Privacy policy
Last updated 2026-09-28
This describes what BubbleSong Diving World stores about you, why, who else can see it, and how to take it back. It is written from the code: every claim here corresponds to something the application does, and where the application is careful we say exactly how.
What we hold
Only what you give us or create by using the service. There is no advertising identifier, no profile bought from anyone, and nothing inferred about you from elsewhere.
- Your email address. It is how you sign in and it is never shown to another diver.
- If you sign in with Google: the name and profile picture address Google hands over. The picture address is stored and never displayed — a public profile shows your diver character instead, so viewing a profile never contacts Google.
- A username you choose, which is public. We suggest one made of ordinary diving words; it is never derived from your email address.
- Your profile: a short description, country, certification agency and level, and — only if you choose to state it — gender.
- Your dives: date and time, depth, duration, water temperature, visibility, current, gas, weights, notes, the site, and the equipment you used.
- Photos you upload, and separately their camera, lens and capture time. Coordinates are read from a photo only if you have turned that on; it is off unless you turn it on.
- What you write in public: posts, comments, likes, saved items, shop reviews, condition reports, site names you propose.
- Plans and trips, including who is in them and the messages in that thread.
- Technical records: your signed-in devices (browser description and when each was last used), and counters that stop one account flooding the site.
- Preferences: units, currency, time zone, language.
Photographs, specifically
A photo from a camera or a phone usually carries hidden metadata, and that metadata often includes where it was taken. Two things happen to every image you upload.
First, the file we store has every application and comment segment removed. Camera, lens, time and location are gone from the bytes themselves, so an image that ever escaped would say nothing about where you were.
Second, the camera and capture time are recorded separately in our database, because they describe the photograph. Coordinates are recorded only if you switched on "Store GPS from photo EXIF" in settings. That switch is off for every new account.
A photo is exactly as visible as the dive it is attached to. One on a private dive is served through a route that asks who is asking, not by a guessable link.
Why we hold it
To run the thing you signed up for, and nothing else. Your dives make your logbook and your statistics. Your public writing appears where you published it. Your email delivers the sign-in link. Device records exist so you can see where you are signed in and end a session you do not recognise. The counters exist so one account cannot flood the site.
We do not profile you, sell anything about you, or use your data to train anything.
Who can see it
You decide, per category, in settings: your profile, your dives, your statistics and your equipment can each be public, visible to people who follow you, or private. New dives are private unless you change the default.
Some things are never shown to another diver whatever you choose: your real name, your email address, your phone number, your stated gender, and your account role. That is enforced in one place in the code rather than by remembering it on each page.
A trip or a plan shows a member only the dives they were already allowed to see, so joining one never widens anything.
Who processes it for us
These companies hold or handle data on our behalf. They act on our instructions and for no other purpose.
- Vercel — runs the site.
- Neon — the database. It is hosted in the United States, so your data is stored outside Korea. Signing up is your consent to that transfer; if you would rather not, do not create an account.
- Resend — delivers sign-in emails. It receives your email address and the link, and nothing else.
- Google — only if you choose to sign in with Google, and only for that.
- Cloudflare R2 — stores uploaded files.
- Open-Meteo supplies forecasts. We send it the coordinates of a dive site. It receives nothing about you.
How long
Your account and everything in it stay until you delete them. Deletion is immediate and it is not a flag — the rows are removed and the stored files with them.
Signed-in sessions expire 90 days after they start, or sooner if you end them. A sign-in link stops working after fifteen minutes, and the record of it — which holds the address it was sent to — is removed by the daily housekeeping, whether or not the link was used. The counters that limit posting are discarded after two days. Records of moderation decisions are kept, without the identity of a deleted account attached to them, because a removal that leaves no trace cannot be reviewed.
What you can do about it
All of this is in settings, and none of it requires asking us.
- See and take it: "Download my data" gives you one file containing everything the account holds — dives, plans, trips, posts, comments, equipment, settings, sign-in history, and the details of every photograph. The pictures themselves are not inside it: the file lists each one with the address it can be downloaded from while you are signed in.
- Correct it: edit your profile, your dives and your posts directly.
- Delete it: "Delete my account" removes it immediately and permanently. Download your data first if you want to keep it.
- Narrow it: change any visibility setting at any time, and turn photo coordinates off.
- End a session: sign out any device from the list in settings.
What deleting your account leaves behind
Everything that is yours goes: dives, photos and the stored files, plans, trips, posts, comments, reviews, equipment, settings, sessions.
A few things stay, and they stay without your name on them: a dive site you added to the map, a name you proposed for one, a group dive other divers attached their own logs to, and a dive another diver logged with you as their buddy. Other people depend on those now. Removing them would delete part of someone else's logbook, so instead the link to you is cut — on that last one their own note of who they dived with stays, and it stops pointing at you.
If you are the only owner of a dive shop, we will not delete your account until the shop has another owner or is removed — a shop page with nobody in charge is one nobody can correct or answer.
How it is protected
There are no passwords to steal: you sign in with a one-time link or with Google, so we never hold a password.
The address you connect from is never stored. What is stored is a keyed hash of it, which lets you recognise your own sessions and tells us nothing about where you are.
The session identifier shown in your device list is a hash of the real one; the real one never leaves the server.
Everything written by one person and read by another is escaped before it reaches a page, and a test fails the build if a new place starts writing HTML directly without going through that. The policy the site sends also refuses images and connections to anywhere but this origin, so a script that did run would have nowhere to send what it read.
Age
This service is not for children under 14. If you are under 14, please do not create an account. If we learn that an account belongs to someone under 14, we will delete it.
Changes
If this policy changes in a way that affects you, the new version appears here with a new date before it takes effect.
Who to contact
- Operator
- BubbleSong
- bubblesongscuba@gmail.com