Privacy
Privacy Policy
This Policy explains how the Ebb mobile app and website handle information. Ebb is designed without a user account, advertising identifier, advertising SDK, cross-app tracking, or server-side user profile.
1. Information that stays on your device
Your saved places and order, tide cache, alarms, display preferences, onboarding state, and cached proof of Pro access are stored locally. Ebb’s own cache service has no user, email, device, location, or purchase table. A saved-place export contains only the NOAA station identifiers you explicitly choose to share through the operating-system share sheet.
2. Location
Ebb requests foreground location only after you select Find nearest and see an explanation. It asks the operating system for one fix, uses it in memory to compare distances to the bundled station index, and then discards it. Latitude, longitude, and location accuracy are not written to Ebb storage or sent in a request, log, analytics event, crash report, or support payload. You can deny or revoke location permission and use offline station search instead.
3. Tide and station requests
When connected, Ebb may request public station metadata and tide files from Ebb’s cache service using a NOAA station identifier and month. The service records station-level request counts for cache operation, promotion, and reliability; it does not receive a user identifier or coordinate. Requests use HTTPS in configured production builds. The mobile app never calls NOAA directly.
4. Optional product analytics
If you choose to enable analytics, Ebb may send a random installation identifier and a closed set of feature-use events to PostHog. Examples include whether an offline read succeeded, whether the tide curve was scrubbed, the public NOAA station identifier for a cache read, bounded timing or byte counts, and purchase-flow outcomes without a receipt. Ebb does not send station searches, station names, coordinates, location accuracy, advertising identifiers, account details, free-form text, or a cross-app identifier. IP geolocation, autocapture, session replay, surveys, person profiles, advertising, and remote feature flags are disabled in Ebb’s approved configuration.
5. Crash diagnostics
If you choose to enable diagnostics, Ebb may send sanitized crash and app-hang information to Sentry so defects can be fixed. Default personal information, screenshots, view hierarchy, request data, session replay, user profiles, performance traces, and coordinate-shaped fields are disabled or removed. Ebb allows only a small set of application breadcrumbs and drops crash payloads containing coordinate-like data.
6. Purchases
Apple or Google processes payment. RevenueCat receives an anonymous app-user identifier and purchase or receipt information needed to verify the Ebb Pro entitlement. Ebb analytics records only the product identifier, numeric store price, and a bounded outcome category; it does not receive or send payment-card details. Store and RevenueCat handling is governed by their own privacy terms as well as Ebb’s configuration and this Policy.
7. Purposes, sharing, and sale
Ebb uses data only to provide tide files and purchases, understand whether core features work, diagnose faults, prevent duplicate analytics delivery, and operate the service. Data is shared only with the applicable app store, RevenueCat, and—when you enable them—PostHog and Sentry for those purposes. Ebb does not sell information, serve ads, share information with data brokers, or use data for cross-app tracking. Production vendors must provide protections consistent with this Policy.
8. Retention and deletion
Device-local information remains until you remove it, clear app data, or uninstall Ebb. Undelivered analytics are bounded to 500 events and remain on the device until delivery, repair, or uninstall. The intended production policy is to retain delivered analytics and crash diagnostics for no more than 90 days; the operator must configure and verify that limit before release. Station-level cache request accounting uses a rolling 30-day window. RevenueCat and the app stores may retain purchase records as needed to provide entitlements, restore purchases, prevent fraud, and meet legal obligations.
Because Ebb has no account, it cannot identify your device from a name or email. You can turn analytics and diagnostics off in Ebb’s settings, revoke location or notification permission in system settings, delete local data by removing places or uninstalling, and request deletion of vendor-held data using the official contact below. A deletion request may require the random installation or anonymous purchase identifier displayed by a support-enabled build so the correct record can be located.
9. Security and children
Ebb minimizes transmitted fields, validates remote content before storing it, restricts mobile networking to one audited module, and uses HTTPS for configured production services. No security control is absolute. Ebb is a general-audience utility and is not directed to children under 13; it does not knowingly collect names, contact details, or profiles from children.
10. Changes and contact
A material Policy change will update the effective date. Current practices must also match the privacy disclosures on Ebb’s store listings. For privacy questions or deletion requests, email support@useebb.com. The same address must appear in Ebb’s store listings and in the app’s About & data screen.