Privacy Policy

Last updated August 22, 2026

In short

We collect your email, the dive data you enter, and basic billing status. We never see your card number, and photo GPS coordinates are stripped in your browser before upload. We don't sell your data or run advertising. You can export everything or delete your account at any time.

1. Who we are

Fishbros LLC operates Scuba Diving Logbook at scubadivinglogbook.com. For data protection law we are the controller of the personal data described here. Questions or requests: fishbrosllc@gmail.com.

2. What we collect

DataWhere it comes fromWhy
Email address and passwordYou, at sign-upTo create your account, verify it, sign you in, and send essential service messages. Passwords are held by AWS Cognito and stored hashed — we never see them.
Dive records — dates, sites, coordinates, depths, times, conditions, buddies, equipment, creatures, notes, ratingsYou, or a file you importTo store your logbook and show it back to you.
PhotosYou, on the paid planTo attach images to a dive or a certification card.
Certifications and insurance details, including card imagesYou, on the paid planTo keep your credentials to hand.
Subscription status and billing identifiersStripeTo know which plan you are on and to handle renewals. We store a Stripe customer/subscription identifier and plan state.
Technical and log data — IP address, timestamps, error logsAutomatically, when you use the ServiceSecurity, abuse prevention, debugging, and reliability.

Location data

Dive coordinates are only ever stored if you type them or use the “use my location” button on the coordinates field, which asks your browser for permission first and fills in the field for you to review. You can edit or clear it before saving. We do not track your location in the background.

3. What we deliberately do not collect

  • Card numbers. Payment details go directly from your browser to Stripe. We never receive or store your full card number, CVC, or expiry.
  • Photo metadata. Every image is re-encoded in your browser before upload, which removes all EXIF data — including GPS coordinates, camera serial numbers, and timestamps. That metadata never reaches our servers.
  • Advertising and cross-site tracking. We do not run ad networks, third-party trackers, or advertising cookies, and we do not build advertising profiles.
  • Special category data. Please do not record medical or health information in free-text fields; the Service is not designed to hold it.

4. Why we use it, and our legal basis

For users in the UK, EEA, and Switzerland, our lawful bases under the GDPR are:

  • Performance of a contract — operating your account, storing your dives, providing paid features, and processing payments.
  • Legitimate interests — keeping the Service secure, preventing abuse, debugging, and improving reliability. We balance these against your rights.
  • Legal obligation — retaining billing and tax records.
  • Consent — where you explicitly opt in, such as sharing a dive publicly or granting browser location access. You can withdraw consent at any time.

We do not sell your personal data, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws.

5. Who processes your data

We keep the list short on purpose. These providers act as our processors and may only handle your data on our instructions.

ProviderWhat it handles
Amazon Web ServicesAuthentication (Cognito), database (DynamoDB), photo storage (S3), application hosting and logs.
StripePayment processing and subscription management. Stripe is an independent controller for its own payment and fraud-prevention purposes; see its privacy policy.

We may also disclose data where legally required, to enforce our Terms, to protect rights and safety, or as part of a merger or acquisition — in which case we will give notice before your data becomes subject to a different policy.

6. Dives you choose to share

Sharing is off by default. If you mark a dive as shared, that dive's details and photos become viewable by anyone with the link, without signing in, and a preview image may be generated for it. Your email address is never included. Turning sharing off prevents new visits, but we cannot recall copies already made or cached elsewhere.

7. How long we keep it

  • Account and dive data — until you delete it or close your account.
  • After account deletion — removed from live systems promptly, with residual copies in encrypted backups purged on our normal backup rotation (up to 35 days).
  • Photos — deleted when you delete the photo, the dive, or your account. Photos may also be removed after a grace period if a paid subscription lapses.
  • Billing records — retained as long as tax and accounting law requires, typically 7 years, even after account deletion.
  • Security and error logs — typically 90 days.

8. Security

Data is encrypted in transit with TLS and at rest by our infrastructure providers. Passwords are hashed by AWS Cognito. Photo access uses short-lived signed URLs that expire rather than permanently public links. Access to production data is limited to those who need it.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant supervisory authority where the law requires it.

9. Where your data is stored

The Service is hosted on AWS in US East (N. Virginia), us-east-1. If you use it from outside that region, your data is transferred there. For transfers out of the UK/EEA we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with our providers' supplementary safeguards.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our use of your personal data; to receive a portable copy; and to withdraw consent. Most of these you can exercise yourself, immediately:

  • Access and portability — export your complete logbook as JSON, CSV, XLSX, or PDF from the Import & export page.
  • Correction — edit any dive or profile field directly.
  • Deletion — delete individual dives, or your whole account and its data, from Settings.

For anything else, email fishbrosllc@gmail.com. We respond within 30 days (45 days in the US where permitted). We will not discriminate against you for exercising these rights.

UK/EEA users may complain to their local supervisory authority. California residents have rights under the CCPA/CPRA to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal data as those terms are defined, and you may use an authorised agent.

11. Cookies and local storage

We use no advertising or analytics cookies. We use browser storage strictly to make the Service work:

  • Session tokens — to keep you signed in.
  • Preferences — units, time format, theme, and which form fields you have enabled.
  • Guest drafts — dives entered without an account, which stay on your device until you sign up or clear them.

These are strictly necessary, so no consent banner is required. Clearing browser data signs you out and discards guest drafts.

12. Children

The Service is not intended for children under 13, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes to this policy

We may update this policy. If a change materially affects how we use your personal data, we will give notice by email or in the app before it takes effect. The “last updated” date at the top always reflects the current version.

14. Contact

Fishbros LLC
5700 Grover Ave. Unit 1133 Austin, TX 78756
fishbrosllc@gmail.com