Contents

  1. The principle: nothing is public
  2. Adding a friend: by link, never by directory
  3. Sharing a route
  4. Sharing a place — and why it is the most sensitive
  5. Clubs: approved by hand
  6. A club's places go through a moderation queue
  7. Sharing a passage: the consent screen
  8. Withdrawing a share — and what a withdrawal cannot do
  9. Deleting your account, handing over your boat

1. The principle: nothing is public

Solano publishes nothing. There is no public profile, no feed, no open link to a route or a passage. Everything that leaves your account goes to people you added yourself, or to a club you belong to.

Three objects can be shared, and they are nothing alike in terms of what they reveal:

🗺️
A route is a plan: a track, a departure time, some models. It does not say where you were, it says where you intend to go.
📍
A favourite place is often an address. “Home”, a mooring buoy, a habitual anchorage — counter-intuitively, it is the most sensitive of the three.
🧭
A passage is a timestamped history of movements, with photos, and often the names of the people aboard. That is no longer only your data.

2. Adding a friend: by link, never by directory

From the 👥 My friends menu, you create an invitation link and send it to whoever you want. It works for one person only and expires after 7 days.

There is no directory: nobody can find you from your email address or your display name. That is not an omission, it is the choice: a searchable directory is an account-enumeration feature, exactly what we do not want to offer.

In practice: there are no “friend requests” to accept, so no queue of solicitations to sort through. Whoever opens the link has already consented by clicking.

3. Sharing a route

In 🗺️ My routes, the 👤 button on a route sends it to a friend — or to a club. Your friend then sees your live route, not a copy: if you edit it, they see the edit.

This is deliberate. A copy would survive revocation, and “withdraw the share” would stop meaning anything.

4. Sharing a place — and why it is the most sensitive

In ⭐ My places, the same 👤 button. The person sees the place's name and its exact coordinates.

Keep in mind: a favourite place is often an address. Only share it with someone you would give it to in person.

That is why a place is only shared with named friends, never directly with a club. Towards a club it goes through a moderation queue — see below.

5. Clubs: approved by hand

A club (an association, a circle of crew mates, a sailing school) is requested from 🏛 My clubs. It is born pending: until it is approved, nobody can join it and nothing can be shared in it.

Why this friction? Because a club becomes responsible for the data its members put there. We do not let anyone open one on a whim.

Once active, its members share routes with each other. Anyone can belong to several clubs, with a different role in each: manager here, plain member there.

Three roles. The owner is the account that requested the club — ideally an account in the club's name rather than one person's, so it outlives committee changes; it alone appoints or demotes managers, and hands over or deletes the club. Managers run day-to-day matters: they invite and remove members and approve proposed places. Members share and propose.

The club details — description, e-mail, phone, website, home port, logo — are kept by the owner and managers, and readable by every member. The contact e-mail is displayed information only: no message is ever sent to it.

A passage never goes to a club. With five members a club is a restricted circle; with three hundred it is a publication. The same button must not produce both.

6. A club's places go through a moderation queue

A place is not “shared” with a club, it is proposed. A manager approves or declines it, with a reason. Three states are visible: pending, approved, declined.

1
You propose
One or several of your favourite places at once, from the club's card.
2
A manager decides
Once approved, the place becomes visible to every member — it is the club's commons: anchorages, race marks, meeting points.
3
You keep control
You can withdraw your proposal at any time, even after approval. Without that right, proposing would amount to permanent publication.
What no setting can fix: managers see the proposal — name and coordinates — before deciding. Declining does not erase what they have seen. Do not propose a personal place.

7. Sharing a passage: the consent screen

This is the most committing share, and the only one that goes through a dedicated screen. It is reserved to the boat's owner: a logbook holds the entries, photos and names of the whole crew — the person accountable for it is the owner.

What leaves

Every timestamped position (including departure and arrival, often your home port or mooring), the conditions you logged (wind, sea, pressure), points of sail, propulsion, the logbook photos, and the boat — its name and identity (registration, MMSI, home port). Your friend knows your boat: hiding it would protect nothing.

What never leaves

👥
Crew and watch names — that is your crew mates' data, not yours: you cannot share it on their behalf.
✍️
Free-text notes — your entry-by-entry comments, whatever they say.

There is nothing to tick, and this is not display filtering: these fields are not even read by your friend's app.

Your agreement is recorded: its date and the version of the text displayed. That is what makes it possible to establish later what was accepted, and when — a tick box nobody records proves nothing.

8. Withdrawing a share — and what a withdrawal cannot do

The 👥 My friends panel lists everything you are sharing. One click on “Withdraw” cuts access immediately. Removing someone from your friends also cuts every share, in both directions.

A withdrawal is not retroactive. Your friend may have exported the route as GPX or saved an image. What has already crossed to the other side does not come back — that is true of any sharing, here as elsewhere, and it is written on the screen before you share.

9. Deleting your account, handing over your boat

Deleting your account erases everything you shared. But a boat is not only yours: its passages and its logbook also belong to the crew who kept them.

So the deletion screen offers to hand the boat over to a crew member (and a club to one of its managers) rather than erase it with its whole log. Without an accepted handover, everything goes — that is the erasure promise, kept to the end.

By the way: the entries a crew member wrote stay in the boat's logbook even if they delete their account. They are then shown without an author. A logbook is a dated, signed document; its pages are not reassigned to someone else.

Going further

The detail of what is stored, why, and for how long is in the privacy policy. How the logbook itself works is described in Logbook: keeping your navigation journal.

Disclaimer: Solano is not a maritime safety service. Navigation decisions remain the skipper's responsibility, who must account for their experience, their equipment and official weather bulletins.
Open Solano →