At a glance
  • We're a UK-based indie developer building DIVR — not a big tech company.
  • We collect what we need to run the App: your account info, your dives, your photos, and basic usage data.
  • We don't sell your data. We don't show ads.
  • You control who sees your dives through privacy settings, and you can delete your account anytime.
  • Some data is processed by Google (Firebase) and Apple to make the App work.

1. Introduction

This Privacy Policy explains how Rafferty Clarke Mathews ("we," "us," or "our") collects, uses, and protects your personal information when you use DIVR (the "App") and our related website at divrhq.com (together, the "Services").

DIVR is a social platform for scuba, free, and snorkel divers. The App lets you log your dives digitally, share them with followers, discover dive sites, and connect with other divers. To do this, we need to handle some personal information — including the content you post, the location of your dives, and the photos you share.

We've written this policy in plain English wherever we can. If you have questions, get in touch at hello@divrhq.com.

Who's responsible for your data

For UK and EU users, the "data controller" responsible for your personal information is Rafferty Clarke Mathews, based in the United Kingdom. You can reach the data controller at hello@divrhq.com.

What this policy covers

This policy applies to the DIVR iOS app and the divrhq.com website. It does not cover third-party services that the App connects to (like Apple Sign In, Google Sign In, or external map providers), which are governed by their own privacy policies. Where we name a third-party service in this policy, we'll link to their policy so you can read it directly.

When this policy applies

This policy applies from the moment you visit divrhq.com, sign up for the waitlist, download the App, create an account, or otherwise interact with our Services.

2. Information we collect

We collect information in three ways: information you give us directly, information we collect automatically when you use the Services, and information we receive from third parties.

Information you give us directly

Account information. When you create an account we collect your username, email address, and password (if you sign up with email). You can also add an optional display name, bio, and profile photo.

Your dive content. Every dive you log includes the data you enter — dive site name, date and time, depth, bottom time, water temperature, visibility, gear used, gas mix, notes, and any photos or videos you upload. You can also tag other DIVR users as dive buddies on a dive. You can only tag people who already have a DIVR account.

Photos and videos. When you upload a photo or video, we automatically strip the embedded metadata (EXIF data) such as GPS coordinates, camera model, and capture time before storing it. The photo itself is stored as you uploaded it; the hidden technical metadata is removed to protect your privacy.

Location data. When you pin a dive site, you provide its location (either by choosing a known site or by entering coordinates). You control the precision of locations you share through your privacy settings.

Logbook scan images. If you use the AI logbook scanning feature, you provide a photograph of a logbook page. As described in Section 6, we do not retain these images — they are processed by the AI service to extract dive data and then discarded.

Social activity. Comments you post, likes, follows, dive buddy tags, and similar interactions on the Services.

Communications with us. If you contact us at hello@divrhq.com, sign up to the waitlist on divrhq.com, or send a support request, we collect what you tell us, including your email address and the content of your message.

Information we collect automatically

Device and technical information. When you use the App, we automatically collect your device model, iOS version, app version, device language, and time zone. This helps us make the App work on your device and troubleshoot problems.

Usage data. Through Firebase Analytics, we collect information about how you use the App — which screens you visit, which features you use, how often, and for how long. This data is aggregated and used to understand what's working in the App and what needs improving.

Crash and diagnostic data. Through Firebase Crashlytics, we collect technical information when the App crashes — including the device state, what the App was doing, and a "stack trace" of the crash. This helps us fix bugs.

IP address and approximate location. Our infrastructure receives your IP address when you connect to our Services. We use this for security (e.g. to spot suspicious logins) and to route requests through Firebase's regional servers. From your IP we can infer your approximate location (country or region level), but we do not use this to determine your precise location.

Date and time of access. We log when you access the Services, which helps with security investigations and account recovery.

Information we receive from third parties

Sign-in providers. If you sign up using Apple Sign In or Google Sign In, those services share certain information with us:

We don't receive your Apple ID or Google password, and we don't get ongoing access to your Apple or Google account beyond what's needed to verify it's you.

Firebase Authentication. Firebase issues us an authentication token and a unique user ID when you sign in, which we use to identify your account on the back-end.

Cookies and similar technologies on divrhq.com

Our website uses a small number of cookies and similar technologies:

The website does not currently use third-party analytics, advertising, or tracking cookies. If we add any in the future, we will update this policy and ask for your consent where required.

What we don't collect

We don't collect health data, biometric identifiers, precise real-time location tracking, or data about your activity off DIVR. We don't integrate with Apple Health.

3. How we use your information

We use your information only for the purposes set out below. For each purpose, we've identified the "legal basis" under UK and EU data protection law (UK GDPR / EU GDPR) that gives us the right to process your data that way.

To run the App and provide your account

Contract

To create and maintain your account, save your dive logs, store your photos, show you your feed, let you follow other divers and tag dive buddies, and generally provide the features you signed up for.

To process logbook scans with AI

Contract

When you use the AI logbook scanning feature, we send your photo to Google Gemini (via Firebase AI Logic) to extract dive data, then discard the photo. We don't use scan images to train AI models. See Section 6 of the Terms of Service for more.

To send you essential service emails

Contract

Password resets, account verification, security alerts (e.g. a sign-in from a new device), changes to these Terms or this policy, and replies to your support questions. These are not marketing — they're emails you'd expect from any service you've signed up for.

To understand and improve the App

Legitimate interests

Through Firebase Analytics and Crashlytics, we collect usage and crash data to understand how the App is used, fix bugs, and improve features. We rely on our legitimate interest in running a working, evolving product. You can turn analytics and crash reporting off at any time in Settings → Privacy in the App.

To keep the App and our users safe

Legitimate interests

To detect and prevent fraud, abuse, spam, and security threats; to enforce our Terms of Service and Community Guidelines; and to investigate and respond to reports of content or conduct that breaks our rules.

To send you the waitlist launch email

Consent

If you signed up to the waitlist on divrhq.com, we'll send you one email when DIVR launches on the App Store. You can unsubscribe at any time. You gave us your consent when you submitted the form.

To send you product updates and feature announcements

Consent

From time to time we may email you about new features, dive-related stories, or other DIVR news. We'll only do this if you've opted in, and you can unsubscribe from any of these emails with one tap. Service emails (above) are separate and not affected by your marketing preferences.

To comply with the law

Legal obligation

To respond to lawful requests from public authorities, comply with tax and accounting requirements, respond to legal claims, and meet other legal obligations we're subject to.

What we don't do with your data

4. How we share information

We do not sell your personal information to anyone. We share information only in the specific situations described below.

With other DIVR users

DIVR is a social platform, so some of your information is shared with other users when you use the App. You control how much, and with whom, through your privacy settings.

You can change your account privacy setting and individual dive visibility at any time, but content already seen, screenshot, or saved by other users may continue to exist outside the App.

With our service providers (sub-processors)

We use a small number of third-party services to run DIVR. These providers process your data on our behalf, under contracts that require them to keep it safe and use it only as we instruct. The main ones are:

Google — Firebase

We use the Firebase platform (operated by Google) for most of the App's back-end, including:

  • Firebase Authentication — sign-in and account management
  • Cloud Firestore — storing your dive logs, profile, and other account data
  • Firebase Storage — storing your photos and videos
  • Firebase Analytics — understanding how the App is used
  • Firebase Crashlytics — diagnosing and fixing crashes
  • Firebase AI Logic (Google Gemini) — extracting dive data from your logbook scans (the scan image itself is not retained)
  • Firebase Cloud Messaging — delivering push notifications to your device

Google's handling of this data is governed by the Firebase Privacy and Security policy and the Google Privacy Policy.

Apple

Because DIVR is an iOS app distributed through the App Store, Apple is involved in several ways:

  • App Store — Apple processes app downloads and any future in-app purchases.
  • Sign in with Apple — if you sign in this way, Apple shares your name and email (or a private relay address) with us.
  • MapKit — when you view or pin a dive site, the App uses Apple Maps (via MapKit) to display map tiles and search for places. Apple may receive map-related requests from your device.
  • Apple's own App Analytics — Apple collects its own usage analytics at the device level, separate from anything we do, governed by your iOS privacy settings.

Apple's handling of this data is governed by the Apple Privacy Policy.

Google — Sign In

If you choose to sign in to DIVR with your Google account, Google processes your sign-in request and shares your name, email, and profile photo with us. Google's handling of this is governed by the Google Privacy Policy.

GitHub (GitHub Pages)

Our website divrhq.com is hosted by GitHub Pages (operated by GitHub, Inc., a subsidiary of Microsoft). When you visit our website, GitHub processes basic technical information needed to serve the site to your device, such as your IP address and browser type. GitHub's handling of this data is governed by the GitHub Privacy Statement.

Static Forms

The waitlist signup form on divrhq.com is processed by Static Forms, a third-party form-handling service. When you submit the form, your email address is sent to Static Forms, which delivers it to our email inbox and stores a copy in their dashboard until we send the launch email and remove the list (or you ask us to delete it earlier). Static Forms' handling of this data is governed by the Static Forms Privacy Policy.

GoDaddy and Microsoft (email)

Our contact email address hello@divrhq.com is provided by GoDaddy, which is powered by Microsoft 365. When you email us, the contents of your message and your email address are processed by GoDaddy and Microsoft to deliver the message to our inbox. Their handling of this data is governed by the GoDaddy Privacy Policy and the Microsoft Privacy Statement.

Outbound email delivery

To send essential service emails (password resets, security alerts) and, in the future, the launch announcement and any product update emails you've opted into, we will use a third-party email delivery service. We haven't chosen the provider yet; once we do, we will update this policy and name them here.

For legal and safety reasons

We may share information when we believe in good faith that it's necessary to:

Where legally permitted, we'll let you know about a request for your data before responding, so you have a chance to object.

In connection with a business transfer

If DIVR is ever involved in a merger, acquisition, sale of assets, or similar business transaction, your information may be transferred to the new owner as part of that transaction. If that happens, we'll let you know in advance, and the new owner will be bound to handle your data in a way that's at least as protective as this policy — or you'll be given the option to delete your account first.

Anonymous and aggregated information

We may share information that has been aggregated or fully anonymised — meaning it cannot be linked back to you — for things like community statistics ("most-logged dive sites this year") or research. This is not personal data and isn't subject to the rest of this policy.

5. Data storage & security

Where your data is stored

Your account data, dive logs, photos, and other content are stored on Google Firebase servers in the europe-west2 region (London, United Kingdom). Our website divrhq.com is hosted by GitHub Pages on their global CDN.

Some data is processed in other regions depending on the service — for example, Firebase Crashlytics may process crash diagnostics in the United States, and Apple's services may process data in the regions Apple operates. Where data leaves the UK or EU, it is transferred under safeguards approved by UK and EU data protection law (see Section 8 for more on international transfers).

How we keep your data safe

We take security seriously. The main measures we have in place are:

No service is 100% secure. We do everything we reasonably can to protect your data, but we can't guarantee perfect security. If a data breach ever affects your information, we'll notify you and the relevant authorities (such as the UK ICO) as required by law.

How long we keep your data

We keep your data only for as long as we need it. Different categories have different retention periods:

What happens when you delete your account

You can delete your DIVR account at any time from Settings → Account → Delete Account in the App.

When you delete your account:

Deletion is permanent. If you change your mind within the first 30 days, contact us at hello@divrhq.com and we may be able to restore your account from backup, but we can't guarantee it.

6. Your rights

You have meaningful rights over the personal data we hold about you. The exact rights depend on where you live, but most of them apply to everyone using DIVR. We've described them in plain English below.

Your rights under UK and EU data protection law

If you live in the UK or EU, you have all of the following rights under UK GDPR and EU GDPR:

How to exercise your rights

You can exercise most of your rights directly in the App:

For anything you can't do in the App — such as a formal access request, data portability export, or a question about how we use your data — email us at hello@divrhq.com with a brief description of what you're asking for.

What to expect when you make a request

Right to lodge a complaint

If you think we've handled your personal data unfairly or in breach of the law, please get in touch first so we can try to put it right. You also have the right to complain to a data protection authority:

If you live in California

If you're a California resident, you have similar rights under the California Consumer Privacy Act (CCPA / CPRA). The terminology is different but the rights largely mirror those described above:

To exercise these rights, email us at hello@divrhq.com. You may use an authorised agent to make a request on your behalf, in which case we'll need proof of authorisation.

7. Children's privacy

DIVR is not intended for children under 13. In some EU jurisdictions the minimum age is 16, or whatever minimum age is required by your local law, whichever is higher.

We do not knowingly collect personal information from anyone below the minimum age. If we discover that we've collected information from someone below the minimum age, we will close the account and delete the associated information.

If you're a parent or guardian and you believe your child has created a DIVR account without your consent, please email us at hello@divrhq.com so we can take action quickly. To manage how a minor in your household uses iOS apps, we recommend using Apple Family Sharing and parental controls, which give you tools to approve downloads, restrict content, and manage screen time.

Where required by local law, we will not process the personal information of a minor for marketing purposes or for purposes that go beyond what's needed to provide the App.

8. International users and data transfers

DIVR is operated from the United Kingdom, and we primarily store your data on servers in the UK (see Section 5). But the App relies on services from Google and Apple, which sometimes process data in other countries — most notably the United States. This section explains how that works and what protections are in place.

Where your data may be processed

Your personal data may be processed in the following places:

Safeguards for international transfers

When your personal data is transferred outside the UK or EU, we make sure it's protected by appropriate safeguards under UK GDPR and EU GDPR:

You can request more information about any of these safeguards by emailing hello@divrhq.com.

If you're using DIVR from outside the UK or EU

DIVR is designed to work for divers anywhere in the world. If you use the App from outside the UK or EU, your data will still be stored primarily on servers in the UK, and processed in line with this Privacy Policy and UK data protection law. By using the App, you understand and agree that your information will be transferred to and processed in the UK and the other regions described above.

If your country's law gives you additional rights — for example, under Brazil's LGPD, Australia's Privacy Act, or any state-level US privacy law — those rights still apply, and you can exercise them by contacting us at hello@divrhq.com.

9. Changes to this policy

We may update this Privacy Policy from time to time — for example, when we add new features, change how we handle data, or update our list of service providers. When we do, we'll always update the "Last updated" date at the top of this page so you can see when the most recent change was made.

For material changes — meaning changes that significantly affect how we collect, use, or share your personal information — we'll give you advance notice through one or more of the following, where available:

Where the law requires it, we'll ask for your fresh consent before the change takes effect.

Continued use of DIVR after a change to this policy takes effect means you accept the updated policy. If you don't agree with a change, you can delete your account at any time from Settings → Account → Delete Account, and your data will be removed in line with Section 5.

10. Contact us

If you have questions about this Privacy Policy, want to exercise your rights, or just want to talk through anything about how we handle your data, please get in touch.

Rafferty Clarke Mathews
Email: hello@divrhq.com

We aim to reply to all privacy-related enquiries within five working days, and to formal data requests within the timeframes set out in Section 6.