Sea Messagesالعربية

Privacy Policy

Last updated: June 27, 2026

Sea Messages is a quiet place to send anonymous notes. This page explains what we collect, why, and how to control it. We try to keep this short and honest.

In short

  • We collect the minimum needed to run the app: an account, your island name, and the messages you cast or receive.
  • Every bottle stores the real sender on our servers — even when sent as Anonymous — so we can act on reports and blocks. The sender is never shown to recipients.
  • Moderation runs at send time; flagged messages are held and never reach a recipient.
  • You can change your island name, control who reaches you, or delete your account from Settings.

What we collect

  • Account: when you sign in with Google or Facebook, we receive a provider user ID and your email address. We never see your provider password.
  • Profile: a generated handle, your island name, an avatar seed, and your preference for receiving open-sea bottles.
  • Bottles: the message text you send or receive, the chosen identity mode (revealed / covered), the target (a link, a person, or the open sea), and timestamps.
  • Sender identity: every bottle stores the real sender's account ID on our servers, even when sent as Anonymous. This is the moderation backbone. It is never returned to recipients through any field of our API.
  • Push subscription: if you opt in to notifications, we store the browser-provided push token so we can tell you when a bottle washes up.
  • Technical: standard server logs (IP address, user agent) for security, and — if configured — anonymous analytics (page views) and error reports.

How we use it

  • To deliver bottles to the right shore and notify recipients.
  • To run synchronous moderation on every cast: message text is sent to our moderation model so we can hold abusive content before delivery.
  • To act on reports and blocks. Blocking a covered sender works because we know who they are on the server, even if you don't.
  • To keep the service safe (rate limits, ban enforcement).

Who we share it with

  • Supabase — our database, authentication, and realtime provider. The current project is hosted in Singapore.
  • Our moderation model provider — receives message text at send time only. We do not send your identity to it.
  • Web push service — receives the notification payload and your browser token to deliver pushes.
  • Sentry and Google Analytics — only if configured, only for errors and aggregate usage. Easy to disable.
  • We do not sell your data, and we do not run ads.

How long we keep it

Bottles are kept while your account exists so conversation history stays intact. Held or rejected bottles are kept for moderation review. Deleting your account removes your profile and bottles related to it.

Your rights

  • Access and change your data from the Me tab (island name, open-sea toggle, share link).
  • Delete your account by signing in and using the delete option in Me, or by emailing us.
  • Block any sender from the bottle they sent you — even if they appear Anonymous.
  • Report a bottle to our crew for human review.

Age

Sea Messages is for people 13 and over.

Changes

When we change this page, we update the date at the top. Material changes will be flagged in the app.

Contact

Questions, deletion requests, or privacy concerns: support@seamessages.com.