Seacove Privacy
Last updated: 29 August 2026.
This notice explains what personal data Seacove collects, why, who else sees it, how long it is kept, and what rights you have. It is written for crew whose first language may not be English. If a word here is unclear, ask us. Contact details are in section 12.
What changed in version 1.1. Section 7 now describes how the Ports tab schedule is built. It comes from two sources: a licensed itinerary dataset for most cruise lines, and verified crew aboard your ship for the rest. The tab no longer shows arrival and departure times, only which port a ship is in on a day. Section 4, section 9, section 11 and section 13 are updated to match.
1. Who is responsible for your data
Seacove is operated by a company currently being incorporated in the EU. This notice will be updated to name that company, its registration details and jurisdiction, once incorporation completes.
Until then, the person responsible for your data under data protection law (the “controller,” GDPR Article 4(7)) is the operator of Seacove, reachable at:
Being between the closed-beta stage and formal incorporation does not remove or reduce your rights under this notice, or the operator’s obligations to you. All the same duties apply: the same lawful bases, the same consent standard for sexual orientation in section 3, the same 30-day response commitment in section 9, and the same breach-notification duty in section 15.
There is no separate Data Protection Officer today. At the scale Seacove is at now, one is not legally required. Article 37(1)(c) requires a DPO where an organisation’s core activity is large-scale processing of special-category data, which sexual orientation is. Seacove is not at that scale yet. It will be revisited as the user base grows, and stated plainly here if and when it changes.
support@seacoveapp.com is the contact point for every privacy question and every rights request. See section 12.
2. What this notice covers
This notice covers the Seacove app as it is built and operated: sign-up, profile creation, matching, chat, the Ports tab and the schedule you can contribute to it, selfie verification, photo moderation, subscriptions and advertising. It reflects what the product actually does, not an aspirational future version. Where something is described as “not yet live,” that is stated plainly.
3. Why we need your separate, explicit consent for sexual orientation
Seacove asks for your sexual orientation because it is a dating app and matching depends on it.
Under GDPR Article 9, sexual orientation is “special category” data. It carries stronger protection than an ordinary field like your name or date of birth, because if it were exposed or misused it could put you at real risk, especially given how small and close-knit crew communities are.
Because of this, the app asks for your consent to process this one specific piece of data:
- Separately from your acceptance of the Terms of Service. Agreeing to the Terms does not count as consent to process your sexual orientation.
- Separately from your consent to the rest of your profile (photos, bio, age, languages, interests).
- Explicitly. You take one clear, deliberate action, a checkbox that names sexual orientation specifically, never pre-checked and never assumed from general sign-up.
- Provably. The app records the exact wording you saw, the language it was in, and the exact time you agreed, so there is a timestamped, reconstructable record of what you consented to.
You can withdraw this consent at any time, from Settings. Withdrawing removes your orientation from the record entirely, not just from view: the field is deleted, not hidden. It stops your orientation from being used for matching or shown to anyone else. Withdrawing this consent alone does not delete your whole account. For full account deletion, see section 9.
4. What data Seacove collects, and why
| Data | Why we collect it | Legal basis |
|---|---|---|
| Email address, or your Apple or Google sign-in identifier | To create and secure your account | Contract, Art. 6(1)(b) |
| Confirmation that your email is verified (a timestamp, not the message itself) | To confirm you control the inbox you signed up with, separately from proving you are a real live person. See section 6 | Contract and legitimate interest in account security, Art. 6(1)(b) and (f) |
| Date of birth | To confirm you are 18 or over. Seacove is adults only | Legal obligation and legitimate interest, Art. 6(1)(c) and (f) |
| A one-time, on-device estimate of your age from your verification selfie | An extra check against under-18 use, run entirely on your phone. See section 6 and section 10 | Legitimate interest in preventing underage use, Art. 6(1)(f) |
| Display name, bio, gender, languages, favourite artists, interests | To build your dating profile | Contract, Art. 6(1)(b) |
| Sexual orientation | To build your profile and enable matching | Explicit, separate consent, Art. 9(2)(a). See section 3 |
| Profile photos | To build your profile and let others recognise you | Contract, Art. 6(1)(b) |
| A verification selfie, and the pass or fail result of that check | To confirm you are a real, live person, matching your profile photo, so the app is safer from fake accounts. See section 6 for exactly what leaves your phone | Legitimate interest in platform safety, and contract, since verification is mandatory before you can like, match or message |
| Cruise line, ship, department, position | To power matching, the Ports tab and discovery. Department and position are free text you type yourself, not picked from a list | Contract, Art. 6(1)(b) |
| The ports your ship calls at, and on which day, if you are onboard | To power the Ports tab: your schedule, and when your ship shares a port with a match’s ship on the same day. This schedule comes from a licensed itinerary data provider for most cruise lines, or from crew aboard your ship for the rest. It is a day-by-day schedule, not clock times, and not your live position. See section 7 | Contract, Art. 6(1)(b) |
| Port-call entries you submit for your ship, and the record that you submitted them: your account identifier and the time of the entry | To build the Ports tab schedule for ships a data provider does not cover, and to keep that schedule correctable if an entry is wrong. The record of who made an entry is internal only and is never shown to other users. See section 7 | Contract, Art. 6(1)(b), for the contribution feature. Legitimate interest in keeping the schedule accurate and traceable, Art. 6(1)(f), for the record of who made each entry |
| A typed home city, if you are at home | To show a general location on your profile while you’re on leave. This is a place name you type, never a GPS coordinate | Contract, Art. 6(1)(b) |
| Swipes, matches and messages | To run matching and chat | Contract, Art. 6(1)(b) |
| Reports you file, or that are filed about you, and their outcome | To act on the 24-hour moderation commitment and keep the app safe | Legitimate interest in user safety, Art. 6(1)(f) |
| Subscription tier and entitlement status, not your card or payment details | To unlock the features your tier includes | Contract, Art. 6(1)(b) |
| Device push notification token | To send you match and message alerts | Consent, granted through your device’s own notification permission |
| Basic technical and crash logs | To find and fix bugs | Legitimate interest in a working, safe app, Art. 6(1)(f) |
Seacove never asks for your device’s GPS location. This is a deliberate design choice, checked and re-checked at every stage of the build, not an oversight. See section 7.
5. Special category data, stated in full
Two categories of special category data (GDPR Article 9) exist in Seacove today:
- Sexual orientation. Covered fully in section 3.
- A biometric similarity score from verification, and only briefly, because of how the check works. See section 6. Seacove does not use this data to categorise you by any Article 9 characteristic, including sexual orientation. The EU AI Act separately prohibits biometric systems used to infer sexual orientation. Seacove’s face-matching pipeline is built so it cannot do this: it produces a single same-person similarity score, on your device, and nothing else. That design constraint is deliberate, not incidental, and it is what keeps the verification system outside the AI Act’s prohibited use.
Religion, political opinion, trade union membership, health data and racial or ethnic origin are not collected by Seacove, by design. The Ports tab schedule data added in version 1.1 is not special category data: it describes where a ship goes, not anything protected about a person.
6. How verification works, and what actually leaves your phone
Before you can like, super like, match or message, Seacove needs to confirm two separate things: that you are a real, live human being, and that you are the person in your profile photos. These are two different checks and neither substitutes for the other.
The liveness check runs on your phone. It uses Google’s ML Kit face detection to guide you through a short prompted sequence (for example, turn your head, blink) and checks that your face’s movement matches the prompts in real time. This defeats the two attacks it needs to defeat in a small, close crew community: a photo of a photo, and a static stolen image.
The face match also runs on your phone. A small on-device model (MobileFaceNet) compares the passing selfie frame against your existing profile photo and produces a similarity score, entirely on your device. Only that score, a number, is sent to Seacove’s server. Your face image and the mathematical representation of it (the “embedding”) never leave your phone during this automatic check. No third-party company, including any face-recognition vendor, ever sees your face for this purpose. This is different from many verification systems, including an earlier design of Seacove’s own, which would have sent your face to a cloud service. That approach was replaced specifically to keep your face data on your device.
If the automatic check does not pass, or fails repeatedly, your account moves to manual review. In that case, the raw selfie capture is uploaded to a private storage bucket, visible only to the small team running that review, so a human can review it by eye. It is kept only as long as the review takes, and deleted once the review is complete. It is never shown to other users and is never treated as a normal profile photo.
Age estimation works the same way: an on-device model gives a rough age estimate from the same selfie frame, used as an extra signal against underage use, on top of the date of birth you provide. This estimate never leaves your phone in a form that identifies you; it feeds into the same pass or fail decision as the rest of verification.
Device integrity. Alongside the score itself, Seacove’s server checks a signed statement from your phone’s own operating system (Android’s Play Integrity, or iOS’s App Attest) confirming the app on your device is genuine and unmodified. This is a technical anti-fraud signal about your device’s software state, not personal data about you, and it exists so a modified copy of the app cannot fake a passing verification score.
A passing verification puts a Verified badge next to your name everywhere it appears.
7. How ship position and the Ports tab actually work
Seacove never requests your phone’s GPS location, ever. It has never asked for that permission, and no version of the app has that permission in its code.
What the Ports tab shows is a day-by-day schedule: which port your ship is in on a given day, and whether your ship and a match’s ship are in the same port on the same day. It is not your live location. It does not show clock times for arrival or departure. Earlier versions of this notice mentioned published arrival and departure times; those are no longer part of the tab.
The schedule comes from two sources.
- A licensed third-party itinerary dataset, for most cruise lines. This dataset carries ship schedules only: cruise line, ship, port and calendar date. It holds no personal data about you or about any other person, and Seacove sends it no information about you. Seacove joins it to your ship, which you already told us, on Seacove’s own servers in the EU. The provider of this dataset is a data source, not a company that processes your data for us. See section 13.
- Other verified crew aboard your ship, for cruise lines the dataset does not cover. A verified crew member can enter their own ship’s upcoming port calls, picking the port and the date from set lists, never free text. Any verified crew member on the same ship can correct an entry. Seacove records which crew member made or last changed each entry, so a wrong or bad entry can be traced and rolled back, and so edits by different crew on the same ship are attributable. That record is internal. It is never shown to other users, and the tab never displays who entered a schedule. If you delete your account, your schedule entries stay, because they describe the ship’s schedule and other crew rely on them, but the link between those entries and you is removed. See section 9 and section 11.
Nobody has to enter a schedule. If your ship has no schedule from either source, the tab tells you so, and you still appear for crew searching your port.
Three things are true and enforced in the database itself, not just in the screen you see, so they cannot be bypassed by a bug in the app:
- Ship visibility is your choice, on by default. Turn it off in your profile and every surface in the app, including a stranger’s swipe deck, a match’s chat header, and the Ports tab, shows you as a general sea region instead (for example, “somewhere in the Caribbean”), never your actual ship. This is enforced at the database query level for every viewer, with no exception for a match or a paying subscriber.
- A user you block cannot see your profile, your ship, or that you exist on the app, anywhere. This is total and enforced in the database, not a client-side filter.
- Your personal GPS location is never collected. Nothing about your position comes from your device. It always comes from your ship’s schedule, never your individual location.
8. Photo moderation
Every profile photo you upload is automatically checked, before anyone else can see it, for nudity, violence and other prohibited content. This is done by an automated third-party service, Sightengine. Rejected photos are never shown publicly. Sightengine sees the photo only for the moment it takes to check it.
9. Your rights
Under GDPR you have the right to:
- Access the data Seacove holds about you.
- Correct it, if it’s wrong. Most of your profile you can correct yourself, in the app.
- Delete it, in full (“erasure”). You can delete your account from inside the app, or from seacoveapp.com/delete-account, a web page that works even if you’ve uninstalled the app or can’t sign in. Deleting your account deletes your profile, photos, messages and swipes, and removes your Storage files, not just the database rows pointing at them. Port-call entries you made for your ship are handled differently: the schedule rows themselves stay, because they are the ship’s schedule and other crew depend on them, but the record that links those entries to you is deleted or pointed at an anonymous placeholder. See section 7 and section 11. Some limited data may be kept a short additional period where the law requires it, for example records needed to investigate an open safety report. See section 11 for retention.
- Export your data (“portability”), as a plain, machine-readable file of your profile, messages and swipes. Request this by writing to support@seacoveapp.com. Seacove will compile it and send it to you within 30 days, the deadline set by GDPR Article 12. A self-service, in-app export tool that produces this file instantly, without needing to write in, is planned for a future version of the app.
- Withdraw consent, at any time, including the separate consent for sexual orientation in section 3, without affecting anything done lawfully before you withdrew it.
- Object to processing based on legitimate interest, including the moderation and safety uses in this notice, and the record of who made a Ports tab schedule entry in section 7.
- Complain to a data protection authority. You can complain to the data protection authority in the EU country where Seacove’s operating entity is established, once it is named here, or to your own country’s authority; GDPR does not require you to complain in any one specific country.
All of these rights are exercised by writing to support@seacoveapp.com. This inbox is monitored and commits to acting within 30 days, matching the GDPR Article 12 deadline. Today, several of these are handled manually rather than by a fully automated in-app tool; that does not change your right to ask, or the 30-day commitment to answer.
10. Age
Seacove is for adults only, 18 and over. You give your date of birth at sign-up.
In some countries, an operating system additionally requires confirmation of your age range before you can even install an adults-only app. On iOS, this uses Apple’s own Declared Age Range signal, a check Apple runs, not data Seacove collects separately.
A note for users in the United Kingdom. Seacove requires every account to pass age verification, described in section 6, before access to likes and messages. This check runs on every user, with no exceptions. It works alongside other safeguards in this notice, including reporting, blocking and moderation, to keep the platform for verified adults.
11. How long we keep your data
- Your profile, photos, matches, swipes and chat history: kept while your account is active, and deleted within 30 days of a verified deletion request.
- Your sexual orientation consent record: the specific consent event (what you were shown, when, in what language) is never deleted while you have an account, because it is the proof required by GDPR Article 7 that your consent was real. If you withdraw consent, the current value is deleted from your profile; the historical record that you once consented, and later withdrew, is kept as the audit trail the law requires.
- Port-call schedule entries you submitted: the schedule row is kept while the date is still in the future, and pruned once the date has passed or another crew member replaces it. The record of which account made the entry is removed when you delete your account, or sooner if the row is pruned. There is no separate long-term history of your contributions.
- A verification selfie sent for manual review: kept only as long as the review takes, then deleted. It is never kept as a standing record once a decision is made.
- Reports you file, or that are filed against you, and their outcome: kept longer than most other data, because they may be needed to investigate a later report, to defend a moderation decision, or to respond to a legal claim. They are deleted once none of those reasons still apply.
- Basic crash and error logs: kept on the default schedule of the tools that generate them (see section 14), typically weeks, not months, and never linked back to your profile beyond what’s needed to fix the specific bug.
12. How to contact us
For any question about this notice, or to use any right in section 9, write to:
This inbox is monitored and every message gets a reply.
13. Who else processes your data, and where
Seacove uses a small number of specialist companies to run the app. Each only gets the data it needs for its specific job. Seacove’s policy is that no processor handles a real user’s data without a signed data processing agreement in place first, the contract GDPR Article 28 requires between a controller and each processor it uses.
| Service | What it does | What data it sees | Where |
|---|---|---|---|
| Supabase | Hosts the database, login, file storage and realtime chat | Effectively everything in section 4. This is the core database | EU, specifically Frankfurt, Germany. Your data does not leave the EU through Supabase |
| Sightengine | Automated photo content moderation, section 8 | Uploaded profile photos, at the moment of the check | Covered by a signed DPA before it processes any real user’s photo |
| RevenueCat | Tracks subscription status across Apple and Google so the app knows what tier you’re on | Subscription and entitlement status. Never your card number or payment details, which Apple and Google hold directly | US-based. Transferred under EU Standard Contractual Clauses, and covered by a signed DPA before it processes any real user’s data |
| Expo / EAS | Delivers app updates and push notifications | Your device’s push token, and basic crash and device diagnostics | US-based. Same transfer mechanism and DPA requirement as RevenueCat |
| Sentry | Error tracking, if and when it is switched on | Crash and error logs | Not live in the current build |
| Apple and Google | Payment processing for subscriptions, and platform-level identity for Sign in with Apple / Google | Your payment method, and (for social sign-in) the identifier those platforms already hold about you | Apple and Google’s own global infrastructure, under their own privacy terms, not Seacove’s |
No vendor of any kind processes your face for identity verification. That check runs entirely on your device. See section 6.
The Ports tab itinerary dataset is a data source, not a processor. Ship schedule data for most cruise lines is licensed from a third-party itinerary data provider. That provider receives no personal data from Seacove and does not process any personal data on Seacove’s behalf. Under GDPR Article 4(8) and Article 28 it is a data source, the same category as a public reference list, not a processor, so it is not in the table above and there is no data processing agreement with it. The GDPR question it raises, a wrong schedule row shown against your ship, is answered by your right to have data corrected (section 9), not by a processor contract.
The controller is responsible for making sure each processor handles your data properly, and for keeping a signed DPA and a lawful transfer mechanism in place for every one of them for as long as they process your data.
14. Advertising
Seacove’s free tier shows contextual ads. Paid tiers (Pearl, Diamond, Black Pearl) do not.
These ads are never personalised, and this is not a setting you can turn on. No advertising identifier, no device identifier, and no signal about who you are or what you’ve done in the app is ever sent to an ad network. The ad shown is chosen from the context of the request alone, not from anything known about you.
This matters specifically because Seacove asks your sexual orientation and stores it. Contextual-only advertising is how Seacove avoids the risk that comes with that: nothing about you, including the fact that you use Seacove at all, ever reaches an ad network.
Because ads are contextual only, Apple’s App Tracking Transparency prompt does not apply; there is nothing to ask permission to track.
A consent management platform, certified against the ad industry’s IAB Transparency and Consent Framework, will be in place before a single ad serves to anyone in the EEA, UK or Switzerland. This is a legal requirement for ad serving in those regions, separate from the personalisation question above, and it is not switched on until that is confirmed working.
Ads can be turned off entirely, everywhere, with a single setting, and this will happen immediately if an ad network ever serves something inappropriate next to a dating product, or if any compliance problem is found.
15. Security
Seacove’s database uses Row Level Security on every table: the database itself, not just the app, enforces who can see what. A blocked user, for example, is invisible in the database’s own query results, not merely hidden by the screen. This is described in more detail in the product’s technical documentation, available on request.
No security measure is perfect. If Seacove ever experiences a data breach affecting your personal data, you will be told, and the relevant data protection authority will be notified, within the timeframes GDPR Article 33 requires.
16. Crew based outside the EU
Most Seacove crew are not EU nationals. GDPR still applies to your data, in full, because the controller is established in the EU. Your nationality or your ship’s flag does not change this.
17. Changes to this notice
This notice is a live document. It changes when the product changes in a way that affects your data, or when the controller is formally named. When that happens, a new dated version replaces this one, the old version is kept in the project’s own records rather than deleted, and you’ll be told inside the app.
You can always find the current version at seacoveapp.com/legal/privacy and inside the app.