SafetyStop

SafetyStop

Developed by Divers, for Divers

Privacy Policy

Last updated 20 September 2026

SafetyStop does not track you, contains no analytics, and shows no ads. This policy describes exactly what the app stores, what leaves your device, and what does not.

The short version. Your dive log lives on your phone. An account is optional and free. Cloud sync — keeping a copy of your log on a SafetyStop server so it follows you to another device — is a paid subscription, bought through Apple. Nothing else is collected, nothing is sold, and no third party receives your data.

Using the app without an account

The app is fully usable with no account and no network connection. In that mode:

If you create an account

An account is optional and free. Cloud sync is not: it is a paid subscription, bought through Apple, and it is what puts your log on the SafetyStop server so it follows you to another device. Without it the account still signs in, any dives it synced before stay readable (photos it synced are still listed, but their images are not served), and nothing new is stored from your device — not a dive, an edit or a deletion. What this page used to say was that creating an account stored your log on the server so it could sync; what is true now is that, of the list below, the first two items exist for every account and the rest reach the server only through cloud sync:

Share links

You can create a share link for one dive. Anyone holding the link sees that dive's fields (date, site, depth, time, gas, conditions, buddy and notes), its coordinate if you included it, its photographs if you included them, and its depth-and-time profile — and nothing else from your log. The link identifies no person: your name is not on the page.

Another SafetyStop subscriber who opens the link can save a copy of the dive into their own logbook — the fields and the profile, never the photographs. From that moment the copy is their record, not yours: you are not told it was made, it does not change when you edit your dive, and it is not removed when you revoke the link, suspend or delete your account. Revoking the link only stops new copies. Copies can be made only while your own subscription is active.

What is deliberately never uploaded

A photo of your certification card stays on your device. The app lets you photograph your certification card so you have it to hand. That photograph is stored on your phone only. It is not sent to the server, there is no database column for it, and the sync code cannot read it — an automated test fails the build if that ever changes.

The reason is that a certification card is an identity document: it carries your name, your photograph, your certification number and often your signature and date of birth. Being the custodian of that for every diver who uses the app is a responsibility this service declines.

The photo is included if you export a backup file yourself, because that is you moving your own data to a file you control.

Location

SafetyStop asks for your location only when you tap Use My Location on the dive form. It is never read in the background and the app does not track your movements.

When you tap it, the coordinate is used to name the body of water you are in and to set salt or fresh water, which matter for the gas calculations. The coordinate is stored with that dive, and goes to the server with it if the dive syncs.

Identifying the water may involve a request to OpenStreetMap's Overpass and Nominatim services, which are operated by third parties and receive the coordinate in order to answer. This only happens when the offline data bundled with the app cannot name the water. Their privacy practices are their own.

On the website, a dive that has a coordinate can also show a map of the dive site. The map is not loaded until you tap Show map on that dive: until then the page shows the coordinate as text and requests nothing. When you do tap it, map images are requested from OpenStreetMap, which is operated by a third party and will see the approximate location of the dive and your IP address in order to send those images. Nothing else about you or your log is sent with them, and the request does not tell OpenStreetMap which page you had open. Their privacy practices are their own. Map data is © OpenStreetMap contributors (ODbL).

The optional Dive Sites download

Tools → Dive Sites offers a database of dive site names and coordinates, so the site field and Use My Location can answer with no signal at all. It is optional: the app ships with United States water features already built in, and your log and every calculator work without it.

When you open that screen the app asks safetystop.cloud — a SafetyStop server, not a third party — whether a newer version of the file exists. That request sends nothing about you or your log; it is a request for a small text file, and the server sees only that some copy of the app asked for it, along with your IP address as any web request does. Nothing is downloaded until you tap Download, because the file is several megabytes and that is your data allowance to spend. You can delete it again from the same screen at any time.

The file contains no personal data of any kind. It is built from public sources — © OpenStreetMap contributors (ODbL) and Wikidata (CC0) — and it is a plain download, so nothing about which sites you look at, search for or dive is sent anywhere.

The map above is the only thing on this website that contacts anyone other than SafetyStop, and it never happens by itself. Every other page — including the dive log, a dive's own page and this policy — loads without any third-party request at all.

What the app does not do

How your data is protected

Your certification number, if you enter one, is stored as ordinary text on your device and, if your profile has synced, on the server. It is not treated as a credential because it does not grant access to anything.

Operator access

The person who operates this service, and anyone else given operator access, can look at accounts on the server to answer a support request. An operator does not need your email address in hand to find you: an operator can see a list of every account on the server, read a page at a time. For each account that list shows the email address, the date it was created, whether the address has been verified, its subscription status, whether a deletion is pending, and how many dives it holds.

Opening one account shows:

That includes your coordinates. A coordinate is the sharpest thing in a dive log: it says where you were, on a date, at a time. It is not encrypted and it is not hidden from an operator, so this page names it instead of saying your dive data and leaving you to work it out. If a dive site is somewhere you would rather nobody could ever read, leave the coordinate off that dive and type the site name instead.

Opening an account does not show:

What an operator can change

An operator can do seven specific things to an account, and nothing else:

Those two emails go to you, never to the operator. A verification link and a reset link are sent to the address on the account — your address. An operator can cause the message to be sent; they cannot receive it, see the link inside it or use it. That is what stops either of those actions being a way into your account.

Everything else is still out of reach, and none of it has been weakened. An operator cannot read your password, because only a bcrypt hash of it is stored. An operator cannot see a dive photograph, cannot see your certification card photo — there is no column on the server for it — cannot publish a share link, cannot edit or delete a dive, and cannot sign in as you. What this page used to say was that an operator cannot change anything at all; what is true now is that an operator can do those seven things, and nothing else.

Two of those seven are worth reading twice, because they are the two you cannot undo yourself. If an operator suspends the account you can still sign in and get all your data out — that is deliberate, and an operator is not able to shut you out of your own dive log. But if an operator closes the account, you cannot sign in and you cannot reverse it; only an operator can reopen it, and only within 90 days. Closing your own account is different in exactly that respect: you stay signed in the whole time and can call it off yourself.

Every look and every action is recorded. Each one writes down who did it, which account it was done to, when, what was done, and, for a look, whether coordinates were among what was seen. Something that left no trace would be indistinguishable from nothing having happened, which is the whole reason for writing it down. Those records are kept even after the account is deleted: they are a record of what an operator did, not part of your log, and nothing from your dives is in them.

Operator access itself is granted only by the owner of the service, directly. There is no way to request it and no way to grant it through the app or the website — no form, no setting, no support ticket — and one operator cannot grant or revoke it for another.

Deleting your data

You can log out at any time, which removes the session from your device. While the account has cloud sync, deleting a dive removes it from your device and from the server. Without cloud sync, the app cannot delete a dive while you are signed in: it tells you the dive could not be removed from your account, and the dive stays on your device and, if it had synced, on the server, readable to you, until you delete the account or have cloud sync again and delete it then. Signed out, deleting a dive removes it from your device only.

Deleting your account

You do this yourself, and nobody has to approve it. In the iPhone app, go to Tools, then Sync & Backup, and use Delete Account under Account — directly below Sign Out Everywhere. You can also do it here on the web after signing in. It shows you what will happen, asks for your password, and takes a second tap to confirm. Export a backup first if you want to keep your log. If you would rather not do it yourself, email support@safetystop.cloud from the address the account uses and it will be done for you.

The moment you ask:

Then the account is closed for 90 days, and you can still take it back. During those 90 days you can sign in, read your log and export a backup, and a banner at the top of the page offers to cancel the deletion. If you cancel, your dives come back untouched. The 90 days exist for exactly that reason: signing you out or locking your log would put the undo behind a door that had just been shut.

Cancelling does not bring your share links back, and it cannot. Only a one-way hash of each share link is stored, never the link itself, so revoking one is irreversible — there is no copy of the address left to switch back on. This is the one thing a cancelled deletion does not restore. You would need to create new links from the dives you want to share again.

After the 90 days, what is stored on the server is erased — deleted, not archived and not deactivated. There are three exceptions, and each is named below:

Nothing is destroyed by a timer. After 90 days the account becomes eligible to be erased; the erasure is then run by hand, one account at a time, each one confirmed individually. That is deliberate — no clock should be able to delete a diver's log by itself — and it means the data goes on or after the ninetieth day rather than exactly on it.

The first exception: Apple's billing notices

If you ever paid for cloud sync, the notices Apple sent about that subscription — a renewal, a lapse, a refund — are kept after the account is erased, so that a later dispute about a payment can be answered. The subscription record tied to your account goes with everything else; what stays is the list of billing events Apple reported: a transaction identifier, the dates, what happened, and the account's internal number, which after the erasure refers to nothing. No dive, photo, coordinate, name or email address is part of it.

The second exception: the record of what an operator did

If an operator ever looked at your account, or took one of the seven actions described above, the record of that is kept after the account is erased — who did it, when, which account, what was done, and whether coordinates were included in a look. It has to outlive the account to be worth anything: a log that disappears along with the thing it was watching would let a look or an action be erased by erasing the diver. See Operator access for what an operator can see and can do.

What is kept is a record of what an operator did, not a copy of your log. It holds no dive, no coordinate, no photo, no note, no name and no email address — only the account's internal number, which after the erasure refers to nothing.

The third exception: feedback you sent

Send Feedback does not use your account at all. It is sent without signing in, so a feedback record is not linked to you, and deleting your account neither reaches it nor needs to. A record holds four things: the text you typed, the name from your diver profile if you have set one, which app build and iOS version you were on so a problem can be reproduced, and a device identifier that proves the message came from the real SafetyStop app rather than from a bot.

That device identifier names an installation, not a person: it cannot be turned back into your identity, your account or your device, and it is there only so a hundred messages from one install can be told apart from a hundred divers. If you never filled in a profile name, nothing in a feedback record identifies you.

Feedback is kept after an account is erased, for the same reason as the billing notices above: a bug report may need to be re-read long after whoever sent it has stopped using the app, and it is often the only record of why something was changed. No dive, photo, coordinate or email address is ever part of a feedback record.

Your subscription is separate

Deleting your account does not cancel a paid subscription. Only you can cancel that, in Apple Settings on your iPhone, and if you do not it renews as usual. Cancel it there as well, before or after you delete the account — a subscription is an arrangement between you and Apple, and nothing SafetyStop deletes can reach it.

Two more things worth knowing: the dives already on your phone are not deleted, and you cannot register a new account with the same email address until the old one has actually been erased, because it still holds that address.

Children

SafetyStop is not directed at children under 13 and does not knowingly collect their information.

Changes

If this policy changes in a way that affects what is collected or where it goes, the app will say so before the change takes effect. The date at the top of this page reflects the current version.

Contact

support@safetystop.cloud