๐ŸŒŠ Sondaq

Privacy policy

Effective August 5, 2026

Sondaq is built and operated by GraniteCore Technologies. This page describes what we actually collect across the Sondaq website and mobile app, why, and who else sees it -- in plain language, matching what the app really does rather than a generic template.

The short version

Account & sign-in

Signing in is optional -- only needed to purchase or restore Pro access. Sign-in itself happens through Microsoft Entra External ID; Sondaq's servers never receive or store a password. Once you sign in, we store:

WhatWhy
Your email addressTo identify your account and, if applicable, apply a comped Pro grant
An internal account IDTies your entitlement (free/Pro) to your account, kept separate from any identity-provider ID
Sign-in timestampsBasic account activity, not shared or published

Location

The mobile app can use your device's location, with your permission, to center the map on you and find nearby lakes and boat access sites. The website's optional "locate me" control works the same way through your browser. In both cases, your location is used only on your own device to draw a map marker -- it is never sent to or stored on our servers.

Purchases (Sondaq Pro)

Pro subscriptions are sold and billed entirely through the Apple App Store or Google Play, using RevenueCat to keep your Pro status in sync across the app and website. We never see your card number or other payment details -- that stays between you, the store, and RevenueCat. Our own servers store only your subscription's product, tier, status, and renewal/expiration dates, tied to your account ID.

Feedback reports

If you submit a bug report or feature request in the app, we collect the description you write, your app and OS version, device model, a recent diagnostic log, an optional screenshot, and the IP address the request came from (used only for spam/abuse prevention). Feedback is tied to a random, anonymous device identifier generated on your device -- never your account, email, or a real device advertising ID -- and it resets if you reinstall the app.

Diagnostics & technical telemetry

Our backend uses Microsoft Azure Application Insights to monitor errors and the health of calls to outside data sources (like the National Weather Service and USGS). This is operational monitoring of our servers, not behavioral tracking of you -- we don't run Google Analytics, Firebase, ad-network SDKs, or any cross-app tracking of any kind.

Cookies

The website sets one cookie, sondaq_session, when you sign in -- it holds your sign-in token for one hour, is marked HttpOnly and Secure, and is deleted when you sign out or it expires. We don't use advertising or third-party tracking cookies.

Map tiles & weather data

Map imagery is loaded from OpenStreetMap and Esri; live weather and water-level conditions come from the National Weather Service and USGS. Requesting a map tile or forecast sends your device's IP address to that provider directly, the same as loading any image from a website -- subject to their own privacy practices, not ours.

Data deletion

You can delete your account and its data yourself, any time, from the app's Account screen or the website. See what gets deleted, what's retained, and why for the details -- or, if you can't sign in, how to request deletion by email instead.

Children

Sondaq is a general-audience app, not directed at children, and we don't knowingly collect personal information from anyone under 13. If you believe a child has provided us personal information, contact us and we'll delete it.

Changes to this policy

If this policy changes in a material way, we'll update the effective date above. Continued use of Sondaq after a change means you accept the updated policy.

Contact

Sondaq is operated by GraniteCore Technologies. Questions about this policy or your data: contact@granitecoretech.com.