Privacy Policy

DingHai does not use advertising or third-party analytics services. You may choose to use a DingHai account with Sign in with Apple; local anchor watch requires no account and does not depend on DingHai servers.

Effective date: August 7, 2026.

1. Scope

This policy applies to the DingHai app for iOS and iPadOS and to the privacy and support pages on this website.

2. On-device location processing and anchor-watch records

While anchor watch is active, DingHai processes your precise vessel position on your device to:

  • place an anchor on the map and calculate the distance between the vessel and anchor;
  • determine whether the vessel has moved beyond your safety range;
  • draw the movement track for the current anchor watch; and
  • continue monitoring on the Lock Screen or in the background and alert you to a potential anchor drag.

Anchor positions, tracks, safety ranges, times, maximum drift, display preferences, and anchor-watch photos you explicitly select are stored first in the app's local data container and may be synchronized by Apple CloudKit to your private database under the same iCloud account. Signing in to a DingHai account does not automatically upload these records to DingHai servers.

Local location processing, distance decisions, and alarms remain on the device. Local anchor watch continues when the account, network, or remote service is unavailable.

3. DingHai accounts and authentication

Sign in with Apple is optional. After you sign in, DingHai servers process:

  • an internal DingHai account identifier derived from the Apple identity association;
  • a device identifier, platform, and system-provided device display name;
  • hashes or status records for DingHai access and refresh sessions; and
  • an encrypted Apple refresh token used only to revoke Apple authorization when you delete the account.

DingHai never asks for or stores your Apple ID password. DingHai session tokens on the device are stored in the Keychain.

4. Remote anchor-watch data

Only when you use remote anchor watch, DingHai servers process the remote session's anchor coordinate, safety range, latest device-reported vessel position and accuracy, distance from anchor, monitoring status, controlling device, handoff state, and session times. This data lets your devices see one consistent state and safely transfer control.

Local historical tracks and anchor-watch photos are not automatically uploaded as part of a remote session and are not used for advertising, profiling, or cross-app tracking.

5. Apple and infrastructure services

Maps, device location, notifications, and Live Activities are provided through Apple system services, including MapKit, Core Location, UserNotifications, and ActivityKit; local records may synchronize through your private Apple CloudKit database. Apple's own privacy policy applies to its processing through those services.

DingHai uses Cloudflare Workers, D1, and Durable Objects to provide account and remote anchor-watch services. DingHai includes no advertising SDKs or third-party analytics SDKs.

6. Permissions

  • Location while using the app: shows the vessel position, places the anchor, and calculates distance.
  • Always and precise location: continues anchor watch while locked, in another app, or when iOS wakes the app for a location condition.
  • Notifications: alerts you when an anchor-drag risk is detected.

DingHai does not request microphone, camera, or contacts access and does not record audio. Only photos you explicitly choose through the system photo picker are added to anchor-watch records.

7. Retention, deletion, and control

Anchor-watch records in local storage and your private iCloud database remain until you delete them individually in the app. Deleting the app removes only the local copy on that device; records already synchronized to iCloud may return after reinstallation or remain on other devices.

You can sign out or delete the DingHai account from the account screen. Account deletion closes and clears remote anchor-watch sessions on DingHai servers, revokes Apple authorization, and deletes server-side account, device, and DingHai session data. Local and private iCloud records are not automatically deleted with the server account.

You can revoke location or notification access at any time in Settings. Revoking a permission required for anchor watch will stop the corresponding protection.

8. Use and sharing

DingHai processes the data described above only to provide accounts, secure cross-device remote anchor watch, and support. DingHai does not sell personal data or share it with advertising, analytics, or data-broker services. Apart from Apple and Cloudflare processing required to provide system and infrastructure services, DingHai does not provide this data to other third parties.

This website uses no cookies, analytics, tracking pixels, or third-party fonts.

9. Intended use

DingHai is an anchor-watch aid. It does not provide emergency rescue or vessel control and cannot replace safe anchoring procedures, a human watch, or compliant marine equipment. Always maintain independent safety measures.

10. Updates and contact

If our data practices materially change, we will update this policy, this effective date, and the App Store Privacy Nutrition Label together, and provide an in-app notice when appropriate.

For privacy questions, contact the development team through GitHub Issues. Do not include vessel positions, tracks, or other sensitive information in a public issue.