Privacy Policy — Azure AI Weather
Version: 1.1.1 Effective date: 15 July 2026 Last reviewed: 16 July 2026
Executive Summary
In plain language:
- What we collect: account details (email, password hash, name, country, language), maritime profile and vessel information, location/GPS when you use Black Box or related features, voyage logs, chat and messaging content you send, technical security data (IP, device sessions), and consent records.
- We do not sell personal data. Your chat and voyage data are not used to train third-party AI models without explicit consent.
- Your control: you can export your data (
GET /api/privacy/export) and delete your account or voyage history via Privacy settings / the privacy API. - AI use: artificial intelligence is used only to provide the Service (for example natural-language briefings and chat replies). Weather models and the Operational Risk Index remain advisory decision-support tools — you remain responsible for navigation decisions.
Table of contents
- Revision history
- Who we are
- Scope
- What data we collect
- Why we collect data (purposes & lawful basis)
- AI usage & transparency
- Black Box & GPS data
- Weather stations
- Cookies & local storage
- Third-party processors
- Data retention
- Your rights
- Security
- Children
- Changes
- Contact
Revision history
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 2026-07-15 | Initial Founder Beta privacy policy |
| 1.1.0 | 2026-07-16 | Readability: Executive Summary, table of contents, callouts |
| 1.1.1 | 2026-07-16 | Controller contact details completed (entity, NIF, address, emails) |
1. Who we are
Operator
Diogo Botelho Moniz
Trading as
Azure AI Weather
A FrontSea Intelligence product
Portugal
Contact: contact@azureai.pt
| Legal field | Value |
|---|---|
| Business / registered address | Rua da Trindade n.º 12, 4.º, 1200-468 Lisboa, Portugal |
| Tax / VAT number (NIF) | 234623470 |
| Data protection contact | contact@azureai.pt |
Azure AI Weather provides maritime weather intelligence, operational insight, voyage logging, and AI-assisted advisory tools for recreational and professional skippers.
2. Scope
This policy applies to:
- The Azure AI Weather web application and progressive web app (PWA)
- Authenticated services (Skipper, Pro, Founders)
- Public home chat (anonymous)
- Partner integrations (FrontSea Hub weather callbacks, IoT weather stations)
3. What data we collect
| Category | Examples | When |
|---|---|---|
| Account data | Email, password hash, name, country, language, nickname | Registration / login |
| Maritime profile | Vessel specs, experience level, preferences, home marina | Onboarding |
| Location / GPS | Latitude, longitude, accuracy, heading, speed | Black Box, vessel position API, SOS |
| Voyage data (Black Box) | Session events, GO/CAUTION/NO-GO snapshots, timestamps | Pro / Founders voyage logging |
| Chat content | Messages to home chat, Crew Chat, Marine Radio | When you use chat features |
| Operational memory | Similar voyage patterns, session context | Pro / Founders |
| Messaging | DM content, global channel posts, optional location labels | Skipper+ messaging |
| SOS / radio | Contact phone (if provided), alert context | SOS flow |
| Technical data | IP address, browser user-agent, device sessions | Security, rate limiting |
| Consent records | Policy version accepted, timestamp, IP | Registration |
| Founder field data | Operational feedback, ground-truth observations | Founders programme only |
| Weather context | Coordinates used for forecasts (not stored long-term for anonymous chat) | Forecast requests |
4. Why we collect data (purposes & lawful basis)
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Provide weather & operational services | Contract |
| Account authentication & security | Contract / Legitimate interest |
| Black Box voyage logging | Contract (Pro/Founders feature) |
| Public anonymous chat | Legitimate interest (minimal data) |
| Email verification & password reset | Contract |
| Security logs & fraud prevention | Legitimate interest |
| Founder research / field checks | Contract + Consent where shared |
| Marketing emails | Consent only (opt-in) |
| Legal compliance (billing records) | Legal obligation |
5. AI usage & transparency
Azure AI Weather uses:
- Deterministic weather models (ERA5, coastal models, tides) — not personal data
- Operational Risk Index — calculated from weather and voyage context; advisory only
- Large Language Models (LLM) via Hugging Face API — processes your chat and insight requests to generate natural-language responses
6. Black Box & GPS data
The Black Box is an operational recording and replay system. It records voyage sessions including GPS tracks, weather/operational context, and decision snapshots when you use Pro or Founders features. It does not control a vessel, issue navigation commands, or replace skipper judgement.
- Data is owned by you and isolated from other users
- Retention: see Data Retention Policy
- You may delete voyage history via Settings → Privacy or
DELETE /api/privacy/voyages
7. Weather stations
Public IoT weather station data (e.g. Hetzner Azure_Station_V1) is environmental sensor data, not personal data. If linked to your account for calibration feedback, it is processed under Contract.
8. Cookies & local storage
| Storage | Type | Purpose | Consent |
|---|---|---|---|
azure_access_token / azure_refresh_token | HttpOnly cookies | Session authentication | Strictly necessary |
localStorage legacy token | Client storage | Backward-compatible auth | Strictly necessary during migration |
| Analytics cookies | — | Not used in Founder Beta | N/A |
We do not use non-essential cookies without consent.
9. Third-party processors
| Processor | Purpose | Location |
|---|---|---|
| Hugging Face | LLM inference | US/EU (region-dependent) |
| OpenWeather | Weather enrichment | EU/US |
| Hetzner | IoT weather station API | EU (Germany/Finland) |
| FrontSea Hub | SOS events, GIS (if enabled) | EU |
| Email provider (SMTP/Mailgun/SendGrid/SES/Resend) | Transactional email | Configurable |
| Hosting provider | Application infrastructure | EU preferred |
Data Processing Agreements (DPAs) and Standard Contractual Clauses apply where data leaves the EEA.
10. Data retention
See DATA_RETENTION_POLICY.md. Summary:
- Account data: life of account + 30 days
- Black Box: up to 2 years (user-deletable)
- Chat memory: 90 days inactive
- Security logs: 90 days
11. Your rights
Under GDPR you have the right to:
- Access your data —
GET /api/privacy/export - Rectification — update profile in account settings
- Erasure —
DELETE /api/privacy/account - Restriction — contact contact@azureai.pt
- Portability — JSON export via privacy API
- Object — opt out of marketing; object to legitimate-interest processing
- Withdraw consent — marketing preferences
- Lodge a complaint with your supervisory authority
Full details: USER_RIGHTS.md
12. Security
We implement encryption in transit (TLS), access controls, session isolation, and security audits. See SECURITY_AUDIT.md.
13. Children
Azure AI Weather is not directed at persons under 16. We do not knowingly collect data from children.
14. Changes
We will notify registered users of material changes. Continued use after the effective date constitutes acceptance of the updated policy.
15. Contact
| Enquiry | Contact |
|---|---|
| Privacy enquiries | contact@azureai.pt |
| Data protection contact | contact@azureai.pt |
| General support | contact@azureai.pt |
*This document is provided for Founder Beta. Final legal review by qualified counsel is required before commercial public launch.*