Privacy Policy

Effective: October 9, 2026

Panda Bear Technology LLC operates Capt. Ron’s Navigation (the WXRR website at captronsnavigation.com and the Capt Ron app). Developer site: pandabeartech.com. Privacy contact: feedback@captronsnavigation.com.

This policy describes what the website and the app collect, who receives it, and how to delete an account. It is decision-support for captains. It is not a substitute for your judgment or an official National Weather Service forecast.

Delete your account — including if you cannot open the app or cannot sign in.

Information you give us

  • Account. Email and a password. Supabase Auth stores the password as a hash. We do not store the plaintext password. Optional: captain nickname, home port (a Florida zone), ride limits, tide-station choices, and notification choices (Friday outlook, rule updates, product news). The product-news switch is saved. Those messages are not sent.
  • WXRR reports. Zone, time window, weather snapshot, and the verdict. Signed-in reports are stored with your account id and email. Reports generated while signed out are not tagged with an account.
  • Feedback. A rating, a category, a comment, an optional email, the page you were on, and an optional zone. Also after-ride notes (good / mixed / rough) and radar-direction notes (matched / slightly off / way off). Feedback is stored and emailed to the operator.
  • Tour requests. Name, email, and any phone, party size, date, experience, or message you add. Stored and emailed to the operator.
  • Ask Capt. Ron. The messages you send, kept on the server so the next turn has context. The server creates the session id. A secret is returned once and kept in browser or app storage. The server stores a hash of that secret. A chat started while you are signed in is also stored with your account id. A chat started while signed out is not.
  • Custom pins. Name, coordinates, type, notes, and whether the pin is public. Your email is stored on the pin row. A public pin can be shown to other people as the name, position, and notes. That public view does not include your email.
  • Surface chart upload. If you upload a chart image for Ron’s take, that image is sent for the reading and may be stored with the cached result.

Location

Location is optional. You can pick a launch zone and never grant GPS. When you do grant it, this is what runs:

  • Website Ride Mode (/ride). GPS while that page is open. It is not collected in the background after you leave the page. If you start a recorded ride, position (latitude, longitude, heading, speed, accuracy, and the storm status word) is sent to our server about every 20 seconds.
  • App Ride tab. Foreground GPS while the Ride screen is open.
  • App background location. Only after you arm Ride and allow “Always” / background location. The iOS app declares background modes location and fetch. Android declares fine, coarse, and background location plus a location foreground service. Updates run about every 45 seconds or 40 meters while armed, with a notification that the storm watch is on. Disarming stops those updates. We do not use background location for ads.
  • Can I go / use my location. A one-time fix on the device to choose the nearest Florida zone. Those coordinates are not uploaded. The report request sends the zone id.
  • Radar “my position.” A one-time fix. That latitude and longitude are sent to our server for the radar and lightning read.
  • Web-push lightning wording. If you subscribed to browser alerts and a recorded ride is pinging, the latest latitude and longitude are saved on that push subscription. An alert uses the point when it is under three hours old. The point can remain stored after that until you unsubscribe or the browser endpoint is rejected. The alert text sent to the push service names distance and direction. It does not include the raw coordinates.
  • Buddy Watch. If you share a ride code, anyone with the code can see the live position and the recent track. The code is the access. The write token stays on your device.

Lightning and forecast lookups for a zone or pin use that place’s coordinates, which are not your GPS unless you used a control above.

Cookies and on-device storage

We do not use an advertising cookie. Sign-in is not stored in a cookie.

  • Sign-in token. Supabase Auth keeps the session (access token and refresh token) in the browser’s local storage on the website. Account inside the app is that same website.
  • Push device cookie (wxrr_push_device). Set when you subscribe to web push alerts. HttpOnly, SameSite=Lax, path /, about 400 days, and Secure on HTTPS. It is a device secret so a position update has to come from that browser. The database stores a hash of the secret, not the cookie value.
  • Chat secret (ron_chat_session_secret on the web, the same idea in app storage). Local storage, not a cookie. The server stores only the hash.
  • Other website storage. Sun or night mode, last zone, ride limits, tide stations, a this-tab copy of the last report, up to eight past ride codes (code, zone name, end time), feedback-widget position, radar-feedback flags, alert sound, and a dismissed banner. These stay in your browser until you clear site data.
  • App storage. Last zone, preset, last report id, chat session id and secret, whether Ride is armed, ride id and share code, last threat level, last lightning flash id, and the cell-strength setting. Uninstalling the app removes them.

Technical data

  • Feedback rows store a SHA-256 prefix of the IP address (not the raw address), the user agent, and the time. That hash is for spam triage.
  • Rate-limit counters for report, lightning, radar, outlook, pin, surface-chart, sign-up, password-reset, and push routes. The durable row id is a SHA-256 prefix of the IP address, the limit name, and the window start. The raw IP address is not written. Each window is one minute or one hour. A daily job deletes those rows once they are older than 48 hours. If the database write fails, the same cap is counted in memory on that server and disappears when the server stops. Some chat and feedback caps are memory-only and are not written as a durable IP record.
  • Client errors. A short error message, digest, page path, and user agent. No account id.
  • Vercel hosts the site and keeps its own request logs (IP address, URL, user agent, time). We do not copy those logs into our database. Vercel Web Analytics records page views (path, referrer, browser, operating system, device type, and country) without a cookie and without an advertising profile.

Who receives data

We do not sell personal information and we do not run ads. These services receive data because a feature calls them. NOAA and USGS receive a station or gauge id, not your name.

  • Supabase — login, and the database for profiles, reports, rides, chat, feedback, pins, push subscriptions, rate-limit hashes, and client errors. This repository does not record the Supabase region.
  • Vercel — hosting, request logs, and page-view analytics, as described above. API calls that include a latitude and longitude reach this host first.
  • xAI (Grok) — Ask Capt. Ron messages and the weather digest needed to answer them; a place name you typed, when we parse it; a surface-chart image (the NOAA chart, or a chart you uploaded). Grok does not choose the GO / CAUTION / NO GO verdict.
  • Resend — the recipient address and the message, for welcome mail, password reset, Friday outlook and rule updates when you opted in, and operator copies of feedback and tour requests.
  • Warpulse — a box around the latitude and longitude being scored (your GPS when Ride or Radar is using it, otherwise a zone or pin). No name or email.
  • Open-Meteo — latitude and longitude of the forecast point. No name or email. A paid customer endpoint is used when a key is configured. Otherwise the public endpoint is used.
  • RainViewer — radar tiles. A tile request shows the map area. Your browser’s IP address is visible to RainViewer when the map loads on your device. Our server also requests tiles when it scores a cell.
  • Esri — street-map tiles loaded in the browser from ArcGIS Online. The request shows the map area and your IP address, not your account.
  • NOAA CO-OPS — tide-station predictions. We send the station id.
  • USGS Water Services — readings for a gauge site code. We send the site code.
  • Web push services (Apple, Google, or Mozilla, whichever endpoint the browser returns) — the alert text when a browser alert is sent. Not raw GPS. The native app’s storm alerts are local notifications on the phone. The app does not register an Expo push token and does not send those alerts through Expo’s push service.
  • Google Fonts — the website loads typefaces from Google. That request includes the browser IP address. We do not send account data with it.

We do not collect payment card numbers. We do not access contacts, camera, or microphone.

How long we keep it

  • Sign-in and associated account data. Until the delete button succeeds, or we remove them from an email request. The button deletes the profile, pins, account-linked chats, rides, and push subscriptions, and it strips the account id and email from reports, saved bookmarks, and feedback. Details are in the next section.
  • Anonymous archive. After deletion, a signed-in WXRR can remain as zone, verdict, and weather numbers, without the account id or email. A feedback grade can remain without the email.
  • Chats, rides, and push subscriptions created while signed out. Not tied to an account. They stay until you email us with enough to match them, or the push endpoint is rejected.
  • Rate-limit hashes. Deleted by a daily job once the row is older than 48 hours. The raw IP address is not stored.
  • Ride track length and push coordinates. A live ride is treated as stale for watchers after 12 hours without a ping. The track is not deleted then. A track keeps at most the last 720 points. Push coordinates are used for alert wording only when they are under three hours old. They are not wiped at three hours. A surface-chart cache is reused for about 3 hours 15 minutes. The row is not deleted on that timer. Client-error rows have no account id and are not deleted by the account button.
  • On-device storage and the push cookie. Until you clear site data, the cookie expires (about 400 days), or you uninstall the app.
  • Vercel logs and analytics. Kept under Vercel’s retention, not a timer in this app.

Email deletion requests: we will delete the sign-in and the categories you name that we can match to the email, within 30 days.

Your choices

  • Access. Signed in, open /account, account menu, Download my data. The file includes the profile, reports tagged with your account, saved reports, site feedback tied to your account id, and chat rows stored with your account id. A chat started while signed out is keyed only by the session secret, so that download does not include it.
  • Correction. Edit the nickname, home port, limits, and notification choices on /account.
  • Deletion. /account/delete, described in the next section.
  • Email. Friday outlook and rule updates are sent only if you turn them on and save. Product news is not sent. Password reset and the welcome note are part of the account, not a mailing list.
  • Location and alerts. Deny or revoke location in the browser or the phone settings. Unsubscribe web push from the alert control. Disarm Ride to stop background GPS.

Delete your account

You can request deletion in a web browser. You do not need the iOS or Android app installed. The address for that request is https://captronsnavigation.com/account/delete. The website and the app use the same delete action.

If you can sign in

  1. Open captronsnavigation.com/account in a browser and sign in.
  2. Open the account menu and choose Delete account.
  3. Type the account email and confirm.

That button removes the sign-in and the data tied to that account:

  • The Supabase Auth user (email and password hash). You cannot sign in with that account afterward.
  • The profile row (nickname, home port, ride limits, notification choices, and the email stored there).
  • Custom map pins, including a public pin and the email stored on it.
  • Saved-report bookmarks. The account id and email are removed. Zone, verdict, and weather numbers can remain only when the bookmark can be stored without an account id. If it cannot, the bookmark is deleted.
  • Ask Capt. Ron chats, recorded rides (the track points and the Buddy Watch share), and web-push subscriptions (the endpoint, keys, and the last stored position) when those rows were saved while you were signed in.
  • Tour requests that used the account email (name, phone, and message go with the row).
  • Feedback email linkage. A star rating, category, and comment can remain with the account id and email cleared. After-ride and radar-direction notes stored with the account lose that id. The grade can remain for the accuracy log.

WXRR reports generated while you were signed in stay in the archive without your account id, email, phone, ZIP, typed description, or custom-pin name. The zone, verdict, and weather numbers remain.

A chat, ride, or browser alert created while signed out is not stored with an account id, so this button cannot find it. Email us and name the ride code or the address you used if you want those removed too.

If you cannot sign in

Email feedback@captronsnavigation.com with the subject Delete my account. Send it from the address on the account, or name that address. We will delete the sign-in and the associated data listed above that we can match to that email, within 30 days.

Copies on your phone or in the browser (chat secret, ride codes, sun mode, and the other on-device settings described in the privacy policy) stay until you clear site data or uninstall the app. Rate-limit rows are a hash of a network address, not an account. A daily job deletes those hashes once they are older than 48 hours.

Children

This service is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us an account or a tour request, email us and we will delete the records we can match.

Changes

When this policy changes, we update this page and the effective date. We do not send an automatic email for a policy change.

Contact

Panda Bear Technology LLC
feedback@captronsnavigation.com
pandabeartech.com
captronsnavigation.com