Privacy in the app
This notice covers the LazyJack app at https://app.lazyjack.app: your account, your boat's records and how they are kept. The website and its waiting list have their own short note.
Last changed 3 October 2026.
In short
- Your boat's records are yours. We keep them to run the app for you, and do not sell them or use them for advertising.
- The app sets no cookies, shows no advertising and loads no tracking scripts.
- We count how the app is used, per account, without the contents of your records.
- You can download everything and delete your account yourself, in the app.
Who is responsible
LazyJack is run by Amit Peer, a private person in Norway, who is responsible for your data under the GDPR (the data controller). Write to support@lazyjack.app about anything on this page.
What is stored
- Your sign-in. Your email address and password. Sign-in is handled by Supabase Auth, which stores the email and a scrambled form of the password; we never see the password itself. Supabase also sends the emails that confirm your address and reset your password. Our database keeps your email address with your account.
- Your boat's records. What you enter: the boat's details, equipment, jobs and problems, engine-hour readings, trips and their log, places, people, checklists, parts, projects and costs, and your profile (your name, and an email address and phone number if you add them). Archiving a record keeps it, so it can be brought back. Records leave our database only when you clear your data or delete your account.
- Other people you record. If you add crew or a float plan's emergency contact, their names and any contact details you type are stored as part of your records. Please add only what they would expect you to keep.
- Files and photos. The documents, photos and receipts you upload, with their file name, size and a checksum. When you remove a file, the file itself is deleted from the server; the record that it existed (its name and size) stays in the document's history.
- Positions. The positions saved on trips, log entries and problems, and your places, including your home port.
- Activity history. A list of the changes made to your records: what changed, on which record and when. It includes changes made by an assistant you connect, and does not yet say which changes were whose.
- Assistant connections. For each AI assistant you connect: the name it gave itself, the permissions you approved, when it was connected and last used, its requests for your approval, and scrambled forms of its access keys.
- Usage counts. Described below.
- Feedback you send. Described below.
Your phone's location
The app reads your phone's location only while a form that records a position for a sail is open (Start a sail, End sail, and Add to log or Something's wrong during a sail), or when you choose Use my location. Your browser asks your permission first, and you can say no: the form still saves. Each request stops after at most 15 seconds. Only the position the form saves is stored, and the app does not follow your location in the background. You can always choose a saved place, pick a point on the map or type coordinates instead.
Usage counts
For each account and each day, the server counts how many changes were saved or refused, by kind of change (for example "trip completed" or "file uploaded"), whether each came from the app or from an assistant (with the name the assistant gave itself), which of the assistant tools that only read were used, and whether the app was open that day.
- Counts only. No contents of your records, no record ids, no text you typed and nothing an assistant asked.
- Not anonymous. They are kept with your account, and the person who runs LazyJack sees them next to your account's email address.
- What they are for. To see whether people use LazyJack, which parts of it, and where changes are refused, so problems can be fixed and the right things built next. They are not used for advertising and not given to anyone.
- How long. As long as your account exists. Clearing your data does not remove them; deleting your account does.
Feedback you send
When you use Send feedback (in the account menu at the top of every page), we keep what you wrote and the kind you chose with your account, together with a few facts about the app at that moment: the app's version, the page you were on (not which record), phone or wide screen, the look, whether you were online, how many changes and files were waiting to sync, your browser and device type, and your device's time zone. Unless you remove it, a screenshot of the screen you were on goes with it; you see it before you send. It shows what was on that screen (which can include your boat's name, records and positions, and what you had typed in a form); email and phone fields and contact details are hidden in it.
- Copied to Linear. We copy each message, with those facts and the screenshot but without your name or email address, to our issue tracker, Linear (linear.app, a US company), so we can sort and act on it. The form says so before you send.
- Who sees it. The person who runs LazyJack, who sees it next to your account's email address so they can reply.
- How long. The message stays in our database as long as your account exists: clearing your data does not remove it, deleting your account does. Our copy of the screenshot is deleted once it has reached Linear (if Linear does not take it, we keep it with the message), and stays in the nightly backups for up to 14 days. The copy in Linear is not removed by deleting your account; write to us and we delete it.
Where it is kept
- Supabase (supabase.com) runs the database that holds your records, your sign-in and the usage counts, in its West EU (Ireland) region. When you sign in, your browser talks to Supabase directly.
- Hetzner (hetzner.com) rents us the server that runs the app and stores the files you upload. It is in Helsinki, Finland, in the EU.
- Backups. Every night a copy of the database is saved on that server and kept for 14 days. Hetzner also keeps backups of the whole server, including your files, for 7 days. After you delete your account, your data stays in these copies until they are replaced.
- Maps. When the app shows a map (choosing a position, a place, a trip's page), your browser fetches the map pictures directly from the OpenStreetMap servers (tile.openstreetmap.org) and the OpenSeaMap servers (tiles.openseamap.org). They see your IP address, your browser and which part of the map you look at, as with any website, under their own privacy policies. The app sends them nothing else.
- Linear (linear.app, in the US) holds the copies of the feedback you send, as described above. Nothing else of yours goes there.
- Typefaces. The app's pages load two typefaces from Google Fonts (fonts.googleapis.com), so Google sees your IP address and browser when your browser fetches them.
AI assistants
LazyJack has no AI of its own. It sends nothing to any AI company on its own, and pays for no AI.
If you connect an assistant (ChatGPT, Claude or another), it reads and changes your records with the permissions you approved. What it reads goes to the company that runs it, under your own agreement with that company. LazyJack does not see your conversation with the assistant, only the requests it sends.
- You see and approve what a connection may do before it connects.
- Archiving, restoring or removing something needs an extra permission and, by default, waits for your approval each time.
- You can revoke a connection at any time in Settings, Connected access. It stops at once.
The server's logs
The app's server writes one line per request: the time, the kind of request, the address within the app (which can include a record's id; the parts of an address that work as a key, such as a download link, are hidden), the result and how long it took. For an assistant's request it adds the name of the tool and, if the request was refused, the reason. When something goes wrong, it writes a description of the error. It does not write your IP address, your password or session, or what you sent.
The web server in front of the app keeps no log of the app's requests. It does record a request that fails inside the web server itself, and that record can include the IP address.
Both logs are kept for 14 days. To slow down password guessing and abuse, the server also counts recent failed sign-ins on the page where you connect an assistant (by email address and IP address), recent requests that fail to sign in (by IP address), recent assistant registrations (by IP address), and how many requests each account and each connected assistant made in the last few minutes. These counts are held in memory only, are never written down, and are gone when the server restarts.
On your device
So that the app works without a signal, your browser keeps a copy of your records (in its local storage) and the files that have not uploaded yet (in IndexedDB). It also keeps your sign-in session, the look you chose and the last few records you opened, for search. These are stored under your account, so another account signed in on the same browser does not see them.
Signing out keeps the copy on that device for the next time you sign in. Deleting your account removes the copy and the files waiting to upload from the device you delete it on; on any other device, clear the site's data in the browser.
Your rights
- See and download everything. On the Account page, Download everything gives one zip file with every record, every file, the whole activity history, a description of the data and a page you can read or print. It leaves out the assistant connections' keys and approval requests, and the usage counts: write to us and we send you your usage counts. The file is not encrypted, so keep it somewhere safe.
- Correct. Edit any record in the app. To change the email address you sign in with, write to us.
- Delete. On the Account page, Delete account deletes your records, your files, your account, its usage counts, the feedback you sent (the copies in Linear on request, see above) and your sign-in at Supabase. One thing is kept: the id of the deleted sign-in (not your email address), for 30 days, so that a sign-in made before the deletion cannot quietly create a new, empty account. Copies in the backups go as the backups are replaced (above). Clear all data, on the same page, removes the boat and everything recorded for it but keeps your account and sign-in.
- Object, restrict or ask a question. Write to support@lazyjack.app. We answer within a month.
- Complain. You can complain to the Norwegian data protection authority, Datatilsynet (datatilsynet.no), or to the authority where you live.
Why we may keep it
We keep your sign-in, your records and your files because you asked us to keep them for you: that is the service (GDPR article 6(1)(b)). The feedback you send is kept because you sent it to us to act on. The usage counts, the logs and the backups rest on our legitimate interest in keeping the service working, safe and worth using (article 6(1)(f)); you can object to that by writing to us.
Changes to this notice
If this notice changes in a way that matters to you, we tell you in the app or by email before the change applies.