SafetyStop

SafetyStop

Developed by Divers, for Divers

Privacy Policy

Last updated 25 September 2026

SafetyStop does not track you — no analytics SDK, no attribution framework, no advertising identifier — and shows no ads.

The short version. Your dive log lives on your phone. An account is optional and free. Cloud sync — a copy of your log on a SafetyStop server so it follows you to another device — is a paid subscription bought through Apple. Nothing is sold, and the only outside services that ever receive anything are named on this page: Apple (your purchase, and vouching for the app behind Send Feedback), OpenStreetMap and SSI, each only in the cases described.

Using the app without an account

If you create an account

Every account stores your email address, used to identify the account and to send verification messages (re-sent at most once a day while you use the app unverified), password-reset links and a notice when your password changes — never marketing; a bcrypt hash of your password, never the password itself; the dates the account was created, verified and last signed in; and a record of failed sign-in attempts against your address.

Everything else reaches the server only through cloud sync, which is a paid subscription:

Without a subscription the account still signs in, dives it synced before stay readable (photos are listed but their images are not served), and nothing new is stored from your device.

Share links

You can create a share link for one dive. Anyone holding it sees that dive's fields (date, site, depth, time, gas, conditions, buddy and notes), its coordinate if you included it, its photographs if you included them, and its depth profile — nothing else from your log, and not your name.

Another subscriber who opens the link can save a copy of the dive (fields and profile, never photographs) into their own logbook. That copy is theirs: you are not told it was made, it does not follow your edits, and it is not removed when you revoke the link or when your account is suspended or deleted. Copies can be made only while your subscription is active or in its grace period.

Never uploaded

A photo of your certification card stays on your device. It is never sent to the server and is not in the app's backup file.

Location

SafetyStop reads your location only when you tap Use My Location on the dive form, never in the background. The coordinate names the body of water and sets salt or fresh water for the gas calculations. It is stored with that dive and goes to the server with it if the dive syncs.

Naming the water may involve a request to OpenStreetMap's Overpass and Nominatim services, which are run by third parties and receive the coordinate in order to answer. This happens only when the offline data bundled with the app cannot name the water. Their privacy practices are their own.

On the website, a dive with a coordinate can show a map of the site. Nothing is loaded until you tap Show map; then map images are requested from OpenStreetMap, which sees the approximate location of the dive, your IP address, and that the request came from safetystop.cloud — not which page or which dive you had open. Apart from those map images, your browser talks only to SafetyStop on this website.

MySSI codes. If your diver profile names SSI as your agency and carries a certification number, the website builds MySSI codes for your dives. To fill in the SSI dive site, SafetyStop's server asks my.divessi.com for sites within about 2 km of each dive that has a coordinate and a site name. SSI receives that area and SafetyStop's server address — not your name, your IP address or your site name. Leave the agency or the number blank to prevent it.

The optional Dive Sites download

Tools → Dive Sites offers a database of dive site names and coordinates so the site field and Use My Location work with no signal. Opening that screen asks safetystop.cloud whether a newer file exists; that request carries nothing about you or your log, and the server sees only your IP address, as with any web request. Nothing is downloaded until you tap Download, and you can delete the file from the same screen. It is built from OpenStreetMap and Wikidata data, contains no personal data, and nothing about which sites you search for or dive is sent anywhere.

How your data is protected

Your certification number, if you enter one, is stored as ordinary text.

Operator access

The person who runs this service, and anyone they give operator access to, can look at accounts to answer a support request. An operator can see a list of every account: email address, when it was created and last signed in, whether the address is verified, subscription status, whether it is suspended or a deletion is pending, and how many dives it holds. An operator can also find an account by the name or the certification number on its diver profile. Opening one account shows those details and the dive log itself, including coordinates, buddy names and notes. Operators can also see aggregate figures across all accounts — counts, medians, and site and water names typed by at least two different divers — never anything more per account than the above.

That includes your coordinates. A coordinate says where you were, on a date, at a time. If a dive site is somewhere you would rather nobody could ever read, leave the coordinate off that dive and type the site name instead.

An operator cannot see your password or any dive photograph, and cannot publish a share link, edit or delete a dive, or sign in as you.

What an operator can change

An operator can do seven specific things to an account, and nothing else:

Every look and every action is recorded — who, which account, when, what was done, and whether coordinates were among what was seen. Those records are kept after the account is deleted and contain nothing from your dives. Operator access is granted only by the owner of the service.

Deleting your data

Logging out removes the session from your device. With cloud sync, deleting a dive removes it from your log on every device (each device keeps it in Recently Deleted for 30 days first); the server keeps the deleted dive's contents out of sight until the account itself is erased. Without cloud sync the app cannot delete a dive while you are signed in: it tells you so, and the dive stays on your device (and on the server, if it had synced) until you delete the account or have cloud sync again. Signed out, deleting a dive moves it to Recently Deleted on your device, where it is erased after 30 days unless you restore it or delete it permanently; nothing leaves the device.

Deleting your account

You do this yourself: in the iPhone app under Tools → Sync & Backup → Delete Account, or on the web after signing in. It asks for your password and a second tap. Export a backup first if you want to keep your log. If you email support@safetystop.cloud from the account's address instead, an operator closes the account for you — which locks you out at once, as described under Close the account above — so delete it yourself if you want the 90 days below.

The moment you ask, every share link you created stops working (a holder sees the same not-found page as a made-up link) and the account stops accepting changes.

For 90 days the account is closed but recoverable. You can still sign in, read your log, export a backup, and cancel the deletion from the banner at the top of the page. Cancelling brings your dives back untouched — but not your share links, which cannot be restored; make new ones.

After 90 days, what is stored on the server is erased: every dive with its notes, coordinate and profile graph; every photo and its image file; your diver profile and picture; your equipment profiles; your sessions, reset and verification tokens, and the record of failed sign-in attempts against your address; and the account itself with your email address and password hash. Erasure is run by hand, so it happens on or after the ninetieth day, not exactly on it.

Three things outlive the account:

Your subscription is separate. Deleting the account does not cancel a subscription; cancel it in your iPhone's Apple settings, before or after. The dives already on your phone are not deleted, and the email address cannot register a new account until the old one has been erased.

Children

SafetyStop is not directed at children under 13 and does not knowingly collect their information.

Changes

If this policy changes in a way that affects what is collected or where it goes, the app will say so before the change takes effect. The date at the top is the current version.

Contact

support@safetystop.cloud