Privacy Policy & Data Governance
Effective Date: August 29, 2026 | Last Updated: August 29, 2026 | Version: 2.1
1. Introduction & Developer Identity
Welcome to SeaCalm ("we," "our," or "us"). We are deeply committed to safeguarding user privacy, practicing radical transparency, and ensuring strict compliance with global data protection standards, including the Google Play Developer Distribution Agreement, Google Play User Data Policies, the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), and the California Consumer Privacy Act (CCPA / CPRA).
This Privacy Policy governs your use of the SeaCalm mobile application for Android (Package Name: com.samsuggest.seacalm) and the official website located at https://seacalm.samsuggest.com (collectively, the "Services").
đĸ Developer & Data Controller Information
Developer Entity: SeaCalm Labs / SamSuggest
Application Name: SeaCalm â Active Seasickness Prevention & Relief
Application Package ID: com.samsuggest.seacalm
Data Protection Officer & Support Email: support@samsuggest.com
Official Web Portal: https://seacalm.samsuggest.com
Public Account & Data Deletion URL: https://seacalm.samsuggest.com/delete-account.php
đ Core Privacy Commitments
- Offline-First Architecture: The app is fully operational without creating an account or connecting to the internet. All questionnaires, symptom logs, and calculations run on your device.
- No Sale or Commercialization of User Data: We NEVER sell, monetize, lease, or broker your personal information, demographic profiles, or wellness logs to data brokers or advertising networks.
- Zero-Retention Sensor Computing: Real-time hardware accelerometer data operates strictly in volatile RAM and is immediately discarded. It is never logged or transmitted.
- Total User Autonomy & Easy Deletion: You can wipe your local app data immediately or request permanent cloud record purging via in-app controls or our public web portal.
2. Specific User Data Collection & Processing Disclosures
We believe in absolute clarity regarding what data we handle. The table below specifies every distinct data element, its collection requirement, specific functional purpose, storage tier, and third-party sharing status:
| Data Category & Element | Required / Optional | Functional Purpose | Storage Location | Third-Party Sharing |
|---|---|---|---|---|
| Email Address | Optional (Mandatory only if creating sync account) | Account authentication, password reset, delivery of 6-digit verification OTPs, and cloud sync identification. | Local Room DB & Secure MySQL Server (if signed in) | None (Never Shared) |
| Password (Cryptographic Hash) | Optional (Mandatory only for email login) | Secure account authentication. Salting & hashing via Bcrypt (PASSWORD_DEFAULT). Plaintext is never stored. |
Local Room DB & Secure MySQL Server | None (Never Shared) |
| Google OAuth Identity (ID, Name, Email, Picture URL) | Optional (Used only if choosing Google Sign-In) | Federated authentication, profile sync, and deep-link token authorization back to Android application. | Local Room DB & Secure MySQL Server | Google Identity Services (Authentication only) |
| Profile Name | Optional | Personalizing in-app interface, greeting traveler, and labeling generated clinical PDF journey summaries. | Local Room DB & Secure MySQL Server | None (Never Shared) |
| Demographics (DOB, Age Group, Gender, Height, Weight) | Optional | Customizing visual cue shapes (pediatric vs. adult desensitization styles), estimating vestibular sensitivity, and hydration guidelines. | Local Room DB & Secure MySQL Server | None (Never Shared) |
| MSSQ Susceptibility Score | Optional | Assessing baseline motion sensitivity (score 0â15) to calibrate proactive look-up and fresh air interval alerts. | Local Room DB & Secure MySQL Server | None (Never Shared) |
| Pregnancy Status Flag | Optional | Surfacing safe, non-pharmacological relief options and displaying contraindication warnings for high-dose supplements or medications. | Local Room DB & Secure MySQL Server | None (Never Shared) |
| Voyage Records & Symptom Logs | Optional | Chronological logging of voyage timestamps, vessel types, feeling levels (Fine/Uneasy/Nauseous), vomiting/nausea events, food intake, and relief methods used. | Local Room DB & Secure MySQL Server | None (Never Shared) |
| User-Provided AI API Keys | Optional (For custom AI Coach providers) | Directly authorizing requests from your device to your selected generative AI provider (Gemini, OpenAI, Groq, OpenRouter). | Encrypted Android DataStore / Local Preferences | Direct transmission solely to user's selected API endpoint |
| AI Coach Chat Inquiries & Prompts | Optional | Providing interactive nautical seasickness desensitization guidance and dietary recommendations. | Local device JSON cache (last 20 messages) | Direct HTTPS payload to user's chosen AI provider |
| Hardware Accelerometer Sensor Stream | Required for Visual Motion Cues | Real-time physics calculation to animate screen-edge motion dots matching vehicle acceleration at 25â50 Hz. | Volatile RAM only (0s Retention / Zero Disk Storage) | None (Never Shared or Uploaded) |
| Website Contact Inquiries | Optional | Customer service, answering technical inquiries, and providing assistance. | Secure MySQL Database | None (Never Shared) |
| Newsletter Subscriptions | Optional | Distributing educational articles, feature updates, and seasickness prevention guides. | Secure MySQL Database | None (Never Shared) |
3. Data Retention & Automatic Disposal Schedule
We adhere to strict data minimization principles. We retain data only for as long as functionally necessary to fulfill the services requested by the user. The table below provides the exact retention schedules and disposal protocols for each data tier:
| Data Category | Retention Duration | Disposal Trigger / Condition | Disposal Method |
|---|---|---|---|
| Local On-Device Data (Room SQLite DB & DataStore) | Duration of app installation or until manual wipe. | App uninstallation, clearing app cache/storage, tapping "Logout", or tapping "Delete Account" in Account Settings. | Immediate atomic database purge (db.clearAllTables()) and DataStore preference file wipe. |
| Cloud Account & Synced Voyage Logs | Duration of active account lifecycle. | User-initiated deletion request (in-app or web portal) OR automatic purge after 24 consecutive months of account inactivity. | Permanent database purge (DELETE CASCADE) from user_accounts, journeys, and symptom_logs. |
| Hardware Accelerometer Sensor Stream | 0 Seconds (Instantaneous / Zero Retention) | Immediately upon rendering each graphic frame (~20â40ms cycle). | Overwritten in volatile memory (RAM); never written to disk or transmitted over network. |
| AI Coach Local Chat Context | Last 20 conversation messages. | First-In, First-Out (FIFO) rolling window; cleared on app logout or storage clear. | Local JSON file truncation and overwrite. |
| Email Verification OTP Codes | 10 Minutes from issuance. | Expiration of 10-minute timestamp OR successful OTP verification. | Column reset to NULL in database. |
| Customer Support Messages | 12 Months from submission. | Resolution of inquiry + 12-month customer satisfaction audit window. | Permanent row deletion from contact_messages table. |
| Newsletter Subscriber Emails | Until user unsubscribes or submits deletion request. | Clicking "Unsubscribe" in email footer or submitting web deletion request. | Permanent row deletion from newsletter_subscribers table. |
| Web Server Access & Security Logs | 90 Days. | Automated log rotation and security audit cycle. | Automated file overwrite and log rotation. |
4. Device Hardware Sensors & Android Permissions Rationale
The SeaCalm Android app requests the minimum permissions required to provide its core wellness capabilities. Below is our explicit justification for every requested permission:
Sensor.TYPE_ACCELEROMETER)
Used by the Visual Motion Cues overlay and the Sea Horizon tool in real time to calculate dynamic physical vehicle acceleration and displace optical indicators on screen. Handling: Processed instantaneously in volatile RAM at 25â50 Hz, never written to disk, and NEVER uploaded or shared across any network.
android.permission.SYSTEM_ALERT_WINDOW)
Required exclusively for the Visual Motion Cues Overlay Service. This allows the app to render synchronized peripheral moving dots along the borders of your screen while using other reading or navigation apps, helping eliminate visual-vestibular motion conflict.
FOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USE, FOREGROUND_SERVICE_MEDIA_PLAYBACK)
Enables continuous execution for: (1) BreathingService (specialUse: diaphragmatic vagal pacing with audio/haptic cues); (2) JourneyTrackingService (specialUse: active voyage duration timing and periodic look-up reminders); and (3) AudioPlaybackService (mediaPlayback: continuous playback of soothing binaural soundscapes via ExoPlayer).
android.permission.VIBRATE)
Used to deliver gentle haptic pulses during guided breathing exercises (synchronizing inhale, hold, and exhale cycles) and interval safety reminders without requiring the user to look at the screen.
INTERNET, ACCESS_NETWORK_STATE)
Used to check network connectivity, authenticate accounts, execute cloud profile synchronization with our secure backend, and connect to AI provider APIs when explicitly triggered by the user.
androidx.core.content.FileProvider)
Allows travelers to export their personal voyage symptom logs as structured PDF clinical reports directly from their device using the native Android share sheet.
5. Account & Data Deletion Policy (Google Play Mandatory Compliance)
In full compliance with Google Play's User Data & Account Deletion Policy, we provide both an immediate in-app deletion pathway and a dedicated, publicly accessible web deletion portal.
đą In-App Instant Deletion
Users can permanently purge their local database and submit a cloud deletion request directly from within the app:
- Open the SeaCalm app.
- Navigate to Settings → Account Settings.
- Tap Request Account Deletion.
- Confirm your request. All local SQLite records are wiped instantly, and your server account is queued for complete deletion.
đ Public Web Deletion Portal
If you have uninstalled the app or wish to delete your web records, visit our dedicated web portal:
https://seacalm.samsuggest.com/delete-account.php
Enter your registered email address and submit. All remote account credentials, synced voyage logs, symptom entries, newsletter subscriptions, and support tickets will be permanently deleted within 30 calendar days.
đī¸ What is Permanently Purged Upon Deletion?
When an account deletion is processed, our system permanently purges: (1) Account credentials and password hashes; (2) All linked profile parameters (name, demographics, vessel choice, MSSQ scores); (3) All historical voyage records and notes; (4) All symptom logs and nausea reports; and (5) Associated newsletter subscriptions and support correspondence. No ghost profiles or inactive shadow records are retained.
6. Third-Party Service Providers & Data Transfers
We work with select third-party service providers solely to deliver specific technical capabilities:
- Google Sign-In & Google Play Services: Used for secure user authentication and app distribution. Governing Policy: Google Privacy Policy.
- Generative AI Providers (User-Initiated): When utilizing the AI Voyage Coach, requests are transmitted over encrypted TLS directly to your chosen provider:
- Google Generative AI (Gemini): Google AI Terms
- OpenAI: OpenAI Privacy Policy
- Groq: Groq Privacy Policy
- OpenRouter: OpenRouter Privacy Policy
- Transactional Email (Hostinger SMTP): Used exclusively to dispatch automated verification OTP codes and deletion confirmation notices over encrypted TLS (Port 465/587).
- Website Cookies & Google AdSense: The web platform may use basic session cookies and Google AdSense to serve personalized ads based on web visits. Opt-out at: Google Ads Settings.
7. Technical Data Security & Cryptography
We implement rigorous organizational, administrative, and technical safeguards:
- Encryption in Transit: 100% of data transmitted across network boundaries utilizes Transport Layer Security (TLS 1.3 / HTTPS) with strong cipher suites.
- Local Sandbox Isolation: Android application data is protected by the Linux kernel application sandbox, isolating SQLite Room databases and preferences from other apps.
- Salted Cryptographic Hashing: Passwords are protected using salted Bcrypt/Argon2 hashes. Plaintext passwords never touch our database.
- Server Hardening: MySQL backend databases reside behind strict firewalls with automated rate-limiting and brute-force lockout safeguards.
8. Children's Privacy (COPPA & GDPR-K Compliance)
SeaCalm is designed for general audiences and maritime travelers. We do not knowingly solicit, harvest, or collect personal information from children under the age of 13 (or under 16 in the European Union). While the application provides pediatric visual desensitization modes, all child usage of motion cues, breathing guidance, and preparation tools must be actively supervised by a parent or legal guardian.
If we discover that personal data has been inadvertently collected from a child under 13 without verified parental consent, we will immediately delete that information from our servers. Parents or legal guardians may contact us directly at support@samsuggest.com to request immediate record removal.
9. Your Global Privacy Rights (GDPR, CCPA/CPRA)
Regardless of where you reside, you possess comprehensive rights over your personal data:
- Right to Know & Access: Request a complete summary of all data collected regarding your profile.
- Right to Rectification: Edit and update inaccurate profile attributes directly in App Settings or Web Account.
- Right to Erasure (Right to Be Forgotten): Permanently delete all local and cloud data via in-app controls or our web deletion portal.
- Right to Data Portability: Export your full voyage and symptom history as structured PDF clinical logs directly from your device.
- Right to Non-Discrimination: We will never deny services, alter quality, or charge different prices for exercising your privacy rights.
10. Medical Disclaimer
SeaCalm is a digital wellness and desensitization coaching tool. It is NOT a clinical or medical device, is not FDA-approved, and is not a substitute for professional medical advice, clinical diagnosis, or medical treatment. Always consult a qualified physician or ship medical officer for persistent vomiting, extreme dehydration, or chronic vestibular conditions. Review our full Medical Disclaimer.
11. Policy Changes & Data Protection Contact
We may update this Privacy Policy periodically to reflect technological updates, regulatory enhancements, or new app features. Any modifications will be posted on this page with an updated "Last Updated" timestamp.
For any privacy inquiries, data requests, or compliance questions, please contact our Data Protection Team:
SeaCalm Labs / SamSuggest Privacy Team
Email: support@samsuggest.com
Official Website: https://seacalm.samsuggest.com
Public Deletion Portal: https://seacalm.samsuggest.com/delete-account.php