Privacy
SeaPapers is run by Magentic, South Africa. Questions about your data go to ahoy@seapapers.com. This page says what we hold, why, where, for how long, who else touches it, and how you get it back or make it go away.
What we hold and why
Your email address and password, to sign you in. Everything you type into the CV editor and any headshot you upload, so we can build and render your CV. Your subscription status from our payment provider, so we know whether Pro is on. If you use the Document Folio, the files you upload and the dates recorded against them. We do not sell any of it, we do not use it to train models, and we do not show it to anyone unless you create a share link or ask us to.
Everything lives on servers in Frankfurt, in the European Union. It is kept while your account exists.
Your controls
From your account settings you can download every field you have entered as a file, turn reminder emails on or off, and delete your account. Deleting your account removes your CV, your files, your share links and your record with us. Billing records stay with our payment provider for as long as tax law asks them to keep receipts.
If you asked us to hold a founding spot, we keep that email address until card payments open, so that we can tell you. It is in your data download. Deleting your account does not remove it, because the address can be given without an account. Email ahoy@seapapers.com and we will delete it.
Document Folio
The folio holds the files you upload, the document type you give each one, and the issue and expiry dates recorded against it. We use those dates to tell you what is running out.
Medical documents are treated separately. An ENG1 or any other seafarer medical is health information, so we ask for a separate consent before the first one is stored, and you can use the rest of the folio without giving it.
Your files are kept while your account exists. You can delete any document on its own at any time. Delete your account and the files go with it.
Files sit in private storage and are encrypted at rest. They are not browsable. A file is only reachable through a link you create, and every link runs out.
A share link is kept for 30 days after it expires or you revoke it, so you can still see who opened it. The record of opens and downloads is kept for 90 days. After that both are removed.
Who else handles your data
A small number of companies process data for us, each for one job and under a written contract. A database and file storage provider in the EU (Frankfurt) holds your CV and your documents. A hosting provider in the EU (Frankfurt) runs the website. A payment provider acting as merchant of record takes the payment and holds your billing details; we never see your card. It is named in our Terms and on your receipt. When you ask us to read a document and fill in the dates, or to rewrite your profile or your duty bullets, a document reading and writing provider is sent that one file or those few lines and nothing else, and it does not train on them. An email delivery provider in the EU sends the reminder emails from ahoy@seapapers.com and is given only your email address and the words of the email. An analytics provider in the EU counts page visits and a handful of anonymous product events, without cookies. Unless you press Accept on the cookie banner it keeps nothing on your device, so each visit is counted on its own; if you accept, it keeps a random number in your browser's local storage so a return visit counts as the same visitor. It never receives the identifier an ad adds to a link. Either way it is never told who you are, it records nothing you type, and it does not record your screen. While we are running paid ads, and only if you press Accept on the cookie banner, an advertising pixel from Meta (Facebook/Instagram), based in the US, is loaded too. It sets its own cookies and is told the page you are on and the name of a handful of funnel moments (completing the evaluation, creating an account, opening checkout, completing a purchase) and, for a purchase, the amount and currency. With the same permission our server tells Meta about those moments directly, with your browser's address and type, Meta's own cookie values and, when you create an account or buy, your email address in scrambled (hashed) form so Meta can match it to an ad. It is never given your name or anything from your CV or your documents. We keep a named list of these providers and will send it to you on request at ahoy@seapapers.com.
Passport, identity and visa numbers are never taken off a document and never stored. If a reading picks one up it is dropped before anything is written down.
Cookies and your choice
Some cookies are needed for the site to work. They keep you signed in, carry an evaluation you ran over to your new account, and remember your cookie choice. These are always on.
The rest are only set if you press Accept on the cookie banner. One remembers for 90 days where your first visit came from: the name of the campaign or the website that linked to us, and the page you arrived on. It never holds your name or the ad click's own identifier. Our analytics provider's random number in local storage, described above, is another. The others are the Meta advertising cookies described above. Choose Only necessary and none of these are set. You can change your answer at any time from Cookie settings at the foot of every page, or here: .
When you create an account we record, on the account, where the visit you signed up in came from, in the same coarse terms, so we can tell which posts and ads bring crew to SeaPapers. It is kept with your account and deleted with it.