Privacy in the app

This notice covers the LazyJack app at https://app.lazyjack.app: your account, your boat's records and how they are kept. The website and its waiting list have their own short note.

Last changed 3 October 2026.

In short

Who is responsible

LazyJack is run by Amit Peer, a private person in Norway, who is responsible for your data under the GDPR (the data controller). Write to support@lazyjack.app about anything on this page.

What is stored

Your phone's location

The app reads your phone's location only while a form that records a position for a sail is open (Start a sail, End sail, and Add to log or Something's wrong during a sail), or when you choose Use my location. Your browser asks your permission first, and you can say no: the form still saves. Each request stops after at most 15 seconds. Only the position the form saves is stored, and the app does not follow your location in the background. You can always choose a saved place, pick a point on the map or type coordinates instead.

Usage counts

For each account and each day, the server counts how many changes were saved or refused, by kind of change (for example "trip completed" or "file uploaded"), whether each came from the app or from an assistant (with the name the assistant gave itself), which of the assistant tools that only read were used, and whether the app was open that day.

Feedback you send

When you use Send feedback (in the account menu at the top of every page), we keep what you wrote and the kind you chose with your account, together with a few facts about the app at that moment: the app's version, the page you were on (not which record), phone or wide screen, the look, whether you were online, how many changes and files were waiting to sync, your browser and device type, and your device's time zone. Unless you remove it, a screenshot of the screen you were on goes with it; you see it before you send. It shows what was on that screen (which can include your boat's name, records and positions, and what you had typed in a form); email and phone fields and contact details are hidden in it.

Where it is kept

AI assistants

LazyJack has no AI of its own. It sends nothing to any AI company on its own, and pays for no AI.

If you connect an assistant (ChatGPT, Claude or another), it reads and changes your records with the permissions you approved. What it reads goes to the company that runs it, under your own agreement with that company. LazyJack does not see your conversation with the assistant, only the requests it sends.

The server's logs

The app's server writes one line per request: the time, the kind of request, the address within the app (which can include a record's id; the parts of an address that work as a key, such as a download link, are hidden), the result and how long it took. For an assistant's request it adds the name of the tool and, if the request was refused, the reason. When something goes wrong, it writes a description of the error. It does not write your IP address, your password or session, or what you sent.

The web server in front of the app keeps no log of the app's requests. It does record a request that fails inside the web server itself, and that record can include the IP address.

Both logs are kept for 14 days. To slow down password guessing and abuse, the server also counts recent failed sign-ins on the page where you connect an assistant (by email address and IP address), recent requests that fail to sign in (by IP address), recent assistant registrations (by IP address), and how many requests each account and each connected assistant made in the last few minutes. These counts are held in memory only, are never written down, and are gone when the server restarts.

On your device

So that the app works without a signal, your browser keeps a copy of your records (in its local storage) and the files that have not uploaded yet (in IndexedDB). It also keeps your sign-in session, the look you chose and the last few records you opened, for search. These are stored under your account, so another account signed in on the same browser does not see them.

Signing out keeps the copy on that device for the next time you sign in. Deleting your account removes the copy and the files waiting to upload from the device you delete it on; on any other device, clear the site's data in the browser.

Your rights

Why we may keep it

We keep your sign-in, your records and your files because you asked us to keep them for you: that is the service (GDPR article 6(1)(b)). The feedback you send is kept because you sent it to us to act on. The usage counts, the logs and the backups rest on our legitimate interest in keeping the service working, safe and worth using (article 6(1)(f)); you can object to that by writing to us.

Changes to this notice

If this notice changes in a way that matters to you, we tell you in the app or by email before the change applies.