Privacy Policy
This Privacy Policy explains what information WaveSage collects, how we use it, and the choices you have. By using WaveSage, you agree to this Policy. If you do not agree, please do not use the Service.
This document is provided to help you understand our practices and to support App Store / Google Play disclosure requirements. It is not legal advice. You should review it with counsel before relying on it for a commercial launch.
1. Who we are
WaveSage provides surf conditions, style-based outlook, and optional user-submitted condition photos for Southern California surf spots. The Service is operated from the United States and hosted on third-party cloud infrastructure.
Privacy contact: privacy@wavesage.app
2. Information we collect
2.1 Account information
When you create an account, we collect:
- Email address
- Username
- Password (stored only as a secure one-way hash; we cannot read your password)
- Name
- Age
- Experience level and surfing style preference
- Favorite surf spot(s) and quick-spot selections you choose
2.2 Session and authentication data
- An HTTP-only session cookie (
wavesage-session) used to keep you signed in - Optional password-reset tokens (time-limited) when you request a password reset
- Optional email-verification tokens when account verification is used
2.3 Precise location (User Wave Reports)
If you submit a User Wave Report (photo of conditions), the App requests precise location from your device so we can confirm you are near the selected surf spot (approximately within 2 miles / 3.2 km). We may also read location metadata embedded in the photo (EXIF) when available.
Location for reports is collected only when you choose to submit a report, not continuously in the background for tracking.
Guests who are not signed in cannot submit reports. Guest browsing of the User Reports gallery is limited to publicly accepted reports for Lower Trestles.
2.4 Photos and captions
When you submit a User Wave Report, we collect:
- The photo you upload (JPEG/PNG)
- An optional caption (limited length)
- Related metadata needed for validation (submission time, distance to spot, basic image-content confidence signals, and moderation notes)
Accepted reports may be shown to other users in the App (for example, on the User Reports tab or near spot conditions).
2.5 App usage and device information
- Basic technical information needed to operate the Service (such as IP address as processed by our hosting provider, browser or app type, and request logs)
- Optional in-app feedback about Sage responses (for example thumbs up/down, optional short comments, and related message context used for product improvement)
- Limited on-device storage (for example, a “last check” snapshot for a spot stored in your browser/app local storage so we can show changes since your previous visit)
2.6 Information from guests (not signed in)
If you browse without an account, we may still process:
- Requests needed to show public preview content (for example Lower Trestles outlook and regional live spot conditions)
- Standard hosting/server logs as described above
Guests cannot submit User Wave Reports or set account favorites.
3. How we use information
We use information to:
- Create and manage your account and keep you signed in
- Personalize surf outlook and recommendations based on your style and favorite spots
- Validate User Wave Reports (including proximity to the break) and display accepted reports
- Provide password reset and account support
- Improve product quality, reliability, and safety/moderation
- Protect against abuse, fraud, and unauthorized access
- Comply with law and enforce our terms
We do not sell your personal information. We do not use your precise location to build advertising profiles or to track you across other companies’ apps/websites for ads.
4. Mobile app permissions
On iOS and Android, WaveSage may request permissions only when needed for features you use:
- Location (when submitting a User Wave Report): to verify you are at or near the selected spot
- Camera / photo library (when submitting a report): to capture or select a conditions photo
- Network access: to load conditions, accounts, and reports from our servers
You can deny permissions in device settings; some features (especially User Wave Reports) will not work without them.
5. Cookies and similar technologies
We use an essential session cookie to authenticate signed-in users. This cookie is required for account features and is not used for third-party advertising. We may also use local storage on your device for small convenience features described above.
6. Third-party services
We use trusted processors and data sources to operate WaveSage, including:
- Hosting / infrastructure (for example Render or similar providers) to run the App and store account and report data
- Marine / weather / tide data providers (for example Open-Meteo and NOAA) to generate conditions and forecasts. These providers receive location coordinates for the surf spot being queried, not your name or password.
- Optional AI providers (for example OpenAI), if enabled, to help generate certain Sage responses. Content needed for the reply may be sent to the provider under their terms and our configuration.
- Optional email delivery (for example Resend), if enabled, to send password-reset or verification emails.
These providers process data only as needed to provide their services to us. Their own privacy policies apply to their processing.
7. How we share information
We may share information:
- With other users, when you submit an accepted User Wave Report (photo, caption, spot, and related display metadata)
- With service providers who help us host and operate the App
- If required by law, legal process, or to protect rights, safety, and security
- In connection with a merger, acquisition, or asset transfer, subject to appropriate protections
We do not sell personal information to data brokers.
8. Data retention
- Account data is retained while your account remains active and for a reasonable period afterward if needed for security, backups, or legal obligations
- User Wave Reports may remain visible while accepted and not deleted; you may delete your own reports in the App where that control is available
- Password-reset tokens expire automatically (about one hour) and are cleared when used
- Server logs are retained for a limited operational period by our hosting environment
9. Security
We use industry-standard measures appropriate to our size and risk profile, including password hashing, HTTPS in production, and restricted session cookies. No method of transmission or storage is 100% secure. Please use a strong unique password and protect your device.
10. Children’s privacy
WaveSage is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us and we will take steps to delete the information.
11. Your choices and rights
Depending on where you live, you may have rights to:
- Access the personal information we hold about you
- Correct inaccurate information (including via Edit profile)
- Delete your account or certain content (such as your reports)
- Withdraw consent for optional features (for example location/camera)
To request access or deletion of your account data, email privacy@wavesage.app from the email address on your account. We may need to verify your identity before fulfilling a request.
California residents: we do not sell or share personal information for cross-context behavioral advertising as those terms are commonly defined under the CCPA/CPRA. You may still contact us to exercise applicable rights.
12. International users
WaveSage is operated in the United States. If you use the Service from another country, your information may be processed in the United States, where laws may differ from those in your jurisdiction.
13. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the effective date. Continued use of WaveSage after changes become effective constitutes acceptance of the updated Policy.
14. Contact us
Questions about privacy or this Policy:
Email: privacy@wavesage.app
Website: https://wavesage.app
