Privacy Policy
Operated by CMARE LLC, trading as The Mess Room. Last updated 4 September 2026. This page is for information and is not legal advice.
Last updated: 4 September 2026
Effective date: 6 August 2026
1. Data Controller — Who We Are
The Mess Room is operated by CMARE LLC, a limited liability company formed under the laws of the State of Wyoming, United States, which trades globally as The Mess Room (collectively, 'The Mess Room', 'we', 'us', 'our'). CMARE LLC is the data controller with respect to personal data processed through The Mess Room mobile application and related services (the 'App').
For the purposes of Regulation (EU) 2016/679 (General Data Protection Regulation, 'GDPR') and the UK GDPR, to the extent either applies to the processing of personal data of individuals in the EEA or UK, CMARE LLC is the data controller. Privacy queries may be directed to the contacts set out in Section 17.
Contact: support@themessroom.net
Registered address: 30 N Gould St Ste R, Sheridan, WY 82801, United States
2. Scope and Application
This Privacy Policy applies worldwide to all users of the App, regardless of location. Where applicable law imposes additional obligations or grants additional rights beyond those set out in this Policy, those obligations and rights shall apply to the extent required by law.
This Policy covers:
- The Mess Room iOS and Android mobile application
- In-app features including Crew Chat, Maritime Assistant (including Guided Steps and Action Playbooks), Wellbeing Guide, Expert Chat, bookmarks, notes, and subscriptions.
- The website at themessroom.net and associated web pages
- All communications with our support team
By creating an account or using the App, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, you must not use the App.
3. Privacy by Design — Pseudonymous Architecture
The Mess Room is built on a pseudonymous-first architecture. An email address is required only for account recovery purposes and is not displayed to other users or used for marketing. Your display alias is automatically generated — no real name, passport number, or phone number is required This design is intentional: seafarers may face professional or personal risks in disclosing their identity when seeking welfare support or discussing employment conditions.
IMPORTANT — What pseudonymous means in practice: Your alias and uid are pseudonymous, not anonymous. We hold a pseudonymous user identifier (uid) linked to your alias. If you voluntarily disclose identifying information in messages, that pseudonymity may be compromised. We strongly recommend you do not share your real name, passport number, vessel name, or employer in Crew Chat or any message unless you are comfortable with that information being seen by other users.
4. Information We Collect and Process
4.1 Information You Provide Directly
- Pseudonymous user identifier (uid): generated on account creation; used for authentication, routing, and subscription management
- Alias (display name): generated on account creation; visible to other Crew Chat users.
- Account email: collected for account authentication and account recovery only; not displayed to other users and not used for marketing.
- Rank class, vessel type, nationality, and contract phase: optional onboarding data stored locally on your device; used to personalise content and for aggregated (non-identifying) experience analytics if analytics services are enabled
- Crew Chat messages (text): stored on our Firebase Firestore servers to enable delivery to other users; not end-to-end encrypted
- Expert Chat messages (text and audio): encrypted on your device before upload; servers store ciphertext, cryptographic nonces, session metadata, and encrypted audio blobs only — not plaintext content
- Support and welfare requests: submitted via Wellbeing flows, stored in Firebase under anonymous or pseudonymous reference for welfare follow-up
- Bookmarks, notes, and Guided Steps situation notes: stored exclusively on your device (SQLite / AsyncStorage); never transmitted to our servers
- Subscription tier: Basic or Premium; communicated by the relevant app store platform
We do not require and ask you not to submit: real legal name, home address, passport or national ID number, employer name, vessel name, or any other unnecessary personal identifiers in free-text fields.
4.2 Information Collected Automatically
- Device type, operating system version, and app version: used for debugging, security, and compatibility
- Network connectivity status: used for offline sync and message queue management
- Presence and activity signals (online status, last seen, typing indicators): used for Crew Chat user experience
- Read receipts (Crew Chat): indicate when messages were read
- Push notification tokens: to deliver in-app notifications if enabled
- Technical logs: minimal logs necessary to operate Firebase services; retained for security and abuse prevention
- Crash and error reports: if the App crashes or hits an unhandled error, we may write a diagnostic record to Firebase Firestore. A report may include the error message, a truncated stack trace, app version, device platform, a random local identifier, and a technical source label. Reports do not include your alias, email, uid, chat content, or other profile data. We use them only to find and fix bugs. This is our own Firestore logging — we do not use Firebase Crashlytics, Sentry, or advertising analytics.
We do not collect precise GPS location data. We do not use your data for advertising or behavioural tracking.
4.3 Device Permissions
- Microphone: required to record voice messages in Expert Chat (Premium feature); requested only when you initiate a voice message
- Internet / network access: required for all online features
- Local storage: required for offline rights content, bookmarks, and encrypted Expert Chat cache
You may deny permissions in your device settings; certain features will be unavailable if relevant permissions are denied.
4.4 Information We Do NOT Collect
- Payment card details, banking information, or billing addresses — all payment processing is handled exclusively by Apple App Store or Google Play
- Plaintext Expert Chat message content — our servers hold only encrypted ciphertext
- GPS location, accelerometer, camera, contacts, or call logs
- Cross-app tracking identifiers for advertising purposes
5. Legal Bases for Processing (GDPR / UK GDPR)
For users in the EEA and UK, we rely on the following legal bases under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b)): processing necessary to provide the App’s core features, including account management, Crew Chat, Expert Chat, and subscriptions
- Legitimate interests (Art. 6(1)(f)): security and fraud prevention, abuse moderation, service improvement, and pseudonymous analytics — where our interests do not override your fundamental rights
- Legal obligation (Art. 6(1)(c)): where processing is required to comply with applicable law, including responding to lawful law-enforcement or court requests
- Consent (Art. 6(1)(a)): for optional permissions (e.g. microphone) and, where applicable, for cookies or tracking technologies not strictly necessary for the service
Special category / health-related data (Art. 9 GDPR): Because Expert Chat message content is end-to-end encrypted on your device before upload and we do not hold the decryption keys, we do not process the plaintext content of Expert Chat messages and therefore do not process Expert Chat message content as special category data under Article 9 GDPR.
If you voluntarily include health or other special category information in non-encrypted channels (for example Crew Chat or support/welfare requests that are stored in readable form), that information may be processed on the basis of your explicit consent (Art. 9(2)(a)) and/or other applicable Art. 9 grounds where required by law. We strongly recommend that you do not share sensitive health information in Crew Chat.
For users outside the EEA/UK, processing is based on this Policy and applicable local law.
6. Purposes of Processing
- To create and manage your pseudonymous account
- To operate Crew Chat: store, route, and deliver messages between users; enforce community standards
- To operate Expert Chat: transmit encrypted payloads to the assigned expert; manage session metadata
- To deliver offline features: Maritime Assistant, Guided Steps, Wellbeing content, bookmarks
- To enforce subscription tiers and verify entitlement (Basic vs. Premium)
- To process anonymous welfare and support requests
- To diagnose crashes and improve App reliability
- To maintain security, detect and prevent abuse, fraud, and illegal activity
- To comply with legal obligations and respond to lawful government or court requests
- To communicate with you regarding your account, support requests, or material policy changes
- To improve the App using aggregated or anonymised data only
We do not sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes.
7. Crew Chat and Expert Chat — Critical Distinction
7.1 Crew Chat
- Messages are stored in readable (unencrypted) form on our Firebase Firestore servers
- Storage is necessary for delivery to recipients and for moderation in response to abuse reports
- Vault / disappearing messages (where enabled) auto-expire per the retention schedule in Section 9
- Other users see your alias, not your legal identity, unless you choose to share identifying content in a message
- Crew Chat messages may be reviewed by authorized staff for moderation, legal compliance, or safety purposes
7.2 Expert Chat (Premium)
- Messages are encrypted on your device using end-to-end encryption (E2EE) before upload
- Our servers store only: encrypted ciphertext, cryptographic nonces, session metadata (timestamps, session IDs, pseudonymous uid), and encrypted audio blobs
- Encryption keys are stored in your device's secure storage; we do not hold the keys and cannot read message content
- If you lose your device or uninstall the App without a backup, you may permanently lose access to your Expert Chat message history
- The expert sees only what you send in the encrypted channel — not your legal name, employer, vessel, or contract details unless you voluntarily disclose them
- Experts are independent licensed professionals subject to their own professional confidentiality obligations and may be required to breach confidentiality in circumstances required by applicable law (e.g. imminent risk of harm)
- Expert Chat is not an emergency service. In an emergency, follow your vessel’s / company’s emergency procedures and contact appropriate emergency services.
8. Third-Party Service Providers and Data Processors
We engage trusted third-party processors who handle personal data on our behalf under contractual data-protection obligations consistent with GDPR and applicable law:
- Google Firebase (Firestore, Storage, Authentication) — backend database, file storage, and optional authentication; data may be stored in the United States and other Google Cloud regions. Google LLC participates in the EU–U.S. Data Privacy Framework and provides Standard Contractual Clauses (SCCs) for international transfers.
- Apple Inc. (App Store, StoreKit, TestFlight) — subscription and payment processing; Apple handles all billing data. We receive only subscription status and tier.
- Google LLC (Google Play, billing) — subscription and payment processing on Android; Google handles all billing data. We receive only subscription status and tier.
- RevenueCat — subscription management; receives pseudonymous app user ID and purchase receipts from Apple App Store and Google Play for the purpose of managing subscription status and entitlements. RevenueCat does not receive payment card details.
We do not permit processors to use your data for their own commercial purposes beyond the services they provide to us. We do not engage in third-party advertising networks, data brokers, or behavioural advertising.
9. International Data Transfers
CMARE LLC is a Wyoming (U.S.) company. Data may be transferred between and processed in the United States, the European Union, and other countries where our processors operate.
For transfers of personal data from the EEA or UK to third countries (including the United States), we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, as implemented in our agreements with processors including Google
- The EU–U.S. Data Privacy Framework, where applicable and where our processors are certified
- The UK International Data Transfer Agreement (IDTA), for UK transfers where applicable
The relevant transfer safeguards (Standard Contractual Clauses) are available at:
- Google Firebase: https://firebase.google.com/terms/data-processing-terms
- Apple: https://www.apple.com/legal/enterprise/data-transfer-agreements
10. Data Retention
- Crew Chat messages: deleted from our servers 30 days after the message was sent (vault messages expire sooner per the applicable vault setting)
- Expert Chat ciphertext, session metadata, and encrypted audio blobs: deleted from our servers 30 days after the message was sent; local audio cache on device is auto-deleted within approximately 7 days
- Pseudonymous account profile (uid, alias, subscription tier): retained while your account is active; deleted or anonymised within 30 days of a valid account deletion request, subject to legal hold obligations
- Support requests (technical): retained for 30 days after the issue is marked resolved, then deleted.
- Abuse and moderation reports: retained for 12 months from the date of submission for moderation and safety purposes, regardless of account deletion, then permanently deleted
- Crash and error reports: stored in Firebase Firestore as technical diagnostics; they are not linked to your account profile
Where a legal hold applies (e.g. in response to a court order or regulatory investigation), data may be retained beyond the standard periods above and will be disclosed only as required by law.
11. Security Measures
We implement technical and organizational security measures including:
- Encryption of all data in transit via TLS 1.2 or higher
- End-to-end encryption for Expert Chat message content (E2EE design)
- Pseudonymous identifiers in place of legal names across all server-side records
- Firebase Security Rules restricting data access to authenticated users with valid session tokens
- Minimal data collection principle — we collect only what is necessary for stated purposes
- Access controls limiting staff access to personal data on a need-to-know basis
- Incident response procedures, including notification obligations under GDPR Art. 33–34 where applicable
No technical system is 100% secure. You are responsible for maintaining the security of your device and account. You should not share your device or alias with others if you wish to remain pseudonymous.
11a. Health Data and Expert Chat — Special Categories
Expert Chat messages are end-to-end encrypted on your device before transmission. Our servers store only encrypted ciphertext, cryptographic nonces, session metadata, and encrypted audio blobs — not plaintext message content. We do not hold the decryption keys and cannot read Expert Chat message content. Accordingly, we do not process the plaintext content of Expert Chat messages as health data or other special category data under Article 9 GDPR.
If you voluntarily disclose health information in Crew Chat or in support/welfare requests that are stored in readable form on our servers, such information may constitute special category data and will be handled as described in Section 5. We strongly recommend that you do not share sensitive health or medical information in Crew Chat.
Wellbeing content in the App consists of informational resources only. We do not collect, analyse, or infer a medical diagnosis from your use of Wellbeing features alone.
11b. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the competent supervisory authority in the relevant jurisdiction within 72 hours of becoming aware of the breach, as required by Article 33 GDPR
- Notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34 GDPR
- Document all breaches in our internal breach register, including those that do not require notification
Breach notifications will be provided via in-app notification, email (where available), or prominent notice on our website at themessroom.net. Given the pseudonymous nature of accounts, notification may be made via in-app alert linked to your uid where direct contact information is not held.
To report a suspected security vulnerability or data breach, contact: support@themessroom.net
11c. Government and Law Enforcement Requests
We may be required by law to disclose personal data in response to lawful requests by public authorities, courts, or law enforcement agencies. Our policy is:
- We will disclose only the minimum data required to comply with a specific, lawful legal obligation or binding court order
- We will scrutinize all requests for legal validity before complying
- Where legally permitted to do so, we will notify the affected user before complying with a disclosure request
- We will not voluntarily cooperate with government requests that exceed the scope of a specific legal obligation
- We maintain a record of all government disclosure requests received
Because Expert Chat content is end-to-end encrypted and we do not hold decryption keys, we are technically unable to provide plaintext Expert Chat content even if compelled to do so. We can only provide session metadata (timestamps, pseudonymous uid, session IDs).
11d. International Privacy Laws — Brazil and China
Brazil — LGPD
If you are located in Brazil, the Lei Geral de Protecao de Dados (LGPD, Law No. 13,709/2018) may apply to the processing of your personal data. We process data on the legal bases of contract performance, legitimate interest, and consent where required under the LGPD. You have rights of access, correction, deletion, portability, and information about third-party sharing. To exercise your rights under the LGPD, contact: support@themessroom.net
China — PIPL
If you are located in the People’s Republic of China, the Personal Information Protection Law (“PIPL”) may apply to the extent required by law. Where PIPL applies, we process personal information as described in this Policy and, where required, on the basis of your consent and/or other applicable legal grounds. Cross-border transfers (including to service providers such as Firebase outside China) are carried out only as needed to operate the App and, to the extent required by PIPL, subject to applicable transfer requirements. You may request access, correction, deletion, or withdrawal of consent where applicable by contacting support@themessroom.net. If you do not agree to the processing described in this Policy, do not use the App.
12. Your Privacy Rights
12.1 Rights Under GDPR (EEA / UK Users)
If you are located in the EEA or UK, you have the following rights under GDPR / UK GDPR:
- Right of access (Art. 15): request confirmation of whether we process your data and obtain a copy
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data
- Right to erasure / 'right to be forgotten' (Art. 17): request deletion of your data, subject to legal retention obligations
- Right to restriction of processing (Art. 18): request limitation of processing in certain circumstances
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format where processing is based on consent or contract
- Right to object (Art. 21): object to processing based on legitimate interests
- Right to withdraw consent (Art. 7(3)): where processing is based on consent, you may withdraw at any time without affecting prior processing
- Rights related to automated decision-making (Art. 22): we do not engage in solely automated decision-making with legal or similarly significant effects
To exercise any right, email support@themessroom.net with your pseudonymous uid or alias. We will respond within 30 days (extendable by a further 60 days for complex requests, with notice). We may ask for reasonable verification steps without requiring disclosure of your legal identity.
You also have the right to lodge a complaint with your local supervisory authority.
12.2 Rights Under US State Privacy Laws
Residents of certain US states (including California under CCPA/CPRA, and other states with comprehensive privacy laws) may have additional rights including the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share personal information as defined under applicable US state privacy laws. To exercise applicable rights, contact support@themessroom.net.
12.3 Account Deletion
You may delete your account at any time via: App → Dashboard → Edit Profile → Delete Account, or by emailing support@themessroom.net. We will delete or anonymise account data within 30 days, subject to legal retention obligations and any active legal hold.
13. Minimum Age and Children
The App is intended exclusively for users who are at least 18 years of age (or the applicable age of majority in their country). We do not knowingly collect personal data from individuals under 18. If we become aware that a minor has created an account, we will delete the account and associated data promptly. If you believe a minor has used the App, contact support@themessroom.net immediately.
14. Cookies and Tracking Technologies
Our website uses Vercel Analytics to collect anonymous, aggregate usage statistics. Vercel Analytics does not use cookies and does not collect personally identifiable information. For details, see: https://vercel.com/docs/analytics/privacy-policy
15. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the following additional disclosures apply under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Categories of personal information collected: identifiers (pseudonymous uid, alias), internet/network activity (device type, app version), diagnostic crash/error reports (error message and stack; not linked to your account), geolocation (none), commercial information (subscription tier), and inferences (none) drawn from the above
- Business purposes for collection: as set out in Section 6
- Categories of third parties with whom we share information: service providers (Firebase, Apple, Google) for operational purposes only
- We do not sell or share personal information for cross-context behavioural advertising
- Right to know, delete, correct, and opt out of sale/sharing: contact support@themessroom.net
- We do not discriminate against users who exercise their privacy rights
- Authorized agent requests: we will require written authorization and verify your identity
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Policy at themessroom.net/privacy and update the 'Last updated' date. Continued use of the App after the effective date constitutes acceptance of the updated Policy. If you do not accept the updated Policy, you must stop using the App and may request account deletion.
17. Contact and Data Protection Queries
For all privacy-related requests, questions, or complaints:
Support email: support@themessroom.net
Postal address: CMARE LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States