SafetyStop
Developed by Divers, for Divers
Privacy Policy
SafetyStop does not track you — no analytics SDK, no attribution framework, no advertising identifier — and shows no ads.
The short version. Your dive log lives on your phone. An account is optional and free. Cloud sync — a copy of your log on a SafetyStop server so it follows you to another device — is a paid subscription bought through Apple. Nothing is sold, and the only outside services that ever receive anything are named on this page: Apple (your purchase, and vouching for the app behind Send Feedback), OpenStreetMap and SSI, each only in the cases described.
Using the app without an account
- Your dives, diver profile and equipment profiles are stored only on your device, and you can export the whole log to a file and import it back at any time.
- Your dive log is not transmitted anywhere. Each time it opens, the app asks safetystop.cloud whether there is a service notice to show; that request carries nothing about you or your log, and the server sees only your IP address, as with any web request. Beyond that, three features reach the internet without an account, and only when you ask: naming the body of water you are diving in, the optional Dive Sites download, and Send Feedback.
If you create an account
Every account stores your email address, used to identify the account and to send verification messages (re-sent at most once a day while you use the app unverified), password-reset links and a notice when your password changes — never marketing; a bcrypt hash of your password, never the password itself; the dates the account was created, verified and last signed in; and a record of failed sign-in attempts against your address.
Everything else reaches the server only through cloud sync, which is a paid subscription:
- Your dive log — site names, dates, depths, times, gas mixes, equipment, buddy names and notes exactly as you typed them.
- Dive site coordinates, when you have used Use My Location.
- Your diver profile (name, birthday, agency, certification number, body weight — all optional), your equipment profiles and your profile picture, if you set one. Body weight is optional and is there because the Weight Calculator can start from it: it is stored as the number you typed and the unit you chose, it is never used for marketing, and like every other profile field it syncs to your account and is deleted with it.
- Your dive photographs, if you add them. They are resized before they leave your device, and the server strips every camera tag — including any GPS location your camera wrote into the file — before storing them. You can add and remove them in the iPhone app and on this website.
Without a subscription the account still signs in, dives it synced before stay readable (photos are listed but their images are not served), and nothing new is stored from your device.
Share links
You can create a share link for one dive. Anyone holding it sees that dive's fields (date, site, depth, time, gas, conditions, buddy and notes), its coordinate if you included it, its photographs if you included them, and its depth profile — nothing else from your log, and not your name.
Another subscriber who opens the link can save a copy of the dive (fields and profile, never photographs) into their own logbook. That copy is theirs: you are not told it was made, it does not follow your edits, and it is not removed when you revoke the link or when your account is suspended or deleted. Copies can be made only while your subscription is active or in its grace period.
Never uploaded
A photo of your certification card stays on your device. It is never sent to the server and is not in the app's backup file.
Location
SafetyStop reads your location only when you tap Use My Location on the dive form, never in the background. The coordinate names the body of water and sets salt or fresh water for the gas calculations. It is stored with that dive and goes to the server with it if the dive syncs.
Naming the water may involve a request to OpenStreetMap's Overpass and Nominatim services, which are run by third parties and receive the coordinate in order to answer. This happens only when the offline data bundled with the app cannot name the water. Their privacy practices are their own.
On the website, a dive with a coordinate can show a map of the site. Nothing is loaded until you tap Show map; then map images are requested from OpenStreetMap, which sees the approximate location of the dive, your IP address, and that the request came from safetystop.cloud — not which page or which dive you had open. Apart from those map images, your browser talks only to SafetyStop on this website.
MySSI codes. If your diver profile names SSI as your agency and carries a certification number, the website builds MySSI codes for your dives. To fill in the SSI dive site, SafetyStop's server asks my.divessi.com for sites within about 2 km of each dive that has a coordinate and a site name. SSI receives that area and SafetyStop's server address — not your name, your IP address or your site name. Leave the agency or the number blank to prevent it.
The optional Dive Sites download
Tools → Dive Sites offers a database of dive site names and coordinates so the site field and Use My Location work with no signal. Opening that screen asks safetystop.cloud whether a newer file exists; that request carries nothing about you or your log, and the server sees only your IP address, as with any web request. Nothing is downloaded until you tap Download, and you can delete the file from the same screen. It is built from OpenStreetMap and Wikidata data, contains no personal data, and nothing about which sites you search for or dive is sent anywhere.
How your data is protected
- All communication with the server uses HTTPS; the app refuses an unencrypted connection.
- Your session token lives in the iOS Keychain, encrypted by the device and excluded from unencrypted backups. A password you save for Face ID or Touch ID is kept there too, protected by your biometry, and becomes permanently unreadable if a new face or fingerprint is enrolled.
- Every dive, photo and profile is keyed to the account that owns it, so one account cannot read or modify another's. The one exception is operator access, below.
Your certification number, if you enter one, is stored as ordinary text.
Operator access
The person who runs this service, and anyone they give operator access to, can look at accounts to answer a support request. An operator can see a list of every account: email address, when it was created and last signed in, whether the address is verified, subscription status, whether it is suspended or a deletion is pending, and how many dives it holds. An operator can also find an account by the name or the certification number on its diver profile. Opening one account shows those details and the dive log itself, including coordinates, buddy names and notes. Operators can also see aggregate figures across all accounts — counts, medians, and site and water names typed by at least two different divers — never anything more per account than the above.
That includes your coordinates. A coordinate says where you were, on a date, at a time. If a dive site is somewhere you would rather nobody could ever read, leave the coordinate off that dive and type the site name instead.
An operator cannot see your password or any dive photograph, and cannot publish a share link, edit or delete a dive, or sign in as you.
What an operator can change
An operator can do seven specific things to an account, and nothing else:
- Send the verification email again.
- Send a password-reset email. Both go to your address, never to the operator, who cannot see or use the link inside.
- Grant or remove free, unlimited cloud sync (given by hand rather than bought through Apple).
- Cancel a pending account deletion at your request.
- Suspend the account: it stops saving changes and your shared dives come off the web, but you can still sign in, read and export everything, and close the account yourself. Lifting the suspension puts the shared dives back.
- Close the account: you can no longer sign in and cannot undo it yourself. Only an operator can reopen it, within 90 days, so email support@safetystop.cloud if it happened by mistake; after that it is erased like any other deletion.
- Reopen an account closed that way, within those 90 days. Share links do not come back; they are gone the moment the account is closed.
Every look and every action is recorded — who, which account, when, what was done, and whether coordinates were among what was seen. Those records are kept after the account is deleted and contain nothing from your dives. Operator access is granted only by the owner of the service.
Deleting your data
Logging out removes the session from your device. With cloud sync, deleting a dive removes it from your log on every device (each device keeps it in Recently Deleted for 30 days first); the server keeps the deleted dive's contents out of sight until the account itself is erased. Without cloud sync the app cannot delete a dive while you are signed in: it tells you so, and the dive stays on your device (and on the server, if it had synced) until you delete the account or have cloud sync again. Signed out, deleting a dive moves it to Recently Deleted on your device, where it is erased after 30 days unless you restore it or delete it permanently; nothing leaves the device.
Deleting your account
You do this yourself: in the iPhone app under Tools → Sync & Backup → Delete Account, or on the web after signing in. It asks for your password and a second tap. Export a backup first if you want to keep your log. If you email support@safetystop.cloud from the account's address instead, an operator closes the account for you — which locks you out at once, as described under Close the account above — so delete it yourself if you want the 90 days below.
The moment you ask, every share link you created stops working (a holder sees the same not-found page as a made-up link) and the account stops accepting changes.
For 90 days the account is closed but recoverable. You can still sign in, read your log, export a backup, and cancel the deletion from the banner at the top of the page. Cancelling brings your dives back untouched — but not your share links, which cannot be restored; make new ones.
After 90 days, what is stored on the server is erased: every dive with its notes, coordinate and profile graph; every photo and its image file; your diver profile and picture; your equipment profiles; your sessions, reset and verification tokens, and the record of failed sign-in attempts against your address; and the account itself with your email address and password hash. Erasure is run by hand, so it happens on or after the ninetieth day, not exactly on it.
Three things outlive the account:
- Apple's billing notices, if you ever paid for cloud sync — a renewal, a lapse, a refund — kept so a later payment dispute can be answered. Each holds a transaction identifier, the dates, what happened, and the account's internal number, which after erasure refers to nothing. No dive, photo, coordinate, name or email address is part of it.
- The record of what an operator did to your account, described above. Of your data it holds only the account's internal number.
- Feedback you sent. Send Feedback does not use your account, so it is not linked to you. A record holds the text you typed, the name from your diver profile if you set one, the app build and iOS version, and an installation identifier that proves the message came from the real app (the app asks Apple to vouch for it) and cannot be turned back into you or your device.
Your subscription is separate. Deleting the account does not cancel a subscription; cancel it in your iPhone's Apple settings, before or after. The dives already on your phone are not deleted, and the email address cannot register a new account until the old one has been erased.
Children
SafetyStop is not directed at children under 13 and does not knowingly collect their information.
Changes
If this policy changes in a way that affects what is collected or where it goes, the app will say so before the change takes effect. The date at the top is the current version.