Legal • Last updated: August 30, 2026

Privacy Policy

For CruiseLoom (com.charles.cruiseapp) — Offline-First Cruise Companion. This policy explains what stays on your device and how Google Firebase, Google Mobile Ads, Open-Meteo, OpenStreetMap, GitHub, and Firebase Hosting process limited data.

🔒
TL;DR: Your cruises, ports, events and party chats stay on your device. We run no account or chat server and do not sell personal data. The app displays Google AdMob ads and uses Firebase diagnostics; those Google services may process device identifiers, ad interactions, diagnostics, and approximate location derived from IP. Weather, map, and optional deck downloads send only the request needed to their providers.

1. Overview & controller

App: CruiseLoom, package com.charles.cruiseapp, Android minSdk 26, targetSdk 36, v1.0.0.

Controller: Charles (project chartmann1590/cruise-app). CruiseLoom is distributed through Google Play and is supported by advertising.

Hosting: This website is hosted on Firebase Hosting (cruise-app-2026.web.app). Firebase Hosting logs standard access logs (IP, user-agent) for operations — see Google's privacy policy.

Effective: August 30, 2026. If you do not agree, do not install or use the app.

2. What stays on your device (offline-first)

The app is offline-first. Room database cruise_db v3 is the source of truth and lives only on your phone. Nothing is uploaded to our servers — because we run none.

You can clear data at any time through Android Settings → Apps → CruiseLoom → Storage → Clear Data, or by uninstalling. Android cloud backup is disabled for the app, so the local database and preferences are not backed up by CruiseLoom.

3. Firebase Crashlytics & Performance Monitoring

We use Firebase Crashlytics and Firebase Performance Monitoring (Google LLC) to keep the app stable and fast. Both are enabled via google-services.json (project cruise-app-2026, app 1:142214388007:android:adb81f9e0787ff0f8a3102) with SDKs:

What they collect

ServiceDataPurpose
CrashlyticsCrash stack traces, exception messages, device model/OS version, app version/build type, and an anonymized installation identifier. Production builds do not attach party IDs, chat text, ship names, port searches, or detailed app breadcrumbs.Diagnose crashes and non-fatal errors.
PerformanceApp-start and feature timing traces, duration/success/error metrics, coarse technical attributes, HTTP metrics such as URL host/method/response code/payload size, and automatic screen/network traces. Production traces do not attach event titles, ship names, or search text.Measure speed, success rates, and where the app slows.
Analytics (core)Firebase Analytics is a dependency of Crashlytics/Performance; collects anonymized usage, session, device, OS. No events with personal cruise content.Required by SDK; we send no custom purchase/ads events.

Opt-out: Crashlytics and Performance collection are enabled to maintain app reliability. Disable them by uninstalling or blocking network access at the OS level. Diagnostic data is not linked to a CruiseLoom account because the app has no accounts.

Processing: Google processes crash/perf data under its terms (firebase.google.com/support/privacy). Data may be stored in the US. Retention ~90 days (Crashlytics) and ~recent traces for Performance.

3a. Google Mobile Ads (AdMob)

CruiseLoom contains banner and interstitial ads supplied by Google Mobile Ads. Google and its advertising partners may process the advertising ID or other device identifiers, IP address and IP-derived approximate location, app interactions, ad views/clicks, and diagnostic information to deliver, measure, prevent fraud in, and—where permitted by your region and consent choices—personalize ads. CruiseLoom does not receive your name, email address, cruise itinerary, or chat messages from AdMob.

Where required, Google’s consent flow or ad controls determine whether personalized ads may be used. You can reset or delete your advertising ID and manage ad privacy choices in Android settings. See Google’s advertising privacy information.

4. Open-Meteo weather & geocoding

When you add a port or view weather, the app calls:

This is a direct request from your device to Open-Meteo. We do not proxy or log it. Your query text and lat/lon are sent to Open-Meteo per their privacy policy and CC BY 4.0 attribution (shown in WeatherCard.kt). They may log IP & request. Pull once on port Wi-Fi, then the response is cached 3h in WeatherCache for offline sea days. Block via firewall or skip weather if you prefer not to share location.

5. Port maps — OpenStreetMap

Port Map uses OpenStreetMap tiles via osmdroid 6.1.20 (TileSourceFactory.MAPNIK). Tiles are fetched directly from tile.openstreetmap.org on your device — we run no proxy. Requests include your IP and a User-Agent: com.charles.cruiseapp header per OSM usage policy. Tiles are cached in filesDir/osmdroid/tiles so sea days work offline after a Download offline on port Wi-Fi. Attribution © OpenStreetMap contributors (ODbL) is shown on the map. No API key, no billing. You can use port maps entirely offline by downloading before sailing; the map also works with limited cache from panning.

Optional My Location dot uses ACCESS_FINE_LOCATION only when you tap it and grant permission. Location never leaves the device except as part of normal tile requests (your IP is visible to the OSM CDN). Deny the permission and port maps still show your itinerary polyline.

6. Ship deck maps — GitHub & Firebase Hosting (optional download)

Ship deck maps are optional CC0-1.0 original schematics hosted inside this repo and served via Firebase Hosting (cruise-app-2026.web.app/decks/) and raw GitHub fallback (raw.githubusercontent.com/chartmann1590/cruise-app/main/public/decks/). When you tap Download for your ship, the app fetches manifest.json + selected *.webp images directly from those CDNs. Only the CDN sees your IP + URL (e.g., /decks/ships/royal-caribbean__symphony-of-the-seas/deck-05.webp). No cruise itinerary, party message, or personal data is uploaded.

Images are saved to app-private storage filesDir/decks/<shipId>/ and work fully offline thereafter. A small manifest.json (~65 KB) is also cached in assets for offline fallback. If a ship has no CC0 image yet, the app shows an Open official deck plan link to the cruise line's own site (requires internet, not tracked by us). You may decline the download entirely and still use the planner. All deck images are CC0 (public domain) original schematics — we do not redistribute cruise line copyrighted PDFs.

Daily countdown notifications (if your cruise is in the future) use AlarmManager and may enrich text with a brief weather snippet from your departure port's cached WeatherCache (or a one-shot Open-Meteo fetch if stale). No extra data collection.

7. Nearby Connections — offline party chat

Party chat uses Google Play Services Nearby Connections Strategy.P2P_CLUSTER — an encrypted peer-to-peer mesh over Bluetooth + BLE + Wi-Fi Direct. No internet, no server, ~100m per hop.

QR identity: Your QR is generated locally via ZXing QRCodeWriter (no upload). Scanning adds PartyMember with that code. No contacts are uploaded.

8. Permissions we request & why

PermissionWhyOptional?
INTERNET, ACCESS_NETWORK_STATEWeather/geocoding, deck/map downloads, Firebase diagnostics, and Google Mobile Ads.These are normal permissions with no runtime prompt; core itinerary tools remain local-first when offline.
POST_NOTIFICATIONSShow event reminders on cruise_reminders & party messages (PARTY_CHANNEL).Android 13+: you can deny; reminders silent.
RECEIVE_BOOT_COMPLETED, VIBRATEReschedule inexact event and countdown reminders after reboot and provide notification feedback.Disable notifications in Android settings to silence reminders.
BLUETOOTH_SCAN, BLUETOOTH_ADVERTISE, BLUETOOTH_CONNECT, NEARBY_WIFI_DEVICES, ACCESS_WIFI_STATE, CHANGE_WIFI_STATE, BLUETOOTH / BLUETOOTH_ADMIN (maxSdk 30)Nearby Connections needs to scan/advertise/connect over BT/BLE/Wi-Fi Direct. On Android ≤10 location was required for BT scan (we set neverForLocation where supported).Denial: party chat disabled.
ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATIONPort Map My Location dot (osmdroid MyLocationNewOverlay). Requested only when you tap the location button. Also covers legacy Nearby on older Android.Denial: port maps still show itinerary polyline; dot disabled.
CAMERA + hardware.camera (required false)Scan QR via zxing-android-embedded:4.3.0 + zxing:core:3.5.3 ScanContract.Denial: add party members by typing code or manual add.

We never request READ_CONTACTS or STORAGE. Location is requested only for the optional Port Map dot; deck maps and weather use device IP only.

9. Data we collect — summary table

CategoryCollected?DetailsShared?
Cruise / ports / events / messages you create❌ Not collectedLocal Room only. Never to our server (we have none). Export only if you choose (e.g., screenshot).No
Crash stack traces & perf traces✅ Yes, pseudonymousVia Firebase Crashlytics/Performance as above. Production builds do not set the local party code as a Crashlytics user ID.Google Firebase only
Device or advertising identifiers, ad interactions, diagnostics, IP-derived approximate location✅ YesProcessed by Google Mobile Ads to provide, measure, secure, and where permitted personalize ads.Google and advertising partners
Weather queries (text, lat/lon, IP)✅ When you use weatherSent directly to Open-Meteo per their policy. Cached 3h.Open-Meteo only
Port map tiles (z/x/y + IP, User-Agent)✅ When you view Port MapFetched directly from tile.openstreetmap.org (OSM), cached in filesDir/osmdroid for offline sea days. © OSM ODbL.OpenStreetMap CDN only
Ship deck manifest + webp (shipId + IP)✅ When you download deck mapsFetched from cruise-app-2026.web.app/decks/ / raw.githubusercontent.com/.../public/decks/ (GitHub). Cached in filesDir/decks/. Optional; offline after. CC0.Firebase Hosting / GitHub CDN only
Countdown daily notification text (weather snippet)✅ If future cruiseLocal AlarmManager notification at 9 AM; may include cached weather for departure port.None (local only)
Bluetooth peer names/codes & chat content❌ Not collected by usP2P encrypted between your devices; stored locally.No
Hosting access logs (IP, UA) on this site✅ By Firebase HostingAutomatically for operations; not used for profiling.Google

We do not sell, rent, or trade your cruise itinerary or chat data. Third-party processing is limited to the services disclosed above, including Google Mobile Ads and Firebase.

10. Retention & deletion

11. Security

Local DB uses Android app-private storage. Nearby Connections is encrypted by Google Play Services. Weather uses HTTPS. Firebase uses TLS. No app-level encryption of Room at rest in v1.0 — device encryption (Android file-based) is relied upon. Report issues via GitHub or contact email.

12. Children

The app is not directed to children under 13 and does not knowingly collect personal data from children. It is for travelers planning cruises (general audience). If you believe a child’s data was sent via Crashlytics (e.g., a display name containing a child's name you typed), uninstall and contact us to request deletion.

13. Your rights & choices

14. Changes to this policy

We will update the date above and, for material changes, bump versionName and note in GitHub releases. Hosting shows this always at /privacy. Check occasionally.

15. Contact

Questions, requests, or takedown: open an issue at github.com/chartmann1590/cruise-app or email the maintainer via GitHub profile. For Firebase-related deletion requests, include your installation UUID (self_code) and app version.

This policy does not replace Google's (policies.google.com/privacy) or Open-Meteo's privacy policies. We are not affiliated with Open-Meteo, Google Nearby, or any cruise line.

← Back to CruiseLoom View source

© 2026 CruiseLoom • cruise-app-2026.web.app • Firebase project cruise-app-2026 (142214388007)