Legal

Privacy Policy

Last Updated: 14 August 2026

The Muster App Ltd ("we", "us", or "our") operates the Muster application and the Muster Mate companion application (together, the "Service"). This Privacy Policy explains how we collect, use, and protect information when you use our Service.

The Service consists of two applications:

  • The Muster App — the iPad application used by vessels for visitor check-in, crew management, safety documents, and emergency muster procedures.
  • Muster Mate — the companion mobile application (iOS and Android) used by individual crew members to view their muster duties, abandon ship station, deliveries, and to receive notifications from their vessel.

1. Information We Collect

Crew Member Account Information (Muster Mate)

When a crew member creates an account in Muster Mate, we collect:

  • Full name
  • Email address (used for sign-in and password reset)
  • Password (stored hashed and salted — we never store or transmit your password in plain text)
  • Phone number (optional, used by your vessel for contact purposes)
  • Profile photo (optional, displayed on your vessel's crew board)
  • The yacht(s) you have joined (linked via an access code or invite code provided by your captain)
  • Push notification token (Apple Push Notification service token on iOS, Firebase Cloud Messaging token on Android — used solely to deliver notifications from your vessel)
  • Device platform and app version (used for support and compatibility checks)

Information Crew Members Provide Through Muster Mate

While using Muster Mate, crew members may submit:

  • Delivery photos — photos of packages or deliveries received on the vessel, captured with the device camera and uploaded to the vessel's records. The app may use on-device optical character recognition (OCR) to read recipient names from labels, helping to match deliveries to crew members. OCR processing happens on the device.
  • Contact form messages — if you use the in-app "Contact Us" form, the message you write and your name and email address are sent to our support team at support@themusterapp.com.

Muster Mate does not collect your location, contacts, browsing history, advertising identifiers, or any data not listed above.

Visitor Information

When visitors check in to a vessel using the Service, we collect:

  • Full name
  • Company/organization (if applicable)
  • Photograph (for identification badges)
  • Government-issued identity document (passport, driving licence) — image captured for verification. We do not perform biometric facial recognition on visitor photographs or identity documents
  • Check-in and check-out timestamps
  • Reason for visit

Device Information

For authorized devices running the Service:

  • Device identifier (UUID)
  • Device name
  • App version and platform
  • Last active timestamp

Vessel Information

For vessels using the Service:

  • Vessel name and details
  • Crew member information (names, roles)
  • Safety documents uploaded by vessel administrators

Audio Recordings

If enabled by the vessel, audio may be recorded during active muster (emergency drill) sessions. This feature:

  • Purpose: Supports compliance with maritime safety regulations including the International Safety Management (ISM) Code and Safety of Life at Sea (SOLAS) Convention requirements for emergency preparedness and drill documentation
  • Consent Required: All persons present during a recorded muster session must be informed that recording is taking place. Vessel operators are responsible for obtaining appropriate consent or providing notice before recording begins
  • Vessel Control: Audio recording is disabled by default and must be explicitly enabled by the vessel administrator. It can be disabled at any time
  • Limited Scope: Recording only occurs during active muster/emergency drill sessions, not during normal vessel operations
  • Deletion: Vessel administrators may delete audio recordings at any time. Recordings are automatically deleted after the configured retention period

2. How We Use Information

We use collected information for:

  • Vessel Safety: Tracking who is on board for emergency muster and evacuation procedures
  • Identification: Generating visitor badges for security purposes
  • Compliance support: Helping vessel operators maintain their own records in support of maritime safety regulations (such as the ISM and ISPS Codes). The Service is a supplementary aid and does not by itself ensure or guarantee compliance; responsibility for compliance remains with the vessel operator (see our Terms of Service)
  • Service Operation: Authenticating devices, syncing data, providing the Service
  • Safety Audits: Recording muster sessions when enabled by vessel administrators

3. Legal Basis for Processing (GDPR)

We process personal data under the following legal bases:

  • Legitimate Interests: Vessel safety and security, emergency preparedness
  • Legal Obligation: Compliance with maritime safety regulations requiring vessels to track personnel on board
  • Contractual Necessity: Providing the Service to vessel operators

4. Data Retention

Except for muster audio recordings (see below) and copies of imported files (see Section 6), we do not automatically delete personal data. Visitor, crew, vessel and document data are retained until the vessel administrator deletes them, or until a valid erasure request is fulfilled. Retention is configured and controlled by each vessel administrator.

  • Visitor Records: Retained until deleted by the vessel administrator or on a valid erasure request
  • Visitor Photos/IDs: Retained until deleted by the vessel administrator or on a valid erasure request
  • Crew Information: Retained until removed by the vessel administrator or on a valid erasure request — it is not automatically deleted when a crew member leaves the vessel
  • Safety Documents: Retained until deleted by the vessel administrator
  • Muster Audio Recordings: The one exception — where enabled, muster audio recordings are automatically deleted after the retention period configured by the vessel, and may also be deleted by the vessel administrator at any time before then

Vessel administrators may delete visitor and other vessel data at any time through the admin interface. We retain records we are required to keep by law (for example, billing and accounting records) for the period required.

5. Data Storage and Security

  • Data is stored on Amazon Web Services (AWS) infrastructure
  • All data is encrypted in transit using HTTPS/TLS
  • Files are stored with server-side encryption at rest
  • Access to documents is controlled via time-limited signed URLs
  • Devices must be authorized by vessel administrators to access data

Access by our staff

Running the Service means that, in limited circumstances, our own people can see data held in a vessel's account. We set out here exactly when that happens and what limits apply.

  • Named purposes only. Our staff access vessel data only to: provide support that a vessel has asked for; investigate, diagnose and fix a fault, error or data problem; keep the Service secure and investigate a suspected security incident or misuse; and meet a legal obligation. We do not access vessel data for any other purpose.
  • Least privilege. Access is limited to the people who need it for the task in hand, and to the data needed for that task. Administrative and infrastructure access is held by a small number of named individuals and is reviewed when a person's role changes or their engagement ends.
  • Confidentiality. Everyone we authorise to access vessel data is bound by a written confidentiality obligation that survives the end of their engagement with us.
  • Recorded. Actions taken through the admin interface are written to the vessel's audit trail, which vessel administrators can inspect. Direct administrative access to our servers and databases is restricted to authorised personnel and is recorded in our infrastructure access logs.
  • We tell you. Where we access an identifiable individual's records in order to investigate a fault, we will normally tell the vessel administrator what we accessed and why. We may not be able to do so where telling you would prejudice an active security investigation, or where we are prohibited by law.
  • Not for our own purposes. We do not use vessel data to build profiles of individuals, to market to your crew or visitors, or to inform any commercial dealing concerning your vessel. The only use we make of it beyond the purposes above is the aggregated and anonymised statistics described below.

Aggregated and anonymised statistics

We use aggregated and anonymised information about how the Service is used in order to run, secure and improve it — for example, how long an import takes, how many vessels use a given feature, or the typical size of a crew list so that screens perform properly at real scale.

Before information is used for this purpose it is aggregated across customers and stripped of anything that identifies a vessel, a person, or an individual record, so that it is no longer personal data and cannot reasonably be used to re-identify anyone. We do not publish, disclose or otherwise use a named vessel's figures, or figures attributable to an identifiable vessel, without that vessel operator's prior written agreement.

6. AI Features and Your Data

Some features of the Service use artificial intelligence — for example, reading a guest list, crew list or stores list that an administrator imports, turning a scanned muster list or checklist document into an editable one, and (where available) answering questions in the in-app help assistant. This section explains exactly what those features do with your data.

  • AI runs only when you choose to use it. AI features process only the content an administrator chooses to run through them, at the moment they use the feature. Nothing on your vessel — visitor records, crew details, documents — is sent to an AI system automatically or in the background.
  • Visitor check-in does not use AI. Visitor photographs and identity documents captured at check-in are not processed by any AI provider. Label reading for deliveries happens on the device (see Section 1).
  • Who processes it: AI processing is performed by Anthropic, the provider of the Claude models, acting as a Data Processor on our behalf under its commercial terms.
  • Not used to train AI. Data submitted through these features is not used by Anthropic to train its AI models.
  • Retention by the AI provider: Anthropic retains inputs for a limited period for trust and safety purposes and then deletes them; it does not store your data for other uses.
  • Our copy of imported files: A file run through an import feature is kept in our own AWS storage for up to six months and is then deleted automatically. We use these copies to investigate failed or incorrect imports and to develop and improve the import features of the Service. They are encrypted at rest, accessible only to The Muster App Ltd, never shared with anyone outside the organisation, never sold, and never used to train AI models.
  • A person stays in control. Import features propose a result that an administrator reviews before anything is saved to vessel records. The help assistant can only suggest changes; an administrator confirms before anything is applied.

If you have questions about AI features and your data, contact us at support@themusterapp.com.

7. Data Sharing

This section is about disclosure outside our organisation. Access to vessel data by our own staff is described separately in Section 5 (Access by our staff).

We do not sell personal data. We do not use personal data for advertising. We may share data with:

  • Vessel Operators: The vessel that collected your information has full access to their own data. For Muster Mate users, your vessel can see the same information about you as appears on their crew board.
  • Hosting Provider (AWS): Crew, visitor and guest data is stored and processed on Amazon Web Services infrastructure in the London region (eu-west-2). AWS acts as a Data Processor on our behalf.
  • Push Notification Providers: Apple Push Notification service (APNs) on iOS devices and Firebase Cloud Messaging (FCM) on Android devices are used solely to deliver notifications to your device. Notification payloads do not contain sensitive personal data.
  • Email Provider: Amazon Simple Email Service (SES) is used to send password reset emails, agreement copies, and product update emails. SES sends from the same London region.
  • Payments (Stripe): Card details are handled by Stripe and never reach our servers. We hold a customer reference and the subscription status, not a card number.
  • Voice calls (Twilio): When a fire, DPA or medical call is placed from the iPad, Twilio carries it. Twilio receives the number being dialled in order to connect the call.
  • AI Provider (Anthropic): When an administrator uses an AI feature, the content they provide is processed by Anthropic as described in Section 6. Anthropic acts as a Data Processor.
  • Legal Requirements: When required by law, court order, or to protect safety.

8. Your Rights

Depending on your location, you may have rights to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Receive your data in a portable format
  • Object: Object to processing based on legitimate interests

To exercise these rights, contact the vessel operator who collected your information, or contact us at support@themusterapp.com.

9. International Transfers

Your records live in the United Kingdom. Crew, visitor and guest data, uploaded documents, photographs and signed agreements are stored and processed in AWS’s London region, and our email is sent from the same region.

Four things necessarily leave it. Push notifications are delivered through Apple’s and Google’s global networks; card payments are handled by Stripe; calls placed from the iPad are carried by Twilio; and when an administrator chooses to use an AI feature, that content is processed by Anthropic. Each is a Data Processor operating under its own safeguards, and we send them the minimum needed to do the job — a push payload, for example, carries no sensitive personal data.

10. Children's Privacy

The Service is not intended for use by children under 13, and Muster Mate is rated 13+ on the App Store and Google Play. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has provided us with personal data, please contact us at support@themusterapp.com and we will delete it promptly.

11. Device Permissions Used by Muster Mate

Muster Mate requests the following permissions on your device. You may grant or deny each permission, and you can revoke them at any time in your device's system settings.

  • Camera — used only when you choose to take a photo of a delivery package. Photos are uploaded to your vessel's records. The camera is never accessed in the background.
  • Photos / Photo Library — used only when you choose a profile photo or add an existing photo to a delivery record.
  • Push Notifications — used to alert you to muster activations, abandon ship drills, deliveries assigned to you, and other vessel-initiated notifications. You can disable notifications in your device settings at any time.
  • Internet — used to communicate with our servers (HTTPS only).

Muster Mate does not request access to your contacts, location, microphone, calendar, SMS, call logs, or any other sensitive permissions.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify vessel operators of significant changes.

13. Contact Us

For questions about this Privacy Policy:

The Muster App Ltd
support@themusterapp.com

For Vessel Operators

As a vessel operator using the Service, you are the Data Controller for visitor and crew data collected through the Service. We act as a Data Processor on your behalf.

You are responsible for:

  • Informing visitors that their data is being collected
  • Responding to data subject requests from visitors
  • Configuring appropriate retention periods
  • Ensuring lawful basis for processing

Our Data Processing Agreement sets out that relationship in full: the instructions we act on, our security and confidentiality obligations, our sub-processors, breach notification, and your audit rights. It forms part of the Terms of Service and applies automatically; you do not need to request it. If your procurement process requires a countersigned copy, or a copy on your own paper, email support@themusterapp.com and we will provide one.