🫧 BubblesPrivacy Policy
Last updated: 29 August 2026
Bubbles is a personal scuba diving logbook operated by GradSprint ("we" — see the imprint for operator details). This policy describes what data the Bubbles app and the divewithbubbles.com service process, why, how long it is kept, and what control you have over it.
What we store, and why
- Account data — your email address, display name and a hash of your password. Your password itself is never stored. Basis: providing the service you signed up for.
- Logbook data — the dives you log or import: depth and temperature profiles, GPS positions and routes, dive sites, notes, marine-life sightings (with photo links), certifications, insurance details, gear, breathing sessions and your life list. This is the product; we process it solely to run your logbook.
- Location data — GPS coordinates are stored only when you attach them to a dive (from an imported dive-computer file or by picking a site on the map). The app requests location permission solely for these features.
- Invite records — which invite code your account was created with, and codes you were issued. Basis: operating invite-only registration.
- Push tokens — if you enable notifications, the device registration token issued by Firebase Cloud Messaging, so reminders can reach your device.
- Technical logs — API requests (path, status, IP address, user agent). Basis: security (abuse and rate limiting) and debugging.
- Support requests — what you send through the support form (name, email, message), kept while we handle your request; closed requests are deleted after 180 days.
How long we keep it
- Your account and logbook: until you delete them (see below).
- Technical request logs: 14 days, deleted automatically.
- Logbook-export emails you request: the document is queued for sending and its receipt removed within 3 days of delivery.
- Nightly backups: rolling 14 days; used only for disaster recovery, never to restore deleted accounts.
- Administrative audit records (e.g. that an account was created or deleted): kept as a permanent operational record, without your logbook content.
What we don't do
- We don't sell your data or share it with advertisers.
- We don't run third-party analytics or ad SDKs in the app.
- The website sets no tracking cookies; the only cookie on this domain is the technical sign-in cookie of our own administration console.
- We don't read your logbook except as needed to operate the service.
- We don't make automated decisions about you or profile you.
- To operate and improve the service we compute aggregate usage statistics from the data above (for example: total dives imported, or overall time spent in breathing training across all users). These are counts and sums, not individual tracking — no additional data is collected for them.
Sharing between users
Dive sharing and the buddy system only expose your data to people you explicitly connect with: a buddy you accept sees your name, email address and the dives you choose to share. A shared dive a buddy copies into their own logbook becomes part of their data.
Service providers (processors)
- Hosting and database: Amazon Web Services.
- Push notifications: Firebase Cloud Messaging (Google).
- Transactional email (password reset, verification, logbook exports): Resend.
- Species search: queries you type in the fish catalog are forwarded to iNaturalist to fetch species data; they are not tied to your account there.
These providers process data on our behalf to run the service; depending on their infrastructure this can involve processing outside your country.
Your rights and controls
- Access & portability — download your complete logbook as JSON (Settings → Export my data) or receive it by email as a UDDF file (Settings → Email my logbook), an open format other dive-log software reads.
- Deletion — Settings → Delete account, effective immediately; the full details are on the account & data deletion page. No app access? Email us instead.
- Correction — everything in your logbook and profile can be edited in the app.
- Depending on where you live you may have further statutory rights (objection, restriction, complaint to your data-protection authority). To exercise any right, write to support@divewithbubbles.com.
Children
Bubbles is not directed at children; accounts are created by invitation for certified or trainee divers.
Changes
When this policy changes materially we will update the date above and, for significant changes, inform you in the app or by email.
Contact
Questions or requests: support@divewithbubbles.com