← Back to theONE

Security & your data

theONE Vessel Command Center · JEMS Marine, LLC

A boat’s record holds things that matter: who is aboard, their health notes, where she has been, her papers. This page says, in plain words, how theONE looks after them — and where the limits are. The full detail of what we hold is in our Privacy Policy; where the two touch, they say the same thing.

If you never sign in

theONE works with no account. Until you sign in, your boat’s record lives on your iPhone and nowhere else: we have no copy of it, and no profile of you. It sits in the app’s own storage on the device and in your iPhone’s backup (iCloud Backup or an encrypted local backup, whichever you use), which is Apple’s and under your control. The few things that do leave the phone without an account — mainly a position sent to NOAA and the other weather and chart services — are listed in section 4 of the Privacy Policy, and they carry nothing about you.

On the phone itself, you can lock theONE behind Face ID or Touch ID in Menu (☰) → Settings → Privacy & Lock. Boat IT passwords are kept in the iOS Keychain on that device only and are never sent to our server. Hide passwords until Face ID, on the same page, is on unless you turn it off: each password opens only after Face ID, Touch ID or the phone’s passcode.

How signing in works

Signing in is optional. It is what lets a second device of yours, and your crew, reach the same boat.

Sign out of every device, in the app’s Account screen, ends every session your account has, everywhere, at once.

Where your boat’s record lives

Once your boat is in the cloud, her changes travel through our own server, at api.theonevcc.com, which runs on Cloudflare. It is built so that boats are kept apart from one another:

Encryption

Who on a boat can see what

Every boat has six ordered roles — owner, manager, captain, crew, vendor and guest — and what each one receives is decided on our server, not by hiding buttons on a phone. The owner holds every permission on the boat; everyone else has only what their role, and the owner’s choices, give them, and nobody can hand on a permission they do not hold themselves. The details are on Crew & access; the parts that matter most for privacy:

The owner’s access log

Roles stop the wrong person seeing the wrong thing. The access log is for the other case: someone who does have access, using it in a way they should not. Signed in on theonevcc.com, a boat’s owner can see:

Only the owner can read it — it mostly records the captain’s and manager’s reading, so it would mean little if they could. Entries are kept for a year. It keeps no network (IP) addresses.

What we do not do

Deleting your account

You can delete your account yourself in the app: Menu (☰) → Settings → Account → Delete my account. Or write to ops@jems-marine.com and we will do it.

Deleting an account removes the identity — the account itself, its sign-in, its sessions, the devices it had signed in on, and its memberships. Records of work done on a vessel stay part of that vessel’s record, because a boat’s maintenance history must not develop holes when a person leaves it. If you owned a boat, we keep only what lets us give her back to you if you return; Delete your account says exactly what goes, what stays and for how long. Deleting the app removes its data from your device, apart from what iOS keeps in its Keychain — a kept sign-in and your Boat IT passwords — which theONE clears the first time it opens if it is installed on that device again; check your device backups if you want it gone from those too.

Reporting a security problem

If you think you have found a weakness in theONE, this website or our server, please write to ops@jems-marine.com. A person reads every message. Tell us what you found, how to see it for ourselves, and how to reach you. Please do not read, change or delete anyone else’s data while you look, or disrupt the service for other people; test only against your own account and your own boat. The same contact is published, in the standard form, at theonevcc.com/.well-known/security.txt.

If something goes wrong

If your information is ever involved in a security incident, we will tell the people affected, as the law requires, in plain words: what happened, what of theirs was involved, what we have done and what they should do.

Honest about the edges

The legal part

Privacy Policy · Terms of Service · Support