Privacy Policy
This policy covers this website and the RideScore app. It is written to be read, not to be survived.
The short version
- RideScore measures how rough the water is and how a boat rides in it.
- There is no account, no name and no password. Your phone gets an anonymous identity the first time you open the app. You can optionally add Sign in with Apple so the same rides come back on a new phone; that is the only way we ever hold an email address, and Apple lets you hide yours behind a relay.
- When you record a ride, it is shared. Its motion and position data is uploaded to our servers, where it feeds our own research into how boats ride, and will build the shared conditions map when that is switched on. That is the trade the app is built on. The map in the app today is computed from public weather data, not from anyone's rides.
- Recording without sharing is a paid feature. It is called private mode, and it is part of RideScore Pro. On the free app, the rides you record are contributed.
- Contributed time is also how Pro is earned: every 25 hours of shared ride data is a month of it, up to twelve banked months, credited to the boat's owner.
- Spot Guard is a separate setting that keeps the places you stop off our servers at any resolution that could find them. It is on by default.
- Saved points live on your phone and in your own iCloud account. We hold nothing about them unless you switch on an alert for one — and then only a seven-mile square.
- We will sell data built from many users' rides: statistics, aggregated and anonymised. We never sell your ride, your track, or your location.
- When the shared map is switched on it will show water conditions in grid cells only — never boats, tracks, dots, or people.
- This website sets no cookies, runs no analytics, and makes no third-party requests.
Who we are
RideScore is made by Solitary Labs LLC, Mount Pleasant, South Carolina, USA. We are the controller of the data described here. When this policy says “our servers” it means the systems we operate for RideScore: a database, accounts, file storage and server functions hosted at Supabase; forecast data stored and delivered from Supabase Storage and Cloudflare; and the machines that compute the forecasts, which we operate. Those providers host it; we control what is stored and who can read it, and they are listed under Who processes your data. We are not part of any boat manufacturer, dealer, insurer, or marine electronics company.
Privacy questions, and requests for a copy of your data or its deletion, go to support@solitarylabs.com.
This website
solitarylabs.com is a handful of static pages. There is no login, no comment box, no form, and no newsletter.
- No cookies. The site sets none, of any kind, first- or third-party.
- No analytics and no tracking. There is no Google Analytics, no tag manager, no advertising pixel, no session recorder, and no third-party script of any kind.
- No third-party requests. The typefaces are served from this domain rather than from a font CDN, so loading a page here does not tell anyone else that you did.
- Hosting. The pages are served by Cloudflare Pages. Cloudflare necessarily processes your IP address and request in order to deliver the page, and keeps short-lived operational and security logs. We do not add anything to that, and we do not build a profile from it.
Your identity in RideScore
The app works without an account. On first launch your phone is issued an anonymous identifier, which is what your data is stored against. We do not ask for a name, a phone number, or a password, and there is no way to give us one.
You can optionally add Sign in with Apple, which exists so your rides follow you to a new phone. It gives us an email address — your own, or Apple's private relay address — and we use it to find your account and for nothing else. We do not request your name, and we never receive your Apple password.
What the app collects on your phone
- Motion sensors — accelerometer and gyroscope — during a ride you start.
- Location — GPS track, speed and heading during a ride you start. Recording continues in the background while a ride is running, so you can put the phone down.
- Your boat profile — anything you enter: name, make, model, year, dimensions, weight, hull details, engines, fuel, load, cruise speed, ride equipment, and how and where the phone is mounted.
- Your rides — start and end time, distance, scores, and the raw sensor archive for the ride.
These live on your phone at full resolution, always, whatever your sharing settings say.
When you look at the forecast
To draw a forecast we send our servers the map area you are looking at — or the point you pinned — along with the specifications of your boats (the point sheet sends your whole fleet so it can compare them), and return the forecast for that water. Your device also downloads background map tiles from OpenFreeMap and water and forecast tiles from our own storage; those requests carry the map area being viewed.
Your saved points
Points you save — a dock, a reef, a spot — are yours, and they are handled differently from everything else in this policy.
- They are stored on your phone and in your own iCloud account (Apple's private database, which we cannot read). We hold nothing about a point on our servers unless you switch on an alert for it.
- When you open a point's forecast, or when the planner ranks your favourite points, we send that point's position so we can compute a forecast for that water. We do not send the name you gave it, and nothing we store from that request carries your account.
- If you turn on “Alert me when it turns good” for a point, what is stored on our servers is a rough square, roughly seven miles on a side, the condition you are waiting for, and an id for that point under your account — never the exact position, and never the name.
What leaves the phone when you record
Unless you have Pro and have turned private mode on, recording a ride uploads it. Two lanes of data leave the phone while you are out:
- Above 15 knots (the transit lane): once you get up above 15 knots (and until you drop back below 12), per-second position, speed, heading, vertical and lateral motion statistics, roll and pitch rate, and the live score, uploaded as a full-resolution track segment. With Spot Guard on, the first and last stretch of each run is trimmed off and never sent.
- Below 15 knots (the fishing lane): ten-minute motion summaries — roll and heave statistics, drift speed and direction. With Spot Guard on, these are stripped of precise coordinates on your phone before upload and carry only a coarse cell (roughly 5 nautical miles across) and a depth band. With Spot Guard off, they upload at full resolution.
- Also uploaded: one row per ride (start, end, app and algorithm version, the Spot Guard setting in force for that ride, your selected boat), one row per boat you set up, a sanitised copy of the ride's sensor archive — the same Spot Guard filter applied to it — and a contributor-hours tally. From that archive our server also computes a ride study and the per-hit research record described below, both stored under your account.
What Spot Guard does
Spot Guard exists because the secret is not how rough the water is — it is where you stop. With Spot Guard on:
- Below 15 knots, no precise coordinate leaves your phone. Your time stopped or drifting is tagged with the centre of a wide cell — roughly 5 nautical miles across — plus a depth band, and nothing finer is uploaded. The motion data still goes: a drifting boat measures true sea state better than anything else we have, which is why the guard coarsens the position rather than dropping the data.
- Both ends of every run are withheld. The stretch before you drop off plane never uploads, and neither does the stretch after you get up on it — at least 2 nautical miles and at least 10 minutes at each end, whichever of the two is longer. Both are discarded on the phone, not delayed.
- Your own history is untouched. Spot Guard is an exit filter and nothing more. Your recording stays full resolution on your phone, always, whatever it is set to.
What Spot Guard does not do
We would rather tell you this plainly than have you find out later.
- It does not hide where you run. Above 15 knots, with sharing on, your position track leaves the phone at full resolution and is stored on our servers. Spot Guard trims the two ends; the middle of the run is data we hold.
- It does not make your uploads anonymous. Data we receive is stored against your account identifier. Other users cannot read it. Solitary Labs can, and does: we read and process it for our research into how boats ride, to check and improve the forecast, and to run the service. It is not published and it is not sold as your data (what we do sell is described under Aggregated statistics below) — but it exists, it is linked to your account, and valid legal process can reach it.
- It is a filter, not a guarantee against every inference. A track that begins and ends at your dock says something about you even with the middle removed.
- It does not apply to your own device. If someone has your unlocked phone, they have your spots.
When the app crashes
If RideScore crashes or freezes, iOS collects a diagnostic report and hands it to the app the next time you open it. We send that report to our own servers so we can fix what broke.
- What is in it: the app version, the iOS version, your device model as iOS reports it (“iPhone17,1”, not your phone's name), and the technical stack, exception codes and termination reason for where the code stopped.
- What is not in it: no account identifier, no device or install identifier, no location, and nothing about which rides or spots you have. The report is not stored against your account and there is no way for us to tell whose phone it came from.
- We use Apple's own MetricKit for this. There is no crash-reporting or analytics company involved.
One more thing the app sends about itself. When you open a point's forecast, the app compares the number it got from our published forecast data against the number our server computes, and sends us the difference: the size of the disagreement, a square about seventy miles on a side, and the same app, iOS and device-model facts as a crash report. No coordinate, no point name, no boat, no account identifier. It is how we check that the fast path is telling you the truth.
What we do not collect
- No name, no phone number, no password. The only optional sign-in is Sign in with Apple, and the only thing it gives us is an email address.
- No contacts, photos, calendar, microphone, camera, or health data.
- No advertising identifier, and no advertising or analytics SDK. The app contains exactly one third-party library, MapLibre, for drawing the map.
- No cross-app or cross-site tracking of any kind. We do not use your data for advertising and we do not let anyone else do so.
- No purchase or payment information. Apple handles any transaction; we never see your card, and all we receive back is whether a subscription is active.
What is ever shown publicly
- The shared conditions map is not built yet. The map in the app today is computed from public weather data, not from anyone's rides. When the shared map is switched on it will render grid cells only — no dots, no track lines, no names — and only from the coarsened fishing lane.
- Full-resolution data above 15 knots is stored under your account, where no other user can read it. We read it: it feeds our own research and the accuracy of the forecast. It is never rendered on a shared surface. There is no research toggle — every ride is treated the same way. Our server does derive an internal research record from each ride's archive, holding the hard hits and how the boat was sitting when they happened; it is stored under your account, no app can read it, and deleting your account deletes it.
Aggregated statistics, and licensing
Statistics built from many users' rides — how rough given water is, how a given hull model rides in given conditions, and comparable fleet-scale figures — are the product of this whole exercise. We will show them in the app, publish them, and sell and license them to third parties. That is part of how this company makes money, and we say so plainly. What we license or publish is bounded, and the bounds are commitments, not preferences:
- Aggregated and anonymised only. Nothing that identifies you, your account, your device, or your individual vessel.
- Never individual rides or tracks. No track line, no ride record, no trip — yours or anyone's — leaves this company in any licensed or published output.
- Never location finer than the coarse cell (roughly 5 nautical miles across). Precise position is never in a licensed output, whatever your Spot Guard setting was for that ride.
- Never raw telemetry. Not your raw sensor archive, not the raw NMEA bus log, not the per-second series.
- Never for advertising, ad measurement, or profiling of you.
If we ever want to go beyond these five bounds, we will ask you again in the app. A posted update to this page is not enough for that.
How long we keep things
- Your rides, tracks, station windows, studies, research records and uploaded archives are kept for as long as your account exists. We do not delete them on a schedule, because the archives are what the forecast's physics is fitted from.
- Crash reports and the fast-path check rows are deleted after 90 days.
- Alert squares are deleted the moment you switch the alert off or delete the point.
- Anonymous accounts that were never signed in with Apple, never recorded a ride, have no boats, and have been silent for twelve months are deleted.
- When you delete your account, your rows and files are removed from our database and storage immediately. Copies in our database backups expire within 30 days.
- Aggregated statistics are kept indefinitely. There is nothing personal in them.
- This website stores nothing about you. Cloudflare's own request logs are short-lived and are not ours.
Who processes your data
- Supabase — our database, file storage, authentication and server functions (United States).
- Cloudflare — this website, part of the forecast data delivery, DNS and domain registration.
- Apple — App Store distribution, TestFlight, device attestation, and subscription billing.
- NOAA and the National Weather Service — public wave, wind, tide and current model data we read to compute forecasts. We send them nothing about you; it is a one-way download of public data.
- OpenFreeMap, OpenMapTiles and OpenStreetMap — basemap vector tiles your phone downloads while you view the map.
We do not have a contract that lets any of these use your data for their own purposes; they process it to run our service. Everything we store about you is in the United States. If you use RideScore outside the US, your data is stored and processed in the US.
Security
- Every table carrying your data has row-level security from the first migration: from the app, your rows are readable and writable only by your account, and cross-account access is denied at the database, not just in the app. Our own servers and staff can read every row; that access is what lets us do our research, fix the forecast and answer support.
- File storage is separated by account in the same way: an upload into another user's folder is refused, and our servers can read all of it.
- Server ingestion validates every payload for physical plausibility and rejects impossible speeds, teleporting tracks, impossible accelerations and bad timestamps.
- Transport is HTTPS throughout.
- No system is perfectly secure, and we do not claim otherwise.
Legal requests
We will only disclose data in response to valid legal process — a subpoena, court order, or warrant that we believe is lawful and that actually reaches the data described. Our practice: we require valid process; we read it narrowly and produce only what it actually compels; we push back on requests that are overbroad or facially invalid; and we notify the affected user in advance where the law permits and we have a way to reach them.
Your choices and your rights
- Turn on private mode and nothing from your rides leaves the phone at all. It is a Pro feature; on the free app, recording contributes.
- Leave Spot Guard on — it is on by default — and the places you stop are not uploaded at a resolution that could find them.
- Do not record. The forecast, the map and your boat profiles work whether or not you ever start a run.
- Export. You can export a ride — the raw sensor archive as a ZIP — from the trip screen.
- Delete a trip from this phone. Deleting a trip in the Trips list removes it and its files from the phone. It does not remove a ride you already uploaded from our servers — deleting your account does that, and it deletes all of them.
- Delete your account. Settings › Delete account › Delete my account and data, behind two confirmations. It removes your rides, your track segments, your station summaries, your ride studies and research records, your boats, your watched squares, your uploaded archives, and any Pro months you have banked, and signs this phone out. It cannot be undone. Crash reports and the fast-path check rows described above are not touched, because nothing on them says they were yours.
- Turn off permissions. iOS Settings controls location and motion access. The app will not record without them.
If you would rather make one of these requests in writing, email support@solitarylabs.com. We do not charge for it, and we will not treat you differently for asking.
Children
RideScore is intended for adults operating boats. It is not directed to children and we do not knowingly collect data from anyone under 13. If we learn that we have collected data from a child under 13, we delete it.
Flash
Flash, our nutrition tracker, is not on the App Store; it exists only as an internal test build and is still in development. Its privacy policy will be published on this site before it ships, and it will describe that app's own data handling specifically. Nothing on this page should be read as a description of Flash.
Changes
We will post changes here and update the date at the top. For a change that materially expands what we collect or how we use it, we will ask again in the app rather than rely on a posted update.
About the RideScore number
RideScore is a conditions index — a measurement and a forecast of how rough the water is and how a given hull is expected to ride it. It is not navigation guidance, not a safety determination, and not advice about whether to go out. Conditions change, forecasts are wrong, and the operator is responsible for the vessel.