#SKWADE Privacy Policy
Version: 2.0 Effective Date: 10 July 2026 Previous Version: 1.0 (superseded)
#Version History
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | Initial | Initial publication covering account, dive log, dive computer, Digital Passport, certifications, medical documents, library, marine life observations, device, location, weather and AI processing. |
| 2.0 | 10 Jul 2026 | Full legal review. Aligned with current SKWADE architecture: Ocean Knowledge (Marine Guide, Coral Guide, Dive Sites), Ocean Observations, Ocean Media Engine, Collections, Achievements, Statistics, Digital Wallet, Sync Engine v1.0, Post-Processing Framework, Runtime CMS, Ocean CMS, Assets Library, Feature Management, Professional Accounts. Rewritten Security, Synchronization, Third-Party Services and Legal Basis chapters. Added Community Content and Copyright chapters. Clear separation between current features and planned roadmap. Harmonized terminology with the SKWADE Terms of Service. |
#Table of Contents
Part I — Introduction
- Introduction
- Scope of this Privacy Policy
- Definitions
- Privacy Principles
Part II — Personal Data We Collect
- Account Information
- Profile & Identity Information
- Emergency Contacts, Medical Information & Insurance
- Certifications
- Digital Passport
- Dive Log Data
- Dive Computer & Synchronization Data
- Ocean Knowledge & Ocean Observations
- Ocean Media Engine
- Geolocation & Dive Sites
- Collections, Achievements & Statistics
- Library, Photos, Videos & Documents
- Digital Wallet
- Notifications & Communications
- Professional Accounts & Dive Centers
- Premium Subscriptions & Payments
- Feature Management
- Device, Analytics & Crash Reports
- Artificial Intelligence Processing
Part III — How We Use, Share and Protect Information
- Purposes and Legal Basis
- Sharing with Other Users
- Third-Party Service Providers
- Legal Disclosures and Business Transfers
- Security Measures
- Cookies, Local Storage and Session Tokens
- International Data Transfers
- Data Retention
Part IV — Your Rights and Final Provisions
- User Rights (GDPR, UK GDPR, CCPA/CPRA, PDPA, PIPA and others)
- Children
- Community Content
- Copyright and Attribution
- Future Modules and Planned Features
- Contact
- Changes to this Privacy Policy
#Part I — Introduction
#1. Introduction
#1.1 Welcome
Welcome to SKWADE. SKWADE is a digital platform designed to support divers throughout their underwater journey, providing tools for dive logging, digital certifications, dive planning, marine life documentation, learning, synchronization with compatible dive computers and other diving-related services.
Because many of these Services involve personal information, protecting your privacy is fundamental to everything we build.
#1.2 Our Commitment
Privacy is a core design principle of SKWADE. We are committed to:
- collecting only the information reasonably necessary to provide our Services;
- being transparent about how information is used;
- giving users meaningful control over their data;
- protecting personal information through appropriate technical and organizational security measures;
- respecting applicable privacy laws around the world.
#1.3 Purpose of this Privacy Policy
This Privacy Policy explains what personal information SKWADE collects, why we collect it, how we use it, when we share it, how long we retain it, how we protect it, and the rights available to you.
It applies to the use of all SKWADE Services unless a separate privacy notice expressly applies.
#1.4 Privacy by Design
SKWADE is developed using Privacy by Design principles, including secure authentication, encrypted communications, user-controlled sharing, configurable privacy settings, minimal data collection, secure cloud storage, role-based access controls, row-level database security and signed URLs for private media.
#1.5 Related Documents
This Privacy Policy should be read together with the SKWADE Terms of Service, the Cookie Policy, the Data Retention Policy, the Community Guidelines, the AI Transparency Statement, the Security Overview and any other documents published within the SKWADE Legal Center.
#2. Scope of this Privacy Policy
#2.1 Services Covered
This Privacy Policy applies to your use of all SKWADE Services, including:
- the SKWADE Mobile Apps (iOS and Android);
- the SKWADE Web Application;
- future Desktop Apps distributed by SKWADE, when made available;
- the SKWADE Admin Portal, used by SKWADE staff and authorized administrators;
- the SKWADE Professional Portal, used by dive professionals and Dive Centers, when made available;
- the Digital Passport and its Wallet integrations (Apple Wallet and Google Wallet);
- any related APIs, background services, synchronization connectors, notification services and support channels operated by SKWADE.
#2.2 Devices
This Privacy Policy applies whenever you access SKWADE using compatible devices, including smartphones, tablets, desktop computers and, where supported, dive computers connected through our synchronization framework.
#2.3 Users Covered
This Privacy Policy applies to individual divers, holders of Professional Accounts and, subject to their own contractual terms, Dive Centers and organizations using SKWADE.
#2.4 Services Not Covered
This Privacy Policy does not apply to third-party websites, applications or services that we do not operate, even when they are accessible from within SKWADE. When you interact with a third-party service, that provider's own privacy policy applies.
#3. Definitions
For the purposes of this Privacy Policy, the following terms have the meaning set out below.
- SKWADE — the digital platform operated by SKWADE, comprising the Mobile Apps, Web Application, Admin Portal, Professional Portal, Digital Passport, synchronization connectors, and related services.
- Services — all products, features, applications and integrations provided by SKWADE.
- User — any natural person who accesses or uses the Services.
- Personal Data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, restriction, erasure or destruction.
- Digital Passport — the personal, identity-bearing surface of SKWADE aggregating your certifications, achievements, collections, statistics and observation summaries, and exposing them through a Passport ID, QR code and Wallet passes.
- Ocean Knowledge — the SKWADE editorial and scientific corpus covering the Marine Guide, the Coral Guide, Dive Sites, and, on the roadmap, Marine Plants, Habitats and Ocean Articles.
- Marine Guide — the SKWADE catalogue of marine species, including scientific and common names, taxonomy, distribution and media.
- Coral Guide — the SKWADE catalogue of coral taxa, following the same editorial model as the Marine Guide.
- Dive Sites — geolocated diving locations, including operator-provided and user-observed data.
- Ocean Observations — user-recorded observations of marine species and corals linked to a dive, a location and, optionally, media.
- Ocean Media Engine — the automated pipeline that enriches Ocean Knowledge content with images and other media from approved providers, subject to licensing, attribution and editorial validation.
- Collections — user-facing progress trackers for species, corals, countries and dive sites.
- Achievements — automatically evaluated badges recognizing diving milestones and Ocean Knowledge progress.
- Statistics — computed aggregates covering diving activity, marine life, travel, passport and observations.
- AI Assistant — the current in-app assistant that answers diving-related questions on request; it does not make legal, medical or safety decisions.
- Sync Engine — the connector-agnostic synchronization architecture (Sync Engine v1.0) governing every current and future dive-computer or provider integration.
- Runtime CMS — the delivery layer that serves published editorial content to the Mobile Apps and Web Application.
- Ocean CMS — the authoring and moderation layer used by SKWADE editors and administrators to curate Ocean Knowledge.
- Assets Library — the single storage layer for all media used by SKWADE, whether user-uploaded, editorial or provider-imported.
- Feature Management — the internal system that governs the availability, gating (including Premium) and progressive rollout of features across the Services.
- Dive Centers — professional organizations operating Dive Center Profiles within SKWADE.
- Professional Accounts — accounts held by dive instructors, guides, managers, staff or other diving professionals with elevated capabilities in SKWADE.
- Third-Party Provider — an independent organization providing infrastructure, tools or content that support the operation of SKWADE.
#4. Privacy Principles
SKWADE processes Personal Data in accordance with the following principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability; and user control.
Wherever technically feasible, users remain in control of their Personal Data and may access, correct, export, restrict or delete it as described in Chapter 32.
#Part II — Personal Data We Collect
#5. Account Information
#5.1 Purpose
We collect account information to create and secure your SKWADE account, provide the Services, authenticate you across devices, and comply with our legal obligations.
#5.2 Data Collected
- Identity: first name, last name, and, where required, date of birth.
- Contact: email address (used as your authentication identifier).
- Credentials: password (hashed and salted; never stored in plain text) and, where applicable, third-party identity provider identifiers (for example Google sign-in).
- Account metadata: internal user identifier (immutable UUID), account creation date, last sign-in, session tokens, security events and audit records.
#5.3 Identity Architecture
Your account is identified internally by an immutable UUID. SKWADE never uses email addresses as an identity, authorization or business-logic key. Email changes flow exclusively through authenticated account updates and are propagated automatically to your profile.
#6. Profile & Identity Information
#6.1 Purpose
Profile information personalizes your experience, populates your Digital Passport and enables features such as sharing with buddies.
#6.2 Data Collected
- profile photograph (optional);
- nationality (optional);
- home region or country (optional);
- language preferences;
- diving experience and preferences;
- equipment preferences;
- accessibility and display preferences.
#6.3 Visibility
Every profile field is subject to granular privacy controls. Fields are hidden by default unless you explicitly share them (see Chapter 25).
#7. Emergency Contacts, Medical Information & Insurance
#7.1 Purpose
Emergency contacts, medical information and insurance data support safety during diving activities. These categories are treated with the highest confidentiality.
#7.2 Data Collected
- primary and secondary emergency contacts (name, relationship, phone, optional secondary phone and email);
- medical information (blood type, allergies, chronic conditions, current medications, organ donor status);
- DAN membership details;
- insurance policy (provider, policy number, holder name, 24 h emergency phone, coverage region, validity, notes).
#7.3 Special Categories of Personal Data
Medical information constitutes a special category of Personal Data under the GDPR and equivalent laws. It is processed strictly on the basis of your explicit consent, is stored in a dedicated table protected by strict row-level security, and is never shared by default.
#7.4 Sharing
All safety and medical fields are governed by independent, opt-in privacy flags. Defaults are OFF. You may choose to expose selected fields to confirmed dive buddies or to your public Digital Passport, and you may revoke that consent at any time.
#8. Certifications
#8.1 Purpose
Certification data enables SKWADE to display your qualifications, populate the Digital Passport, aggregate diving progression and, where you choose, share credentials with buddies or Dive Centers.
#8.2 Data Collected
- issuing agency, certification name and level;
- certification number (optional);
- issue date and, where applicable, validity date;
- instructor information (optional);
- uploaded certification images or PDF documents (optional).
#8.3 Storage and Access
Certification images are stored in the Assets Library behind private access controls and delivered through short-lived signed URLs. Sharing is per-certification and per-field, and defaults to private.
#9. Digital Passport
#9.1 Purpose
The Digital Passport is a personal, identity-bearing surface that consolidates your diving journey.
#9.2 Data Included
- Passport ID: a stable, unique identifier used to reference your Passport within SKWADE and on Wallet passes;
- QR Code: an encoded representation of the Passport ID used for in-person verification;
- Certification aggregation: a summary of your active certifications;
- Collections, Achievements and Statistics: automatically computed progress and milestones;
- Observation summaries: aggregated counts of species and coral observations, when you choose to share them.
#9.3 Apple Wallet and Google Wallet
Where Premium is enabled, you may install the Passport as a signed pass on Apple Wallet or Google Wallet. Passes contain the same fields as the in-app Passport, subject to the same privacy flags. Pass updates are pushed through the respective Wallet issuer APIs. Wallet passes are governed by Apple's and Google's own privacy notices for their Wallet services.
#9.4 Sharing Controls
Every Passport section is governed by an opt-in privacy flag. No field is shared unless you explicitly enable it.
#10. Dive Log Data
#10.1 Purpose
Dive Log data is the historical record of your dives. It is processed to display your dives, compute statistics and achievements, populate Collections, and, where applicable, feed the Digital Passport.
#10.2 Manual Dives
Data you enter manually may include: date, time, dive site, buddy, boat, dive type, entry and exit methods, environmental conditions, depth, duration, temperature, visibility, gas mixtures and consumption, ratings and personal notes.
#10.3 Imported Dives
Dives may also be imported from compatible dive computers or third-party accounts through the Sync Engine (see Chapter 11).
#10.4 Ownership
Every dive belongs to a single owner — your SKWADE account. Ownership is enforced by the Ownership Registry within the Sync Engine and by row-level security policies.
#10.5 Synchronization and Conflict Resolution
When the same dive is imported from multiple sources, the Sync Engine's Smart Merge deduplicates entries and, when conflicts arise, either applies a deterministic reconciliation rule or presents the conflict in the Import Inbox for your decision. User edits always take precedence over automatic decisions.
#10.6 Audit History
Every meaningful change to a dive is recorded in dive audit records so you retain full traceability of the sources and modifications applied to your log.
#10.7 Associated Media
Dives may be linked to photographs, videos and observations. Linked media are subject to the rules of Chapter 16 and the Ocean Media Engine (Chapter 13).
#11. Dive Computer & Synchronization Data
#11.1 Purpose
Dive Computer Data enables SKWADE to import dive information from compatible devices and third-party accounts.
#11.2 Sync Engine v1.0
All synchronization is governed by the frozen Sync Engine v1.0 architecture, which enforces observability, resumability, ownership and a single termination path.
#11.3 Current Connectors
- SSI — synchronization of certifications and dives from SSI accounts;
- Garmin — synchronization of dive activities from Garmin Connect;
- libdivecomputer — direct import from a wide range of supported dive computers through the bundled libdivecomputer library.
#11.4 Future Connectors
Additional connectors are planned on the roadmap (for example Suunto, Shearwater, PADI, Subsurface, Oceanic+, Apple Watch). Any such connector will reuse the Sync Engine architecture and will only implement authentication, transport and provider-to-canonical parsing. This Privacy Policy will govern such connectors automatically.
#11.5 Data Collected
- provider account identifiers and OAuth tokens or API keys stored in the SKWADE Secrets Vault (encrypted with AES-256-GCM);
- device information (make, model, firmware, serial number where exposed);
- dive activity metadata and per-dive samples (depth profile, temperature, tank pressure, alarms) where provided;
- synchronization telemetry: sync runs, per-step timings, retry counts, error messages, and the deterministic result summary generated by the Sync Engine.
#11.6 Ownership Registry, Sync History, Conflict Handling
- Ownership Registry ensures each imported dive is bound to a single account.
- Sync History exposes every synchronization session and its outcome.
- Conflict Handling surfaces duplicates and mismatches in the Import Inbox.
- Deleted Data: dives you delete are removed from the log; the Sync Engine records the deletion to prevent unintended re-import.
- Partial Synchronization: when a run cannot complete fully, the engine reports partial success and the remaining work is safely resumed or retried without duplication.
#11.7 Heavy Post-Processing
Long-running post-import work (for example FIT profile extraction) is dispatched to the Post-Processing Framework and runs outside the synchronization request to avoid runtime limits. The same privacy rules apply.
#11.8 Credentials Vault
Provider credentials are never persisted in plain text. They are stored in the SKWADE Secrets Vault, encrypted at rest and reachable only by privileged server-side code.
#12. Ocean Knowledge & Ocean Observations
#12.1 Ocean Knowledge
Ocean Knowledge is SKWADE's editorial and scientific corpus. Currently it covers:
- Marine Guide — marine species, with scientific and common names, taxonomy and distribution;
- Coral Guide — coral taxa;
- Dive Sites — geolocated diving locations.
Planned additions include Marine Plants, Habitats and Ocean Articles. Planned content is not available in the current Services and no data related to it is collected until it is released.
Ocean Knowledge editorial descriptions are managed by SKWADE editors through the Ocean CMS. Third-party encyclopedic textual content (such as Wikipedia articles) is never imported, copied, summarized or rewritten into SKWADE editorial descriptions.
#12.2 Ocean Observations
You may record observations of species and corals encountered during a dive.
Data collected includes:
- reference to the observed species or coral;
- association with a dive (date, location, country, region, depth);
- optional photographs and personal notes;
- optional descriptive fields (behaviour, life stage, quantity).
#12.3 Uses
Ocean Observations feed your Digital Passport, Collections, Achievements and Statistics. Aggregate, non-identifying observation data may be used to improve Ocean Knowledge editorial coverage. Individual observations are never shared without your explicit action.
#13. Ocean Media Engine
#13.1 Purpose
The Ocean Media Engine automatically enriches Ocean Knowledge content with high-quality media from approved providers, so that Marine Guide, Coral Guide and Dive Sites entries can be illustrated without manual work per entry.
#13.2 Approved Providers
Current approved media providers are:
- Wikimedia Commons — free-licence media (CC BY, CC BY-SA, CC0, public domain);
- GBIF — biodiversity media, restricted to compatible open licences.
Wikipedia is not used as a source of editorial text.
#13.3 Licensing, Credits and Attribution
Only media distributed under acceptable open licences are imported. For every imported asset SKWADE records and displays:
- the source provider and record identifier;
- the source URL;
- the licence and, where available, the licence URL;
- the author or rights holder and, where required by the licence, the attribution notice.
#13.4 Editorial Validation, Moderation, Replacement and Removal
Imported media are scored and classified automatically, then subject to editorial validation through the Ocean CMS. Editors may accept, reject, replace or remove any media at any time. Manual editorial decisions always override automatic choices.
#13.5 Storage
All Ocean Media are stored through the SKWADE Assets Library. There is no duplicated media storage.
#13.6 Future Community and Partner Media
The Ocean Media Engine is designed to support community-submitted media and partner-provided media in the future. Such capabilities are on the roadmap and are not currently open to end-user submissions.
#13.7 Personal Data
Ocean Media generally does not contain Personal Data about SKWADE users. Where attribution names third parties, the data displayed is limited to what the source licence requires.
#14. Geolocation & Dive Sites
#14.1 Purpose
Geolocation enables features such as nearby dive sites, "Seen Around You", location-based recommendations and, on the roadmap, weather integration.
#14.2 Permission
Location is never requested automatically. It is only requested when you activate a feature that needs it, and you may revoke the permission at any time from your device settings.
#14.3 Precision
We use the lowest precision reasonably required by the feature you activate. Coarse location may be used for regional recommendations; precise location is used only when strictly necessary (for example to determine the nearest dive sites in the vicinity).
#14.4 Dive Sites
Data related to dive sites includes visited sites, favourite sites, nearby sites, observation statistics per site, and personalized recommendations.
#14.5 Future Weather Integration
Planned weather features would fetch environmental data (sea and surface conditions) for the location of a dive. When released, they will be governed by this Privacy Policy and by the applicable third-party provider notice.
#15. Collections, Achievements & Statistics
#15.1 Collections
Collections are personal progress trackers covering species, corals, countries and dive sites. Collections are derived from your dives and observations and are visible only to you unless you choose to share them via the Digital Passport.
#15.2 Achievements
Achievements are computed automatically from your activity. They produce badges and progress indicators. Achievements are informational only; they never produce automated legal, contractual or safety decisions concerning you.
#15.3 Statistics
SKWADE computes the following statistics from your data:
- Dive Statistics — number of dives, depth, duration, gases;
- Species and Coral Statistics — observations, distinct taxa, rarity;
- Travel Statistics — countries, regions, dive sites;
- Passport Statistics — aggregate summary for the Digital Passport;
- Observation Statistics — density, recency, seasonal patterns;
- Progress Statistics — evolution of the above over time.
Statistics are computed for you and are not shared unless the corresponding Passport privacy flags are enabled.
#16. Library, Photos, Videos & Documents
#16.1 Purpose
The Library is your personal storage area within SKWADE for documents (certifications, insurance, medical records), photos, videos and other files.
#16.2 Storage
All Library content is stored in the Assets Library. Private items are served through short-lived signed URLs; public items are served through immutable CDN URLs.
#16.3 Metadata
Uploaded photos may contain metadata (EXIF), including capture date and, where present, GPS coordinates. You may strip or edit metadata within the app.
#16.4 Sharing
Library items are private by default. You may explicitly share individual items with buddies or attach them to a dive, an observation or your Passport.
#16.5 Retention and Deletion
Library items remain available until you delete them or until your account is deleted. Deleted items are removed from active storage and purged from backups in accordance with our retention schedule.
#16.6 Cloud Storage Downgrade Policy
Where a Premium subscription is downgraded, SKWADE applies the published Cloud Storage Downgrade Policy: your content is retained in a grace state and never silently destroyed; you are notified before any restriction takes effect.
#17. Digital Wallet
#17.1 Purpose
The Digital Wallet integration provides signed passes for Apple Wallet and Google Wallet that mirror your Digital Passport.
#17.2 Data Included
Passes contain your Passport ID, QR code, the fields explicitly shared through Passport privacy flags, and a signature ensuring authenticity.
#17.3 Third-Party Wallet Providers
Apple Wallet and Google Wallet operate under their own terms and privacy notices. SKWADE only pushes the object payload that you have chosen to expose on your Passport.
#17.4 Digital Identity
Wallet passes are diving credentials only. They do not constitute a government-issued identity document.
#18. Notifications & Communications
#18.1 Channels
SKWADE may send you:
- Push notifications (Mobile Apps);
- In-app Inbox messages;
- Emails relating to service, security, subscription or, with your consent, marketing.
#18.2 Categories
- Reminders (e.g. incomplete dive log entries);
- Synchronization notifications (e.g. successful or failed sync runs);
- Ocean notifications (e.g. editorial updates or achievements);
- Security alerts and legal notices.
#18.3 Preferences
You may configure notification preferences per channel and per category from the app settings. Transactional and security notifications may be sent regardless of marketing preferences to the extent permitted by law.
#19. Professional Accounts & Dive Centers
#19.1 Professional Accounts
Professional Accounts are held by dive instructors, guides and other diving professionals. They may include additional profile fields such as instructor credentials, teaching languages and specialty certifications.
#19.2 Dive Centers
Dive Center Profiles represent professional organizations. They may include contact information, opening hours, services offered, media, and lists of managers, staff, instructors and, where applicable, customers.
#19.3 Roles
Dive Centers may operate with a role hierarchy (Managers, Staff, Instructors, Customers). Each role has scoped access enforced by SKWADE's server-side authorization model.
#19.4 Bookings
Where Dive Centers use booking features, information related to booked activities (dates, participants, requested services) is processed to deliver those services.
#19.5 Future CRM
A dedicated Customer Relationship Management module for Dive Centers is on the roadmap. When released, it will be governed by this Privacy Policy and by a specific processing addendum where required.
#20. Premium Subscriptions & Payments
#20.1 Subscriptions
Certain features require a Premium subscription. Subscription status is stored on your profile (plan, status, expiry date) and is used to gate access.
#20.2 Payments
Payment processing is performed by our payment providers (see Chapter 26). SKWADE does not store full payment card details on its servers. We retain transaction references, subscription plan, status and dates as required for accounting, tax and customer support.
#20.3 Refunds
Refunds are processed in accordance with the SKWADE Terms of Service and applicable consumer protection law.
#20.4 Premium Features
The list of features requiring Premium is governed by Feature Management (Chapter 21) and may evolve over time. Downgrades are handled in accordance with the Cloud Storage Downgrade Policy referenced in Chapter 16.
#21. Feature Management
#21.1 Purpose
Feature Management is the internal system that determines which features are available to which users, whether a feature requires Premium, and whether a feature is generally available or in a limited rollout.
#21.2 Data Collected
Feature Management records feature flags, access decisions and roll-out cohorts. It does not create new categories of Personal Data beyond the identifiers necessary to associate a user with a feature state.
#21.3 Experimental Features
Where a feature is offered as experimental, this is disclosed in the app. Experimental features may collect additional diagnostic information limited to the operation of the feature, which is deleted when the feature graduates or is retired.
#22. Device, Analytics & Crash Reports
#22.1 Device Information
We collect limited device information necessary to operate the Services: device model, operating system version, application version, language settings and technical identifiers.
#22.2 Analytics
We use privacy-respecting analytics to understand how the Services are used in aggregate, to improve them and to detect abuse. Analytics data is minimized and, where feasible, aggregated or pseudonymized.
#22.3 Crash Reports
Crash reports include the state of the application at the moment of failure. We take reasonable steps to strip Personal Data from crash payloads.
#22.4 Support Requests
When you contact support, we process the information you provide (message, attachments, contact details) to answer your request.
#23. Artificial Intelligence Processing
#23.1 Current AI Assistant
SKWADE provides an in-app AI Assistant capable of answering diving-related questions on request. Requests are transmitted to our AI provider through the Lovable AI Gateway. Only the content necessary to answer the request is transmitted.
#23.2 Guardrails
The AI Assistant:
- assists divers but does not replace certified training;
- does not perform medical, legal or safety decisions;
- does not make automated decisions producing legal or similarly significant effects concerning you within the meaning of Article 22 GDPR.
#23.3 Future AI Features (Roadmap)
The following AI features are on the roadmap and are not currently available:
- Species Recognition from photographs;
- Dive Recommendations based on your history and preferences;
- Ocean Insights — aggregated insights derived from anonymized data;
- Automatic Summaries of dives, trips or seasons.
When released, each feature will be documented, gated by Feature Management, and, where required, subject to your explicit consent.
#23.4 AI Metadata
If and when AI features generate derived data (embeddings, classification scores, recommendation vectors), such data will be treated as Personal Data where it relates to you, and will be subject to this Privacy Policy.
#Part III — How We Use, Share and Protect Information
#24. Purposes and Legal Basis
The table below summarizes the purposes for which SKWADE processes Personal Data and the legal basis relied upon under the GDPR (equivalents apply in other jurisdictions).
| Purpose | Categories of Personal Data | Legal basis |
|---|---|---|
| Create and operate your account | Account, credentials | Performance of contract |
| Provide dive logging and the Digital Passport | Dive Log, Certifications, Passport | Performance of contract |
| Synchronize with dive computers and third-party providers | Provider credentials, dive data, sync telemetry | Performance of contract; legitimate interest in reliable operation |
| Emergency contacts, medical data, insurance | Special-category and sensitive data | Explicit consent |
| Ocean Observations, Collections, Achievements, Statistics | Dives, observations | Performance of contract; legitimate interest in feature quality |
| Ocean Media Engine — media enrichment | No user Personal Data; third-party attribution | Legitimate interest in editorial quality; licence compliance |
| Geolocation features | Coarse or precise location | Consent (device permission) |
| Wallet passes (Apple / Google) | Passport fields you have chosen to share | Performance of contract; consent for optional fields |
| Notifications and communications | Contact details, preferences | Performance of contract; consent for marketing |
| Payments and subscriptions | Subscription metadata, transaction references | Performance of contract; legal obligation (tax, accounting) |
| Security, fraud prevention, abuse detection | Account, device, audit data | Legitimate interest; legal obligation |
| Analytics and product improvement | Aggregated usage data, crash reports | Legitimate interest; consent where required |
| AI Assistant | Request content | Performance of contract; consent for optional processing |
| Legal compliance and legal claims | All relevant categories | Legal obligation; legitimate interest |
#25. Sharing with Other Users
#25.1 Buddy Sharing
You may confirm other SKWADE users as buddies. Confirmed buddies may see the fields of your profile and Passport for which you have enabled the corresponding privacy flag. Every flag defaults to OFF for sensitive or safety-relevant data.
#25.2 Public Passport
Where you enable public Passport sharing, selected fields become accessible through your Passport URL and QR code. Only fields explicitly enabled are exposed.
#25.3 Community Content
Chapter 34 governs any content you make available to the broader community, where such features are enabled.
#26. Third-Party Service Providers
SKWADE relies on the following categories of Third-Party Providers to operate the Services. Each provider processes Personal Data only on our instructions and subject to appropriate contractual and technical safeguards.
| Category | Purpose |
|---|---|
| Authentication | Managed identity, session and token management |
| Hosting | Application and API hosting on edge and cloud infrastructure |
| Database | Managed relational database with row-level security |
| Storage | Object storage for the Assets Library and backups |
| Payments | Subscription billing and payment processing |
| Analytics | Aggregate product analytics |
| Crash reporting | Diagnostic capture |
| Email delivery | Transactional email |
| Push notifications | Apple Push Notification service; Google Firebase Cloud Messaging |
| Maps and geocoding | Map tiles, geocoding and reverse geocoding for Dive Sites |
| Wallet issuers | Apple Wallet and Google Wallet pass distribution |
| Synchronization providers | SSI, Garmin, and future connectors listed in Chapter 11 |
| Media providers | Wikimedia Commons and GBIF, as documented in Chapter 13 |
| AI providers | Lovable AI Gateway for the AI Assistant |
The current list of providers may evolve. Material changes will be reflected in an updated version of this Privacy Policy.
#27. Legal Disclosures and Business Transfers
SKWADE may disclose Personal Data where required by law, court order or lawful request from a competent authority, or where necessary to protect the rights, property or safety of SKWADE, its users or the public.
In the event of a merger, acquisition, reorganization or sale of assets, Personal Data may be transferred as part of the transaction, subject to the continued application of this Privacy Policy or an equally protective successor policy.
#28. Security Measures
SKWADE implements defense-in-depth security controls, including:
- Transport encryption — TLS 1.2+ for all client-server communications;
- Storage encryption — encryption at rest for database volumes and object storage;
- Application-level encryption — AES-256-GCM for the Secrets Vault storing provider credentials;
- Authentication — managed identity provider, hashed and salted passwords, secure session management, optional third-party sign-in;
- Authorization — JWT-based session tokens combined with server-enforced role-based access control and dedicated
user_rolestables governed by security-definer functions; - Row-Level Security (RLS) — every user-facing database table enforces RLS policies so that a user can access only their own data;
- Signed URLs — private media in the Assets Library are served through short-lived signed URLs;
- Private storage — sensitive documents (certifications, medical, insurance) are stored in private buckets;
- Media protection — Ocean Media provenance and licences are recorded; user media are private by default;
- Audit logs — security-relevant events are recorded for forensic analysis;
- Backups — regular encrypted backups managed by our Backup Center, with documented restore procedures;
- Monitoring — health, security and abuse monitoring; automated alerts on anomalous activity;
- Post-processing isolation — heavy background work is dispatched through the Post-Processing Framework so that user-facing requests remain unaffected;
- Secrets Vault — provider credentials are never persisted in plain text and never exposed through public APIs.
No system is completely secure. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify affected users and competent authorities as required by law.
#29. Cookies, Local Storage and Session Tokens
SKWADE uses a limited set of client-side storage mechanisms:
- Essential cookies and session tokens — required to keep you signed in and to operate the Services;
- Local storage — used to persist UI preferences (for example the selected layout of the Dive Log, language, unit system, display preferences);
- Analytics — where analytics is enabled and permitted by applicable law, limited usage information may be collected;
- Preferences — user preferences stored locally to personalize the interface.
You may control cookies and equivalent technologies through your device and browser settings. Disabling essential cookies will prevent the Services from functioning correctly.
Detailed information is provided in the SKWADE Cookie Policy.
#30. International Data Transfers
SKWADE is a global platform. Personal Data may be processed in countries other than your country of residence, including through our hosting, storage, payment and analytics providers.
Where transfers occur from the European Economic Area, the United Kingdom, Switzerland or other jurisdictions imposing restrictions on international transfers, SKWADE relies on appropriate safeguards, including:
- adequacy decisions where available;
- Standard Contractual Clauses (SCCs) and, for the UK, the International Data Transfer Agreement or the UK Addendum;
- supplementary technical and organizational measures where required.
You may request a summary of the safeguards applicable to a specific transfer by contacting SKWADE (Chapter 37).
#31. Data Retention
We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required or permitted by law.
Indicative retention periods:
| Category | Retention |
|---|---|
| Account information | For the life of the account, plus a limited grace period after deletion. |
| Dive Log and Ocean Observations | For the life of the account or until you delete the individual records. |
| Certifications | For the life of the account or until you delete them. |
| Emergency contacts, medical, insurance | Until you delete them or your account is deleted. |
| Provider credentials (Secrets Vault) | Until you disconnect the provider or your account is deleted; deleted immediately on request. |
| Sync runs, audit logs | Rolling window sufficient to support troubleshooting and security; older records are purged automatically. |
| Notifications | Inbox messages remain available until you delete them; push and email logs are retained for a short operational window. |
| Library content (documents, photos, videos) | Until you delete them or your account is deleted, subject to the Cloud Storage Downgrade Policy. |
| Payment records | For the period required by applicable tax and accounting law. |
| Backups | Encrypted rolling backups. Deleted data is purged from backups within the applicable backup rotation window. |
| Anonymized statistical data | May be retained indefinitely, provided it can no longer be linked to an identifiable individual. |
#Part IV — Your Rights and Final Provisions
#32. User Rights
Subject to applicable law, you have the following rights concerning your Personal Data:
- Access — obtain a copy of the Personal Data we hold about you;
- Rectification — correct inaccurate or incomplete data;
- Erasure — request deletion of your Personal Data, subject to legal retention obligations;
- Restriction — request that we restrict processing in specific cases;
- Portability — receive your data in a structured, commonly used, machine-readable format;
- Objection — object to processing based on legitimate interest, and to direct marketing at any time;
- Withdrawal of consent — withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing;
- Right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects (SKWADE does not conduct such processing);
- Right to lodge a complaint with a supervisory authority.
#32.1 GDPR (EU) and UK GDPR
Users in the European Economic Area and the United Kingdom have all rights above under the GDPR and UK GDPR respectively. Complaints may be lodged with the competent supervisory authority.
#32.2 California (CCPA / CPRA)
California residents have additional rights, including the right to know, the right to delete, the right to correct, the right to opt out of the sale or sharing of personal information (SKWADE does not sell your Personal Data) and the right to limit the use of sensitive personal information.
#32.3 Singapore (PDPA)
Users in Singapore have rights of access and correction under the Personal Data Protection Act, and may withdraw consent for processing.
#32.4 South Korea (PIPA)
Users in South Korea have rights of access, correction, deletion and suspension of processing under the Personal Information Protection Act.
#32.5 Other Jurisdictions
Where local laws grant additional rights (Brazil LGPD, Canada PIPEDA, Australia Privacy Act, Japan APPI, and others), those rights apply in addition to the rights described above.
#32.6 Exercising Your Rights
Most rights can be exercised directly from within the app (profile, privacy settings, data export, account deletion). For requests that cannot be handled in-app, contact SKWADE using the details in Chapter 37. We may need to verify your identity before acting on a request.
#33. Children
SKWADE is not directed at children under the age of 16 (or the higher age required by applicable law in your jurisdiction).
We do not knowingly collect Personal Data from children below that age without verifiable parental or guardian consent, where required. If you believe a child has provided us with Personal Data without appropriate consent, please contact us so that we can take appropriate action.
Certain features (for example medical information, insurance, professional accounts) are inherently intended for adult divers and are not made available to minors.
#34. Community Content
Where SKWADE enables community features (for example public dive site contributions, shared observations, community media), the following rules apply:
- content you make public is visible to other users and, where indexed, to the general internet;
- you retain ownership of your content, subject to the licence granted to SKWADE in the Terms of Service to host, display and distribute it within the Services;
- SKWADE moderates community content through the Ocean CMS and may remove content that violates the Community Guidelines or applicable law;
- other users' content is subject to the same rules and to SKWADE's copyright and reporting procedures (Chapter 35).
Community submission features that are on the roadmap are not currently open to end-user submissions.
#35. Copyright and Attribution
#35.1 Ocean Media
Ocean Media imported through the Ocean Media Engine are handled in accordance with their source licence. For every asset, SKWADE records and displays the source provider, source URL, licence, attribution and, where applicable, the licence URL.
#35.2 Sources
Current media sources are Wikimedia Commons and GBIF. Additional partner sources may be added in accordance with this Privacy Policy and the applicable licences.
#35.3 User Media
You retain all rights in the media you upload. You grant SKWADE the licence set out in the Terms of Service to host, process and, where applicable, display your media within the Services.
#35.4 Copyright Requests
If you believe that content available through the Services infringes your copyright, please submit a notice using the contact details in Chapter 37. Notices should include sufficient information to identify the content, your ownership or authority to act, and a statement made under penalty of perjury where required by applicable law (e.g. DMCA).
#36. Future Modules and Planned Features
Certain modules and features referenced in this Privacy Policy are on the SKWADE roadmap. They include, without limitation, Marine Plants, Habitats, Ocean Articles, community media, partner media, weather integration, additional dive-computer connectors, additional AI features (species recognition, dive recommendations, Ocean insights, automatic summaries), Desktop Apps, the Professional CRM and additional Wallet integrations.
These features are not currently available. They do not process Personal Data until released. When released, they will be governed by this Privacy Policy and, where required, by a specific processing notice.
#37. Contact
For questions regarding this Privacy Policy or the way SKWADE processes your Personal Data, or to exercise the rights described in Chapter 32, please contact us through the SKWADE Legal Center. Contact details are published within the app and on the SKWADE website.
Where required by law, SKWADE will designate a representative in the relevant jurisdiction and publish the corresponding contact information.
#38. Changes to this Privacy Policy
SKWADE may update this Privacy Policy from time to time to reflect changes in the Services, in applicable law or in our privacy practices. The effective date at the top of this document reflects the date of the most recent version.
Material changes will be communicated in advance through in-app notification, email or another appropriate channel. Continued use of the Services after the effective date of the updated Privacy Policy constitutes acceptance of the updated Policy, subject to any additional consent required by law.
End of SKWADE Privacy Policy — Version 2.0.