Mariner GPS Tools Developer Platform
Privacy
What Mariner GPS Tools processes, what we retain, and what you should protect when using the REST API and MCP server.
Calculation data
When you send a REST or MCP request, Mariner GPS Tools uses the values in that request to validate the input, perform the calculation, and return the result. We do not store complete request bodies, coordinates, MCP tool arguments, or calculation results.
Account information
You do not need an account to use the public calculators. An account is required to create and manage API keys and view usage. We retain the details needed to identify and secure your account, such as your email address, display name, profile image, and sign-in information. Watch & Navy does not receive or store your plaintext password.
Usage and analytics
Your account stores successful request counts by tool, day, and API key so you can review your usage. We also retain limited operational information needed to secure, maintain, and improve the service, such as the requested endpoint, response status, and request timing.
Usage records and operational analytics do not contain coordinates, calculation inputs, request or response bodies, calculation results, or plaintext API keys. Optional website analytics is separate and runs only if you accept analytics cookies.
API keys
Your complete API key is shown only when it is created or rotated. It is not stored in plaintext. Later account views show only the key prefix and identifier; the secret is replaced with dots. Keep API keys secret, do not include them in public client code or source control, and avoid personal or sensitive information in key names.
Connected applications
When you authorize an AI client, we store the application's registration details, your authorization (which application, which permissions, when it was created and last used), and the credentials that keep it signed in. Those credentials are stored only in hashed form, the same way API keys are. Calculation inputs and results are still not stored.
Authorization records expire automatically: short-lived sign-in artifacts within minutes, access credentials within an hour of expiry, and unused registrations after 30 days. Revoking an application from your account page cuts its access immediately and its remaining records are cleaned up on expiry.
Read the full privacy policy