waypoints, tracks, boat profile, settings and downloaded charts are stored on your device. Exports and optional live position sharing send the data you choose.
- Online features send the request data described below to our server. Optional live sharing stores positions and a recent trail until deletion or expiry. Requests also generate technical logs; having no account does not make these data anonymous.
- Background location runs only for track recording and the anchor alarm, only while you have switched them on.
1. Controller
The controller responsible for processing personal data in connection with Kurshalter (Art. 4 (7) GDPR) is:
Luke Friedrichs
Leibnizstraße 2
48565 Steinfurt, Germany
Email: contact@kurshalter.com
You can contact the controller directly about privacy.
1.1 Website, hosting and delivery
Our website is hosted by Cloudflare, Inc. When you visit, Cloudflare processes your IP address, requested address, time, browser and connection data and response status to deliver the page and prevent attacks. For shared links, the path can contain the share identifier. We do not use visitor profiles, advertising pixels or separate audience analytics. Fonts and images are served with our website and chart resources; Google Fonts is not embedded.
The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in a secure, accessible presentation of our product. Technical connection data is necessary to deliver the page; delivery is not possible without it. You need not provide other details to browse.
The website sets no cookies itself and uses neither local storage nor session storage to recognise visitors. The selected chart mode and browser information about platform, screen, colour scheme and reduced motion are processed temporarily for presentation. We do not create a device fingerprint. Necessary device access and ordinary caching of requested files serve the requested display (§25(2) TDDDG). Browsing does not require consent to advertising.
We do not create an additional database of website visits. Cloudflare also processes security and network data for its own security purposes. Its retention depends on what is necessary for delivery, detecting and investigating attacks, and legal obligations. The 30-day limit for our API logs below is not a blanket promise about Cloudflare's own systems. See Cloudflare's privacy policy.
1.2 Chart demo
When the chart view is available, the homepage automatically loads charts, fonts and a data manifest from our Cloudflare R2 storage at tiles.kurshalter.com. This transmits your IP address, file paths and requested byte ranges. The demo plays a prepared voyage; it does not read GPS location or request an individual route calculation. Chart requests can reveal the displayed area. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in demonstrating the product. Recipients and retention are covered in sections 1.1 and 8.
1.3 Opening a live share
Opening a share link sends its identifier and your IP address with technical connection data to our API server at Railway. The viewer periodically requests the shared position and loads charts from Cloudflare. Chart requests can reveal the area of the shared position. Your own device location is not requested. The display ends when sharing is stopped or expires; closing the page stops further requests.
The legal basis for delivery to viewers and abuse prevention is Art. 6(1)(f) GDPR, our legitimate interest in securely displaying what the sender chose to share. Section 5 covers API logs. The positions originate from the person who created the link in the app. Anyone holding the link can view them and save copies, so treat the link as confidential. Server deletion does not delete recipients' copies. The website stores no additional history; server-side sharing storage is described in section 4.
1.4 Email contact and external links
Our email links open your email program. Only when you send a message do we receive your address, any name provided, message, attachments and technical message details. We process them to handle your enquiry: under Art. 6(1)(b) GDPR for contractual or pre-contractual matters, otherwise under Art. 6(1)(f) GDPR for our legitimate interest in answering. Providing information is voluntary; we cannot reply without a reachable sender address. Contacting us does not subscribe you to newsletters or marketing emails.
Messages to contact@kurshalter.com are forwarded through Cloudflare Email Routing to our personal Gmail inbox. Cloudflare, Inc. processes the message, including attachments, sender and recipient addresses, and technical message details to deliver it. See section 8 and Cloudflare’s privacy policy for information about Cloudflare and possible international transfers. Our replies currently come from the Gmail address. Google processes message content and metadata. For the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is the provider named in Google's privacy policy. Google LLC in the USA and other Google service providers may also receive data. Google's own processing is governed by the purposes, retention rules and transfer mechanisms described in its privacy policy and international-transfer information. This is not a Google Workspace business mailbox.
We delete ordinary enquiries once they are fully handled and no follow-up is expected, at the latest after six months. Only where legal retention obligations or establishing, exercising or defending specific legal claims require longer retention do we keep the necessary data until the applicable period ends or the matter is finally resolved. The legal bases are then Art. 6(1)(c) or (f) GDPR respectively.
External websites, such as data sources or app stores, are contacted when you follow their links. Their respective providers' privacy information applies there.
2. Accounts and optional advertising
The app works without registration. Its navigation services use our own API and chart storage. There is no separate analytics or crash-reporting service.
The current Free/Plus app does not show advertising. The binary still includes Google Mobile Ads (AdMob) and Google's User Messaging Platform (UMP), but this app version does not load the advertising provider, request consent messages or load ads. A server setting cannot enable advertising in this version. Introducing advertising would require an app update and updated disclosures. The following paragraphs describe that optional future functionality, not current advertising activity.
If advertising is enabled, a labelled, non-personalized banner may appear below the saved-route list, track list or offline-chart catalogue. No banners appear on the chart, during route navigation, track recording, anchor watch, a MOB situation or in night mode. Core functionality does not depend on accepting advertising consent.
Before requesting ads, UMP updates the relevant consent requirements and displays a consent message where required. Google determines the permitted ad-serving mode from these choices. Non-personalized does not mean anonymous or consent-free. Google may process IP addresses (including approximate location inferred from them), device and advertising identifiers, ad interactions and diagnostics for delivery, measurement and fraud prevention. We do not attach precise location, boat details, routes, search queries or custom audience identifiers to ad requests. We do not request Apple's tracking permission or intentionally enable personalized advertising.
Where consent is required for accessing information on your device or processing personal data for advertising, the legal basis is §25(1) TDDDG and Art. 6(1)(a) GDPR. Refusing or withdrawing consent leaves the navigation features available. Use Settings → Advertising → Ad privacy choices to review available choices. Google may offer limited ads under its consent framework; the app never treats a dismissed form alone as permission to load ads.
Google's advertising and consent services may transmit data outside the EEA. See Google's partner-data explanation and Google's privacy policy for processing, retention and transfer information. Our own retention limit in section 5 applies to our server logs, not to Google's services. Advertising will only be enabled after the operator has completed AdMob's privacy messages, contractual and international-transfer review, and the store disclosures for the shipped SDK version.
3. Data stored on your device only
The following data is stored locally by default. Exports and live position sharing that you explicitly start are exceptions:
- routes, waypoints and recorded tracks (including GPX files you import or export)
- your boat profile (boat type, draft, air draft, cruising speed, safety margin)
- app settings (units, language, chart mode, alarm settings)
- downloaded offline region packs (chart tiles, place database, routing grid)
- the local record that you accepted the "not for navigation" disclaimer
You can delete individual items in the app; uninstalling the app removes everything. If you use your operating system's device backup (iCloud or Google backup), this local data may be included in that backup under your OS settings — that backup relationship is between you and Apple or Google, not us.
4. Location
Location is used for the navigation features described below. Optional advertising data is described separately in section 2.
While using the app (when-in-use): your position, course and speed are read from the OS to show your vessel on the chart, follow your navigation along a route, drive alarms and evaluate depth and speed-limit awareness. This processing happens on your device.
In the background: only two features use location while the app is not on screen, and only while you have started them:
- track recording
- the anchor alarm
On Android this runs as a foreground service with a persistent notification, so it is always visible that recording or the alarm is active. On iOS the "Always" location permission is requested only when you use these features. You can revoke location permission at any time in the OS settings; the chart remains fully usable without it.
Without live sharing, we receive location only for the online requests described below. When you explicitly start live sharing, the app sends periodic position updates until you stop sharing or the link expires. Anyone with the link can view the shared position and recent trail; recipients can save copies. The server keeps the share token, creator IP for abuse prevention, position and recent trail in memory until deletion or expiry (the expiry is shown in the app; normally 48 hours). Expired links cannot be read; expired records are removed during subsequent cleanup. Stopping sharing requests server deletion. Processing provides the sharing service you request (Art. 6(1)(b) GDPR).
5. Data sent to our server
When you use online features, the app sends the minimum needed to answer the request to our own API server:
| Feature | What is sent |
|---|---|
| Weather and tides | the coordinates of the requested point (often your position or a point on the chart) |
| AIS vessel traffic | the chart viewport (a bounding box), so vessel positions in that area can be streamed to you |
| Search and geocoding | your search text, optionally a position used to rank nearby results |
| Autorouting | start, end and via coordinates plus boat profile values (e.g. draft) |
| Chart manifest | version request; IP address and request metadata are processed for delivery |
The lookup requests above are processed in memory to generate responses and cached where applicable. Technical logs and optional live sharing have the separate retention described here. Having no account does not make IP addresses or location anonymous.
Technical logs: like any web service, our server writes an access log per request containing your IP address, the request path (without coordinates or search text), timestamp, response status and duration, plus a random request ID. We use these logs solely to operate the service and to prevent abuse (rate limiting). They are retained for up to 30 days and then deleted.
Legal bases: providing the functions you actively request — Art. 6 (1) (b) GDPR; technical logs and abuse prevention — Art. 6 (1) (f) GDPR (our legitimate interest in a secure, reliable service).
6. Chart and pack downloads
Chart tiles, offline region packs, fonts and the data manifest are static files served from our storage at Cloudflare (R2). When the app downloads them, Cloudflare processes your IP address and the requested file and byte ranges to deliver the content and to protect against attacks. These requests contain no search text and no boat data; the requested map files necessarily reveal which chart region you are loading. Legal bases: Art. 6 (1) (b) and (f) GDPR.
7. Upstream data providers
Our server obtains weather data from Open-Meteo, German water levels from PEGELONLINE (WSV) and AIS data from an AIS aggregation service. These requests are made by our server, from our server: your IP address and device details are never passed to these providers. For weather, our server forwards only the coordinates of the requested point (no identifier). Water-level and AIS requests are station- or area-based.
8. Recipients and international transfers
Cloudflare, Inc., USA: email forwarding as described in section 1.4, website hosting and worldwide delivery and storage of charts, fonts and packs. Cloudflare processes request data as our processor when delivering our content; its privacy policy describes its own processing of network and security data. The Cloudflare data processing addendum contains processing terms and provisions for EU Standard Contractual Clauses.
Railway Corporation, USA: hosting of our API server in EU West (Amsterdam, Netherlands), including the share viewer and technical API logs. Railway publishes its data processing addendum with Standard Contractual Clauses, which also provides information about subprocessors. Railway also processes certain usage and security data as a controller for its own operational and security purposes. Retention depends on what is necessary for those purposes and legal obligations; our 30-day limit applies to our API logs. See Railway’s privacy policy.
US providers and their service providers may process data outside the EEA, including through support or administrative access. An EU server region alone does not rule this out. The above processing terms provide for the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) for relevant transfers. Where a transfer is covered by valid EU–U.S. Data Privacy Framework certification, the adequacy decision under Art. 45 GDPR applies. Information and copies of applicable safeguards are available through the linked terms or from the controller.
Section 1.4 describes our email provider; section 2 describes the app's optional advertising recipient. Live shares are available to anyone holding the link. We do not sell your navigation data.
9. Retention
Lookup processing, technical logs and optional live sharing have the retention described in sections 4 and 5. Local records remain until you delete them or uninstall the app, subject to your operating-system backups. If advertising is enabled, Google processes SDK data under its applicable retention policies; the remote ad switch does not erase data already sent. See section 2 for privacy choices and recipient information.
10. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77), for example the one of your place of residence.
You can view, export and delete local records in the app and stop live sharing there. For server-side data, contact the controller above with enough information to locate the relevant processing; do not send a live-sharing write key. If we cannot identify the relevant data, Art. 11(2) GDPR may apply. Advertising privacy choices are described in section 2.
Objection: Where processing relies on legitimate interests, you may object on grounds relating to your particular situation. You may object to direct marketing at any time without giving a reason (Art. 21 GDPR). Withdrawal: You may withdraw consent at any time for the future; this does not affect the lawfulness of processing before withdrawal. Rights apply subject to their statutory conditions. Contact the controller above to exercise them; we do not require unnecessary identity information. You may also complain to the authority responsible for our location, LDI NRW, or another competent supervisory authority.
11. No automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
12. Children
Kurshalter is not directed at children. The processing described in this policy applies to online features, optional sharing and advertising when enabled.
13. Changes
We will update this policy when the website's or app's data processing changes and publish the current version at https://kurshalter.com/privacy. Material changes will be mentioned in the app's release notes.
Subscription verification (billing release addition, 2026-09-19)
When billing is configured, Kurshalter uses RevenueCat to verify purchases with Apple or Google, restore purchases and determine access to Plus. An anonymous app identifier, purchase history, subscription status and technical store information are processed for this purpose, including for Free users when the purchase service initializes. Kurshalter does not send RevenueCat your routes, tracks, boat profile, precise position, name or email. Automatic device-identifier collection is disabled. Payment details are handled by your app store; Kurshalter does not receive your card details. A minimal verified subscription status and your free-region choice are stored on your device.
Release preparation: complete the RevenueCat provider agreement, retention/deletion handling and app privacy disclosures described in subscriptions.md before publishing this updated policy or activating purchases. This addition has not been published to the website.