Privacy Policy
Last updated: 23 September 2026
1. Who is responsible
Felix Rief, trading as Rief Digital Apps (Einzelunternehmen), Herbert-Weichmann-Straße 8, 22085 Hamburg, Germany. Email: privacy@loggerfish.com.
No data protection officer is required at this size (§ 38 BDSG: fewer than 20 people processing personal data). Supervisory authority: the Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg.
2. What we process, why, and on what legal basis
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Account data: email address, password (stored only as a hash), optional display name | Create and secure your account, let you sign in | Art. 6(1)(b) — performing the contract |
| Your log: dives, sites, sightings, conditions, gas, notes, trips, gear, certifications, dive target, settings | Provide the logbook, statistics, sync between your devices | Art. 6(1)(b) |
| Names you enter about other people (buddies, instructors) and identifiers such as certification or member numbers | Part of your own log. You are responsible for entering only what you are comfortable recording; we use it only to show it back to you | Art. 6(1)(b) |
| Emergency contact, optional: the name, phone number and relationship of the person you want called if something happens to you | Show it on the SOS screen of your devices so a buddy or boat crew can reach them. Only you can read it; it is never shown to other users. It is kept on your device, and also in your account while you are signed in | Art. 6(1)(b) for you; for the contact person, Art. 6(1)(f) — the legitimate interest of you and them in being reachable in an emergency. We do not write to that person about this entry: we hold nothing but what you typed, and contacting them would take more data than we have (Art. 14(5)(b)) |
| Subscription data: plan, status, renewal date, payment reference (not card numbers) | Give you Pro features, handle billing and accounting | Art. 6(1)(b), Art. 6(1)(c) — legal duty to keep accounting records |
| Reviews you publish: the site, your rating and text, the name you choose to show, the date you dived it, the language | Show your review publicly to everyone, with that name. Nothing else from your account or log is shown | Art. 6(1)(b) |
| Reports you send about a review, and moderation decisions | Keep reviews lawful and on topic, act on reports, prevent spam | Art. 6(1)(f) — legitimate interest; Art. 6(1)(c) where the EU Digital Services Act requires it |
| Usage statistics, unless switched off in Settings or your browser asks not to be tracked: which screens are opened, counts of actions (a dive logged, an import run), plan tier, settings chosen, device category, approximate location (country, region, city) derived from the IP address, which is not stored. No cookies, no identifier stored on your device, never the content of your log | Learn which features are used, to decide what to improve | Art. 6(1)(f) — legitimate interest in improving the app with data that does not identify you. § 25 TDDDG does not apply, because nothing is stored on or read from your device for this |
| Website visit counts, unless your browser asks not to be tracked: which page of loggerfish.com was opened, the referring site, device category and approximate location derived from the IP address, which is not stored. No cookies, nothing stored on your device, never the address's query part. Same statistics server as the app | Know which pages and languages are read, and where visitors come from | Art. 6(1)(f), as for usage statistics |
| Feedback you choose to give: a 1–5 rating, an optional comment, feature suggestions; stored with your account and your plan, never shown alongside your log | Understand why features are or aren't used | Art. 6(1)(a) — you choose to send it; Art. 6(1)(f) for the rating counted in usage statistics |
| Technical data: IP address and request logs, kept briefly | Keep the service secure and working, detect abuse | Art. 6(1)(f) — legitimate interest |
| Support messages | Answer you | Art. 6(1)(b) or (f) |
| Waitlist or newsletter email address, if you sign up | Send what you asked for | Art. 6(1)(a) — consent, withdrawable at any time |
We do not sell your data, do not use it for advertising, and do not make decisions about you by automated means. Your dive log is never used to train AI models, by us or by anyone else.
3. Who receives data
We use service providers who process data on our instructions under data-processing agreements. This list is what the product actually uses:
- Database, sign-in and API: Supabase, project hosted in the EU (Frankfurt). Holds your account and, while you are signed in, your log.
- Website and app hosting: Cloudflare Pages serves loggerfish.com and app.loggerfish.com, and sees the IP address of every request as any web host does.
- Map tiles: Thunderforest (Gravitystorm Limited, United Kingdom). When a map is on screen, your device asks their servers for the map images, so they see your IP address and which map squares you looked at — which for the tiles is roughly where you are looking, not where you are. Tiles already seen are kept on your device, so the same map costs no further requests. If a build of the app is ever configured without a tile key, it falls back to OpenStreetMap's own tile servers instead; that is a misconfiguration rather than the intended setup, and the same paragraph applies to them.
- Payments: Stripe for the website; Apple for purchases made in the iPhone app, and Google Play once the Android app sells subscriptions. They handle the payment details; we receive only the subscription status and a reference.
- Email delivery: Brevo, operated by SENDINBLUE, a French société par actions simplifiée, 17 rue de Salneuve, 75017 Paris, France, RCS Paris 498 019 298. It sends the messages the service is obliged to send you — above all the confirmation of a withdrawal, which § 356a BGB requires us to send on a durable medium, so the legal basis for that one is Art. 6(1)(c), a legal obligation, not consent. Brevo receives your email address and the content of that message. Sign-in emails come from Supabase's own sender.
- Email to and from our own addresses: IONOS SE, Germany, hosts the mailboxes behind support@loggerfish.com and privacy@loggerfish.com, so a message you send us is stored on their servers as any email is.
- Usage statistics: Umami, run by us on a server rented from Hetzner Online GmbH, Germany (hosting only) — no analytics company receives the data.
- Error reporting: none. Nothing is sent anywhere when the app hits a problem.
3a. Searching for dive sites near you
When you use Search nearby to find dive sites around you, your device asks the OpenStreetMap Overpass API (overpass-api.de, run by Roland Olbricht in Germany) for the dive sites in a radius, and sends the coordinates it is searching around in order to do it.
Be aware of what this one sends. If you have not typed coordinates in yourself, the app asks your device for your position first, so the coordinates sent are where you actually are, not the part of a map you happen to be looking at. Overpass also sees your IP address, as any server you contact does. It sends back public map data and nothing that identifies you, and nothing about your logbook, your account or your name is sent with the query.
Overpass is a free public service, not a company we have engaged: it acts for itself, not on our instructions, so there is no data-processing agreement with it and we cannot make commitments on its behalf. We send the query only because you asked for a search, which is the legal basis for it (Art. 6(1)(b)); the feature is never used on its own. If you would rather not have your position leave your device, do not use Search nearby — everything else in the app works without it, and you can always type a site name or its coordinates yourself.
4. Transfers outside the EU/EEA
- Thunderforest is in the United Kingdom, which the European Commission has recognised as providing an adequate level of protection, so no further safeguard is needed for that transfer. Should that recognition lapse, we will move the transfer onto Standard Contractual Clauses or stop using the service.
- Cloudflare, Stripe, Apple and Google are US companies. Their agreements with us carry the European Commission's Standard Contractual Clauses, and each of them is additionally certified under the EU–US Data Privacy Framework.
5. How long we keep data
- Account and log: until you delete your account. Deletion in the app is immediate and cascading.
- Deletions made on one device are kept for 30 days as a marker, so your other devices learn that the dive was deleted, and are then removed entirely.
- Backups: the provider's own window, up to 90 days.
- Usage statistics: 24 months, then deleted.
- Feedback: until you delete your account. Reviews: until you delete the review or your account.
- Reports about a review: until the review is deleted, or six months after a moderation decision.
- Payment events received from Stripe are kept 90 days, only to recognise a repeat.
- Unconfirmed waitlist addresses: 30 days.
- Accounting records: as long as German tax and commercial law requires — currently up to ten years (§ 147 AO, § 257 HGB).
- Server logs: as short a period as the provider allows, in the order of days.
6. Your rights
You can ask for access (Art. 15), correction (16), deletion (17), restriction (18), a portable copy (20), and object to processing based on legitimate interests (21). In the app you can export everything — as an Excel file, as UDDF (the format other dive logbooks read), or as a full backup — and delete your account yourself. You can withdraw consent at any time. You may complain to a supervisory authority, for example the one in your federal state.
We answer within one month. Contact: privacy@loggerfish.com.
7. Website and app storage
The website and app store your settings (theme, language, your log while offline) on your device.
Photographs stay on your device. Dive photos and videos, and the photo of a certification card you add to show at a dive centre, are stored only in your browser's storage on that device: they are not uploaded, not in the account, not in backups taken by us, and not in the Excel export.
Map images you have looked at are kept for a while so maps work offline and cost no further requests; nothing in them identifies you. This is needed for the service you asked for and is not used for tracking. Usage statistics store nothing on your device except whether you switched them off, and use no cookies. The app also remembers on your device when it last asked for feedback, so it doesn't ask again too soon. Fonts are self-hosted, and the app loads no script from anyone else's server.
8. Age
Loggerfish is for people aged 16 or over.
9. Changes
We will tell you about material changes by email or in the app before they apply.
← Loggerfish