Privacy Policy
Last updated: September 14, 2026
This Privacy Policy explains how the internal tools operated for Freedom Boat Club ("we," "us," or "our") collect, use, and protect information when authorized users access our applications, including but not limited to Marine Tech Pro and related internal tooling (collectively, the "Services").
1. Scope
The Services are internal applications used by Freedom Boat Club employees, contractors, and affiliated service technicians. They are not intended for public or member-facing use. Access requires administrator approval.
2. Information we collect
- Account information. When you sign in with Google, we receive your name, email address, and Google account ID. When you sign up with email and password, we store your email, a name you provide, and a hashed password.
- Usage data. We record which tools you use, which diagnostic flows or features you access, and basic session metadata: a salted, truncated hash of your IP address (the address itself is not stored), your browser user-agent, a session identifier, your account ID and timestamps. This is used for operational monitoring and for administrator dashboards.
- AI assistant interactions. When you use an in-app AI feature (e.g., "Ask a Tech"), the text of your question and any contextual information (such as which diagnostic step you are on) is sent to a third-party AI provider (Anthropic) to generate a response. The question, the response, the diagnostic tree and step you were on (if any), token usage (including prompt-cache counts), response time, any error, your account ID and a hashed form of your IP address are logged, and recent questions and answers are visible to administrators on the admin dashboard for quality monitoring and troubleshooting. Per-user request limits on the AI feature are enforced by an in-memory counter, not from this log.
- Voice input and read-aloud. If you tap the microphone in the AI assistant, your device's or browser's built-in speech recognition service converts your speech to text. That audio may be processed by your browser vendor (e.g., Apple or Google) under its own privacy policy; we never receive or store audio. Only the resulting text is handled as an AI-assistant question as described above. Reading an answer aloud uses your browser's built-in speech-synthesis voices and sends nothing to us; depending on the voice selected (voices marked "device" in the assistant's voice settings are synthesized on your device), the answer text may instead be synthesized by your browser vendor's online voice service (e.g., Google or Microsoft) under its own privacy policy.
- Feedback you submit. When you send a bug report, feedback, or enhancement request from inside the app, we store the category, your message, the page (and diagnostic step, if any) you were on, your browser user-agent, and your name and email so an administrator can follow up.
- Cookies. We use a session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
3. How we use information
- Authenticate you and control access based on your assigned role.
- Provide the requested feature (diagnostic trees, specs lookup, AI answers, admin dashboards, etc.).
- Operate, maintain, and improve the Services, including troubleshooting errors.
- Protect the Services against abuse and comply with legal obligations.
4. Google user data
When you sign in with Google, we access only your basic profile and email address. We do not access Gmail, Drive, Calendar, or any other Google service data. We do not sell or share Google user data with third parties, and we do not use it for advertising. Google user data is used only to authenticate you and to display your name and email inside the Services.
5. Sharing
We do not sell your personal information. We share limited information only with:
- Hosting and infrastructure providers (e.g., Railway) that run the Services on our behalf.
- Authentication providers (Google) when you choose to sign in with them.
- AI providers (Anthropic) to process AI-assistant questions you submit.
- Browser speech-recognition providers (your browser vendor, e.g., Apple or Google) only when you choose to use voice input.
- Authorities when legally required.
6. Retention
We retain account records for as long as your access is active. Usage events and AI-assistant logs are deleted automatically after 90 days by default (the operator can configure this window). Feedback you submit is retained indefinitely, including after it is marked resolved, because it serves as the product's issue tracker; it is not covered by the automatic pruning of usage events and AI logs. You may request deletion of your account by contacting us; deleting an account removes its usage events and AI logs and anonymises any feedback it submitted (your name and email are removed from it; the report text remains). Records of unsuccessful sign-in attempts store the email address that was entered rather than a link to an account, so they are not removed by account deletion; they expire under the usage-event retention window instead.
7. Security
Passwords are stored using industry-standard hashing (bcrypt). Traffic is served over HTTPS. Access is role-gated and new accounts must be approved by an administrator. No online service can be guaranteed to be 100% secure.
8. Your choices
You may request access, correction, or deletion of your account information by emailing us at the address below. You may revoke Google sign-in access from your Google account permissions page at any time.
9. Children
The Services are for authorized FBC staff and contractors only and are not directed to children under 13.
10. Changes
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
11. Contact
Questions about this Privacy Policy or your data: [email protected].