Privacy Policy
Last Updated: July 28, 2026
In Short: You can calculate and browse without an account. Signed-in users can privately save plans and dive-log entries to Firebase. Explorer saved sites, private notes, visited status, and personal map sites remain in the browser. We do not use advertising or first-party analytics.
1. Information We Collect
Scuba Safe is designed to minimize data collection. The information involved in using the Service generally falls into these categories:
- Location data (optional): If you use features like "Use my location" in Explorer, your browser may share your approximate or precise location with the page. We use it to center searches, show nearby results, and fetch localized weather. We do not intentionally store your location history on our servers.
- Search and map requests: When you search for a place (for example "Jupiter, Florida") or load map results, your browser makes requests to third-party services (listed below). Those services may receive information such as your IP address, user agent, and request parameters (for example search terms, coordinates, and bounding boxes).
- Dive planning inputs: Depths, times, gas selection, table mode, surface intervals, and other values you enter in Planner are processed in your browser to generate outputs.
- Account and profile data: If you register, Firebase Authentication processes your email, authentication provider, display name, optional provider profile picture, verification state, account dates, and sign-in activity. Your Scuba Safe profile may also store certifications you choose to list. Passwords are handled by Firebase Authentication and are not visible to Scuba Safe administrators.
- Cloud plans and dive logbook: Signed-in users can store plan names, dates, table settings, dive profiles, site context, and voluntarily entered logbook information such as actual depth, duration, conditions, buddies, and notes.
- Local saved data: Planner working state, a synchronized plan cache, preferences, Explorer saved sites, private notes, visited status, and personal map sites may be stored locally using browser storage.
- Community contributions: Reviews, dive-site submissions, and issue reports include the content you enter, relevant public site details, timestamps, and a Firebase user identifier. Approved reviews and site information are public.
- Site photos: Photo submissions require a registered Google or email/password account and include the image, optional description, public credit (which defaults to your display name), site details, timestamps, and your Firebase account identifier. Your email and other profile information are available to the authentication service and authorized administrators but are not displayed with the photo. Explorer re-encodes uploads to remove embedded camera and GPS metadata before storage.
- Operational security records: To prevent duplicate submissions and abuse, we temporarily store your Firebase user identifier, contribution type, request identifier, and submission time. Hosting, authentication, and cloud providers may also process standard network and error-log data such as IP address, user agent, and request time. We use these records for reliability and security, not behavioral analytics.
2. Third-Party Services
Scuba Safe relies on third-party providers for maps, search, weather, and community features. Your browser connects directly to these services to deliver functionality:
- OpenStreetMap / Overpass API: Used to fetch map data and points of interest.
- Photon (Komoot): Used for place search and autocomplete.
- Open-Meteo (Forecast and Marine APIs): Used to fetch weather and marine conditions.
- RainViewer: Used to fetch radar and precipitation layers (when enabled).
- Firebase: Used for Google and email/password authentication, private cloud plans and dive logs, Cloud Storage for moderated photos, public reviews, issue reports, community site submissions, edit moderation, and the administrator panel.
- Google reCAPTCHA Enterprise / Firebase App Check: Used when enabled to assess whether community requests come from the genuine Scuba Safe website and reduce automated abuse.
- Wikipedia API: Used to fetch context about locations (when enabled).
- Leaflet: Used to render the interactive map.
- Esri World Imagery: Used to render Explorer's satellite basemap.
- Google Maps links: "Get Directions" opens Google Maps in a new tab.
These providers operate under their own privacy policies. We encourage you to review them if you want more detail about how they handle request data.
3. Cookies and Authentication
We do not use advertising cookies, first-party analytics, session replay, or behavioral tracking. Firebase Authentication and App Check may use browser storage or security tokens to keep you signed in, synchronize your library, and protect account or community requests.
4. Local Storage (Your Device)
Scuba Safe uses browser storage to improve usability. This data stays on your device unless you clear it:
- Preferences: Settings like units (feet vs meters), table mode, and similar UI preferences may be stored so the site remembers your choices.
- Saved plans: Signed-in plan saves are stored in your private Firebase account library and cached locally for responsive Planner access.
- Explorer saved sites, recents, and map cache: Saved and recently viewed map locations, recently searched public map areas, and the last Explorer map view are stored in your browser's localStorage. This lets Explorer restore results without downloading them again on every visit. Shared Explorer links place the selected location name and coordinates in the URL you choose to share.
- Explorer notes, visited status, and custom sites: Personal notes, visited status, and custom sites are stored locally unless you explicitly choose to submit a custom site for community review. Personal notes are never submitted.
- Session handoff: Explorer may use sessionStorage to pass selected site details to Planner while you navigate between pages.
You can remove this data at any time by using the Planner controls (for example "Reset Plan" and deleting saved plans), or by clearing site data in your browser.
5. Data Security
Cloud plans, profile information, and logbook entries are private account data handled through authenticated server functions. Community data is protected by Firebase authentication, Firestore rules, and Cloud Storage rules. Pending photos are limited to their contributor and administrators; approved photos are public. No online system is perfectly secure; you are also responsible for securing your account and devices.
6. Retention and Deletion
Local data remains until you delete it or clear site storage. Cloud plans and logged dives remain until you delete them. Contributors can withdraw pending photos. Rejected, withdrawn, and removed image files are deleted, while limited moderation records may remain for audit and abuse prevention. Duplicate-request and rate-limit records are scheduled to expire after eight days. Operational logs follow the applicable cloud provider retention settings, and daily recovery backups are retained for 30 days. To request full account deletion or deletion of submitted community content, contact us from the account email with enough detail to identify the material.
7. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided personal information through the Service, contact us and we will address it.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last Updated" date above.
9. Contact Us
If you have questions about this Privacy Policy, contact us at jacknelsonnsb@gmail.com.