Skip to main content

Legal

Privacy Policy

Version 1.0 · Effective 2026-08-10

The short version: we collect what we need to run your account, sync your training, and keep the app working, and very little else. We never sell your data. We never use your dive or training data for advertising. Your logs are private by default. When you delete your account, it's gone.

This policy covers the Freediving Buddy mobile app (iOS and Android, including the watch apps) and our website, freedivingbuddy.app. It explains what we collect, why we collect it, who handles it, and how you stay in control. Questions or requests: hello@freedivingbuddy.app.

1. Who we are

Freediving Buddy is an independent app, built and operated by a solo developer, not a corporation ("we", "us"). We are the data controller for the personal information described in this policy, and the fastest way to reach the human behind it is hello@freedivingbuddy.app.

2. What we collect, and why

Our guiding principle is simple: collect only what we need. Below is the full list, with the reason we collect each item and the legal basis we rely on.

Your account. An email address and the sign-in method you choose: a one-time code we email you, Sign in with Apple, or Sign in with Google. There are no passwords, so we don't store any. You can also use the app as a guest without telling us anything; guest data is tied to an anonymous session on your device. Why: to run your account. Legal basis: contract.

Your profile. Whatever you decide to add: display name, avatar photo, bio, city, freediving level, certifications, date of birth, gender. All of it is optional. Why: it's your profile. Legal basis: contract.

Training and dive data. Your breath-hold sessions, apnea tables (including custom tables and AI-generated ones), training programs, streaks, personal bests, and depth-dive logs: date, discipline, depth, time, notes, and, if you train with an Apple Watch or Wear OS watch, the heart-rate summaries recorded during the session. This data is the whole point of the app. It is also the most personal thing we hold: breath-hold times and heart rate can say something about your health. So we treat it as health-related data: we process it only with your explicit consent, we never use it for advertising, and we never disclose it to anyone without your say-so. You can withdraw consent at any time by deleting individual entries or your whole account. Legal basis: explicit consent.

Safety screening. If you fill in the optional medical questionnaire or the pre-training readiness check, we store your answers so the app can show you the right warnings. These answers are never shown to other users and are never used for anything except those warnings. Legal basis: explicit consent.

Location. If you allow it, we read your device's approximate location to sort dive sites by distance from you. We request a deliberately low-accuracy reading, we don't store it, and we don't send it to our servers. If you suggest a new dive site, the map pin you drop is sent to OpenStreetMap's Nominatim service to look up a human-readable place name. You can switch location off in your device settings at any time; the app works fine without it. Legal basis: consent.

Subscription status. Whether you have an active subscription and whether you're eligible for a trial, provided by RevenueCat. The purchase itself happens entirely on Apple's or Google's side; we never see your card. Legal basis: contract.

AI conversations. When you use the AI coach, the message you type (and, if you use voice input, the audio recording for transcription) is sent to the AI provider we have configured: currently DeepSeek for chat and Google Gemini or OpenAI for voice transcription. We send the prompt itself plus an obfuscated user id used for rate limiting, never your name or email. We log token counts, model, and cost per request so we can enforce daily usage caps. On devices that support it, some AI features run entirely on your phone and nothing leaves it. Please don't put medical details, financial information, or other personal identifiers into AI prompts. Legal basis: contract, and consent for voice input.

Usage analytics. Anonymous-by-design product events, things like "training session completed" or "paywall viewed", sent via PostHog and keyed to a random user id, scrubbed of personal content before sending. On a small set of screens (onboarding, training, progress, and the paywall) PostHog session replay records how the screen is used so we can find confusing UI, with every text input and image masked. We see taps and navigation, not your content. You can opt out of analytics in the app's settings. Legal basis: consent where your region requires it, otherwise legitimate interest.

Crash reports. When the app crashes, Firebase Crashlytics sends us the stack trace along with your device model, OS version, and locale, so we can fix it. Legal basis: legitimate interest in an app that works.

A record of deletion. When you delete your account we keep one audit row: the timestamp, your email, sign-in provider, platform, and the optional reason you gave. It exists so we can prove the deletion happened if we're ever asked to. Legal basis: legal obligation.

3. What we don't do

  • We don't sell your data. Ever. (For readers in California: we do not sell or share personal information as defined by the CCPA/CPRA, and we haven't in the past 12 months.)
  • We don't run ads, embed advertising SDKs, or deal with data brokers.
  • We don't track you across other companies' apps and websites.
  • We don't read your contacts, your photo library (beyond the photos you explicitly pick), or your movements.
  • We don't use your dive, training, heart-rate, or medical-screening data for advertising, profiling, or "audience building". Full stop.
  • We don't make automated decisions about you that have legal or similarly significant effects.

4. Who processes data for us

We use a short list of service providers, each bound by a data-processing agreement and each receiving only what its job requires:

  • Supabase: our database, authentication, file storage, and server functions. This is where your account and training data live, protected by row-level security so each row is readable only by the account that owns it.
  • RevenueCat: verifies subscription receipts with Apple/Google and tells us your entitlement status.
  • PostHog: product analytics and the masked session replay described above.
  • Google Firebase: crash reporting (Crashlytics) and remote feature flags.
  • AI providers (DeepSeek for chat; Google or OpenAI for voice transcription): receive only the prompt or audio you submit, as described in section 2.
  • Sanity: hosts our public content, learn articles and the dive-site directory. It holds no user accounts or training data.
  • Vercel: hosts freedivingbuddy.app and provides cookieless, aggregate web analytics.
  • OpenStreetMap Nominatim: resolves a place name when you suggest a dive site.
  • Apple and Google: sign-in and billing, under their own terms.

Beyond these processors, we disclose personal information only to legal authorities when a valid legal process requires it, or when we believe disclosure is necessary to prevent serious harm to someone.

5. Where your data lives

Our providers run in the European Union and the United States. Where your information is transferred outside your country of residence, we rely on Standard Contractual Clauses or an equivalent recognized safeguard (such as the EU–US Data Privacy Framework, where the provider is certified). Email us if you'd like a copy of the safeguards that apply to you.

6. What other users can see

Private by default. Your training sessions, dive logs, personal bests, medical answers, and email address are never visible to other users. Two things are shared only because you choose to share them:

  • The buddy directory. If you opt in, we publish the snapshot you approve: display name, avatar, bio, country/city, level, one certification, and the Instagram handle and/or WhatsApp number you choose to list. It's visible to signed-in users only, and you can switch it off at any time, which removes the listing immediately. Think for a second before listing a phone number: you're showing it to strangers who share your hobby, which is the point, but it's still strangers.
  • Dive-site contributions. Site suggestions go through manual review before anything is published. Photos you upload to a dive site are public once published.

One technical honesty note: avatar images and dive-site photos are served from public storage buckets. The URLs are unguessable, but anyone who has a URL can view the image without signing in.

7. How long we keep things

  • Account, profile, and training data: for as long as your account exists.
  • After deletion: your data is removed from our live systems immediately. There is no grace period and no way for us to restore it. Copies can persist in encrypted database backups for up to 30 days before those backups age out.
  • Crash reports: 90 days (Crashlytics default).
  • Analytics events: per PostHog's standard retention.
  • The deletion audit row: retained for legal compliance.
  • On your device: cached content and session tokens persist until you sign out or uninstall the app.

8. Deleting your account

Two ways, your choice:

  • In the app: Settings → Account → Delete Account. This removes your profile, training and dive data, custom and AI tables, program history, subscription records, buddy-directory listing, and avatar, immediately.
  • Without the app: email hello@freedivingbuddy.app from your account's email address (details at freedivingbuddy.app/delete-account). We complete these requests within 30 days.

Deletion is permanent. If you might want your training history later, export it first: Settings → Safety & Privacy → Export My Data generates a CSV on your device that you can save anywhere; nothing is sent to our servers to do it. Note that an active subscription is managed by Apple or Google and must be cancelled in their settings; deleting your account does not cancel the billing.

9. Your rights

Wherever you live, you can ask us to show you what we hold about you, correct it, delete it, export it in a machine-readable format, restrict or object to specific processing, or withdraw a consent you gave earlier (without affecting what was done while the consent stood). The in-app tools cover most of this; for everything else email hello@freedivingbuddy.app and we'll respond within 30 days.

  • EU/EEA/UK: these are your GDPR / UK GDPR rights; you can also complain to your local data-protection authority.
  • California: you additionally have the CCPA/CPRA rights to know, delete, correct, and limit use of sensitive personal information, and we will never discriminate against you for exercising them.
  • Brazil: you have the equivalent rights under the LGPD; we answer LGPD requests within 15 days.

10. The website, cookies, and analytics

freedivingbuddy.app sets a deliberately boring set of cookies:

  • fdb-consent (12 months): remembers your cookie decision so we don't ask again. Strictly necessary.
  • fdb-consent-region (24 hours): remembers which consent rules apply to your region. Strictly necessary.
  • NEXT_LOCALE (1 year): remembers the language you picked. Strictly necessary.
  • PostHog cookies (names starting with ph_; up to 12 months): analytics cookies, set only where allowed; a separate opt-out entry records a withdrawn consent. Analytics.

If you're visiting from the EU, EEA, or UK, nothing non-essential loads until you accept, and "reject all" is exactly as easy as "accept all". In regions with opt-out laws (several US states, Brazil), analytics runs by default and the "Privacy choices" link in the footer lets you turn it off; we honor that choice. The site also uses Vercel Analytics and Speed Insights, which are cookieless and aggregate: they count page views and performance, not people. Website analytics for EU visitors is processed on PostHog's EU servers.

11. Security

All traffic between your device and our servers is encrypted in transit (TLS). Data is encrypted at rest, every database row is locked to its owner by row-level security, and session tokens are kept in your device's secure storage. We'd love to promise perfect security, but nobody can. What we can promise is that if we learn of a breach that puts you at serious risk, we will notify you and the relevant authority within the legally required timeframe (72 hours under the GDPR).

12. Age

Freediving Buddy is for adults: you must be 18 or older. Freediving is a dangerous sport and the app is not designed for minors. We don't knowingly collect data from anyone under 18, and if we learn we have, we'll delete it.

13. Changes to this policy

When we change this policy we'll post the new version here with a fresh date. If a change is material, the app will tell you and ask you to re-accept before you continue. The version stamp at the top of the document in Settings → Legal always tells you which version you agreed to, and we keep prior versions available on request.

14. Contact

Privacy questions, complaints, rights requests, or anything else: hello@freedivingbuddy.app

Effective: 2026-08-10 Version: 1.0