Privacy policy
Last updated: Sep 24, 2026
This document was drafted for The Schoeller Group LLC and is pending legal review. If anything here is unclear, email privacy@seadar.io.
This policy explains what personal data The Schoeller Group LLC ("Voydar", "we", "us") collects when you use seadar.io, terminal.seadar.io, the Voydar mobile app, the Voydar Lens browser extension and the Voydar API, why we collect it, who processes it for us, how long we keep it and what you can do about it.
The short version: you can look up any ship, port or company without an account. We don't show ads, we don't sell your data and we don't build pages about people. An account needs only an email address.
1. Summary
- No account is needed to use the public site. Looking things up is free.
- If you create an account, we store your email address and what you choose to save: follows, alert settings, watchlists and saved routes.
- The public site sets no cookies unless you sign in or choose a language. Its analytics (PostHog, and our host's page counts) run without cookies or browser storage, are not linked to your name or email, and do not look up your location from your IP address.
- We never sell or rent personal data, and there is no advertising on Voydar.
- You can ask for a copy of your data or have your account deleted at any time. See Your rights and Deleting your account.
2. Who we are
Voydar is operated by The Schoeller Group LLC, a limited liability company in the United States. The Schoeller Group LLC is the controller of the personal data described here. You can reach us at privacy@seadar.io.
3. Voydar is about ships, not people
Most of what Voydar shows is public information about ships, ports, companies, flags and shipwrecks: positions that ships broadcast over AIS (the Automatic Identification System), registry particulars, port calls, inspections, sanctions designations and emissions reports. How we handle personal data that appears inside these public datasets is explained in Personal data in public maritime data.
4. What we collect
When you browse without an account
- Request data. Like every website, our servers and hosting providers receive your IP address, browser type, the page requested, the referring page and the time of each request. These server logs are used to run and secure the service and are kept for a short time (see How long we keep data).
- Product analytics (PostHog). On the public site, PostHog runs without cookies or browser storage: its identifier lives only in memory and is new on every visit, so we cannot recognise you when you come back. For each page viewed it records the page address (with any search text or sign-in codes in the address removed), the page that referred you (for example, that you came from a search engine or another site), any campaign tags in the link you followed (such as
utm_source), your browser, operating system, device type and screen size, the page's language, your browser's language and your language setting if you chose one. It also records how the site is used and how well it works: named actions (for example, that a search result was opened, a search found nothing, a tool was run or a pricing button was clicked), which buttons and links are clicked and where on the page (including repeated clicks and clicks that did nothing), how far you scroll, how fast the page loaded (web vitals), and technical details of errors the page hit. It never records what you type into search or any form. On the public site it does not record your screen (no session replay) for visitors who are not signed in. We have switched off PostHog's IP geolocation, so no city, region or country is derived from your IP address. - Vercel Web Analytics. Our host counts page views without cookies, using a daily-rotating hash rather than an identifier stored on your device.
When you create an account
- Email address, used to sign you in (by a one-time email link, or a password if you set one) and to send you the emails you ask for. Passwords are stored only as a salted hash by our authentication provider. If Google sign-in is offered and you use it, Google shares your email address and basic profile with us.
- Account records: an internal user ID, account type, plan, trial dates and, if you set it, a display name.
- What you save: the ships and ports you follow, your alert rules and settings (for example digest hour, email or push on or off), saved vessels, Terminal workspaces and watchlists, saved routes and your notification inbox.
- Receivers you register (if you contribute an AIS or ADS-B station): the station name, any location description you give, its key and feed statistics.
- Sign-in session: cookies that keep you signed in (see Cookies and similar technologies).
When you use signed-in features
- Analytics linked to your account. When you are signed in (on seadar.io, in the Terminal and in the mobile app), and for account actions such as signing in, following a ship or starting checkout, PostHog events are linked to your internal user ID (never your email address or name), with your plan, trial status, Terminal access and language as account properties. In your account pages and in the Terminal, click tracking never includes the text or labels of what you click. The Terminal keeps its analytics identifier in a cookie and browser storage on seadar.io so your sessions can be connected.
- Session recordings (signed-in users only). While you are signed in on seadar.io or in the Terminal, PostHog may record how you move through the product (the layout of each screen, mouse movement, clicks, scrolling and which screens you open) so we can see where it is confusing and fix it. Everything you type and all text on screen is masked in the recording before it leaves your browser, so recordings do not show your email, notes, lists, searches or other content; network requests and console logs are not recorded. Recordings are kept for up to one month. You can turn them off for your account at any time in Profile and security; the choice applies on every device. Visitors who are not signed in are never recorded.
- Push notifications. If you turn on push, we store the push address your browser or phone gives us (a Web Push endpoint and its keys, or an Expo push token for the app), a device label and delivery status. Notifications are delivered through your browser's push service (for example Google, Apple or Mozilla) or through Expo for the app.
- Alert emails. When we email you an alert or a digest, we keep a record of it (recipient, subject, content and delivery status) so we never send the same alert twice and can fix delivery problems. Every alert email has a one-click unsubscribe link.
When you pay for a plan
- Payments are handled by Stripe. You enter your card or other payment details on Stripe's pages; we never see or store full card numbers. We receive and keep your Stripe customer ID, subscription ID, plan, subscription status and renewal date. Stripe processes your payment and billing details under its own privacy policy.
- If you subscribe through the Apple App Store or Google Play (where offered), the store handles the payment and we receive only the subscription status.
In the mobile app
- Location. If you allow it, the app uses your phone's location on the device to centre the map. Your location is not sent to us or stored.
- The map area you are looking at is sent to our live-position server so it can send you the ships in view. It is not stored.
- Searches are sent to our servers to answer them. Search text is not recorded in analytics.
- The app does not use an advertising identifier and does not track you across other apps or websites.
When you contact us: your message, your email address and anything you choose to include.
5. Voydar Lens browser extension
Voydar Lens is our browser extension for Chrome, Edge and Firefox. It is built so that the pages you read stay in your browser.
- When it runs. Lens reads a page only after you click its toolbar button or its right-click menu item on that page, or on sites you have turned on one by one in Lens (your browser asks you to allow each site). It does not run on other pages.
- What it reads. It looks for IMO numbers, MMSIs and, only if you switch it on, ship names in the text of the page, inside your browser. The page's text, its address and your browsing history are never sent to us or anyone else, and Lens keeps no history of the pages you visit.
- What it sends. When you hover over or click a number it found (or select one and use the right-click menu, or search in the Lens window), Lens sends that one identifier or name to seadar.io to look up the ship, the same as a search on our site. Our servers receive your IP address with the request, as for any web request. Answers are kept in the extension's temporary storage until you close the browser.
- Signing in (optional). If you sign in from Lens, you approve it on seadar.io like any connected app. Lens then holds a sign-in token in the extension's own storage, which web pages cannot read, and uses it only to show your plan, to follow and unfollow ships you choose, and to show Open in Terminal. You can sign out in Lens or disconnect it under Account, API keys, Connected apps.
- Usage counts. Unless you switch them off in Lens's settings (in Firefox: unless you switch them on), Lens sends anonymous counts of its own actions to seadar.io, which forwards them to PostHog: that it was installed, that a card was opened (and whether the ship was found), that a link in a card was followed and that Follow was used. Each install has a random identifier that is not linked to your account. These counts never include page addresses, page text, the identifiers you looked up or anything you typed.
- Lens loads no code from the internet, shows no ads and contains no third-party trackers.
6. How we use it, and our legal bases
We use personal data only for these purposes. For people in the EEA and the UK, the legal basis is given for each.
- To provide the service you asked for: your account, sign-in, follows, alerts, push notifications, saved items, the Terminal and paid plans. Basis: performance of our contract with you (the terms of service).
- To keep Voydar secure and working: preventing abuse and fraud, rate limiting, debugging, and enforcing plan limits. Basis: our legitimate interest in running a secure, reliable service.
- To understand and improve Voydar: product analytics (including, for signed-in users, masked session recordings), error reports and acquisition reporting. Basis: our legitimate interest in improving the product and keeping it working, balanced by the limits above (no ads, no selling, no recording of anonymous visitors, masking of everything typed and shown, a switch to turn recordings off, no location lookup in PostHog).
- Push notifications: only after you allow them on your device. Basis: your consent, which you can withdraw in your settings or your device settings at any time.
- Billing, tax and accounting records. Basis: legal obligation.
- Service emails (sign-in links, alerts you set up, and important changes to your account, plan or these policies). We do not send marketing email without your permission.
7. What we don't do
- We don't sell or rent personal data, and we don't "share" it for cross-context behavioral advertising (as those terms are used in California law).
- We don't show ads or use advertising networks, and we don't buy data about you from data brokers.
- We don't record the sessions of visitors who are not signed in, and signed-in session recordings mask everything you type and all text on screen (see What we collect); you can turn them off in your account.
- We don't create pages, profiles or search results about individual people.
- Data you keep private in your account (follows, watchlists, saved routes, alert settings) never becomes public, including in aggregates we publish.
8. Who processes data for us
We use these service providers. They process personal data on our behalf and under our instructions, not for their own purposes (except where noted, such as payment networks, which have their own policies).
- Supabase: database and account sign-in. Data is stored in the United States (US East).
- Vercel: hosting for seadar.io and the Terminal, server logs and cookie-free page counts.
- Fly.io: our live-position server and data-processing workers (United States).
- PostHog: product analytics (United States).
- Google: Google sign-in, where offered. We do not use Google Analytics or any Google advertising service.
- Resend: sending sign-in and alert emails.
- Stripe: payments and subscription billing.
- Expo: delivering push notifications to the mobile app; your browser's push service for web push.
- Apple and Google: app distribution and, where offered, in-app purchases.
We may also disclose information if the law requires it, to protect people's safety or our rights, or as part of a merger or sale of the business (in which case this policy continues to apply to your data).
9. International transfers
The Schoeller Group LLC is based in the United States and our providers store data mainly in the United States. If you use Voydar from outside the United States, your data is transferred there. Where the law requires it, we rely on the safeguards our providers offer for these transfers, such as the European Commission's Standard Contractual Clauses and the UK addendum.
10. How long we keep data
- Your account and everything saved in it (follows, alert settings, notification inbox, alert email and push records, push devices, saved items, watchlists, saved routes, trial record, registered receivers): for as long as you keep the account. Deleting your account deletes them.
- Push devices: until you turn push off, remove the device or sign out of the mobile app. Addresses that stop working are deleted automatically.
- Billing records: Stripe and we keep what tax and accounting law requires, usually up to seven years, even after an account is deleted.
- Security records: a record of any change an administrator makes to your account (for example, granting a plan or a trial) is kept in an append-only audit log, for security and accountability.
- Server logs: kept by our hosting providers for a short period, typically days to a few weeks.
- Analytics: PostHog events and error reports are kept for the retention period of our PostHog plan; session recordings for up to one month.
- Backups: deleted data can remain in encrypted database backups until those backups expire on their normal schedule.
11. Security
All traffic to Voydar is encrypted in transit (HTTPS). Data you save is protected by row-level security in the database, so each account can read only its own rows, and our public website's database connection cannot read account data at all. Administrator access requires multi-factor authentication and every administrative change is logged. No system is perfectly secure; if we learn of a breach that affects your personal data, we will notify you and the authorities as the law requires.
12. Your rights
Wherever you live, you can ask us to:
- tell you what personal data we hold about you and give you a copy, in a portable format where practical;
- correct data that is wrong;
- delete your data and your account;
- stop using your data for analytics, or restrict how we use it;
- withdraw a consent you gave (for example, for push notifications).
EEA and UK (GDPR and UK GDPR). You also have the right to object to processing based on our legitimate interests, and the right to complain to your data protection authority. We would appreciate the chance to address your concern first.
California (CCPA/CPRA) and other US states. You have the right to know what we collect and why, to access, correct and delete it, and not to be discriminated against for using these rights. We don't sell or share personal information for cross-context behavioral advertising and don't use sensitive personal information, so there is nothing to opt out of. You may use an authorized agent; we will ask the agent for proof of authority.
How to make a request. Email privacy@seadar.io from the email address on your account (or tell us which address it is). We verify requests by confirming control of that email address, and we answer within 30 days (45 days where California law allows). We don't charge for requests.
13. Deleting your account
You can delete your account yourself at any time: on seadar.io go to Account → Delete account (seadar.io/account/delete), or in the mobile app go to Account → Delete account. If you can't sign in, email privacy@seadar.io from your account's email address and we will delete it for you.
Deleting your account immediately cancels any active subscription bought on seadar.io, and permanently deletes your account, your follows, alert settings, notification inbox, alert and push records, push devices, saved items, watchlists, saved routes and registered receivers. We keep only what is described under How long we keep data (billing records, the administrative audit log and backups until they expire). Subscriptions bought through Apple or Google must be cancelled in your App Store or Google Play settings.
14. Personal data in public maritime data
Voydar is built from public and licensed data about ships, and most of it is not about people at all. Commercial ships must broadcast their identity and position over AIS for safety at sea, and many smaller boats choose to. Registries, port authorities, inspection bodies and sanctions lists publish information about ships and the companies that own and operate them. Voydar shows where every fact comes from.
Our rules for personal data inside these sources:
- No people pages. We don't create pages, profiles or search results about individual people. We don't publish crew lists or passenger information.
- Companies, not individuals. Some registries list a private individual as a ship's owner. We keep individuals' names and street addresses out of public pages unless there is a specific, documented reason and a legal basis to show them; by default we show at most a city, region or country.
- Suppression and opt-outs. We honour the privacy and suppression programmes of the sources we use, and we don't load files that would expose private individuals without such a basis.
- Photos and news. Ship photos come from openly licensed collections and are credited. News items link to the original public source.
- Derived information (for example, an estimated arrival time) is labelled as Voydar's estimate and never presented as a fact about a person.
Aircraft positions. Aircraft positions received by Beacon ADS-B stations are shown only inside the Voydar Terminal, never on public pages. We honour the FAA's LADD and PIA blocking programmes where their lists are available to us, and opt-out requests from aircraft owners and operators: email privacy@seadar.io with the aircraft's registration or ICAO address. No registration certificate is needed. We never name individual aircraft owners.
Asking for removal. If you believe a Voydar page shows your personal data, or the position of a small private boat that identifies you, email privacy@seadar.io with the page address and what you would like changed. We review every request and, depending on the case, remove or redact the information, stop the page appearing in search results, or explain why the information stays (for example, a commercial ship's mandatory safety broadcasts). We aim to reply within 30 days.
15. Children
Voydar is a general-audience information service. It is not directed at children, and you must be at least 16 years old to create an account. We do not knowingly collect personal data from children under 13 (or under 16 in the EEA and UK). If you believe a child has given us personal data, email privacy@seadar.io and we will delete it.
17. Changes to this policy
We will update this policy when what we collect or how we use it changes, and change the "Last updated" date above. If a change materially affects how we use your data, we will tell account holders by email or in the product before it takes effect.
18. Contact
The Schoeller Group LLC, operator of Voydar. Email: privacy@seadar.io.