Privacy Policy
The short version. You sign in with Apple, so we never hold a password. Apple takes every payment, so we never see a card. Direct messages are end-to-end encrypted on your iPhone and we cannot read them. Room messages and The Dock are not end-to-end encrypted. We keep what a private club needs to run: your account, your profile and boat, what you write in the club, your place on the waiting list, and whether your membership is paid. There is no advertising, no tracking, no analytics and no third-party SDK in the app, and we never sell or share personal information. You can delete your account inside the app at any time: You, then Delete account.
1. Who we are
Sirena Seafarer Club is operated by Anton Dimitrov, a sole trader established in Varna, Bulgaria ("we", "us", "the house"). He is the controller of your personal data. In this policy "the secretary" means the operator acting as the club's moderator; nobody else moderates the club or has access to its data.
The only contact address for privacy questions and requests is support@sirenaclub.io. Because the operator is established in the European Union, the EU General Data Protection Regulation (GDPR) applies to everything described here, wherever you live. Where the UK GDPR requires a representative in the United Kingdom, we will appoint one and publish their details here.
2. What this policy covers
- The Sirena Seafarer Club iPhone app (shown as "Sirena Club" on the Home Screen).
- The club's server at sirena.club, which the app talks to.
- The website sirena.club, including the form where you can leave an email to hear when the app opens.
It does not cover the separate Sirena Seafarer navigation app, which has its own policy, or Apple's services, which are covered by Apple's Privacy Policy. The app is not offered in App Store storefronts in the European Union, but we apply this policy, and the GDPR, to everyone.
3. Data we keep, and where it comes from
Almost everything comes from you, through the app. A few things come from Apple (sign in and purchases) or from your connection (your IP address, for a few minutes). We do not buy data, we do not receive data from data brokers, and we do not combine your data with other sources.
| Data | Source and purpose | Who can see it |
|---|---|---|
| Sign in with Apple: a stable user identifier for this app, the email address you choose to share (often a private relay address from Apple), and the name you choose to share the first time | From Apple, when you sign in. Identifies your account. We also store a token from Apple only so that we can tell Apple to disconnect the club when you delete your account. | The email is visible to you and the secretary only. It is never shown to other people. |
| Profile: handle (chosen once), name, boat, home port, home region (South Florida, Palm Beach, The Keys or The Bahamas) | From you. Your card and the member directory. | Anyone signed in who looks up your exact handle sees your card. The directory is shown to members and captains. Blocking hides two people from each other in the directory and Nearby, hides the blocked person's room messages from the one who blocked, and stops direct messages both ways. |
| Account record: role (guest, member or captain), status (active or suspended), the member a captain sails for, when the account was created, when it was last active (to the nearest few minutes), when you confirmed you are 18 or older and accepted the house rules | Created by the system as you use the club. Runs access, safety and moderation. | Your role and, for captains, the member they sail for appear on your card. The rest is visible to the secretary only. |
| Membership: seat number, whether the seat came from the App Store or the house, the App Store original transaction number, product, status, expiry and grace dates, whether it renews, whether it was a test (sandbox) purchase, when Apple was last asked, and a random account token | From Apple's App Store Server API, about purchases you make in the app. Decides what opens for you. The random account token is handed to Apple at purchase so the purchase can be matched to your account. | Your seat number appears on your card. The rest is visible to you and the secretary only. |
| Waiting list: place number, when you joined, status (waiting, invited, expired, joined or left), when you were invited, which seat release the invitation was for, and when it expires | From you, when you join the list. Runs the list in order. | You see your own place and how many are ahead. The secretary sees the queue. Other people see only totals. |
| Invite codes and referrals: your personal code and link, which accounts joined with your code and when, how many places you moved up, and a one-way hash of the referred person's Apple identifier | Created when you join the list or become a member, and when someone joins with your code. Moves people up the list and stops the same Apple Account being counted twice. | You see your own count. The secretary sees counts per person. Nobody sees who used your code. |
| Room messages: text, replies, time, the rooms and groups you belong to, how far you have read, whether a room is muted | From you. The conversation you joined the club for. | People allowed in that room. Not end-to-end encrypted: the operator can access it on the server and reviews it when it is reported. |
| Rooms you host: the name, description, topic and region of an open room or private group you start, when you started it, and the people you removed from an open room (so they cannot rejoin) | From you. Running member rooms. Starting or renaming an open room posts a notice in it with your handle. | Open rooms are listed for everyone signed in, with you shown as host; private groups only to the people in them. The removal list is visible to the system only. |
| The Dock: questions and answers, stored with your account but shown under a name-free label frozen when you write, such as "58' Viking owner · Palm Beach" | From you. Shared knowledge without names. | Everyone signed in sees the text and the label. Only the secretary can link it to you, when it is reported. |
| Direct messages: the encrypted message, sender, recipient, time sent, time read, the key fingerprints inside the encrypted envelope, and whether a first message from someone new was accepted | From you. Delivering messages and letting people refuse messages from strangers. | Only you and the other person can read the text. We see who wrote to whom and when, never what was said. |
| Messaging keys: your current public key, its fingerprint, and every public key your account has used | Created on your iPhone. Lets others encrypt messages to you and open older history. | Anyone signed in who can write to you. Your private key never leaves your iPhone. |
| Ownership verification: vessel name, registry (USCG, state or other flag), registration number, builder, model, length, and a photo of the registration document | From you, if you ask for the verified owner badge. The app redraws the photo as a new image before sending it, so no camera metadata (such as location) leaves your iPhone. | The secretary only. The photo is stored in our database until the secretary decides, then deleted. After approval your card shows the length and builder, for example "58' Viking". |
| Nearby: a region, a short note and an end time (1 to 72 hours) | From you, when you choose to share. Tells members you are around. It is a region you pick, never your position; the app never uses location services. | Members and captains. |
| Events, captains, safety: events you mark as going, captain invitation codes (who issued, who used, when), people you block, reports you file about people, messages, posts or whole rooms (what, the reason, and any text you add) | From you. Running the club and keeping it safe. | Only going counts are shown to others. Blocks are private. Reports go to the secretary only. |
| Reported direct messages: when you report a direct message, the app sends the text of that one message with the report | From you. The secretary cannot read encrypted messages otherwise. | The secretary only. |
| Session records: a SHA-256 hash of each sign-in token, when it was created and last renewed | Created by the system. Keeps you signed in. | Nobody. The token itself is only on your iPhone. |
| IP address | From your connection. Used only for short-lived rate-limit counters against abuse (IPv6 addresses are shortened to their network prefix). The counters expire within two minutes. | Nobody reads them. |
| Website email list: the email you leave on sirena.club, the page it came from, your country (from your IP address, as Cloudflare reports it), and the date | From you, on the website. Writing to you once, when the app opens. | The secretary. A copy of each new entry is sent to the secretary's private Discord channel. |
We do not collect precise location, contacts, health or financial data, browsing history, advertising identifiers, or device fingerprints. We do not knowingly collect special categories of data (such as health, religion or political views). Please do not put such information in your profile or messages.
4. Data that stays on your iPhone
- In the Keychain, on this device only and not synced to iCloud: your sign-in token, your private messaging key, and your Apple user identifier (used to check that Sign in with Apple is still connected).
- In the app's settings: whether you saw the welcome tour, whether the app lock is on, the age range result described in section 12, which messages a notification already announced, the security codes of the people you write to, and small counters for your ribbons.
- Face ID or your passcode is checked by iOS. The app only learns whether it succeeded.
- The tilt effect on your membership card reads the motion sensor on the device. Nothing is stored or sent.
We cannot see any of this. Deleting your account, or deleting the app, removes it.
5. Why we use it: purposes and legal bases
| Purpose | Legal basis (GDPR article 6) |
|---|---|
| Creating your account, signing in, your profile, rooms, groups, The Dock, direct messages, Nearby, events, captains, the waiting list and invitations | Contract (6(1)(b)): providing the service you asked for |
| Checking your subscription with Apple and opening or closing the rooms | Contract (6(1)(b)) |
| Ownership verification and the verified owner badge | Contract (6(1)(b)): a feature you ask for |
| Rate limits, message requests, the slur filter, reports, blocks, moderation, suspensions and keeping report records | Legitimate interests (6(1)(f)): keeping members safe and the club usable |
| Short internal notes to the secretary on Discord (see section 7) | Legitimate interests (6(1)(f)): acting on reports and documents quickly |
| Confirming you are 18 or older | Legitimate interests (6(1)(f)) and our legal duties to protect minors |
| The website email list | Consent (6(1)(a)). You can withdraw it at any time by writing to us. |
| Answering lawful requests from authorities, and keeping records the law requires | Legal obligation (6(1)(c)) |
| Establishing, exercising or defending legal claims | Legitimate interests (6(1)(f)) |
Where we rely on legitimate interests, we have weighed them against your rights, and you can object (section 14). Giving us data is voluntary, but without the data marked as contract the club cannot work for you.
6. How long we keep it
- Account, profile, membership records, keys, verification details (without the photo), captain invitations and your waiting list row: until you delete your account.
- Referral records: until you delete your account. The one-way hash of a referred Apple identifier is kept after deletion, without any link to a person, only so a deleted and recreated account cannot be counted as a new friend again.
- Sign in with Apple token: until you delete your account, when we revoke it with Apple.
- Session records: a session ends after 30 days without use; it is renewed at most once a day while you use the app. Records are removed when you sign out or delete your account, and an account keeps at most five.
- Room messages: until you delete them, the host of a member room or group deletes them, the secretary removes them, or you delete your account. Deleting a message erases its text. A message hidden after reports keeps its text until the secretary decides, so it can be reviewed. When a host or the house closes a room, it leaves every list, but its messages stay stored so that reports already filed can be handled; each author's messages are still erased when that author deletes their account.
- Automatic notices in member rooms and groups such as "@anna started Bimini Run", "Anna added Ben" or "Ben left" are part of that room's history and are not erased when someone named in them deletes their account. Write to us and we will remove them.
- Removals from an open room: kept until the person who was removed deletes their account.
- The Dock: removing a question or answer hides it from everyone immediately. The text is erased from our database when you delete your account.
- Direct messages: until either person deletes their account, which removes the whole conversation for both. Single messages cannot be unsent.
- Verification photo: deleted as soon as the secretary approves or rejects it. Any photo still undecided after 30 days is deleted automatically.
- Nearby: shown until its end time. The last entry stays stored until you clear it, replace it, or delete your account.
- Events marked as going and blocks: until you undo them or the account is deleted.
- Reports: a report you file, including a report on a whole room, is kept until you delete your account. Reports about you are kept as moderation records while the reporter's account exists; if you delete your account, the reported content is erased with it.
- IP rate-limit counters: under two minutes.
- House notes on Discord: kept in a private channel only the operator reads, and deleted within 90 days.
- Website email list: until the opening email is sent, after which the list is deleted, or earlier if you ask.
- Backups: our database provider keeps a rolling recovery history of up to 30 days. Deleted data leaves it within that time.
Apple keeps its own records of your sign-in and purchases under its own policy. We may keep specific data longer only if the law requires it or to defend a legal claim, and only for that purpose.
7. Who receives data
| Recipient | Role and what they receive | Location |
|---|---|---|
| Cloudflare, Inc. (Pages, D1 database, KV storage) | Processor. Hosts the website and the club server, stores the club database and the website email list, and handles every request, including your IP address. Acts under its data processing terms. | United States, with data centres worldwide |
| Apple (Sign in with Apple, App Store, App Store Server API) | Independent controller for your Apple Account and purchases. We send Apple your sign-in codes to verify, transaction numbers to look up, and the token to revoke on deletion. Apple is the merchant of record and handles billing, taxes and refunds. | United States and Apple's regional entities |
| Discord, Inc. | Service provider for internal notes to the secretary. From the app: "new guest signed in" (no details), a seat number taken with the handle, a captain coming aboard with both handles, a document waiting with the handle and the boat's length and builder, a report with its type, reason and count, and a room report with the room's name and the reason. From the website: each new email on the list, with country, page and time. Never the text of room messages, Dock posts or direct messages, and never app account emails. | United States |
| Google (Google Fonts, website only) | Pages on sirena.club load their fonts from Google, so Google receives your IP address and browser details when you open them. The app does not use Google. | United States |
| US National Hurricane Center | The server downloads public storm data to open Storm Rooms. No personal data is sent. | United States |
| Other people in the club | What section 3 says they can see. | Wherever they are |
| Authorities, courts, advisers | Only when the law requires it, to protect someone's safety, or to defend a legal claim, and only what is needed. | As required |
We do not sell personal information, share it for cross-context behavioural advertising, or give it to data brokers or advertisers. If the club is ever transferred to a new operator, your data would go with it only under this policy, and we would tell you first.
8. International transfers
The operator is in Bulgaria and our providers are in the United States, so personal data is transferred outside the European Economic Area. For providers certified under the EU-U.S. Data Privacy Framework we rely on the European Commission's adequacy decision for that framework. Otherwise, and in addition where needed, transfers rely on the European Commission's Standard Contractual Clauses included in the provider's data processing terms. You can ask us for more information about these safeguards at support@sirenaclub.io.
9. Security and encryption
- Direct messages are end-to-end encrypted. Each iPhone creates its own key pair. Messages are sealed with X25519 key agreement, HKDF-SHA256 and ChaCha20-Poly1305 using Apple's CryptoKit. The server stores only the sealed envelope and public keys. If you lose your iPhone, we cannot recover your messages. Signing in on a second iPhone creates a new key there, and older messages stay readable only on the first.
- Room messages and The Dock are not end-to-end encrypted. They are protected in transit and at rest, and are readable on the server by the operator.
- All traffic between the app, the website and the server uses HTTPS. Our provider encrypts stored data at rest.
- Only a SHA-256 hash of each sign-in token is stored, so a copy of the database cannot be used to sign in.
- No passwords exist: sign-in is through Apple. The secretary's tools are protected by a long secret key.
- Verification photos are redrawn on your iPhone without metadata and deleted after the decision.
- Rate limits and message requests slow down abuse.
No system is perfectly secure. If something goes wrong, section 16 says what we do.
10. Automated decisions
We make no decisions based solely on automated processing that produce legal or similarly significant effects on you, and we do no profiling. A few simple rules run automatically:
- The waiting list is first come, first served: invitations go out once a day at 8:00 New York time, in place order, within the daily quota and the seats left in the open release. Each friend who joins with your code moves you up 50 places, up to 20 friends.
- The price of the next seat release follows a published ladder and the size of the waiting list, not anything about you.
- A short list of hate slurs cannot be posted. Names and descriptions of open member rooms are also checked against a short list of profanity, and two open rooms cannot share a name.
- A message reported by three people is hidden until the secretary reviews it. A person, not the system, decides whether to remove content or suspend an account.
11. Notifications, Face ID and the camera
- Notifications are optional and are created on your iPhone. When iOS lets the app refresh in the background, it checks the club for new activity with your stored sign-in and posts a local notification such as "New message from Anna", "Message request from Anna" or "Storm Room open". Notifications never contain message text. With the app lock on, they say only "New message". We do not use a push notification service, and no notification content passes through Apple or anyone else.
- App lock is optional. It uses Face ID, Touch ID or your passcode through iOS. Biometric data never reaches the app or us.
- The camera is used only when you photograph a registration document for verification. You can also choose a photo; the photo picker runs outside the app and gives it only the photo you pick.
12. Adults only
Sirena Seafarer Club is for adults 18 and over. Before you take part, the house rules ask you to confirm that you are 18 or older, and we record when you did. On iOS 26 and later, where Apple makes it available, the app also asks Apple's Declared Age Range once, with a single age gate at 18. The answer is kept only on your iPhone and is not sent to us. If Apple reports a range under 18, the club does not open and the app offers to delete the account.
We do not knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18, we suspend it and delete it and its data. If you believe a minor is using the club, write to support@sirenaclub.io.
13. Deleting your account
In the app, go to You, then Delete account. Deletion happens straight away and cannot be undone. It:
- erases your account, profile, keys, sessions, membership records, waiting list place, Dock posts and answers (and the answers others gave to your questions), direct message conversations (for both sides), Nearby, events, blocks, reports you filed and verification records;
- blanks your room messages so they no longer carry your name or text;
- retires your seat number, which is never given to anyone else;
- returns your captain, if you have one, to a guest account and cancels any open captain invitation;
- closes the open rooms and private groups you host, and removes the reports you filed and any record of you being removed from an open room;
- revokes Sign in with Apple, so the club no longer appears in your Apple Account's list of apps using Sign in with Apple;
- removes your keys, sign-in and account data the app kept on your iPhone.
Deleting your account does not cancel your App Store subscription. Apple keeps billing it until you cancel it in your Apple Account settings, or at apps.apple.com/account/subscriptions. Apple keeps its own purchase records. Data still in the 30-day recovery history (section 6) leaves it within that time. You can also ask us to delete your account by email.
14. Your rights (GDPR)
You have the right to:
- access your personal data and get a copy (article 15);
- have inaccurate data corrected (article 16); most of your profile can be edited in the app;
- have your data erased (article 17);
- restrict processing (article 18);
- receive the data you gave us in a portable format, and have it sent to someone else where feasible (article 20);
- object to processing based on legitimate interests (article 21);
- not be subject to decisions based solely on automated processing (article 22); we make none;
- withdraw consent at any time, without affecting what was done before (article 7(3)).
How: write to support@sirenaclub.io. To protect your account, we may ask you to confirm the request from inside the app or from the email linked to your account. We answer within one month. If a request is complex or there are many, we may extend this by two more months and will tell you why within the first month. Requests are free unless they are manifestly unfounded or excessive.
Complaints: you can complain to the Bulgarian Commission for Personal Data Protection (2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, www.cpdp.bg), or to the data protection authority where you live or work. We would appreciate the chance to fix things first.
15. US state privacy rights
Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Florida and other US states with consumer privacy laws have rights over their personal information where those laws apply to us. We extend the rights below to every US user.
We do not sell or share personal information
We do not sell personal information, and we do not share it for cross-context behavioural advertising (targeted advertising). We have not done so in the past 12 months. We do no profiling that produces legal or similarly significant effects. We do not knowingly sell or share the personal information of anyone under 16. Because there is nothing to opt out of, we have no "Do Not Sell or Share" link; browser signals such as Global Privacy Control are honoured anyway.
Notice at collection (California)
| Category (CCPA) | What, in this club | Kept |
|---|---|---|
| Identifiers | Apple user identifier, email shared by Apple, handle, account token, IP address (for minutes) | Until account deletion; IP under two minutes |
| Personal information under Cal. Civ. Code 1798.80(e) | Name | Until account deletion |
| Commercial information | Subscription product, status and dates, seat number, waiting list place | Until account deletion |
| Internet or other electronic network activity | Last active time, read times, session records, rooms joined | As in section 6 |
| Audio, electronic or visual information | Photo of a registration document | Until the decision, at most 30 days |
| Other content you provide | Boat, port, region, room messages, Dock posts, Nearby notes, reports | As in section 6 |
| Sensitive personal information | The contents of room messages, where they count as communications not addressed to us. Direct messages are end-to-end encrypted and we cannot read them. | As in section 6 |
We collect no precise geolocation, biometric, health or financial account information, and no inferences about you. We use sensitive personal information only to provide the service you asked for and to keep it safe and secure, as the law permits, so the right to limit its use does not apply. The sources, purposes and recipients are in sections 3, 5 and 7. We do not sell or share any category.
Your rights
- Know and access the personal information we hold about you, including the categories, sources, purposes and recipients.
- Correct inaccurate information.
- Delete your information (the fastest way is You, then Delete account).
- Get a portable copy.
- Opt out of sale, sharing, targeted advertising and significant profiling (none of which we do).
- Not be discriminated against for using these rights. We never charge more or offer less because you made a request.
How: email support@sirenaclub.io. We verify a request by matching it to your account, for example from the email linked to it or a confirmation in the app. An authorised agent may act for you with your signed permission, and we may ask you to confirm your identity directly. We confirm receipt within 10 business days and answer within 45 days, which may be extended once by 45 days with notice.
Appeals: if we decline a request, you can appeal by replying with "Appeal" in the subject. We answer appeals within 45 days in Colorado and within 60 days elsewhere. If you are not satisfied, you can contact your state Attorney General.
16. Data breaches
If a breach of personal data occurs, we contain it and assess the risk. Where the GDPR requires, we notify the Bulgarian Commission for Personal Data Protection within 72 hours of becoming aware of it, and we tell affected people without undue delay when the risk to them is high. We also notify people and authorities as US state breach laws require. Notices go through the app and to the email linked to your account.
17. App Privacy label
The app's App Store privacy details and its privacy manifest list these data types, all linked to your account, none used for tracking, and all used only for App Functionality:
- Email Address: the email Apple shares at sign-in.
- Name: your name.
- User ID: your Apple user identifier, handle and account token.
- Photos or Videos: the registration document photo for verification.
- Purchase History: your subscription records from Apple.
- Emails or Text Messages: messages you post in rooms, which the club stores and shows to the room. Private messages are sealed end to end, so the club cannot read their content.
- Other User Content: your profile details, Dock posts, rooms you start, Nearby notes and reports.
The app contains no third-party SDKs, no analytics and no advertising, and does not track you across other companies' apps or websites.
18. Changes to this policy
We update this policy when the club changes. Material changes are announced in the app before they take effect, and the new version is posted here with a new effective date. Earlier versions are available on request.
19. Contact
Anton Dimitrov, sole trader, Varna, Bulgaria. Email: support@sirenaclub.io. In the app: You, then Write to the secretary.