Privacy policy
Last updated August 3, 2026
This policy explains how Zeil Software LLC, a New Jersey limited liability company (“Zeil,” “we”), collects, uses, and shares personal information when you visit zeilapp.com, use the Zeil application at app.zeilapp.com or a club subdomain, read our docs, or communicate with us (together, the “Service”).
The short version: Zeil is software that sailing clubs use to run their operations. Your club controls the member data in its workspace; we process it on the club’s behalf and never sell it. AI Sail Briefs are generated from reservation, boat, and forecast data and are advisory only. You can download a copy of your data and delete your account yourself, from your profile; no request form needed.
1. Our two roles
Zeil as processor / service provider. Most data in Zeil (member profiles, emergency contacts, certifications, reservations, waiver acknowledgements) is entered by or for your sailing club (“Club Data”). Your club decides what is collected and who can see it; we process it on the club’s instructions. If you are a club member with questions or requests about your data in a club’s workspace, your first stop is your club’s administrators. We support the club in fulfilling your request. Clubs that need a data-processing agreement can contact us.
Zeil as controller (business). We are responsible for your Zeil account itself (your sign-in identity), marketing-site visits, and our communications with prospects and customers.
2. Information we collect
- Account & profile: name and email; optionally phone, mailing address, emergency contact, a short bio, and an avatar photo. Sign-in is passwordless (email links, plus Sign in with Apple where enabled); we never collect or store passwords.
- Sailing credentials: certifications, levels, expiry dates, and boat/class endorsements, entered by your club’s administrators.
- Club & activity records: memberships and roles, reservations and crew participation, crew-chat messages, post-sail debrief notes, course enrollments, announcements, and waiver acknowledgements (which store the waiver text you agreed to, your name and email, and a timestamp).
- Guest information: when a member invites a non-member guest onto a sail, we collect the guest’s name and email to send the invitation and record their waiver acknowledgement.
- Weather & Sail Briefs: your club’s location coordinates, forecast data for reservation windows, and the generated Sail Brief text.
- Usage & device data: IP address, browser/device type, pages viewed, timestamps, and an activity log of significant actions (invitations, role changes, cancellations, and similar).
- Communications: support emails, feedback, and contact-form messages.
- Payment information: none. Zeil has no payment processing today; we do not collect card or bank details.
Please do not submit government ID numbers, health records, or financial account numbers into free-text fields. Emergency-contact and note fields should contain only what your club needs for on-water operations.
3. How we use information
- Provide the Service: authentication, club workspaces, reservations and skipper-eligibility checks, crew coordination, courses, announcements, and weather display.
- Generate Sail Briefs: to produce a brief, we send our AI provider the reservation window, boat name/class/length, the weather and tide forecast, sunset time, the lead skipper’s name, the number of crew aboard, and any local notes your club’s administrators have written. Crew members’ names, emails, and credential details are not sent, and the assembled prompt is not stored. Sail Briefs are advisories only and always carry the notice “AI-generated advisory; verify before sail.”
- Operate and secure: debugging, rate limiting, abuse prevention, backups, and activity logging.
- Communicate: transactional and service email (sign-in links, invitations, reservation notices, digests). If your club’s founder opts in when creating the club, we also send the club’s administrators onboarding tips and product news during and after the club’s trial; you can opt out of these at any time, at Profile → Preferences or via the unsubscribe instructions in any such email. Most categories can be switched off per club at Profile → Preferences; essential notices (sign-in links, reservation confirmations and cancellations, account notices) are always sent while you have an account.
- Improve the Service: aggregate, de-identified usage measures. We do not use Club Data to train generalized AI models without the club’s prior written consent, and our AI provider does not train on data submitted through its API under its commercial terms.
- Legal: comply with law, enforce our terms, and protect rights and safety.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. There are no advertising trackers in the product.
4. Who we share information with
We use a small set of service providers to run Zeil:
- OVH (Canada, Montreal region): hosting for the application, database, and backups. All Service data lives here.
- Anthropic (US): Sail Brief generation; receives exactly the brief inputs described in Section 3.
- Resend (US): transactional email delivery; receives recipient addresses and full message content (which can include names, reservation details, crew-chat excerpts, and one-time sign-in links), plus contact-form submissions from our marketing site.
- Open-Meteo (Switzerland): weather and tide forecasts; receives only your club’s approximate geographic coordinates and a date range; no names, emails, or user identifiers.
- OpenStreetMap Foundation: maps. Address searches by club admins go through our server; map images on pages such as guest invitations load tiles directly in your browser, so OpenStreetMap receives your IP address and the map area shown (your club’s approximate location).
- Cal.com (US): the demo-booking widget on our marketing site’s Contact page. It loads a script and an embedded calendar directly in your browser, so Cal.com receives your IP address and browser information and may set its own cookies to run and style the scheduling flow. If you book a time, the name, email, and any notes you enter go directly to Cal.com — not through our servers.
- Sentry (US): error reporting, where enabled. We do not attach your name or email to error reports and session replay is disabled; reports can include technical context such as the page involved, internal record identifiers, and, at the transport level, an IP address.
- Apple (US): Sign in with Apple, where enabled; Apple shares your name and email with us at your direction when you use it.
Integrations you direct. Some sharing happens only because you choose it: if you connect an AI assistant to Zeil (via our MCP interface), you approve the connection on a consent screen and your club data then flows to that assistant’s vendor at your direction, under an access token scoped to your club and your role. You can end the connection at any time by disconnecting Zeil from the assistant; unused connections expire on their own, and access ends immediately if your membership or role changes. “Add to Google Calendar” opens Google with the event details only when you click it; and year-in-review share links create a public page showing your own sailing statistics and crewmates’ first names only; share them as you see fit (they stop working if you leave the club).
Other disclosures: within your club (your profile, credentials, and sail participation are visible to your club’s administrators and, depending on features used, other members); professional advisers under confidentiality; legal process (courts and regulators, with notice to the affected club where legally permitted); and corporate transactions (with notice and continuity of these commitments). We do not share data with data brokers or advertisers.
5. Children and junior sailing programs
The Service is not directed to children, and we do not knowingly collect personal information online from children under 13. Individual accounts are for people 16 or older.
Many clubs run junior programs. Roster records about junior sailors (for example, a name on a crew list) may be entered by adult club administrators as club records; clubs, not Zeil, decide what junior-program information to enter, and any communications with parents come from the club. If we learn we have collected personal information directly from a child under 13, we will delete it promptly; parents can write to hello@zeilapp.com with the subject “Privacy request”.
6. Your rights and controls
We extend these to all users, regardless of where you live:
- Access and correct: most profile fields are self-service; for anything else, email us.
- Export: Profile → “Export my data” downloads a JSON copy of your core account and activity data across all your clubs, any time. If you need something not included in the export, email us.
- Delete: Profile → “Delete my account” takes effect immediately: your profile details are cleared and your memberships deactivated right away (we keep your sign-in email during the 30-day restore window so you can sign back in and undo the deletion; it is deleted with everything else at the end of that window). You have that 30-day window to restore the account (we send a warning email about a week before the deadline); after that, remaining data is permanently and automatically deleted, except records we must keep for legal or safety reasons: waiver acknowledgements are retained for your club as a record of the acknowledgement, and activity-log entries are kept with your personal details scrubbed (see Retention).
- Email preferences: manage per-category email settings at Profile → Preferences (linked from the footer of Zeil notification emails). Preferences are per club, so members of several clubs manage each separately. Essential service emails are always sent while you have an account.
California and other US state residents: we do not sell or share personal information as those laws define the terms, and we honor requests to know, correct, and delete regardless of whether a given statute applies to us. We honor Global Privacy Control signals for any practice within their scope, and if we decline a request you may appeal by replying with the subject “Appeal”. Send requests to hello@zeilapp.com with the subject “Privacy request”; we verify requests using your account email and respond as promptly as we can, and within any timeframe applicable law requires. Requests concerning Club Data are forwarded to the relevant club, and we help the club respond.
7. Retention
- Account & profile data: kept for the life of your account. On deletion, your profile details are cleared immediately (your sign-in email is kept during the 30-day restore window so you can undo the deletion) and remaining data is permanently purged after that window.
- Club Data: kept while your club uses Zeil. A club that leaves can ask us for a full export of its workspace data in a portable format, for deletion of its workspace, or both; we honor both requests.
- Waiver acknowledgements: designed as standalone records (waiver text snapshot, signer name, timestamp) and retained for the club as a record of the acknowledgement.
- Crew-chat messages: remain with the sail’s conversation even if the author later leaves the club (shown as “Former member”).
- Activity log entries: retained without a fixed period; when an account is permanently deleted, personal data in its log snapshots is scrubbed and links to the account are severed.
- Sail Brief prompts: not stored after generation. Forecast caches are short-lived.
- Backups: nightly database backups on a rolling 30-day retention, so deleted data can persist in backups for up to 30 days after deletion.
8. Security
Safeguards include: passwordless sign-in (there are no passwords to steal; sign-in links are single-use and expire in 15 minutes); encryption in transit (TLS/HTTPS); per-club data isolation enforced at the database layer (row-level security); sign-in link tokens and API tokens for connected apps stored only as cryptographic hashes; role-based access within clubs; rate limiting; activity logging; nightly automated database backups with a 30-day retention window; and production access limited to the operator. No method is 100% secure; report suspected vulnerabilities to hello@zeilapp.com with the subject “Security”.
9. If something goes wrong
If a security incident affects personal information, we will notify affected clubs without undue delay after confirming it, and notify individuals and regulators where and when applicable breach-notification laws require. Notices will describe what happened, what data was involved, and what we and you can do.
10. Where your data lives
Zeil is operated from the United States and built for US clubs. Service data is hosted in Canada (OVH, Montreal region). Transactional email is delivered through Resend in the United States, and weather lookups send only coordinates to Open-Meteo in Switzerland. By using the Service, you understand your information is processed in Canada and the United States.
11. Cookies
In the Zeil application, we use strictly necessary cookies only (session/authentication and security). We do not use third-party advertising cookies, and there are no ad or analytics trackers in the product. The Cal.com booking widget on our marketing site’s Contact page is a scheduling tool, not an ad or analytics tracker, but as a third-party embed it may set its own cookies when it loads — see Section 4. If we add analytics to our marketing site, we will name the tool and its purpose here first.
12. Changes to this policy
We will post changes here and update the date at the top. For material changes, we will notify club administrators in advance.
13. Contact
Email: hello@zeilapp.com. Use the subject “Privacy request” for data requests and “Security” for vulnerability reports.
Mail: Zeil Software LLC, 500 Paterson Plank Rd # 31479, Union City, NJ 07087, USA.