NAUTIQPricingTermsPrivacySign in

Privacy
Policy.

Last updated: 24 June 2026

This Privacy Policy explains how NAUTIQ (“NAUTIQ”, “we”, “us”) collects, uses, and protects your information when you use the NAUTIQ mobile application and the NAUTIQ web portal at nautiq-doc.com (together, the “App”). NAUTIQ is a document-management tool for seafarers that lets you store maritime certificates and documents, track expiry dates, record voyages, build a maritime CV, and back up your data to the cloud.

Who is responsible for your data (Controller)

NAUTIQ is currently operated by [OPERATOR NAME], an individual sole operator based in Romania, acting as the data controller for the purposes of the EU General Data Protection Regulation (GDPR). You can reach the controller at contact@nautiq-doc.com; a postal address is available to data subjects and authorities on request. NAUTIQ is operated as an individual undertaking; this section will be updated if and when NAUTIQ is established as a registered legal entity.

Note: Some clauses below — in particular the lawful basis for processing health-related documents (Article 9 GDPR) and the governing-law and liability terms — are pending review by qualified legal counsel and will be finalised before paid or large-scale launch.

1. Information We Collect

  • Account information — when you sign up, we process your email address and a unique account identifier through Firebase Authentication (email/password, Google, or Apple sign-in). You may also use the App as a guest without an account.
  • Documents and certificates — the document details you enter (name, number, issue/expiry dates, issuer) and any document images or PDF files you scan or attach.
  • Profile information — optional details you provide, such as your name, rank, certificate of competency, nationality, contact details, and CV information.
  • Voyage records — sea-service entries you create (vessel, type, rank, dates).
  • Camera and photos — accessed only when you choose to scan or attach a document. Images are processed on your device and stored with your documents.
  • Diagnostics — crash and error reports (via Firebase Crashlytics) to keep the App stable. These do not include the contents of your documents.

2. How We Use Your Information

  • To provide core features: storing documents, expiry reminders, voyages, and CV building.
  • To back up and synchronise your data across your devices (when signed in).
  • To power AI features (document analysis and the Nautiq AI assistant) — see Section 4.
  • To send local expiry notifications from your device.
  • To diagnose crashes and improve reliability.

3. End-to-End Encryption & What We Can Access

The contents of your documents and scans are end-to-end encrypted on your device (AES-256) before they are uploaded. The keys never leave your devices, so NAUTIQ — and our storage provider — only ever hold unreadable ciphertext. We cannot read your document contents, and we cannot produce a decrypted copy for anyone. We can access a limited set of operational data: your account email and ID, the titles/dates/categories you type in, timestamps, and basic technical logs. See our Security page for the full technical detail.

4. Where Your Data Is Stored & International Transfers

When you are signed in, your data is backed up to Google Firebase / Google Cloud (Cloud Firestore and Firebase Storage) on Google’s infrastructure. Some Google services may process data outside the European Economic Area (for example in the United States). Where that happens, the transfer is covered by Google’s Data Processing Addendum incorporating the EU Standard Contractual Clauses and the EU–US Data Privacy Framework. We are working to keep storage within an EU region where possible. See Google’s privacy documentation at firebase.google.com/support/privacy.

5. Lawful Access Requests

We may receive legally binding requests from competent authorities. We comply with valid requests, but for your encrypted document contents this can only ever yield ciphertext — which is useless without your key, and we do not hold your key. We assess each request’s legal basis and reject requests that are invalid or overly broad. Requests from foreign authorities must come through proper legal-assistance channels, not direct disclosure.

6. AI Features

When you use document scanning analysis or the Nautiq AI assistant, the relevant document text or your question is sent to Google’s Gemini API (via Firebase AI Logic) to generate a response. This processing is used solely to provide the feature and is subject to Google’s terms. We do not use your documents to train our own models.

7. Sharing of Information

We do not sell your personal data. We share data only with the service providers needed to run the App (Google Firebase and Google Gemini, as described above), or where required by law. Any document you choose to export or email is shared only at your explicit request.

8. Data Retention & Deletion

We keep your data for as long as your account is active. You can delete individual documents and voyages in the App at any time. You can delete your entire account and all associated cloud data — see our Account & Data Deletion page.

9. Your Rights & Lawful Bases (GDPR)

We process your data on these legal bases: performance of a contract (to provide the core service you signed up for), legitimate interests (keeping the service secure and reliable), and — for sensitive documents such as medical certificates, which are special-category health data under Article 9 GDPR — your explicit consent, which you give by choosing to store such documents and can withdraw at any time by deleting them or your account.

If you are in the EU/EEA (or another region with similar laws) you have the right to access, correct, export (data portability), and delete your personal data, to object to or restrict processing, and to withdraw consent. For exported data, we provide the information you gave us in a structured, machine-readable form; because document contents are end-to-end encrypted, the files themselves are exportable only from your own device, where they can be decrypted. To exercise any right, contact us at the address below — we respond within one month. You also have the right to lodge a complaint with your local data-protection authority.

10. Cookies

NAUTIQ uses only strictly-necessary cookies — the session cookie that keeps you signed in. We use no analytics, advertising or tracking cookies. Because these cookies are essential to a service you actively requested (signing in), no consent banner is required under EU ePrivacy rules. We will update this section if that ever changes.

11. Documents We Hold & the Maritime Context

NAUTIQ is a private vault you control. The documents you may choose to store can include passports, seaman’s books, visas, medical certificates (health data), next-of-kin and contact details. NAUTIQ is not an official flag-state, port-state or MLC 2006 system of record. We do not provide your document contents to employers, manning agencies, flag states or port authorities — only valid, binding legal orders are handled as described in Section 5, and even then your encrypted contents remain unreadable to us.

12. Service Providers (Subprocessors)

We rely on a small set of providers. Each receives only the data it needs, and your document contents stay encrypted and unreadable to them:

ProviderPurposeDataTransfer basis
Google (Firebase, Google Cloud, Vertex AI)Auth, encrypted storage, hosting, AI featuresAccount ID, encrypted document blobs (unreadable to Google), metadataGoogle DPA + EU SCCs + EU–US DPF
CloudflareBot & abuse protection (Turnstile)IP address, challenge signalsCloudflare DPA + SCCs / DPF
ResendTransactional email (document-expiry reminders)Your email address, document name & expiry date in the reminder (no document contents)Resend DPA + SCCs
Apple App Store / Google PlayApp distribution & in-app billingPurchase & store-account data (handled by the store)Each store’s own terms

13. Children

The App is intended for professional seafarers and is not directed at children under 16.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by the “Last updated” date above.

15. Contact

For any privacy questions or requests, contact us at contact@nautiq-doc.com.

© 2026 Nautiq · Terms & Conditions · Account Deletion

© 2026 NAUTIQ · contact@nautiq-doc.com