Your data

Last updated 22 September 2026. Founding-period version — a legally reviewed version replaces this before public launch.

Crew share tickets, passports and medical certificates with us; vessels share who they are hiring. This page says exactly where that lives, who can see it and what happens to it — in more detail than the privacy notice, and in plain words.

1. Where it is stored

Profile and briefs
A managed Postgres database hosted by Supabase in the EU (Ireland). Encrypted at rest; all connections encrypted in transit.
Documents
A private storage bucket in the same EU region. Files are never public: every upload and every view goes through a signed link that is valid for minutes, issued only to the person uploading or to a signed-in member of the Laiva team. Accepted: PDF, JPEG, PNG, WebP, up to 20 MB each.
Conversations
Every exchange with Finn and Isla is stored in the same database so the Laiva team can review what the agents said.
Email
Sent by Resend from the EU. We send transactional email only — your private link, introduction requests and introductions. No newsletters unless you ask.
WhatsApp
Isla runs on the WhatsApp Business platform through Twilio. Messages pass through Meta and Twilio to reach us; we store the text of the conversation, your number and the brief.
AI
The agents and the matching engine call Anthropic’s models. The model sees the conversation and, for matching, an anonymised profile summary. Anthropic does not train on this data. Documents are never sent to the model.
Hosting
The website and its server code run on Vercel. Vercel does not keep your data; it passes requests to the database.

2. Who can see what

You
Everything on your profile, your transcript and your documents — through your private link. Anyone with the link can open it, so treat it like a password: it is sent only to the email you gave, and you can ask us to issue a new one at any time.
Laiva team
Your full profile, documents and conversations, through a password-protected console, for verification and to run introductions. Private notes the team keeps on a profile stay in the console; they are never sent to a vessel or to the matching engine.
A vessel, before you say yes
An anonymised shortlist entry: first name, role, tickets, sea time, vessel range, rotation, availability, verification status and the reasons for the match. No surname, no contact details, no documents, no current vessel.
A vessel, after you both say yes
Your name and the contact details you gave (email and/or WhatsApp). Still no documents.
Your current vessel
Nothing. Discretion mode is on by default and hides your profile from your current vessel and its management company.
Anyone else
Nothing. There is no public profile, no directory, no search.

3. Documents and verification

Documents are used for one thing: confirming that what your profile says is true. The verification team checks a ticket against the issuing register where one exists, checks STCW and medical certificates for validity and expiry, and records the result as Pending review, Verified or Rejected on your profile. For medical certificates we record validity and expiry only. Documents are never watermarked, forwarded or shown to vessels, because they never leave the console.

You can remove a document yourself from the documents view while it is pending review; removing it deletes the file. Once a document has been checked it stays on file as the record of what was verified — ask us at privacy@laiva.io and we delete it along with the rest of your profile.

4. Getting a copy, correcting or deleting

Tell Finn in your chat, or write to privacy@laiva.io, and we will send you a copy of everything we hold, correct anything wrong, or delete your profile, documents and transcript within 30 days. Where you have already been introduced to a vessel we keep the minimum record of that introduction — who, when, and to which brief — for the period in the privacy notice, to honour the placement agreement with the vessel.

5. What we do not do

We do not sell data. We do not share it with advertisers. We do not train AI models on your profile or documents. We do not post profiles anywhere. We do not contact your references or your current vessel without telling you first.

6. Incidents

If we ever discover that your data has been accessed without authorisation we will tell you directly and without undue delay, and notify the relevant supervisory authority within 72 hours as the law requires.

Questions or requests about your data: privacy@laiva.io