Skip to content
All products

Privacy

Your data should have a clear chart.

This policy explains what Perigee receives, why it is needed, where it goes, and the controls available to you. It applies to Perigee's website, Android and iOS apps, accounts, email, REST API, hosted MCP service, and Perigee Tides & Conditions ChatGPT app and plugin.

Effective July 23, 2026

Who we are

Perigee is operated by Cardin LLC and published under the Cardin Labs brand. In this policy, “Perigee,” “Cardin,” “we,” and “us” refer to Cardin LLC. Questions and privacy requests can be sent to ryandcardin@gmail.com.

NOAA, the National Weather Service (NWS), Stripe, Apple, Google, Firebase, Vercel, Resend, OpenFreeMap, and other linked services have their own privacy practices. This policy covers Perigee's handling of information, not those organizations' independent services.

Information we collect

Information you provide

  • Account information: email address, display name, profile image or selected Perigee avatar, authentication provider, and the Firebase user identifier associated with the account.
  • Preferences and coastal plans: saved and home stations, ordering, activity choices, outings, alert rules, email and push preferences, selected Weekly Tide station, and other settings you choose to save or synchronize.
  • Developer information: API-key names and prefixes, OAuth approvals, request counts, endpoint or tool names, timestamps, and related credential-management records. A newly created API secret is shown once; Perigee stores a one-way hash rather than the raw key.
  • Communications and diagnostic reports: the contents and metadata of support, correction, security, and other messages you send to us. The in-product problem reporter stores your description, a standardized page route and page family, deployment release, occurrence time, and optional request, NOAA station, or opaque workspace identifier. It does not intentionally attach your email, user ID, IP address, cookies, browser history, console output, or credentials.
  • Billing details: product, plan, billing interval, subscription status, renewal or expiration timing, and provider identifiers needed to grant and reconcile access. Stripe hosts web checkout and the billing portal. Apple or Google hosts in-app purchase and subscription management. For Google Play, Perigee sends a purchase token to Google for verification and stores one-way purchase and order hashes, an obfuscated account binding, product and base-plan details, and lifecycle status. Perigee does not receive your full payment-card number from Stripe, Apple, or Google.

Information collected when you use Perigee

  • Request and security data: IP address and request metadata may be processed transiently for delivery, abuse prevention, rate limiting, diagnostics, and security. Hosting providers may keep their own infrastructure logs under their terms.
  • Product analytics: Perigee records privacy-limited events such as page family, anonymous and session identifiers, referral category, campaign tags, and completion of key product steps. The event contract rejects email addresses, exact messages, secrets, authorization values, and raw IP addresses. Perigee also uses Vercel Web Analytics for aggregate page and device statistics.
  • Mobile analytics and diagnostics: production mobile apps use Firebase Analytics, Crashlytics, and Performance Monitoring. These services can receive app interactions, pseudonymous app or installation identifiers, device model, operating-system and app version, crash stack traces, performance and network timing, and related technical metadata. Where Perigee associates app events with signed-in use, it uses a pseudonymous Firebase account identifier; app events are not intended to include an email address, name, password, precise location, purchase token, or advertising identifier. Advertising-ID collection and ad personalization signals are disabled in the Android app.
  • Mobile push delivery: if you enable notifications, Perigee and Firebase Cloud Messaging process a provider registration token, a random app-installation identifier, platform, app and environment identifiers, selected notification topics, timestamps, and delivery or revocation status. Perigee uses this information only to route requested alerts and remove invalid or disconnected devices.
  • API and MCP usage: credential or anonymous rate-limit bucket, surface, operation name, request count, and timing. Request parameters and provider responses may pass through Perigee to answer the request, but API secrets are not intentionally written into usage events.
  • Browser storage: local or session storage can hold authentication state, saved-station state, anonymous analytics identifiers, attribution, and interface preferences needed to operate the requested features.
  • App storage and widgets: the mobile apps store interface preferences, notification consent, a random installation identifier, and limited recent tide or widget state on the device. Android app backups are disabled. Clearing app data or uninstalling removes this local state but does not by itself delete the Perigee account or cancel an app-store subscription.

Perigee Tides & Conditions in ChatGPT

Perigee Tides & Conditions is Perigee's ChatGPT app and plugin. It requires no Perigee account and does not accept a Perigee password, API key, access token, or other credential.

Inputs and request data

  • Station lookup: the public NOAA tide-station name or distinctive leading portion, seven-digit station ID, or two-letter state code that ChatGPT selects for the request, plus a requested result limit from one through eight.
  • Outing read: the selected public NOAA station ID, activity, station-local calendar date, and station-local time.
  • Optional coarse location: ChatGPT may send a city, region, country, time zone, or approximate latitude and longitude to accompany a request. Perigee uses only the city, region, and approximate coordinates in memory to rank public stations for the current lookup; it does not use a supplied country or time zone for this purpose. The context is not sent to NOAA or NWS, written to Perigee storage or analytics, or returned in the tool result. ChatGPT may provide IP-derived approximate location independently of device location permission. Where a location control is available, you can disable it. Supplying a public NOAA station name, station ID, or state code prevents Perigee from using coarse location metadata to rank stations. Do not enter a street address, coordinates, or personal information in a station field.
  • Delivery and security data: the request IP address, HTTP headers, JSON-RPC method or tool name, and timing are processed transiently to deliver and secure the request and enforce the anonymous rate limit.

Tool output returned to OpenAI and ChatGPT

A station lookup returns the resolution method, match count, guidance, and a list of public stations. Each station can include its NOAA station ID, name, state, and prediction class. An outing read can return all of the following fields, including their nested values:

  • the requested station-local instant and time zone; station ID, name, and state; and activity ID and label;
  • the planning state, confidence, headline, summary, cautions, and missing inputs;
  • a recommended window with its label, value, detail, start time, and end time;
  • reasons with a label, value, detail, and positive, caution, or missing tone;
  • sources with their label, provider, kind, freshness category, and detail; and
  • a disclaimer and a contextual Perigee website link. That link repeats the station ID, activity, date, and time in its query string and adds ChatGPT referral source, medium, and campaign tags.

Perigee does not request or receive your full ChatGPT conversation. Its structured and text tool output does not include the optional coarse location, coordinates, Perigee account identifiers, credentials, session IDs, trace IDs, application request IDs, rate-limit or quota debugging data, server logs, or raw NOAA or NWS provider payloads. Standard transport metadata is separate from the tool output: JSON-RPC echoes the correlation ID supplied by its caller, and Vercel can add hosting and routing headers such as x-vercel-id, x-matched-path, or x-nextjs-rewritten-path. OpenAI can receive that transport metadata with the response. Perigee does not use ChatGPT app inputs or outputs for advertising, ad targeting, sale, or cross-context behavioral profiling. The ChatGPT app displays no advertising and does not offer products or subscriptions for sale inside ChatGPT.

Purposes and recipients

  • OpenAI and ChatGPT: ChatGPT selects and sends the tool input, receives the output categories listed above, and may display them in the conversation and app interface. OpenAI controls ChatGPT account data, app connections, conversation history, and retention under the OpenAI Privacy Policy.
  • NOAA and the National Weather Service: Perigee sends the public station ID, coordinates derived from the public NOAA station record, requested date or time, and necessary public-data product parameters to retrieve tides, observations, or forecasts. These providers do not receive the optional coarse location supplied by ChatGPT.
  • Vercel: Vercel hosts and executes the app endpoint. It transiently processes the complete HTTP and JSON-RPC request, tool input, optional metadata supplied by ChatGPT, tool output, and ordinary network, security, routing, and runtime data needed to deliver the response.
  • Upstash Redis or Firebase/Firestore: when Upstash Redis is configured, it processes a pseudonymous SHA-256-derived minute-bucket key, request count, and the limit and expiry values needed for rate limiting. Otherwise, the Firebase/Firestore fallback processes a pseudonymous SHA-256-derived bucket key, window, request count, limit, reset time, update time, and expiration time. Neither counter includes tool input, tool output, a full IP address, or an anonymous monthly usage history.

Perigee uses these data only to resolve a public station, create and render the requested conditions read, generate the contextual website link, deliver and secure the request, prevent abuse, and enforce the anonymous rate limit.

Retention

Perigee processes tool inputs and outputs in memory for the request and does not write them to Perigee product analytics, application request logs, or account storage. An Upstash Redis minute counter, when configured, expires within two minutes. Perigee stops using a Firebase/Firestore fallback counter when its expiration time arrives, one hour after the minute window closes. Firebase states that TTL data is typically deleted within 24 hours after its expiration time, though managed deletion is not instantaneous. No anonymous monthly counter is created for this app.

Vercel may independently retain infrastructure and runtime logs under its terms. Vercel's published runtime-log retention is one hour on Hobby, one day on Pro, three days on Enterprise, or 30 days with Observability Plus, depending on the hosting plan and add-ons. Therefore, runtime-log retention under the currently published options is no more than 30 days. OpenAI separately controls retention of ChatGPT conversation and app history under your OpenAI settings and its policies.

Your controls

  • Do not invoke the app, or remove or disconnect it in ChatGPT, to stop future tool requests.
  • Disable optional device location where that control is available. Supply a public NOAA station name, station ID, or state code to prevent Perigee from using coarse location metadata for station ranking.
  • Manage or delete ChatGPT conversation history and app connections through OpenAI's available controls.
  • Do not open the contextual Perigee link if you do not want to visit the website. Opening it is a separate website interaction: the query fields described above, ordinary browser request data, and referral tags reach Perigee and Vercel. On that ChatGPT-referral page, website analytics can record anonymous or session identifiers, route, referrer, campaign tags, activity category, aggregate result band and freshness, and an elapsed-time bucket. They do not record the station ID, coordinates, requested date, requested time, or full result, and the referral page does not save the full result in browser storage. The other website retention and privacy controls described elsewhere in this policy still apply.
  • Contact ryandcardin@gmail.com with a privacy request. Because the app requires no Perigee account and Perigee does not retain tool inputs or outputs, Perigee generally has no account-linked ChatGPT tool history to export, correct, or delete.

This ChatGPT-app section covers Perigee's handling of the tool request. It does not replace OpenAI's disclosures or the separate website practices that apply after you choose to leave ChatGPT.

Location

Perigee asks the browser for precise location only when a web feature such as “near me” needs it and you grant permission. You can deny permission and search manually. The current Android and iOS apps do not request device location; their nearby and map context starts from your saved home station or a station you select. Coordinates you enter, approve, or select can be sent to NOAA or NWS services to find stations or forecasts and to OpenFreeMap to load the requested map view. Perigee does not use location for advertising.

How we use information

We use information to:

  • provide, personalize, secure, and troubleshoot Perigee;
  • authenticate accounts and preserve saved stations, preferences, alerts, email choices, billing state, API keys, and OAuth grants;
  • process subscriptions, taxes, payment status, cancellations, and account access through Stripe, Apple, or Google Play, depending on where you purchased;
  • send the Weekly Tide, requested alerts, service messages, and replies to communications, subject to your choices;
  • enforce quotas, investigate abuse, protect users and systems, and comply with law;
  • understand aggregate use, diagnose failures, and improve product and decision quality; and
  • establish, exercise, or defend legal claims when necessary.

Depending on where you live, these activities may rely on performing a contract with you, your consent, compliance with law, or legitimate interests such as operating and protecting the service. You can withdraw consent for optional email or browser location without affecting prior processing.

When information is shared

Perigee may share information in these limited circumstances:

  • Service providers: Google Firebase Authentication, Firestore, Analytics, Crashlytics, Performance Monitoring, App Check, Cloud Messaging, and Google Cloud for authentication, application data, integrity checks, mobile diagnostics, and push delivery; Upstash Redis, when configured, for rate-limit counters; Vercel for hosting and web analytics; Stripe for web checkout and subscription management; Apple and Google Play for app distribution, purchases, and subscription lifecycle; Resend for requested email delivery; and OpenFreeMap and its infrastructure provider for map styles and tiles. They process data under their own terms and applicable agreements with Cardin LLC.
  • Data providers:station identifiers, dates, products, or coordinates can be sent to NOAA and NWS endpoints to answer your request. When a map is visible, the selected map area and ordinary network metadata are sent to OpenFreeMap's tile infrastructure; the mobile apps do not send device location to choose that area. Do not place personal information in free-form developer inputs when it is not needed.
  • Legal and safety: when reasonably necessary to comply with law or valid legal process; protect rights, safety, and systems; investigate fraud or abuse; or enforce our terms.
  • Business change: information may transfer as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of relevant assets, subject to applicable law.
  • At your direction: when you connect, share, export, or otherwise direct Perigee to interact with another service or person.

Provider documentation is available from Firebase, Vercel Web Analytics, Stripe, and Resend, and OpenFreeMap. Those links are provided for transparency; their policies can change independently of this one.

Cookies, storage, and analytics

Perigee uses first-party browser storage and authentication mechanisms needed for sign-in, security, preferences, saved state, and privacy-safe product measurement. Vercel states that its Web Analytics product does not use third-party cookies and reports aggregate statistics. Perigee's own analytics identifiers are stored locally in your browser and are not intended to reveal your real-world identity.

You can clear browser storage, block analytics, or use browser privacy controls. Doing so can reset preferences or anonymous attribution and may prevent sign-in or other requested features from working correctly.

Mobile apps use operating-system storage and Firebase services rather than browser cookies. You can deny or later disable notification permission, disconnect native push in Perigee settings, clear local app data, or uninstall the app. Those actions can remove local identifiers or stop future delivery, but server-side account, purchase, and safety records remain subject to the retention and deletion rules below.

When you submit an address with the displayed consent control, enable the Weekly Tide or an alert, or make the same choice in account settings, you ask Cardin LLC to send that category of email to the address provided. Frequency depends on the feature: Weekly Tide is intended as a weekly brief, while an enabled condition alert is event-driven and may send nothing when its rule is not met or required data is unavailable. Consent to optional email is not a condition of purchasing a subscription.

Withdraw optional email consent at any time through the available account setting or the unsubscribe link in the message. A one-click unsubscribe can be processed without signing in. Cardin LLC may still send necessary account, authentication, billing, security, legal, or service messages that are not promotional subscriptions.

SMS is optional and uses a separate verified-number flow. Before Perigee sends account or operational texts, you must affirm the displayed recurring-message disclosure and enter a code sent to the number. Message frequency varies, and message and data rates may apply. Reply STOP to opt out or HELP for help. Consent is not a condition of purchase. A signed START message can restore consent. Trip Watch operators may also provide guest numbers with a recorded consent timestamp; that operator is responsible for collecting lawful consent and Perigee processes the communication on the operator's instruction.

Retention

Retention depends on the record and why it exists. Account settings and saved state generally remain while the account is active. Email opt-in records remain until unsubscribe or deletion. Verified phone destinations remain with the account until removal or deletion. Hashed email and phone suppression data may remain after account deletion as needed to honor an opt-out and prevent another send. Product analytics are configured with a 180-day expiration field, in-product diagnostic bug reports with a 90-day expiration field, and detailed API-key usage events with an expiration field of up to 90 days; the product only displays the history window included with the current plan. Aggregate counters and operational records may remain longer.

Active mobile push registrations remain until you disconnect the device, the provider reports the token invalid, or the account is deleted. Mobile analytics, crash, and performance records follow configured Firebase retention settings and Google's applicable provider terms. App-store purchase ownership, lifecycle, and notification records remain while needed to verify access, resolve refunds or disputes, prevent duplicate claims, meet accounting or legal obligations, or complete account deletion. Perigee stores Google Play purchase and order hashes rather than the raw values in its purchase-ownership records.

Billing, security, fraud-prevention, legal, backup, and transaction records may be retained as reasonably needed for those purposes. App-managed billing-change idempotency records expire after 400 days. A pseudonymous Firebase-UID claim used to enforce the one-time Trip Watch trial expires after seven years, is deleted with the account, and has its workspace link removed when that workspace is deleted. An expiration field requires the relevant storage lifecycle policy to be enabled; deletion from backups and service-provider systems may take additional time.

Your choices and requests

  • Change saved stations, profile details, alerts, and available email settings from the account dashboard.
  • Use the unsubscribe link in a Weekly Tide or alert email. Transactional account, security, and billing messages may still be sent when needed.
  • Revoke browser location permission in your device or browser settings.
  • Disable mobile notifications in Perigee or operating-system settings, and manage or cancel an Apple App Store or Google Play subscription in the store where it was purchased.
  • Revoke developer credentials from the dashboard.
  • Download a privacy-safe JSON export or schedule account deletion from the privacy controls in your authenticated dashboard. Account deletion has a seven-day hold and can be cancelled before processing begins. See the account deletion instructions for the web request path and app-store subscription steps.
  • Organization owners can delete a workspace after resolving its access and billing responsibilities. Perigee makes it inaccessible immediately, then cancels active subscriptions, removes tenant data and membership indexes, deletes public guest pages and queued communications, and pseudonymizes retained audit references after the seven-day safety hold.
  • Request correction, access help, objection, restriction, or another supported privacy action by emailing ryandcardin@gmail.com. Available rights depend on your location and legal exceptions. We may need to verify account ownership before acting.

Automated deletion excludes or pseudonymizes records that Cardin LLC or its processors must retain for security, fraud prevention, tax, accounting, charge disputes, legal compliance, or suppression of a revoked communication channel. Stripe may retain invoices, charges, and payment events under its legal obligations even after its reusable customer profile is deleted.

Security and international processing

Perigee uses safeguards described on the security page, but no internet service can guarantee absolute security. Cardin LLC and its providers may process information in the United States and other locations where they operate. Those locations may have different data-protection laws than your home.

Children

Perigee is a general-audience coastal planning and developer service, not a service directed to children under 13. We do not knowingly collect personal information from a child under 13. A parent or guardian who believes a child submitted such information should contact us.

Changes and contact

We may revise this policy as Perigee changes. The effective date above identifies the current version. Material changes will be presented in a reasonable way through the service or an appropriate account channel when required by law.

Contact: Cardin LLC / Cardin Labs, ryandcardin@gmail.com. Please write “Privacy request” in the subject and do not include passwords, API keys, payment-card numbers, or other unnecessary secrets.