Maintenance Crew is designed around a simple principle: your boat's data belongs to you. This policy describes precisely what data the app uses and what leaves your device.
All app data — maintenance schedules, service logs, parts inventory, vessel information, and PDF bookmarks — is stored in a local SQLite database on your device inside the app's sandboxed Application Support directory. This data is never transmitted to any server operated by Maintenance Crew.
iCloud Backup. If you have iCloud Backup enabled on your device, Apple may include the app's data directory in your encrypted iCloud Backup as part of standard iOS and macOS backup behavior. This backup is controlled entirely by Apple and your own iCloud settings; Maintenance Crew does not initiate or control it. See Apple's Privacy Policy for details on how Apple handles backup data.
Maintenance Crew includes an optional iCloud sync feature. When enabled, the app stores a copy of your data — including any photos you attach to vessels, parts, and schedules — in your personal iCloud private database using Apple's CloudKit infrastructure (container iCloud.app.maintenancecrew). Your data in iCloud is stored in your own Apple account and is accessible only to you — Maintenance Crew does not have access to your iCloud database.
iCloud sync is governed by Apple's Privacy Policy. You can disable it at any time in Settings → iCloud.
Maintenance Crew lets you share one specific boat with another person you invite — a "co-skipper." Sharing is private and invite-only; there is no public link. It uses Apple's CloudKit sharing, so the shared boat's data is transmitted, through your and the co-skipper's own iCloud accounts, to the people you invite. This is the one case in which your data reaches another person's device, and it happens only for a boat you deliberately share and only after the invitee accepts.
Everything attached to the shared boat travels with it — systems, parts, schedules, logs, manuals, and any photos, including a registration or insurance document photo. Maintenance Crew operates no server in this process; it is handled by Apple's CloudKit sharing and governed by Apple's Privacy Policy. If you remove a co-skipper (or one leaves), their copy becomes read-only and stops receiving updates; nothing already on their device is deleted.
Maintenance Crew requests access to your device's location only when you use the Ship's Log feature to record where a log entry was made. Location access requires your explicit permission; the app requests When In Use authorization only.
Your GPS coordinates are stored locally in your log entry and are never transmitted to any server operated by Maintenance Crew.
Reverse geocoding (place names). When the app resolves a human-readable place name from your coordinates — for example, "Anacortes, WA" — it uses Apple's MapKit reverse-geocoding service (MKReverseGeocodingRequest). This sends your coordinates to Apple's servers to look up the place name. This network call is governed by Apple's Privacy Policy. If you do not want your coordinates sent to Apple for this purpose, you can decline location access when the app requests it.
Maintenance Crew includes an optional feature that parses maintenance schedules and part numbers from PDF engine manuals. There are two ways to use it, and both are optional:
AI Assistant (paste flow). By default, the app generates a structured prompt that you copy and paste into any AI chat tool you already use, then paste the response back to import the results. Used this way, the app does not send your PDF content anywhere — no data is transmitted by Maintenance Crew, and no AI account or key is required.
Automatic parsing with your own key. If you choose to add your own AI provider API key in Settings, the app can parse a manual automatically by sending that PDF directly to the AI provider using your key. This is the one case in which the app itself transmits your manual content to an outside service. Your key is stored only in your device's Keychain; the request is billed to your own account; and the developer neither receives your key nor has any access to the content or the response. What the provider does with the content is governed by that provider's own privacy policy. If you never add a key, this path never runs.
PDF files are stored at the location you choose on your device, using a security-scoped bookmark. The app also stores a SHA-256 hash of the file in its local database for change detection.
When you add a spare part, you can optionally scan its packaging with the camera to fill in the manufacturer, name, and part number. The text and barcode recognition runs entirely on your device using Apple's on-device frameworks — the camera image is never uploaded for recognition. The photo you capture is attached to the part and is treated like any other photo (see iCloud sync and sharing above). Camera access requires your explicit permission.
Maintenance Crew can send local notifications for low stock and upcoming maintenance if you turn those options on in Settings. These are scheduled and delivered on your device by the system; no notification content is transmitted to any server operated by Maintenance Crew. Notifications require your explicit permission.
If you enable calendar sync, the app adds your boat's service and expiry dates to Apple Calendar using write-only calendar access, which you grant explicitly. The app only adds, updates, and removes the events it creates; it does not read your existing calendar. Exporting a calendar file instead needs no permission and transmits nothing.
The app fetches a small configuration file from maintenancecrew.app/api/v1/models.json on launch to keep the AI Assistant prompt current. This request contains no personal data or user identifiers. The configuration is cached on your device for up to 24 hours, and a built-in fallback is used if the request fails.
Maintenance Crew is a paid annual subscription managed through Apple's App Store. Payment is processed entirely by Apple. Maintenance Crew does not receive or store your payment information. Your subscription status is verified on-device using Apple's StoreKit framework; no purchase data is transmitted to any server operated by Maintenance Crew.
The app uses Apple's system Keychain to store a tamper-resistant timestamp used to implement a fair offline grace window for subscribers who are temporarily without internet access.
Subscription purchases are governed by Apple's Standard End User License Agreement and Apple's Privacy Policy.
Maintenance Crew does not include any analytics SDKs, crash-reporting services, advertising SDKs, or behavioral tracking. The app's privacy manifest (PrivacyInfo.xcprivacy) declares NSPrivacyTracking: false and no tracking domains.
maintenancecrew.app/api/v1/models.json on launch. No personal data is transmitted.Apart from the optional flows listed above — each of which you turn on yourself — no other data leaves your device.
For questions about this privacy policy, contact privacy@maintenancecrew.app.