Privacy Policy
Effective August 30, 2026. Dive Log & Planner is a dive logbook and planning application for iPhone, iPad, and Mac. This policy explains what information the App handles, when information leaves your device, and the choices available to you.
The App does not contain advertising, does not track you across apps or websites, does not sell personal information, and does not require a Dive Log & Planner account.
1. Information you add to the App
Depending on the features you use, the App may store:
- dive dates, times, profiles, depths, temperatures, gases, equipment, decompression, and planning information;
- dive-site names, coordinates, trips, operators, marine-life sightings, and conditions;
- buddy names and optional photos selected from Contacts;
- notes, tags, certifications, body measurements, preferences, and photos;
- records imported from a dive computer, Apple Health, or files you select; and
- saved plans and model settings learned from your own dives.
This information is used to provide the logbook, planning, import, export, conditions, and personalization features you request. It is not sent to Sentry or used for advertising.
2. Storage, iCloud, imports, and exports
Logbooks are stored in the App's private storage on your device. The App does not operate its own account system or hosted logbook database.
If a version of the App supports iCloud sync and Settings reports that sync is On, the open logbook is also stored in your private Apple CloudKit database so Apple can synchronize it between your devices. If Settings reports sync is Off, the logbook remains local to that device. Apple's handling of iCloud data is governed by Apple's privacy policy and your iCloud settings.
The App accesses an import file, export location, photo, or folder only after you select it through an Apple system picker. Imported content is copied into the logbook as needed. Exported files are placed where you direct them and are thereafter controlled by you and the storage provider you selected.
3. Apple permissions and device services
The App asks for access only when you use a related feature:
- Location: A one-time location request can center a map or place a dive-site pin. The App does not continuously monitor your location in the background. Coordinates saved to a site remain in your logbook. If you request weather or tides, the data described in Section 4 is sent to the relevant provider.
- Maps: Apple MapKit may receive the map region or saved site coordinates needed to display map imagery. The App does not publish a dive site to a public map service.
- Health: On iPhone and iPad, you can authorize read-only access to Apple Health diving workouts, underwater depth, and water temperature. The App does not write to Apple Health. Imported values become ordinary logbook records and are not sent to Sentry or the conditions providers.
- Contacts: On iPhone and iPad, Apple's contact picker lets you select one contact at a time. The App copies that contact's displayed name, contact identifier, and available photo into the current logbook. It does not upload your address book or read contacts you did not select.
- Photos and files: You may select images and logbook files for import. The App does not scan your photo library or file system without your selection.
- Bluetooth: The App communicates directly with a nearby dive computer to download data. Dive-computer records are not sent over the internet by that feature.
You can change these permissions in Apple System Settings. Some related features will no longer work after permission is withdrawn.
4. Network-backed conditions and species features
The App makes a network request only when needed for a feature you use, including:
- Apple WeatherKit: Receives a dive site's coordinates and the requested date or time to return weather conditions.
- NOAA Tides and Currents: Receives a tide-station identifier and requested date. The App downloads NOAA's station list and selects the nearest station on your device.
- Worldwide tides: For this Premium feature, the App sends the dive-site coordinates, local date, and an Apple-signed Premium purchase entitlement to a Dive Log & Planner service hosted on Cloudflare. The service verifies the entitlement and forwards only the coordinates and date to WorldTides. It does not send WorldTides your dive log, notes, contact information, or signed purchase entitlement. Tide responses are not retained in a server-side application database. Cloudflare may retain a sampled invocation log containing request and network metadata for up to seven days; the service does not log the request body or authorization header in application code.
- Marine-life lookup: Search terms are sent to iNaturalist, the World Register of Marine Species (WoRMS), and Encyclopedia of Life (EOL). When the App displays a result photo, the image host receives the ordinary information associated with an internet request, such as IP address and device network information. The App does not post observations or create an account with these providers.
These providers may process request metadata, including an IP address, according to their own privacy policies. The App caches some WeatherKit and NOAA responses on your device to improve performance and reduce repeated requests.
5. Purchases
Premium subscriptions and purchases are processed by Apple through StoreKit. The developer does not receive your payment-card details. The App reads Apple's signed transaction status to unlock purchased features. When you request worldwide tides, the signed entitlement is sent to the Dive Log & Planner Cloudflare service solely to verify access as described in Section 4.
6. Crash reports and technical diagnostics
The App uses Sentry and Apple's MetricKit to identify crashes, hangs, excessive CPU use, excessive disk writes, and related reliability problems. Diagnostic events may include:
- crash stack traces and technical error information;
- App version, operating-system version, device model, and coarse runtime state; and
- performance and reliability measurements supplied by MetricKit.
Sentry is configured not to collect default personal information. The App disables Sentry screenshots, view hierarchies, accessibility identifiers, automatic and network breadcrumbs, failed-network-request capture, memory introspection, source-code uploads, and general performance tracing. Raw MetricKit payload attachments are also disabled. Dive profiles, sites, coordinates, notes, contacts, Health data, imported files, photos, and StoreKit transactions are not intentionally included in diagnostic events.
Sentry is configured to prevent storage of IP addresses. Diagnostic data is used only to operate, secure, debug, and improve the App. It is not linked to your identity and is not used for advertising or tracking. Sentry retains diagnostic events according to the retention period configured for the developer's Sentry account, after which they are deleted.
Apple may separately make aggregated performance information available when users have chosen to share diagnostics with app developers. Apple's processing is governed by Apple's privacy policy and your device analytics settings.
7. Mac local integration server
On Mac, you may choose to enable the App's Model Context Protocol (MCP) server. It listens only on your Mac's loopback interface and makes the open logbook available to software you explicitly configure as a client. The App does not expose that server directly to the public internet.
An MCP client, AI assistant, bridge, or model provider may transmit requested logbook data off your Mac under that provider's own terms and privacy policy. Review the client's configuration and privacy practices before enabling this feature. You can disable the server at any time in the App's settings.
8. Sharing and disclosure
The developer does not sell or rent personal information and does not share it for targeted or cross-context behavioral advertising. Information is disclosed only:
- to the processors and providers described above when necessary to perform a feature you request;
- when you export or otherwise direct the App to share information;
- when required by law or necessary to protect rights, safety, or the security of the App; or
- as part of a business transfer, subject to continued protection under this policy and applicable law.
9. Retention and deletion
Logbook information remains on your device until you delete the applicable item or logbook, erase the App's data, or uninstall the App. Copies you exported remain where you placed them. If iCloud sync is enabled, deletion is synchronized through CloudKit, subject to Apple's normal backup and retention practices.
On-device weather, tide, and image caches may be removed automatically by the operating system or when you remove the App. Server-side diagnostic and sampled request metadata are retained only as described in Sections 4 and 6 or as necessary for security, abuse prevention, legal compliance, and dispute resolution.
10. Security
The App uses Apple platform protections, encrypted HTTPS connections for network requests, private app storage, and access controls provided by Apple and the listed service providers. No method of storage or transmission is completely secure, but the App is designed to limit collection and avoid transmitting logbook content except when required by a feature you choose.
11. Your choices and privacy rights
You can:
- decline or revoke Location, Health, Contacts, Photos, Files, or Bluetooth permissions;
- avoid network-backed conditions and species searches;
- keep iCloud sync off where that option is available;
- disable the Mac MCP server;
- delete individual records or entire logbooks; and
- uninstall the App to remove its local container from the device.
Depending on where you live, you may also have rights to request access, correction, deletion, restriction, portability, or objection concerning personal information controlled by the developer, and to appeal or complain to a privacy regulator. Contact the developer using the address below. Because Sentry diagnostics are not linked to an account or direct identifier, the developer may be unable to associate a diagnostic event with a particular person.
For users in the European Economic Area, United Kingdom, and similar jurisdictions, the developer processes the limited off-device information described here as necessary to provide requested App features, based on legitimate interests in reliability and security, and, where required, with your consent. Service providers may process information in the United States or other countries subject to their contractual and legal safeguards.
For California residents, the developer does not sell or share personal information for cross-context behavioral advertising and has not done so in the preceding 12 months.
12. Children
The App is not directed to children under 13, and the developer does not knowingly collect personal information from children under 13. If you believe a child has provided information to the developer, please use the contact information below.
13. Third-party privacy information
- Apple Privacy Policy
- Sentry Privacy Policy
- Cloudflare Privacy Policy
- NOAA Privacy Information
- iNaturalist Privacy Policy
- World Register of Marine Species
- Encyclopedia of Life Terms of Use
- WorldTides
14. Changes to this policy
This policy may be updated when the App's features or data practices change. The effective date at the top will be revised, and material changes will be communicated as required by law. Your continued use of the App after an update is subject to the updated policy.
15. Contact
Questions, support requests, or privacy requests may be sent to support@divelogandplanner.com.