This privacy policy applies to the WaveCheck app for mobile devices, developed by Austin Urraca as a Freemium service provided "AS IS".
Information You Provide
The app acquires information you supply when you register. Registration is not mandatory, but some features require it.
Automatically Collected Information
The app may collect device type, unique device ID, IP address, mobile OS, browser type, and usage patterns.
Location Data
If you grant location permission, WaveCheck uses your device location to: (1) identify surf spots near you, (2) set your home location for personalized forecasts, and (3) compute distance to spots in search results. Location is used only while the app is in use; we do not track your location in the background. You can deny or revoke location permission at any time in your device settings — the app remains fully usable, but you'll need to manually select your location.
Google User Data
WaveCheck integrates with Google services to provide optional features. This section discloses how we access, use, store, share, and retain Google user data, in accordance with the Google API Services User Data Policy, including the Limited Use requirements.
1. Data Accessed
When you sign in with Google or connect your Google Calendar, WaveCheck accesses the following data from your Google Account:
- Email address and basic profile information
(name, profile picture) — accessed via the standard Google Sign-In
scopes (
profile,email,openid) when you choose to sign in with Google. - Google Calendar events — accessed via the
https://www.googleapis.com/auth/calendar.eventsscope only if you explicitly enable the Google Calendar sync feature in WaveCheck settings. WaveCheck creates and updates events on the calendar you select; it does not read events you did not create through WaveCheck.
2. Data Usage
Google user data is used solely to provide and improve features you have actively opted into:
- Email and profile data are used to create and authenticate your WaveCheck account, populate your profile, and personalize your experience (e.g. displaying your name in the app).
- Calendar data is used exclusively to write surf forecast events to your selected calendar when you enable the calendar sync feature, and to update or delete those events when forecasts change or you modify your preferences. WaveCheck reads events only to identify and update events it previously created.
WaveCheck does not use Google user data for advertising, profiling, or any purpose other than providing the features described above. WaveCheck does not use Google user data to train artificial intelligence or machine learning models.
3. Data Sharing
WaveCheck does not sell, rent, or share your Google user data with third parties for their own purposes. The only third parties that may process Google user data on WaveCheck's behalf are:
- Firebase Authentication (Google LLC) — used to manage authentication sessions when you sign in with Google.
- Railway (Railway Corp.) — our backend hosting provider, which stores your account information (including email and profile data) in our PostgreSQL database located on Railway infrastructure.
These providers act as data processors under our instructions and are contractually obligated to protect your data. We do not share Google user data with advertisers, analytics partners, or any other third parties.
4. Data Storage and Protection
Google user data is stored in our PostgreSQL database hosted on Railway infrastructure. Our hosting provider applies infrastructure- level encryption to data at rest. All data is transmitted between your device, our servers, and Google's APIs over HTTPS/TLS encrypted connections. Access to user data within our infrastructure is restricted to the WaveCheck developer (Austin Urraca) and protected by strong authentication. We do not store your Google password — authentication is handled entirely by Google's OAuth flow, and we receive only the OAuth tokens necessary to access the scopes you have authorized.
Calendar OAuth refresh tokens are retained only while Google Calendar sync is enabled. We do not store copies of your Google Calendar event data on our servers — calendar events are written directly to your Google Calendar via the Google Calendar API and are not duplicated in our database. We read only events that WaveCheck previously created, identified by private metadata tags we set when creating them.
5. Data Retention and Deletion
Google user data is retained only as long as necessary to provide WaveCheck's features:
- Your email and profile data are retained for as long as your WaveCheck account exists.
- Calendar OAuth tokens are retained while Google Calendar sync is enabled. Disconnecting Google Calendar in WaveCheck settings immediately deletes the stored tokens from our servers.
You can revoke WaveCheck's access to your Google data at any time:
- Via Google: visit https://myaccount.google.com/permissions and remove WaveCheck.
- Via WaveCheck: disable Google Calendar sync in Settings, or delete your WaveCheck account entirely from Settings → Account.
To delete your WaveCheck account and all associated data, including Google user data we have stored, use the in-app account deletion feature or contact us at support@wavecheck.surf. Account deletion is processed immediately and is irreversible.
Limited Use Compliance
WaveCheck's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets (with user notification). We do not use Google user data for advertising, including retargeting, personalized advertising, or interest-based advertising. We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, do so for security purposes (such as investigating abuse), to comply with applicable law, or for internal operations where the data has been aggregated and anonymized.
Advertising
WaveCheck does not currently display advertisements. If we introduce ads in the future, they will be served by Google AdMob and we will update this policy to describe the data they collect. Premium subscribers will not see ads at any point. Google user data obtained through the Calendar integration is never used for advertising purposes.
Subscriptions & Payments
WaveCheck Pro subscriptions are processed through Apple App Store or Google Play Store. Payment and subscription management is handled by RevenueCat, which receives a user identifier to manage your subscription status. We do not store your payment information.
Push Notifications
The app uses Firebase Cloud Messaging to send push notifications about surf conditions and session reminders. You can disable notifications in the app settings or your device settings at any time.
Artificial Intelligence
The app does not use AI technologies to process your data. Google user data obtained through the Calendar integration is not used to train any AI or machine learning models.
Third-Party Services
Opt-Out
You can stop all data collection by uninstalling the app. To revoke only Calendar access while continuing to use other features, disconnect Google Calendar in the app's settings or remove WaveCheck from your Google Account permissions.
Data Retention & Deletion
User-provided data is retained while you use the app. Automatically collected data is retained for up to 24 months. Google Calendar access tokens are retained only while your account is connected; when you disconnect, the tokens are immediately deleted from our servers. To request deletion of all account data, contact support@wavecheck.surf or use the "Delete Account" option in the app settings.
Children's Privacy
WaveCheck is intended for users 13 years of age and older. We do not knowingly collect personal data from anyone under 13. In jurisdictions where the minimum age for digital consent is higher (e.g. 16 in some EU countries), the higher local threshold applies. If you believe a child has provided us with personal information, please contact us at support@wavecheck.surf and we will delete it.
Your Rights (GDPR)
If you are located in the European Economic Area or United Kingdom, you have the right to: access your personal data, correct inaccuracies, delete your data, restrict or object to processing, and data portability. To exercise these rights, contact support@wavecheck.surf or use the in-app "Delete Account" option for deletion. The legal basis for processing is your consent (for optional features like Google Calendar) and our legitimate interest in providing the service (for core functionality). We retain data only as long as needed to provide the service or as required by law.
Data Controller
Austin Urraca, sole developer, based in Ferrel, Portugal. Contact: support@wavecheck.surf
Contact
Questions about this policy? support@wavecheck.surf
Back to WaveCheck