Who we are
Into the Blue (“we”, “us”) is developed by Stefano and Jardi, based in Spain. Our registered contact address is [email protected].
This policy covers our apps for iOS and Android and our website at intotheblue.app (together, the “Service”).
What we collect, why, and on what legal basis
We collect only what we need to run the Service. Apart from your account, almost everything below is information you choose to add yourself: if you don’t add it, we don’t have it. For each purpose we name the legal basis under the EU General Data Protection Regulation (GDPR).
- Your account. Your email address and password, or the name, email address and profile photo you share when you sign in with Apple or Google. We use them to create and secure your account. Legal basis: performance of our contract with you.
- Your profile and diver passport. Only what you choose to fill in, such as your name, nickname and profile photo, and in your diver passport your certifications, gear and dive insurance details. All of these are optional. We use them to show your profile and passport in the app. Legal basis: contract.
- Your dives. The dives you log, with the details you choose to add, such as the dive site, dive details, notes, buddies, the species you saw, and any photos and videos you upload. Photos keep the information stored in the file, which can include where and when they were taken. We store your dives so you can see them on all your devices. Legal basis: contract.
- Buddies and other users. When other users search for buddies, they can see your name, nickname and profile photo. When you add a buddy to a dive, that person is invited and notified. If you invite someone who isn’t on Into the Blue yet, we keep the email address you entered for that invitation. Legal basis: contract; for invitees, our legitimate interest in letting you log dives with the people you dive with.
- Dive sites and sightings you contribute. Dive sites you add, and the species you log at a site, help build the public dive-site and species information shown to all users. What we show publicly is aggregated and does not identify you. Legal basis: legitimate interest in keeping the dive-site and species information accurate.
- Fish identification (“Blue”). When you ask Blue to identify a species, we send what you type, with some context such as the dive site or region, to Google’s Gemini service to generate the answer. Don’t include personal information in these messages. We don’t store your conversations. Legal basis: contract.
- Location. If you give the app permission, it uses your device’s location on your device to show nearby dive sites; we don’t store it on our servers. To suggest your region when you first open the app, we look up an approximate location from your IP address, and we don’t store that location (see Usage analytics for the country we record at sign-up). When you save a dive site, we store its coordinates. Legal basis: your consent (the location permission, which you can withdraw in your device settings) and contract.
- Weather and conditions. To show conditions at a dive site, we send that site’s coordinates, never your own location, to our weather provider. Legal basis: contract.
- Subscriptions. If you buy Pro, the payment is handled by Apple or Google; we never see your card details. We and our subscription service receive the status of your subscription. Legal basis: contract.
- Messages from us. We send transactional emails (such as account confirmation, password reset and replies to your requests) and, if you allow them, push notifications (such as buddy invitations). To send push notifications we store an identifier for your device. Legal basis: contract; for push notifications, your consent, which you can withdraw in your device settings.
- Support and feedback. When you report a bug or send us feedback, we keep your message, your email address if you give it, any image you attach and basic information about your device, so we can help you. Legal basis: legitimate interest in supporting users and improving the Service.
- Usage analytics. We record how the app is used: which features you use, the steps of sign-up and searches you run in the app. We don’t include the contents of your profile or passport. Analytics are linked to your account ID, not your email. When you sign up, we also note your device platform and approximate country, to understand where our users come from. Legal basis: legitimate interest in understanding and improving the Service. You can object at any time (see Your rights).
- Crash reports. When the app crashes, we receive a report with technical details and your account ID, so we can fix the problem. Legal basis: legitimate interest in keeping the Service working.
- Advertising measurement. Outside the European Economic Area, the United Kingdom and Switzerland, we tell Meta when you complete sign-up and when you log a dive, and on Android we share your device’s advertising identifier, so we can measure the ads we run to promote the app. We don’t do this in the EEA, the UK or Switzerland, and we never show third-party ads in the app. Legal basis: where required, your consent; otherwise our legitimate interest in measuring our advertising.
- Partner check-in (intotheblue.app/partner). The details you choose to send to a partner dive center, including any optional medical declaration or certificate, are sent by email only, to that dive center and, as a copy, to you. We don’t store the details, the documents or any medical information; we keep only a record that a check-in took place, and limited technical data for a short time to prevent abuse. The dive center is responsible for what you send it. Legal basis: your request, and your explicit consent for any medical information you choose to send.
Medical information stays on your device. Medical questionnaires, declarations and certificates you add in the app are stored only on your device and are never sent to our servers.
We don’t sell your personal data, and we don’t make decisions about you based solely on automated processing that have legal or similarly significant effects.
Who we share it with
We share personal data only with service providers that process it for us under a data processing agreement, and only as far as each one needs:
- Hosting and storage: our database, sign-in and the files you upload. Hosted in the EU.
- Google: crash reports, push notifications, fish identification (Gemini), place search, Sign in with Google and website statistics (Google Analytics).
- Apple: Sign in with Apple, push notifications and maps on iOS.
- Subscription management: handling Pro subscriptions bought through Apple or Google.
- Usage analytics: hosted in the EU.
- Email delivery.
- Meta Platforms: advertising measurement, outside the EEA, the UK and Switzerland only.
- Weather, location and map services: dive-site conditions (from site coordinates only), an approximate location lookup from your IP address when you first open the app, and map tiles. Like any app that loads content, your device connects to these services directly, which reveals your IP address and, for maps, the area you’re viewing.
We also share data:
- With other users, as described above: your name, nickname and profile photo when someone searches for buddies, and the dives you share with your buddies.
- With a dive center, when you send it a partner check-in.
- When the law requires it, for example in response to a valid court order, and only as much as required.
Google and fish identification. We currently use Google’s Gemini service under terms that allow Google to use the text we send to improve its products, which can include review by people at Google. Don’t include information about yourself or others in your messages to Blue.
Transfers outside the EU
Some providers, such as Google, Apple and Meta, may process data in the United States or other countries outside the European Economic Area. When that happens, we rely on the safeguards the GDPR requires: the European Commission’s adequacy decision for the EU–US Data Privacy Framework for certified providers, or the Commission’s Standard Contractual Clauses. You can ask us for more information about these safeguards.
How long we keep it
- Your account and profile: for as long as you have an account.
- Your dives, photos and videos: until you delete them or your account. A deleted dive is kept for a limited period so the deletion can reach all your devices, then permanently erased.
- When you ask us to delete your account, we permanently delete your account, profile, diver passport, dives, photos, videos and buddy connections within 30 days, except where the law requires us to keep something longer. Deleting your account in the app closes it and signs you out; to have all of your data erased, also email us at [email protected].
- Invitations to people without an account: until the invitation is accepted, declined or withdrawn, or the related dive is deleted.
- Support and bug reports: for as long as we need them to handle your request and fix the problem, then deleted.
- Analytics and crash reports: for a limited period, after which they are deleted automatically.
- Partner check-ins: not kept, except the record that a check-in took place.
We may keep anonymized statistics that no longer identify you.
Your rights
You have the right to:
- Access the personal data we hold about you and get a copy.
- Correct data that is inaccurate or incomplete.
- Delete your data. You can close your account in the app under Settings → Legal → Delete Account; to have all of your data erased, email us and we’ll do it within 30 days.
- Receive your data in a structured, machine-readable format and have it sent to another service.
- Restrict how we use your data in certain cases.
- Object to processing based on our legitimate interests, including analytics.
- Withdraw your consent at any time where we rely on it, without affecting what we did before.
To exercise any of these rights, email [email protected]. We’ll reply within one month. We may need to confirm your identity first.
You also have the right to complain to a data protection authority, such as the one in the country where you live.
Security
We protect your data with industry-standard measures, such as encryption and access controls. Only we can access the systems that hold your data.
No system is completely secure. Use a strong, unique password, and tell us straight away at [email protected] if you think your account has been compromised.
Children
The Service is not intended for anyone under 16, and we don’t knowingly collect personal data from children under 16. If you believe a child has given us personal data, contact us and we’ll delete it.
Our website
Our website loads fonts from Google Fonts, which means your browser connects to Google. The partner check-in form saves a draft of what you type in your own browser, so you don’t lose it; it stays on your device.
We count visits to our website with the same EU-hosted analytics service we use for the app: which pages are viewed, where visitors come from (for example the referring site or a campaign link), their approximate country, the type of device and browser, how fast pages load, and whether the app store buttons are tapped. This is cookieless: nothing is stored on your device — no cookies, no local storage. To tell visits apart, the analytics service combines your IP address and browser details into a one-way code that changes every day, so we can’t recognise you from one day to the next and your IP address is not stored. We don’t use website analytics for advertising and don’t link it to an app account. Legal basis: legitimate interest in understanding how people find and use the website. You can object at any time (see Your rights).
We also use Google Analytics on our website, set up so that it stores nothing on your device: no cookies, no local storage, and no advertising features. When you view a page, your browser tells Google which page it is, the referring site, and your type of device and browser; Google uses this to estimate how many people visit, without being able to recognise you from one page or visit to the next. Google may process this data outside the EU, under the European Commission’s standard contractual clauses. Legal basis: legitimate interest in understanding how people find the website. You can object at any time (see Your rights).
Changes to this policy
We may update this policy. If we make significant changes, we’ll tell you by email or in the app at least 14 days before they take effect. The date at the top of this page shows when it was last updated.
Contact
Questions about this policy or your data: [email protected]. If you need a postal address, ask us by email and we’ll give you one.