Privacy Policy
Son güncelleme: 2026-08-03
1. Data controller
The controller of personal data processed in this app is Sefa Ekin. Address: Türkiye (açık adres, talep hâlinde e-posta ile bildirilir). Requests: [email protected].
This policy is prepared under Turkish Personal Data Protection Law No. 6698 (KVKK).
2. Data we process
Only what you enter into the app:
- Account: email address and password. We never see your password — our identity provider stores it hashed. If you enable two-factor authentication, the authenticator secret is stored as well.
- Optional profile: username, full name, profile photo, bio, city, Instagram handle, certification level, agency and specialties.
- Phone number: only if you add one. Required for certain actions such as creating events. Your number is NOT stored in the public part of your profile but in a separate, closed table; only you and an authorised administrator can see it. Other users cannot see your number.
- Certification document: only if you upload one. It is not public; it is kept in a separate closed area and opened only to an authorised reviewer through a single-use link valid for at most 5 minutes.
- Your dive logs: date, duration, maximum depth, water temperature, visibility, dive type, tank pressure, suit thickness, marine life observed, notes and dive buddies.
- Content you share: post text, photos, blog articles, comments and messages.
- Interactions: likes, follows, favourites and notification records.
- Referrals: your referral code and who invited you.
3. Data we do not collect
These are deliberate choices, not omissions:
- Your location. When you tap "find me" on the map, your device location is read solely to centre the map. It is not stored, not sent to our servers, and not shared with anyone.
- Advertising identifiers, tracking pixels or cookie-based ad tracking.
- Third-party analytics or crash reporting services.
- Payment or card details. There are no in-app purchases.
- Your contacts, calendar, or data from other apps on your device.
4. Data that stays on your device
These are kept only on your phone and never sent to a server: your language preference, your light/dark theme preference, and your recent search history. You can clear the search history from within the app.
5. Where data goes
- Hosting and authentication: Supabase. Your account, content and uploaded files are stored there.
- Weather and sea conditions: Open-Meteo. When you view conditions for a dive site, the coordinates of THAT SITE are sent. Your identity, account and location are not.
- Maps: maps are rendered via Apple Maps on iOS and Google Maps on Android. Viewing map tiles is subject to those providers' own terms.
- Translation: when YOU TAP the "Translate" button under a post or blog article, only the text of that content is sent to the Anthropic (Claude) translation service. There is no automatic translation; nothing is sent unless you ask for it. Your identity, account and other data are not sent. The result is stored on our server so the same content is not sent again.
- Beyond this, no data is transferred to third parties, sold, or shared for marketing. Disclosure to authorities where legally required is reserved.
6. Content moderation and community rules
Shared content is subject to community rules. Posts, comments, blog articles and messages containing inappropriate language are blocked automatically BEFORE publication; this check runs on your device and the text is not sent anywhere for this purpose.
Every post, blog article, comment and user can be reported. Reported content goes to moderators for review. You can block a user from their profile or from the chat screen; you will not see their content and they cannot reach you.
Content that breaks the rules is removed and repeat accounts are closed.
7. Who sees what
- Your profile, username and posts are visible to other users.
- Each dive log can be marked individually as "public" or "only me".
- Your messages are visible only to the parties in the conversation.
- Your verification document is shown to no user; only an authorised reviewer can access it.
- Your following and follower lists are visible only to you and to an administrator.
8. Retention and deletion
Your data is retained for as long as your account exists. You can delete content you have shared individually from within the app.
You can delete your account yourself from within the app: Profile > Security > "Delete My Account". Deletion is immediate and permanent; your profile, dive log, posts, messages and uploaded files are removed irreversibly. No approval step, no email required.
You may also write to [email protected] if you prefer; in that case the request is fulfilled within 30 days at the latest.
If your account is suspended for rule violations, your email and phone are kept in a separate record to prevent re-registration. That record is deleted when the suspension is lifted.
9. Your rights (KVKK art. 11)
You have the right to learn whether your personal data is processed, to request information if it is, to learn the purpose of processing, to know the third parties to whom it is transferred domestically or abroad, to request correction if incomplete or inaccurate, to request erasure or destruction, to request that such actions be notified to third parties, to object to adverse outcomes arising from automated analysis, and to claim compensation for damages.
Send requests to [email protected].
10. Security
All connections are encrypted (HTTPS). The database enforces row-level access control: each record is reachable only by those authorised for it. You can protect your account with two-factor authentication (TOTP).
11. Changes
Changes to this policy are published on this page. Last updated: 2026-08-03.