Security & your data
theONE Vessel Command Center · JEMS Marine, LLC
A boat’s record holds things that matter: who is aboard, their health notes, where she has been, her papers. This page says, in plain words, how theONE looks after them — and where the limits are. The full detail of what we hold is in our Privacy Policy; where the two touch, they say the same thing.
If you never sign in
theONE works with no account. Until you sign in, your boat’s record lives on your iPhone and nowhere else: we have no copy of it, and no profile of you. It sits in the app’s own storage on the device and in your iPhone’s backup (iCloud Backup or an encrypted local backup, whichever you use), which is Apple’s and under your control. The few things that do leave the phone without an account — mainly a position sent to NOAA and the other weather and chart services — are listed in section 4 of the Privacy Policy, and they carry nothing about you.
On the phone itself, you can lock theONE behind Face ID or Touch ID in Menu (☰) → Settings → Privacy & Lock. Boat IT passwords are kept in the iOS Keychain on that device only and are never sent to our server. Hide passwords until Face ID, on the same page, is on unless you turn it off: each password opens only after Face ID, Touch ID or the phone’s passcode.
How signing in works
Signing in is optional. It is what lets a second device of yours, and your crew, reach the same boat.
- Your password is never stored. If you set one, we keep only a one-way hash of it (salted Argon2id, keyed with a secret held apart from the database), which can check a password but cannot be turned back into one. When you choose a password we check it against passwords known from public breaches using the Have I Been Pwned service; only the first five characters of the password’s SHA-1 hash are sent, never the password or its full hash.
- Or a link the app asks us to email you. Instead of a password, the app can have us email you a sign-in link. It works once, for fifteen minutes, and only on the phone or iPad that asked for it.
- On theonevcc.com, a code instead. Signing in on the web without a password, you ask for a six-digit code and type it into the page that asked for it. A code works once, for ten minutes, only in the browser that asked for it, and five wrong guesses end it.
- Sign-in mail only goes to real accounts. We only ever send sign-in mail to an address that already has an account. Anyone else gets exactly the same answer on screen, so the sign-in page cannot be used to find out whether someone has an account with us.
- Guessing gets slow, fast. After three wrong passwords, theONE makes you wait 10 minutes. Three more, and the wait is 30 minutes; three more, an hour. That is counted for the account and, separately, for the network the tries come from.
- A second step on a new device. The right password on a phone, iPad or browser your account has not used before is not enough on its own: we email a six-digit code to your account’s address, and you type it in on that device. A stolen password alone signs nobody in on a new device.
- We tell you about new sign-ins. When your account is signed in on a new device, we email you naming the device. We also email you when your password is reset. If it was not you, open Menu (☰) → Settings → Account → Sign out of every device, then change your password.
- Web sessions are short. Signed in on theonevcc.com, you are signed out after 12 hours without use, and after 7 days at most.
Sign out of every device, in the app’s Account screen, ends every session your account has, everywhere, at once.
Where your boat’s record lives
Once your boat is in the cloud, her changes travel through our own server, at api.theonevcc.com, which runs on Cloudflare. It is built so that boats are kept apart from one another:
- Each boat is its own database. Every vessel’s record is kept in a separate database of its own, and a request of yours reaches a boat’s database only after our server has checked that you are a member of that boat. One boat’s record is never stored alongside another’s.
- Accounts are kept separately — your email address, your password’s hash and your sessions — apart from any boat’s record.
- Files are opened only through our server. Document scans, receipts and photos are handed out by our server, after it has checked that you are allowed to see that file. Asking for one you are not allowed to see gets the same answer as asking for one that does not exist.
- Every phone keeps its own copy aboard. The app is not a window onto a server: each device holds what its role allows, so the boat still works with no signal.
Encryption
- On the way. Everything between the app, this website and our server travels over HTTPS (TLS). theonevcc.com also tells browsers to use nothing but HTTPS when they come back.
- Where it is stored, with our own keys, a boat at a time. Our server encrypts the most personal parts of a boat’s record before it stores them (AES-256-GCM), with a key that belongs to that boat alone. Those keys come from a master key that is kept as a secret on our server, apart from the databases and the file storage — so in a copy of the stored records or files, those parts cannot be read. This covers:
- crew and guest cards — names, health notes, contact details, emergency contacts, licences and the card photo;
- jots and notepad notes, with their attachments: photos, voice-memo text and captions;
- where the boat has been — recorded tracks, legs’ places, waypoints and routes, logbook entries, man-overboard records, float plans and their contacts;
- trip invitations, including a guest’s name and contact details;
- every file kept with a record — document scans, receipts and photos.
- New and old records. These are sealed as they are written. Records and files stored before this was switched on are being sealed by a background job on our server, a batch at a time.
- What that does not cover. The rest of the record — for example maintenance, work orders, the boat’s specifications, and the details of documents and bills (their files are covered) — your account details, and the labels our server needs to route and check a change (which boat, which record, when, its status) are not encrypted with our own keys; they are protected by the permission checks below. And our server has to unlock what it sends to the people allowed to see it: this protects stored copies, not what a person you have given access to can see.
Who on a boat can see what
Every boat has six ordered roles — owner, manager, captain, crew, vendor and guest — and what each one receives is decided on our server, not by hiding buttons on a phone. The owner holds every permission on the boat; everyone else has only what their role, and the owner’s choices, give them, and nobody can hand on a permission they do not hold themselves. The details are on Crew & access; the parts that matter most for privacy:
- Health notes and cards. A crew or guest card — health notes included — reaches the owner, captain and manager, and the person the card is about. Never anyone else.
- Money and papers. Documents, bills and what fuel costs reach the owner, captain and manager only. Crew receive the fuel log without the money.
- Vendors receive the boat’s name and the systems they have been given, with those systems’ service history — never a cost or a bill.
- Guests see the trip they were invited to, their own card and that trip’s messages to the crew, and cannot use the web version.
- When access ends — a date runs out, or someone is taken off the boat — the app removes that boat’s records from their device the next time it reaches our server.
The owner’s access log
Roles stop the wrong person seeing the wrong thing. The access log is for the other case: someone who does have access, using it in a way they should not. Signed in on theonevcc.com, a boat’s owner can see:
- whose device received a crew or guest card’s health notes (other than the person the card is about);
- who downloaded a document, a receipt, a card photo or a résumé;
- and on which device, with the date and time.
Only the owner can read it — it mostly records the captain’s and manager’s reading, so it would mean little if they could. Entries are kept for a year. It keeps no network (IP) addresses.
What we do not do
- We do not sell or rent your information.
- We do not use advertising networks or ad tracking, and the app contains no advertising SDK.
- We do not build a profile of you. If you never sign in, no vessel data of yours is on any server of ours.
- Crash reporting and analytics are both off unless you turn them on in the app.
Deleting your account
You can delete your account yourself in the app: Menu (☰) → Settings → Account → Delete my account. Or write to ops@jems-marine.com and we will do it.
Deleting an account removes the identity — the account itself, its sign-in, its sessions, the devices it had signed in on, and its memberships. Records of work done on a vessel stay part of that vessel’s record, because a boat’s maintenance history must not develop holes when a person leaves it. If you owned a boat, we keep only what lets us give her back to you if you return; Delete your account says exactly what goes, what stays and for how long. Deleting the app removes its data from your device, apart from what iOS keeps in its Keychain — a kept sign-in and your Boat IT passwords — which theONE clears the first time it opens if it is installed on that device again; check your device backups if you want it gone from those too.
Reporting a security problem
If you think you have found a weakness in theONE, this website or our server, please write to ops@jems-marine.com. A person reads every message. Tell us what you found, how to see it for ourselves, and how to reach you. Please do not read, change or delete anyone else’s data while you look, or disrupt the service for other people; test only against your own account and your own boat. The same contact is published, in the standard form, at theonevcc.com/.well-known/security.txt.
If something goes wrong
If your information is ever involved in a security incident, we will tell the people affected, as the law requires, in plain words: what happened, what of theirs was involved, what we have done and what they should do.
Honest about the edges
- Your phone is part of the lock. Anyone who has your unlocked iPhone, or knows its passcode, can open what the phone can open. A passcode, and theONE’s own lock, are worth having.
- So is your email. Sign-in codes, links and password-reset codes go to your inbox, so whoever controls that inbox can get into your account. Protect it with a strong password and two-step sign-in.
- Access you give is access. A captain, manager or crew member can see what their role allows, on their own device. The roles keep the wrong person away from the wrong record; they cannot stop someone misusing what they were trusted with.
- No system is free of mistakes. We would rather tell you how this is built than promise it cannot fail. If you find something we got wrong, tell us.