Legal & support

Privacy policy

This policy covers the website divebuddy.pro and the DiveBuddy Pro app. DiveBuddy Pro is not an offline-only app: parts of it work locally, but core features such as accounts, cloud sync, community, Explorer content, sharing and purchases require a server connection.

Version 1.0 · Last updated: 14 September 2026

1. Controller and privacy contact

divebuddypro Owner: Arndt Kemper Lerchenweg 4 34305 Niedenstein Deutschland Email: support@divebuddy.pro

Send privacy requests to support@divebuddy.pro. No statutory data protection officer has been appointed.

2. Website hosting and server logs

When you open this website, the hosting infrastructure processes technically necessary connection data in order to deliver the pages and secure operation.

  • Data that may be processed: IP address, request time, requested address, status code, transferred volume, referrer and browser/operating system details.
  • Purpose: delivery of the pages, stability, error analysis and abuse prevention.
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).
  • The website embeds no analytics, advertising or social media trackers.

3. Account and sign-in

Account and cloud features require registration. Depending on the method used, the following are processed:

  • Email address and authentication data (passwords are stored only as a cryptographic hash).
  • Google Sign-In: provider identifier and the basic data supplied by the provider (e.g. email address).
  • Sign in with Apple: provider identifier and the email address you release or relay.
  • Technical session data (timestamps, tokens, device information) to secure the sign-in.

Legal basis: Art. 6(1)(b) GDPR (contract/use of the app) and Art. 6(1)(f) GDPR for security and abuse prevention.

4. Cloud infrastructure (Supabase)

Supabase is used for authentication, database, cloud sync, file storage and server functions, acting as a processor on behalf of the provider.

  • Content you create in the app is stored insofar as it is synchronised.
  • Server functions deliver, among other things, public share pages and the public community feed.
  • Legal basis: Art. 6(1)(b) GDPR; processing takes place on the basis of the agreements concluded with the provider.

The specific hosting region, sub-processors and contractual details will only be named after a final review of the contract and project configuration and will be added here. Until then we deliberately make no statement about them.

5. Profile, settings and in-app content

  • Profile data: display name, optional personal details, optional profile picture, language and app settings.
  • Digital logbook: dives, dive profiles, imported computer data, places, times, notes and tagged buddies.
  • Dive record: equipment, service and inspection intervals as well as certifications and courses you enter. These are self-declarations; DiveBuddy Pro neither issues nor verifies certifications.
  • Tools and planning: values you enter and the results produced.

Purpose: providing the features you use. Legal basis: Art. 6(1)(b) GDPR. Voluntary additional details rely on Art. 6(1)(a) GDPR and can be deleted at any time.

6. Community, buddies, messages and marketplace

If you use community features, the content and links required for them are processed:

  • Posts, comments, reactions, group and buddy links as well as messages between users.
  • Events, magazine contributions and marketplace listings you create or respond to.
  • Reports and moderation actions to enforce the community guidelines.

Content you publish within the community is visible to the audience you select. Messages are visible to the users involved; end-to-end encryption is not warranted.

Legal basis: Art. 6(1)(b) GDPR for using the features, Art. 6(1)(f) GDPR for moderation and security.

7. Public share links (/s/{token})

You can explicitly share individual content publicly. A share link of the form divebuddy.pro/s/{token} may contain, depending on your sharing settings:

  • author or display name and date
  • the post text
  • photos, videos and preview images you deliberately released
  • a location for the post or dive site
  • tagged buddies, insofar as you released them
  • Share pages are delivered without intermediate caching (no-store) and become unreachable immediately after you revoke sharing.
  • Content that has not been shared, private logbooks and dive records are never displayed on this website.
  • Public shares can be seen and copied by search engines and third parties while they are active.

Legal basis: Art. 6(1)(a) GDPR (your sharing decision).

8. Photos, videos and media

  • Photos and videos you select are processed in the app and, with sync enabled, stored in cloud storage.
  • Preview images and posters may be generated for display.
  • Media can contain technical metadata (e.g. capture time or geocoordinates). Check which metadata your material contains before sharing.

9. DiveSteps and location data

  • Location data is processed only when you start the relevant feature and grant the system permission.
  • Live tracking or background location is used only after explicit activation and can be stopped at any time in the app and in system settings.
  • Trip legs, routes and stops are stored so that you can review them later and share them if you wish.

Legal basis: Art. 6(1)(a) GDPR (consent/activation).

10. Device permissions

  • Camera: only for captures or scans you start.
  • Gallery/files: only for media and imports you select.
  • Bluetooth and local network/Wi-Fi: only to connect compatible devices such as dive computers or cameras.
  • QR/barcode scanning: only during the scan; no permanent camera images are stored.

Permissions can be withdrawn in system settings at any time; the corresponding feature will then be unavailable.

11. Push notifications

If you allow notifications, a push token is generated and processed via Apple (APNs) or Google (FCM) infrastructure in order to deliver notifications to your device. You can disable notifications in system settings at any time.

Legal basis: Art. 6(1)(a) GDPR.

12. Maps and external services in the app

  • Where map views are embedded via Google Maps, technical connection data is transmitted to the map service for display; Google's privacy information applies in addition.
  • Camera integrations (GoPro via OpenGoPro interfaces, Insta360 via the Insta360 Camera SDK) become active only when you connect a camera. Device information, connection status, media listings and the media you import are processed.
  • Real-time communication services (e.g. LiveKit) are used only insofar as the current feature set actually offers a live function and you start it.

Which of these services are active in the currently published app build is verified separately for store declarations and Data Safety (see docs/legal-data-map.md). Services that are not used process no data.

13. Purchases and subscriptions

  • Purchases and subscriptions are handled exclusively through the Apple App Store or Google Play. The provider receives no payment data such as card numbers.
  • RevenueCat may be used as a processor to manage purchase status (e.g. active, expired, restored); anonymous or pseudonymous purchase identifiers and store transaction details are processed.
  • Monthly and yearly subscriptions renew automatically until you cancel them in your store account. Lifetime is a one-off purchase.
  • Prices, taxes and availability are shown by the respective store.

Legal basis: Art. 6(1)(b) GDPR.

14. KAI and AI features

KAI is the app's assistant. It processes your inputs (questions, instructions) and the context you release for the respective answer, such as details of a dive or a plan.

  • Purpose: answering your request and supporting analysis and planning.
  • Legal basis: Art. 6(1)(a) GDPR (your use of the feature).
  • KAI makes no safety decisions and replaces neither training nor a dive computer.

The specific AI provider, processing location and retention period for requests will only be named after reviewing the code and configuration of the published app build. We deliberately name no provider on assumption.

15. Recipients and international transfers

  • Recipients are the service providers required for operation: website hosting, Supabase (auth, database, storage, server functions), Apple and Google for store, push and sign-in, and RevenueCat for purchase status where used.
  • No disclosure for advertising purposes takes place. Personal data is not sold.
  • With services based or hosted outside the EU/EEA, an international transfer may occur. The applicable safeguards are documented on the basis of the existing contracts and will be named specifically here once the review is complete.

16. Retention

  • Account data and synchronised content are stored for as long as your account exists.
  • After account deletion, account data and associated user-generated content are deleted; technically necessary delays caused by backups are possible.
  • Server logs are kept only for the period required for operational security.
  • Statutory retention obligations (e.g. for transaction records, where they exist) remain unaffected.

Specific retention periods in days will only be stated after reviewing the backup and retention configuration.

17. Your rights

  • Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21).
  • You can withdraw consent at any time with effect for the future – for example by stopping location tracking, revoking a share or disabling notifications.
  • You may lodge a complaint with a supervisory authority; in Hesse: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit.

Send requests to support@divebuddy.pro.

18. Local, cloud and public – a clear separation

  • Local: content that stays on your device until you use synchronisation.
  • Cloud: content synchronised with your account and therefore available across devices.
  • Public: exclusively content you have explicitly released via a share link or in the public community.

19. Account deletion

You can delete your account in the app under “Account & security”. An external route by email is also available; both are described on the “Delete account” page.

20. Version and changes

This privacy policy is version 1.0, last updated 14 September 2026.

  • Version 1.0 (14 September 2026): complete rewrite. Earlier statements about an offline-only app, no registration, local-only storage, no server transfer and no background services were removed because they do not reflect the actual feature set.

Contact: support@divebuddy.pro

These documents describe the actual scope of the product to the best of our knowledge. They are not legal advice and do not replace a lawyer's data-protection review.

DiveBuddy Pro

Get the app