Boardcall

Privacy Policy

Effective August 25, 2026

Boardcall ("the app," "we," "us") is a surf-briefing app for iPhone, built and maintained by an independent developer, Zach Weston. This policy describes, plainly, what the app does with data — what stays on your phone, what leaves it, who it goes to, and why. There is no legal team behind this app and no reason to hide anything, so this is meant to be read, not skimmed past.

The short version

What data Boardcall collects, and by whom

Different parts of the app handle data differently. Rather than a single blanket statement, here is exactly what happens in each case:

Stored only on your device

Your profile, boards, spots, and app settings

Boardcall keeps a private file on your iPhone — one only Boardcall can read — containing: your surfer profile (skill level, weight, height, and your chosen notification time), the boards in your quiver (nickname, brand/model, dimensions, volume, type, and fin setup), up to three saved surf spots (chosen from our built-in catalog — never your GPS coordinates), whether you've completed onboarding, a randomly generated device identifier (explained below), and a running weekly count of how many AI-written briefings you've used. Boardcall also caches recent wave, wind, and tide data on your device for up to 60 minutes per spot, along with the most recent briefing text for that spot, purely to avoid re-fetching and re-generating it needlessly.

None of this is uploaded to iCloud or synced anywhere by us. (If you use Apple's own device backup features, that backup is between you and Apple, not something Boardcall controls.) Deleting the app deletes all of it, permanently, from your device.

Sent to our server, not stored

The daily briefing request

When you open Today or Forecast, the app sends a request to our own small server (built on Supabase, a cloud-hosting platform) containing the day's surf conditions at your chosen spot (wave size, swell period, wind, tide, temperature), your skill level and weight, and your boards as ranked by the app's own on-device physics engine. Our server forwards this to Anthropic's Claude — a third-party AI service — to write the plain-English briefing, and returns the result to the app. That content is not written to any database by our server, and on failure our server only logs a generic error code, never the data itself.

Per Anthropic's own API terms, this data is not used to train their models. Anthropic does hold the request and the briefing on their own systems for up to 30 days as an anti-abuse measure, and longer if a request is flagged for review under their usage policies. That retention is theirs, not ours — we never write it to a database and we have no access to what they hold.

Worth knowing: if you give a board a nickname, that nickname is part of what gets sent, because it's how the briefing refers to the board. It's free text you typed, so it's the one field in the request that could contain anything you put there — a plain description like "the yellow one" is all it's designed for.

Sent to our server AND stored

The anonymous rate-limit counter

Alongside that request, the app sends a random identifier that was generated on your device the first time you opened Boardcall — not your Apple ID, name, email address, advertising ID, or any other identifier Apple or anyone else assigns you. Our server stores that random ID together with the date and a count, and nothing else at the application level, purely to enforce a daily limit and prevent abuse of the AI briefing feature. This is the only application-level record our infrastructure retains. We delete these records once they are more than 30 days old. It cannot be linked back to you as a person — it identifies a device-generated random number, not an individual.

Separately, our hosting provider may retain standard technical request logs (such as IP address) for a limited time as part of normal server operation, the way any web server does. We don't access or use those logs for anything beyond troubleshooting an outage.

Handled entirely by Apple

Boardcall Pro subscription payments

If you subscribe to Boardcall Pro, the purchase, payment, and ongoing subscription management happen entirely through Apple's StoreKit system. We never see your card number, billing address, or Apple ID. To determine whether Pro features should be unlocked, the app asks Apple's own StoreKit APIs, live, whether you currently hold an active entitlement — we do not keep our own record of your purchase or subscription status on any server we control.

Third parties Boardcall talks to, and why

WhoWhat they receiveWhy
Open-Meteo
marine-api.open-meteo.com, api.open-meteo.com
A fixed catalog spot's coordinates (never your device's real location) and the wave/wind variables the app requests. Free, keyless marine and weather forecast data. Used under Open-Meteo's CC BY 4.0 license.
NOAA CO-OPS
api.tidesandcurrents.noaa.gov
A fixed tide-station ID and a date range, plus a static application-identifier parameter that NOAA requires of every API caller to identify the calling app (it still reads our old internal code name, "Quiver," from before the app was renamed to Boardcall) — not you. Free tide-prediction data from the U.S. government.
Anthropic
Claude API, a third-party AI service
The day's conditions, your skill level and weight, and your ranked boards — sent only from our own server, never directly from your phone. Writes the plain-English briefing and board-pick explanation you see on Today.
Apple / StoreKit Standard StoreKit purchase and entitlement traffic, handled entirely by Apple's own framework. Processes Boardcall Pro subscription purchases and confirms your active entitlement.

One more note for completeness: opening the Map tab fetches live conditions for the spots in our built-in catalog from Open-Meteo and NOAA, the same way described above and using each spot's fixed catalog coordinates — never your device's location — and without including any of your profile or board data in those particular requests.

Location

Boardcall does not use Core Location, does not request location permission, and has no way to know where your device physically is. Every surf spot in the app — on Today, Forecast, or the Map tab — is a fixed point chosen from a built-in catalog, never a GPS reading.

Children's privacy

Boardcall is a surf-forecasting tool for surfers and is not designed for or directed to children. Our Terms of Use ask that you be at least 13 to use it. The app contains no objectionable content, and no account, sign-up, or personal information is required to use any feature — the app has no accounts and no sign-in of any kind. We do not knowingly collect personal data from children under 13. If you believe a child has provided us information beyond what's described in this policy, contact us at the email below and we'll delete it.

Your rights and how to delete your data

Because almost everything Boardcall touches lives only on your device, deleting the app deletes your profile, your boards, your saved spots, and all cached data completely — there is no separate server-side copy of any of that to request or delete.

The one thing that does exist on our server is the anonymous rate-limit record described above: a random device ID, a date, and a count. We have no way to trace that record back to you as a person, and we delete these records once they are more than 30 days old, whether or not you ask.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. There are no advertisers, data brokers, or analytics companies involved in this app at all.

If you still have questions or concerns about your data, email us — see Contact below.

Security

All network requests the app makes, to every service listed above, use HTTPS encryption in transit. The rate-limit table described above is not readable by the public: it is reachable only by our own server function, using credentials that never leave it.

Where this data is handled

Boardcall is run from the United States, and the services it depends on — our server host, the AI provider, and the weather and tide sources — process data on servers in the United States. If you use the app from outside the US, the briefing request described above is handled there. Given how little is involved — no account, no name, no email, no location, and a random ID rather than an identifier tied to you — this is the whole of the international picture.

Changes to this policy

If Boardcall's data practices change, we'll update this page and change the effective date at the top to match. Because the app has no accounts, email addresses, or push notifications tied to a server, there is no separate mechanism for notifying you of changes beyond this page itself — material changes will be described here directly.

Contact

Questions about this policy or how Boardcall handles data: zachweston5@gmail.com.