Privacy Policy
Last updated 4 September 2026 · Deutsche Fassung
This policy covers both the cruiseblog iOS app and this website. It describes what is actually stored and where — not what a template assumes.
Who is responsible
- Controller
- Arthur Chevts
Gundelfinger Weg 4
86156 Augsburg
Germany - info@cruiseblog.app
No data protection officer has been appointed; the criteria of Art. 37 GDPR are not met for an operation of this size.
What the app stores
Your account
Signing in is possible only through Sign in with Apple. Every other method — Google, email and password, anonymous access — has been switched off. From Apple we receive a user identifier and, if you allow it, your name and an email address. If you choose Hide My Email, we only ever see Apple's relay address and never your real one.
What you write
The cruises you record: title, dates, cruise line and ship, itinerary with ports, notes per port, and an optional log entry. Plus one cover photo per cruise, stored in two sizes. Four statistics — cruises, nights, distinct ports, distinct countries — are calculated from that and stored alongside your profile.
What is not collected
There is no analytics, no crash reporting, no advertising and no tracking of any kind. The app contains exactly three Google services — authentication, database, file storage — and nothing else. No data is sold, and none is passed to third parties beyond the processor named below.
Why, and on what legal basis
All of the above is processed to provide the service you signed up for: Art. 6(1)(b) GDPR, performance of a contract. There is no processing based on legitimate interest for profiling or advertising, because there is none.
No law obliges you to provide any of it. What is required is required by the app itself: without a sign-in there is no account to attach cruises to, and without the cruises there is nothing to keep a logbook of. The consequence of not providing them is simply that the app cannot be used — nothing else follows from it.
Processor and where the data lives
cruiseblog runs on Google Firebase. Google Ireland Limited acts as processor under a data processing agreement including the standard contractual clauses.
| Service | What it holds | Location |
|---|---|---|
| Cloud Firestore | profile, cruises, itineraries, notes | europe-west3 (Frankfurt, Germany) |
| Cloud Storage | cover photos | europe-west3 (Frankfurt, Germany) |
| Firebase Authentication | user identifier, email, sign-in metadata | global Google infrastructure, including the USA |
| Firebase Hosting | access logs for this website | global Google infrastructure |
Your cruises and photos stay in Germany. Authentication is the one component that Google operates globally and that may process data in the United States. Google LLC is certified under the EU-US Data Privacy Framework, which the European Commission recognised as providing an adequate level of protection in its adequacy decision of 10 July 2023.
This website
These pages are static HTML. They set no cookies, run no JavaScript, and embed nothing from other servers — no fonts, no analytics, no social buttons. Firebase Hosting records the usual server access data (IP address, time, requested page, user agent) for delivery and security. That is Art. 6(1)(f) GDPR, legitimate interest in operating the site safely. These logs are held by Google as the processor. I have no access to them and cannot retrieve or read them, so how long they are kept follows Google's own periods for Firebase Hosting rather than any setting of mine.
How long it is kept, and how to delete it
Your data is kept for as long as your account exists. You can delete everything yourself, in the app, under Settings. That deletion removes your profile, every cruise, every photo, the underlying files, and finally the account itself — and it revokes the token issued by Apple, so the sign-in link is severed too. Nothing is retained afterwards; there is no soft delete and no archive copy.
How it is protected
Everything travels over TLS, and what is stored is reachable only through rules that tie each document and each file to the account that owns it — a request without the right sign-in is refused by the server, not by the app. Sign-in runs through Apple alone, so there is no password here that could be guessed or leaked.
No safeguard is absolute, and this page will not pretend otherwise.
Children
cruiseblog is not directed at children and collects nothing from them knowingly. It needs an Apple account to sign in, which Apple itself gates by age. If you believe a child has an account here, write to the address above and it will be deleted.
Your rights
- Access, rectification and erasure (Art. 15, 16, 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
Write to the address above. You may also lodge a complaint with a supervisory authority, in particular the one for your usual residence or place of work.
Your right to object. Where processing rests on a legitimate interest — on this site that is the server access log, and nothing in the app — you may object to it at any time on grounds relating to your particular situation, under Art. 21 GDPR. A message to the address above is enough; no form and no reason given is required.
Changes
If the app starts collecting something new, this page changes before the feature ships, and the date at the top moves.