Privacy Policy
Last updated: August 13, 2026
This policy describes what data Surfbreak collects, why, and the choices you have. The short version: your sessions are recorded and stored on your own devices and an account is optional; we measure how the app is used, without advertising and without the advertising identifier; and everything tied to your account can be deleted from inside the app.
Overview
Surfbreak does two things: it shows a surf forecast for a catalogue of spots, and it records surf sessions on your Apple Watch. Both work without an account. Every session, wave and track is written to a local database on your device first, and the app functions with the radio off. Cloud features — signing in and backing your sessions up — activate only when you choose to use them.
What we collect
Depending on how you use the app, we process the following categories of data:
- Account information. If you sign in with Apple or Google, our backend provider (Supabase) stores your email address, display name and avatar so we can identify your account across devices. Apple and Google act only as identity providers — we receive an identity token from them, never your password.
- Sessions you choose to back up. While you are signed in, your surf sessions sync to your account: the summary and per-wave figures, and a compressed copy of the session's GPS track stored in a folder that only your account can read. This is what brings your history back on a new phone.
- Profile settings. The display name and avatar shown on your profile, if you set them.
- Usage analytics. Which screens and features are opened, so we can see what is worth building next. See Analytics below for exactly what is recorded.
- Subscription state. Whether you have an active Surfbreak Pro subscription and which plan, so the app can unlock Pro on every device you sign in on. See Subscriptions below.
We do not show advertising, we do not use the advertising identifier (IDFA), we do not track you across other companies' apps or websites, and we never sell your data to anyone.
Analytics
Surfbreak uses Google Analytics for Firebase to measure how the app is used. This is aggregate product measurement, not profiling: it tells us that the map is opened more often than the spot list, or that people stop at a particular screen, and that is what it is for.
The events we record ourselves are these, and nothing else:
- opening the map;
- opening a spot's forecast, with the name and identifier of that spot;
- opening the long-range outlook or the statistics screen;
- the subscription screen being shown, a plan being selected, and whether a purchase or restore succeeded or failed.
Alongside those, Firebase collects its own standard measurements: app opens and session length, your device model and iOS version, app version, language and an approximate location (country or region, derived from the IP address of the request — not from your device's GPS). Firebase assigns a random app instance identifier so repeat visits can be counted; it is not your Apple ID and not your account with us.
Analytics is not linked to your surf sessions, your tracks or your health data. It is off entirely in development builds. There is currently no in-app switch to turn it off — if you want your analytics data deleted, email us and we will remove it.
Subscriptions
Surfbreak Pro is an auto-renewable subscription. Apple processes the payment: we never see or receive your card details, and the purchase itself happens entirely inside the App Store.
We use RevenueCat to keep track of whether a subscription is active. It receives the purchase receipt from Apple, the plan you bought and its renewal state, your device type and iOS version, and an identifier for you — a random per-installation identifier while you are a guest, and your Surfbreak account identifier once you sign in, which is what lets Pro follow you to a new phone. RevenueCat does not receive your sessions, tracks, health data or email address.
Location
Surfbreak asks for location access for two reasons: to sort the spot catalogue by how close each break is to you, and — on the Apple Watch, during a session you started — to record the track that the wave detection is computed from. Location updates continue while a session is running with your wrist down and the screen dark; that is what makes the recording usable at all, and it stops when the session does.
Your position is used on your device. It is not sent to us in real time, and it is not shared with third parties. The track of a recorded session leaves your device only if you are signed in and it is backed up to your own account, or if you deliberately export it yourself. You can revoke location access at any time in the iOS or watchOS Settings app — the forecast half of the app keeps working.
Health data
With your explicit permission, Surfbreak reads and writes workouts, heart rate, active and resting energy, and the workout route through Apple HealthKit. This is what records a surf session as a workout in the Health app and puts heart rate and calories on the session summary.
Health data is never used for advertising or analytics, never sold, and never shared with third parties. It stays on your iPhone and Apple Watch with one exception, and we would rather state it plainly than bury it: if you are signed in and backing your sessions up, the summary figures calculated from it — average and maximum heart rate, and calories burned — are stored with that session in your own account, because otherwise a restored history would come back with those numbers missing. The underlying Health samples themselves are not uploaded. Stay a guest and nothing leaves the device at all. You can revoke HealthKit access at any time in the Settings app.
The Apple Watch also reads its motion sensors while a session is running. Those samples are stored with the session on your device and are used to improve wave detection.
Forecast data
Forecast and tide figures come from third-party marine data services (Open-Meteo and WorldTides). When you open a spot, the app requests the forecast for that spot's coordinates — the coordinates of the break, not your own position — and caches the answer on your device.
Guest mode
You can use all of Surfbreak without creating an account. As a guest, your sessions, waves, tracks and favourites stay on your device and nothing is uploaded — there is no account for them to belong to. The trade-off is that a lost or replaced phone takes the history with it.
Data deletion
You can delete your account and everything stored with it at any time in the app: open Profile → Delete account. Deletion takes effect immediately and removes your synced sessions, their tracks, your avatar and your profile from our servers. Deleting a single session in the app removes it from the cloud too. If you would rather we did it for you, email apps.gexik@gmail.com.
Two things sit outside that button and have to be asked for, because they are not keyed to the account you are deleting: the analytics records, which are tied to a random app instance identifier, and your subscription record at RevenueCat, which has to outlive the account for a restore to work. Email us and we will delete either or both. Deleting the subscription record does not cancel the subscription itself — that is done in Settings → Apple Account → Subscriptions on your iPhone, and only you can do it.
Third-party services
Surfbreak relies on a small set of providers, each limited to the purpose described:
- Supabase — authentication, the spot catalogue, and cloud storage for the sessions you back up.
- Apple — Sign in with Apple, HealthKit, and payment processing for subscriptions.
- Google — Sign in with Google, if you choose it, and Google Analytics for Firebase for the usage measurement described above.
- RevenueCat — keeping track of subscription state across your devices.
- Open-Meteo and WorldTides — marine forecast and tide data for spot coordinates.
Each provider processes data under its own privacy policy and only receives what is necessary to provide its service.
Children
Surfbreak is not directed at children under 13, and we do not knowingly collect personal data from them.
Changes to this policy
If we make material changes to this policy, we will update this page and revise the “Last updated” date above. Continued use of the app after a change means you accept the updated policy.
Contact
Questions about privacy or your data? Email apps.gexik@gmail.com — happy to help.