Privacy Policy
Last updated: July 2026
1. Who We Are
BeachCast helps users discover beach conditions, weather, marine forecasts and hazard reports submitted by the community. These reports are not official warnings. You can browse core content without an account. Sign-in is required only for community features such as check-ins, reports, follows, photo uploads, feedback and push notifications.
For privacy requests, contact privacy@beachcast.app. To request account deletion without the app, visit our account deletion page.
2. Data We Collect
- Account data: name, email address, profile image, account identifier, sign-in provider, profile preferences, trust score, rank and account creation date.
- Location data: if you grant permission, BeachCast uses your device location to show nearby beaches. Check-ins store the latitude and longitude used at check-in time so the app can validate and display recent local activity.
- Community activity: check-ins, condition reports, beach requests, beach corrections, followed beaches, tip votes, safety alerts, alert votes and feedback.
- Photos: if you upload beach photos, we store the image, caption, storage path, public URL, dimensions, moderation status and upload date.
- Push notification data: if you opt in, we store a browser/device push subscription endpoint and related technical keys so we can send notifications for followed beaches.
- Diagnostics: error reports may include IP address, browser, device information, app route and technical details needed to diagnose failures.
- Analytics: optional usage analytics are used only after consent and help us understand page views and app usage.
3. How We Use Data
- Provide forecasts, maps, nearby beaches and community features.
- Manage accounts, sessions, preferences and profile settings.
- Validate check-ins and show recent beach activity.
- Send opt-in push notifications for followed beaches.
- Moderate community submissions and investigate abuse.
- Fix bugs, monitor reliability and improve the product.
- Comply with legal, security and platform requirements.
4. Cookies and Local Storage
BeachCast uses two categories of local storage technologies:
- Essential: required for authentication, security, CSRF protection, locale, theme, region preferences and core app functionality. These are always active.
- Analytics: optional analytics and performance monitoring. These are activated only after explicit consent where consent is required.
You can change or withdraw your choice at any time through “Cookie preferences” in the footer.
5. Third-Party Services
- Google OAuth: used for sign-in. Google may process data according to its own privacy policy.
- GitHub OAuth: available as an additional sign-in provider when configured.
- Open-Meteo: weather and marine data provider. We send public beach coordinates, not account data.
- OpenStreetMap: map tiles. Subject to privacy policy.
- S3: used for uploaded beach photos when photo uploads are enabled.
- Sentry: technical browser telemetry enabled only after consent; session replay is disabled. privacy policy.
- Hosting: hosting, logs and delivery infrastructure.
6. Sharing and Disclosure
BeachCast does not sell personal data. We share data only with service providers needed to run the app, when required by law, to protect the service from abuse, or when you choose to publish community content such as reports, alerts or beach photos.
7. Data Retention
- Account data: kept until you delete your account.
- Sessions: kept until expiry or sign-out.
- Check-ins: expire from live views after a short period but may remain in account history until deletion.
- Condition reports and safety alerts: expire from live views based on their configured expiry, but may remain in account history until deletion.
- Followed beaches, preferences, votes, requests, corrections, photos and feedback: kept until account deletion or manual removal where supported.
- Error reports: retained according to the monitoring provider settings, typically up to 90 days.
- Analytics data: retained for the configured analytics window, typically up to 30 days.
- The current weather cache is refreshed regularly; anonymous forecast snapshots may be kept longer to measure and improve accuracy.
8. Your Rights
If you are in the EU/EEA or another region with similar privacy laws, you may have the right to access, correct, export, delete, restrict or object to the processing of your personal data.
- To export your account data, sign in and open Settings.
- To request account deletion without the app, use the public account deletion page. If you can sign in, you can also open Settings and use Delete account for immediate deletion.
- You can also contact privacy@beachcast.app for privacy requests or questions.
9. Children
BeachCast is not directed to children under 14. Children under 14 must not create an account or submit data without consent from a parent or guardian.
10. Changes
We may update this policy as BeachCast evolves. Material changes will be announced in the app or on this page.