Last updated: 8 September 2026
Portolana is intentionally built with data minimisation in mind. The app uses no advertising networks, no IDFA, no behavioural advertising and no cross-app tracking. Most trip data stays locally on your device. Servers are used only for features that require a connection, in particular account & sync, shared trips, weather requests, content downloads and voluntary imports. Product analytics are not sent to the Portolana server in the default release configuration and additionally require your explicit consent. Data are not used for advertising and are not sold.
Lari (Portolana · termi.cloud), Switzerland. Contact: privacy@portolana.com. Further provider details are available in the Legal Notice.
We process data to provide the app functions and contracts you choose, implement your consent, protect and troubleshoot the service, and comply with legal obligations. Where the GDPR applies, the applicable legal basis is performance of a contract or pre-contractual steps (Article 6(1)(b)), consent (point (a)), legitimate interests in a secure and functional service (point (f)), or legal obligations (point (c)), depending on the processing. You may withdraw consent with effect for the future.
On first launch, the app creates a stable random device identifier. It contains no name and is not intended as an advertising identifier, but it is pseudonymous, not anonymous. Depending on the feature used, it supports abuse prevention and daily limits, shared trips and weather requests. For voluntary remote analytics, only a server-side hash derived from it is stored.
The Portolana server runs on Cloudflare Workers and Cloudflare D1. Cloudflare processes technically necessary metadata for each server request, in particular IP address, timestamp, requested address, request headers and security information. Rate-limit counters contain the pseudonymous device identifier, the day and a count. The daily clean-up removes counters whose day is more than two days in the past. Security records or data required by law may be kept longer.
Portolana works without an account. If you voluntarily use Sign in with Apple, Portolana processes an Apple user ID and, if Apple provides it, an email address or private Apple relay alias. The Portolana server exchanges the submitted authorisation code with Apple. An Apple refresh token received in that exchange is stored encrypted with AES-256-GCM so Portolana can attempt revocation with Apple when the account is deleted. Portolana session tokens, the device name, and the time of the most recent access or backup are also stored.
After sign-in, a complete trip-data snapshot may be stored on the Portolana server. It includes trips and port calls, any expense data from earlier builds without receipt photos, packing lists and templates, notes, day plans, booked excursions without photo attachments, onboard events without photo attachments, and selected settings (including return reserve, language, ship-time offset, display settings, nickname and emergency contacts you entered). While you are signed in, the app attempts an automatic backup on launch if the previous backup was at least six hours ago. There is one server snapshot per account; a new backup replaces the previous state.
“Delete account” removes the account, its sessions and the sync snapshot from the Portolana server. Data on your devices remains and must be deleted separately. Shared trip pages are not linked to the account and must also be deleted separately or allowed to expire. On account deletion, the server attempts to revoke an existing Apple authorisation using the encrypted token. Older accounts may not have such a token; a technical revocation error also does not prevent deletion of the Portolana data. You should therefore also check apps using Apple ID in your Apple ID settings.
Only when you actively use “Share trip” does the app transmit the components you select to the Portolana server. In addition to route, ports, ship name and times, these may include a custom page title and sender name, port and country information, arrival/departure details, day plans including notes, excursions including meeting point and provider, onboard events, packing lists and recap statistics. The app does not offer onboard-account or expense data as a component in version 1.0. The server rejects new share payloads containing that component and hides it on previously stored trip pages. Receipt photos and account credentials are not included in shared pages.
The page content, selected components, pseudonymous device identifier, created/updated time, a secret management key and, depending on your selection, expiry time and password hash and salt are stored. The plaintext password is not stored. A shared page is not publicly listed and carries a “noindex” signal, but anyone with the code or link can open and forward it unless you set a password. A password reduces this risk but is not end-to-end encryption.
When you unlock a password-protected page, Portolana sets a technically necessary HTTP-only cookie for that page. It contains a random unlock value, no trip content, and remains stored for no more than 30 days unless you delete it sooner in your browser. For new shared pages, the app selects a 90-day validity period by default. You can select another offered period or deliberately choose no expiry. Without a selected expiry date, a shared page remains stored until it is deleted manually. A selected expiry may be no more than 365 days in the future. Expired pages are removed by the daily clean-up run.
You can delete your own page in the app using the management key stored on your device. If that key is lost, you can request deletion at privacy@portolana.com.
Portolana sends content to Anthropic only when you expressly start the relevant import function. This covers:
Import from third-party cruise-line websites or other URLs is blocked in version 1.0. Portolana does not fetch such pages for import and does not send their content to Anthropic.
The selected content, extracted results and pseudonymous device identifier for the daily limit are processed. Content may include names, booking details, cabin numbers, places, times and other information visible in the document. The Portolana server does not keep the input or result as an import archive; only the daily counter is stored. Check the result and do not upload passports, health data, payment data or other sensitive content that is not needed.
According to Anthropic's current information, commercial API inputs and outputs are deleted within 30 days by default and are not used to train generative models by default. Exceptions may apply in particular for legal or abuse-prevention purposes, expressly agreed different terms, or a voluntary opt-in. Anthropic's current information on retention and model training controls.
The app keeps no more than 200 local product and diagnostic events for no more than 30 days. Examples include opening return mode, using an offline pack, or a handled technical error. This local buffer contains no advertising ID, GPS history, payment data or photos. You can voluntarily create a sanitised diagnostic export and send it yourself through a service you choose.
Automatic upload of product analytics is technically disabled in the default release configuration. Upload occurs only if it has been made available in a release and you have expressly consented in the app. The server then receives the event name and time, app/platform version, a tightly limited set of coarse properties and a hash of the device identifier; it receives no free text, trip destinations or GPS data. Server-side analytics events are automatically deleted after no more than 90 days. You may withdraw consent in the app.
If you install a beta through Apple TestFlight, Apple processes beta data under its own rules. Apple provides us in particular with session and crash metrics and crash logs. If you submit TestFlight feedback, we may see your comment, screenshot, email address (if available), and app, device, operating-system and connection details. Apple states that downloadable crash reports remain available for 120 days. Details: Apple TestFlight feedback.
Portolana Plus purchases are processed through Apple. Portolana receives no credit-card or billing-address data. The app processes product and transaction states provided by StoreKit and stores entitlement status locally; Apple handles payment processing and purchase history.
Excursion buttons may open GetYourGuide or Viator in your browser. A link may contain a Portolana affiliate identifier. This lets the booking platform attribute a booking to Portolana; Portolana does not include your name or account details in the link itself. The respective provider's privacy rules apply once opened.
Community tips, cabin reviews, onboard account/receipt capture, “Ask Portolana”, general accessibility ratings and live ship positions are not available in the public version 1.0; the same applies to importing third-party cruise-line websites by URL. Portolana therefore does not accept new community posts, cabin reviews, receipt photos or free-form chat text through those functions in version 1.0 and does not fetch an import URL. If such functions are introduced later, the in-app notices and this policy will be updated before public activation. Existing legacy expense data may remain locally and in the account snapshot; it is not displayed or newly shared in version 1.0. Local legacy data must be deleted separately on the device. A new backup replaces the previous snapshot but may include the legacy data again; account deletion removes the snapshot. You may also request deletion of data from earlier test versions at privacy@portolana.com.
portolana.com uses no advertising or analytics cookies and no website analytics. Hosting is on Cloudflare, which processes technically necessary server data. The tipping calculator stores an exchange-rate cache in local browser storage for up to 24 hours. Only password- protected shared trip pages use the technically necessary unlock cookie described above. If you send a beta request or support message using an email link, your email provider and we process the information you enter in order to handle the message.
If you are in the European Economic Area, the United Kingdom or Switzerland, you may have rights to access, rectify, delete, restrict or object to the processing of your personal data and to data portability, depending on applicable law. You can delete or export many items in the app; local data, shared pages and account/server data must be deleted separately as described above. You can also contact us at privacy@portolana.com. You have the right to lodge a complaint with a supervisory authority in your country.
If you are a California resident, you have the right to know what personal information we collect, to request access, correction and deletion, and to opt out of any "sale" or "sharing" of personal information. Portolana does not sell personal information or disclose it for behavioural cross-context advertising as defined by CCPA/CPRA. We do not use behavioural advertising or build profiles for cross-context advertising. To exercise your rights, contact privacy@portolana.com. We will verify your request via the email associated with your account (if any) or via a device-bound identifier.
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA) and other US states with comprehensive privacy laws have substantially similar rights (access, correction, deletion, portability, opt-outs). The same contact address applies: privacy@portolana.com.
Portolana is not directed to children under 13 (or under 16 in the EEA, Switzerland or the UK). We do not knowingly collect personal data from children. If you believe a child has provided data through the app, please contact us so we can delete it.
Portolana is operated from Switzerland. Cloudflare and Anthropic may process data in the EU, the United States or other countries. Cloudflare's contractual privacy terms include a Data Processing Addendum and safeguards for international transfers. The applicable safeguard depends on the provider and processing location. You can ask privacy@portolana.com for details of the current position.
We may update this policy from time to time. The current version is always available at portolana.com/en/privacy.html.
© 2026 Lari · termi.cloud