# Privacy Policy

Last updated: 2026-10-07

What you share, why it is used, and the choices you have.

Publication draft

These documents are being prepared for the iOS and Android launch. The legal operator, contact details, service providers, and mobile data practices still need confirmation. This version is not a final notice for a live mobile service.

## 1. Who this policy covers

This policy covers the Cruise.do website, web prototype, and planned iOS and Android apps, including Cove. The operator in the contact section is responsible for personal data processed by Cruise.do. Apple, Google, cruise lines, and external websites have their own policies for services they provide independently.

The current prototype stores customer data in your browser and uses simulated sign-in, AI answers, payments, and invitations. It has no remote customer-account database. The mobile-processing sections below describe the proposed connected service and must be checked against the released app before publication. They are not a claim that cloud sync, real billing, or a mobile AI provider is already running.

## 2. Browsing this website

The landing page stores your chosen language in browser storage. Ship searches run on your device; this version does not send the search text to a search or analytics service. Loading the site sends the network information needed to deliver it, such as your IP address, requested URL, and browser headers, to the website host. Hosting logs and their retention must be confirmed for the production host.

The current landing page has no advertising pixels, third-party analytics SDK, or marketing-cookie integration. Local interaction events are not sent to an analytics endpoint by this version. If this changes, we will describe the provider and purpose and request consent where required. Links to an app store or another website are governed by that destination's privacy policy.

## 3. Information you provide

Depending on the features you use, Cruise.do handles your name, email, chosen sign-in method, language, optional profile photo, ship and sailing dates, party size and child ages, preferences, questions, answers, attachments, plans, favorites, and support messages. These help identify your account, tailor cruise information, preserve your work, and answer requests. Avoid entering sensitive information that a cruise question does not need.

In the connected mobile design, Apple or Google sign-in provides an account identifier and the profile fields you authorize; Apple may provide a relay email. Cruise.do does not receive your Apple or Google password. Email sign-in uses the information needed to verify access. Those provider integrations are simulated in the present web prototype.

## 4. Purchases and service records

For a released mobile purchase, the app would use store transaction references, product, amount and currency where supplied, purchase status, sailing, included accounts, and refund or restoration status to verify and deliver access. Apple or Google processes store billing; Cruise.do does not need your full card details. Free-question counts, request status, and dates help apply limits without charging failed answers twice.

Connected services may also need IP addresses, device and app version, security events, and error records for delivery, abuse prevention, and troubleshooting. The exact diagnostic fields, SDKs, recipients, and retention periods have not been selected for the mobile release. Optional analytics must be identified separately from records necessary to operate the service.

## 5. Cove and AI processing

The web prototype uses authored sample answers and does not send your questions to a live AI model. In a connected release, answering a question may require sending the question, relevant conversation context, and selected cruise details or preferences to an AI provider. Attachments must not be sent for analysis unless that capability is offered and you choose to use it.

Before an external AI feature is enabled, the app must identify the provider, the data being shared, the purpose, and the applicable retention and model-training practices, and obtain any required explicit permission. No mobile AI provider or training arrangement is confirmed in this draft. Do not interpret it as a promise of zero retention or no provider training. AI answers support your planning; they are not decisions about your legal rights or eligibility for essential services.

## 6. Photos, microphone, notifications, and location

Photos and files are optional. The current prototype stores selected profile and chat attachments in local browser storage. Voice starts only when you use the microphone control and allow access. The browser or operating system's speech service may process audio online under its own policy. The prototype retains the resulting text, not an audio recording; cancelling discards the current transcription. A native implementation must disclose any different audio processing before use.

Notifications are optional and can be turned off in device settings. A connected push service would use a device token to deliver them; that provider is not configured in the prototype. Ship directions use the starting point you select. The current prototype does not track your precise or background location and does not upload your address book. Denying an optional permission should leave unrelated features available. Revoke permissions through iOS, Android, or browser settings.

## 7. Your travel party

An organizer may provide a traveler's email to invite them to a paid sailing account. Use this only with that person's permission. In the connected design, the organizer can see membership and invitation status, not another traveler's private conversation, plans, or favorites. Staff access must be limited to the work their role requires. The operations mockup contains fictional records; its role switch is not production security.

## 8. Why information is used

The proposed service uses account, sailing, conversation, and purchase information to provide the features you request and administer your agreement. Optional permissions, marketing, and other consent-based processing rely on your choice where the law requires it. Security, abuse prevention, and proportionate troubleshooting may rely on legitimate interests where that legal basis is available and does not override your rights. Billing and legally required records may be processed to meet legal obligations. We must establish an appropriate basis separately for any sensitive data rather than treating acceptance of the terms as consent.

## 9. Service providers and international transfers

A connected mobile service may use providers for hosting, sign-in, AI, speech, email delivery, push notifications, billing verification, and diagnostics. Only the information needed for each task should be provided, with appropriate contractual and security controls. We may also disclose information when lawfully required, to protect rights or safety, or in a business transfer subject to applicable privacy protections. Cruise.do does not send private conversations to cruise lines merely because you select their ship.

The mobile provider list, processing countries, and transfer arrangements remain unconfirmed. Before launch, this policy must identify the actual recipients and explain applicable transfer safeguards, such as recognized adequacy decisions or approved contractual clauses where required. The current prototype has no data-sale or advertising integration. A statement about the released app's sale, sharing, targeted-advertising, or model-training practices must be based on its actual providers and contracts.

## 10. Storage, retention, and security

In the prototype, profile data, conversations, photos, preferences, plans, favorites, invitations, and downloaded content remain in browser storage until you remove them, use the app's deletion controls, or clear site data. Signing out does not delete stored data. People using the same browser profile may be able to see it. Keep exported files and device backups secure; copies you create are outside Cruise.do's control.

For a connected service, data should be retained only for the feature you requested and for necessary legal, accounting, dispute, or security purposes. Deletion must cover account content and relevant providers, with narrowly justified exceptions. The production retention schedule, backup expiry, provider retention, and deletion completion times are not yet confirmed and must be specified before launch. This draft does not promise immediate removal from every backup or claim end-to-end encryption. Production safeguards must include appropriate access controls and secure transmission and storage, verified against the released app.

## 11. Delete your account and data

In the current web prototype, open Profile & settings and use the account-data deletion controls on that device. Export conversations first if you want to keep them. Clearing this site's browser data removes local site storage as well; it may also remove your language choice and downloads. There is no remote prototype account or real store purchase to cancel.

The released mobile app must provide account deletion within the app and a working external request route on this page for people who no longer have it installed. A request may require proportionate identity verification, but never your password or full card number. Deletion must remove the account and associated personal data, not merely suspend access. Any legally necessary retained records, reason, and retention period must be explained. App-store billing records are also governed by the store's own policy; account deletion is not itself a refund request.

A mobile-account deletion contact has not been configured yet. The current prototype has no remote accounts to delete; use the local deletion controls described above. This web request route must be connected before mobile accounts launch.

## 12. Your privacy choices and rights

You can edit profile information, decline optional permissions, remove local content, and export conversations using the available app controls. Depending on the law that applies, you may also request access, correction, deletion, portability, restrictions, or objection to processing; withdraw consent without changing the lawfulness of earlier processing; and complain to your privacy regulator. Where applicable, you may ask about recipients, challenge an automated decision, or opt out of sale, sharing, or targeted advertising. We must respond within the applicable legal period and explain any lawful refusal. Exercising a right must not lead to unlawful discrimination.

For people protected by the GDPR or UK GDPR, applicable rights include objections to legitimate-interest processing and complaints to a supervisory authority. For people protected by Brazil's LGPD, applicable rights include confirmation of processing, information about sharing, and requests concerning unnecessary or unlawfully processed data. Contact the privacy address below; authorized representatives may act where the law allows. A device-permission setting is separate from a request to erase information already provided.

## 13. Children and young travelers

Cruise.do accounts are not intended for children under 13 or anyone below a higher applicable local minimum age. A parent or guardian should provide only the party details needed for planning, such as a child's age, rather than a child's contact information. Appropriate guardian authorization and local protections are required for eligible minors. If you believe a child has supplied information contrary to these rules, use the privacy contact so it can be reviewed and removed where required.

## 14. Changes to this policy

We will update the date and explain material changes when our actual practices change. Where required, we will give advance notice or obtain a new choice before using data for a new purpose. The published policy, App Store privacy information, Google Play Data safety declarations, and permission prompts must describe the same released behavior. This draft will be replaced after the operator and mobile data practices are confirmed.

## Operator and contact details

Service operator: Pending confirmation before publication

Registered address: Pending confirmation before publication

Registered country: Pending confirmation before publication

Support: Pending confirmation before publication

Privacy contact: Pending confirmation before publication

[Terms of Service](https://cruise.do/terms/)
