Privacy Policy
Last updated: 10 September 2026
The short version: the apps do not collect anything automatically. Signing in is entirely optional. If you never do it, inDepth's apps collect nothing and send nothing to us unless you choose to send feedback. There is no account, no sign-up requirement, no in-app analytics, no advertising and no tracking, and every dive stays in a database on your own phone. In that state, a file leaves only when you export and share it, map imagery is requested only when you open a map, and feedback leaves only when you choose to send it. This website has two small exceptions of its own, described further down this summary and in section 7.
If you choose to sign in with Google or Apple, to turn on cloud backup of your dives, pool sessions and workouts, we then collect your email address, name and a user ID for that account, plus the session records you back up (including heart rate) — stored under your own account in our own Firebase project, for the sole purpose of restoring them on another of your own phones. None of it is sold, shared with a third party, or used for advertising or tracking. You can delete your account and everything stored in the cloud for it at any time, from Settings → Account → Delete account — see section 1 and section 6.
Some actions can send data whether or not you sign in. The phone app draws satellite maps, and satellite imagery has to be downloaded: whenever a map is on screen, the app fetches map tiles from MapTiler. What MapTiler receives is a request for a few squares of the earth's surface — roughly where you are looking, and nothing else. No dive data, no account, nothing that identifies you. Section 2 sets out exactly what is in that request, and what is not.
Two more exceptions are on this website, not in the apps: it runs analytics on every page you visit, and if you sign up on one of its email forms, we store your address to send you the subscription you chose — a roughly-monthly newsletter, important app updates, or a one-off note about watch support, depending on which form and which boxes you ticked. Both are described in section 7.
This policy covers the inDepth Apnea Sync mobile app, the inDepth Apnea Blue and inDepth Apnea Pool Garmin Connect IQ watch apps, the desktop installer, and this website. It explains what is collected by the apps (only data you choose to send) and by this website (this website's own analytics and email forms, described in section 7, run independently of whether you ever sign in to the apps at all), where your data lives, and how to get rid of it.
1. Information we collect
From the apps, signed out: no automatic collection. Signing in is entirely optional, and inDepth never requires it. Signed out, there is no account, no login and no user profile. We do not ask for your name, email address, phone number, date of birth, or any other identifier unless you choose to include a reply email with feedback.
From the apps, if you choose to sign in: Settings → Account offers Sign in with Google (Android and iOS) or Sign in with Apple (iOS only), solely to turn on cloud backup. Signing in collects the email address and name your chosen provider gives us, and a Firebase-issued user ID for that account. From then on, cloud backup pushes your dive sessions, pool sessions and workouts — including heart rate, depth/rep data, any GPS positions and marked spots they carry, and any session name, notes or tags you typed yourself — to a Cloud Firestore database under that user ID, tagged with a device identifier this app generates for itself (not a hardware ID — see the next section for what it is for), so the same account can pull them back down on another of your own phones. Signing out again does not delete that cloud copy; deleting it is a separate, explicit action (Settings → Account → Delete account, see section 6). None of this is used for advertising or tracking, and it is never shared with or sold to a third party.
From this website: if you use one of its email subscribe forms, the address you typed, plus — on the "Tell me when it's supported" form only — the watch model you typed, if you typed one; the technical details are described in section 7. Nothing on this site is connected to your dive data, and using the apps never requires visiting it.
We do not use analytics, crash reporting, advertising SDKs, attribution SDKs, or any other third-party service that observes your use of the apps, whether or not you sign in. The phone app has four outbound paths: it downloads satellite map tiles from MapTiler when there is a map on screen; it hands a single coordinate to your phone's maps app when you request directions beside a marked spot; Firebase Auth and Cloud Firestore run when you choose to sign in for cloud backup; and the Firebase feedback callable runs when you choose Send feedback, then uses Resend to email the report to us. These are the app's outbound paths, and section 2 says what each one contains.
2. Where your data lives
- On your watch: the watch apps record your dives and keep a small rolling buffer of recent sessions so they can be transferred to your phone. That data goes nowhere but your own phone, with one deliberate exception you should know about: marking a spot in inDepth Blue also saves it as a Garmin Saved Location on the watch — a coordinate named after the label and time you marked it, like
Fish 12:47— so Garmin's own Navigate app can steer you back to it with no phone involved. That is the point of it, and it is why the feature is useful on the surface. But Saved Locations are Garmin's feature and Garmin's data store, not ours: once a mark is in there it is part of your Garmin data, and what Garmin's apps and services do with it is governed by Garmin's privacy policy, not this one. Saved Locations are managed by the watch, so removing one is done there rather than in inDepth. inDepth's own copy of the mark is a separate thing and lives on your phone, as below. - On your phone: dive sessions, pool sessions, workouts, session names, tags, notes, per-dive annotations, the GPS positions and marked spots your watch recorded, your unit preferences and a rolling diagnostic log are stored in a database in the app's own private storage on your device. If you never sign in, that is the only local logbook copy. Cloud backup does not upload anything. If you choose to send feedback, it can include the separate technical-log tail described in the feedback section, but does not upload the database. If you sign in, the session data in this database — including its GPS positions and marked spots — is exactly what cloud backup uploads; see the next bullet for what that covers and where it goes.
- On our servers, if you sign in: your account's email address, name and a Firebase user ID, plus a device identifier this app generates for itself (used only to break a tie when two of your phones edit the same session at the same time — not a hardware ID), plus a cloud copy of the dive sessions, pool sessions and workouts you have backed up (including heart rate, depth/rep data, GPS positions and marked spots, and any session name, notes or tags you typed yourself) — stored in Cloud Firestore under that user ID, in our own Firebase project, for the sole purpose of restoring them on another of your own signed-in phones. We do not sell, share, or use any of it for advertising or tracking. If you never sign in, none of this exists — we operate no cloud-backup server that receives your dives or your positions from a signed-out user, not a single one of either. That is a claim about dive data specifically; it does not mean a signed-out visitor's browser never talks to any server of ours at all — the next two bullets are two of the things that do, on this website, regardless of sign-in state (and neither one is dive data); this website's server logs and analytics, which run for every page view whether or not a form is submitted, are two more — see section 7's first paragraph.
- At Resend: Resend, a US-based email provider, holds your address and consent details when you sign up on one of this website's email forms. On the watch-support form, it also holds the watch model described in section 7. Resend sends these emails and app-feedback messages for us. If you send app feedback, it processes the message, context, optional reply email, and optional diagnostics for delivery to us. We do not keep a feedback database. This is entirely separate from, and never joined to, the account/cloud-backup data above; signing in to the apps does not add you to it. See section 7 for website subscriptions, storage, and removal.
- Rate-limit counters, from anyone, signed in or not: submitting a website email form or app feedback writes a counter to our own Firebase project, a one-way hash of your IP address plus a request count, used only to cap abuse. We never use it to look anyone up, and it is never linked to your subscription or to any dive data. It has roughly an hour's life before the next request from that address starts a fresh one. See section 7 for the website-form detail.
- At MapTiler: the satellite imagery underneath the map is served by MapTiler, a Swiss map provider. Drawing a map means asking them for the image tiles covering the area on screen, so what they receive is that: which squares of the world, at what zoom level. Travelling with it is our own map key and the app's identifier — which identify the app, not you — and, as with any request to any website, your IP address. What they do not receive is your dive data, your name, an account, or any identifier of you: none of it is in the request, because the app has nothing of the sort to send. Nor do they receive your marks. A tile is a square of imagery, not a pin — asking for one says which patch of coast or sea is on your screen, which is plainly a hint about where you dive, and we would rather say that out loud than pretend a map can be drawn without it. Tiles are cached on your phone for 90 days, so re-opening a site you have already looked at usually needs no request at all, and a boat with no signal still shows the chart you loaded on the way out. MapTiler's own handling of the requests it receives is governed by MapTiler's privacy policy, which we do not control and are not party to.
- In whichever maps app you choose: the directions button beside a marked spot hands one coordinate, plus the label you gave the mark (
Reef,Wreckand so on), to Apple Maps, Google Maps or whatever else you have installed. Nothing else goes with it, we are not involved in the hand-off, and what that app does with a coordinate is covered by its privacy policy, not ours.
3. Bluetooth
inDepth Sync uses Bluetooth for exactly one purpose: receiving session data from your own Garmin watch. The transfer runs through the Garmin Connect IQ SDK and the Garmin Connect Mobile app on your phone, and is device-to-device — your watch to your phone. inDepth does not scan for, connect to, or identify any other device.
GPS positions arrive the same way. If you switch the watch app's GPS option on, it is the watch that takes every fix — where a session started, where individual dives happened, and the spots you mark deliberately — and those coordinates reach your phone over the same Bluetooth transfer as the rest of the session. inDepth Sync never uses your phone's own location services. It asks for no location permission, and it could not tell you where the phone is if you wanted it to. The pins you see on a map are what the watch recorded, not where the phone happens to be.
Garmin Connect Mobile is a separate app made by Garmin. Your use of it, and anything Garmin's own services do with your watch data, is governed by Garmin's privacy policy, which we do not control and are not party to.
4. Permissions the app does not use
Your phone may show permission descriptions for the camera, photo library or location alongside inDepth Sync. The app never requests any of them. Those descriptions exist because bundled third-party libraries link the relevant system frameworks, and Apple requires a description for any linked framework whether or not it is used.
Camera and photo library: never requested, never accessed. Both descriptions come from the bundled file-picker library, which the app uses for exactly one thing — opening a backup or CSV file you picked yourself.
Location: the app never asks for this phone's location. It requests no location permission at any point and reads no location API, so your phone never reports its position to inDepth Sync. That description is there because the bundled Bluetooth library references location APIs, not because the app wants your position. There are maps in the app, and it would be misleading to leave it at "no location": the positions on them were taken by your watch's GPS and came over Bluetooth, as section 2 and section 3 describe.
The capabilities the app genuinely uses are four: Bluetooth, to receive sessions from your watch; internet access, for satellite map tiles, feedback you choose to send, and, only if you sign in, your account and cloud backup; the ability to open another app, used only to hand a marked spot's coordinate to your maps app when you ask for directions; and, only if you sign in, Sign in with Google or Sign in with Apple's own authentication screen.
5. Files you export
The app can produce three kinds of file, each only when you ask it to:
- CSV export — a spreadsheet-friendly export of your dives.
- Backup — a single
.jsonfile containing everything the app stores, so you can restore it onto another phone. - Diagnostic bundle — a
.zipof app logs for troubleshooting. It contains no dive data.
Each opens your phone's standard share sheet and goes wherever you send it. Once you have shared a file, what happens to it is determined by the app or service you sent it to, not by us. If you email a diagnostic bundle to support, we use it only to investigate your problem and delete it once the issue is resolved.
Feedback sent in the app
You can send feedback from Settings → Help & troubleshooting → Send feedback whether you are signed in or out. Sending it delivers the message through our Firebase feedback service, which uses Resend to email it to us. We do not keep a feedback database.
Every feedback message includes the app version and build number, platform, operating-system version, and device model so we can understand the report. You choose the category and message. A reply email is optional and is used only to answer you. Technical phone-log diagnostics are optional, off by default, and sent only when you turn on Include diagnostics. They can contain account, watch, session, or workout identifiers. Feedback does not include underlying workout, health, location, screenshot, or watch-log data.
Feedback is not saved for later delivery. A confirmation means Resend accepted the message for delivery, not that final delivery is guaranteed. If sending fails, it remains only in the open form for you to retry or discard, and the app does not retry it in the background.
6. Deleting your data
You can delete individual dives and whole sessions inside the app. To erase everything at once, open Settings, press and hold the Version … line for three seconds to reveal the Debug entry, then choose Delete all data — this wipes every session, workout, setting and log and returns the app to its first-launch state. Uninstalling the app removes that same local copy from your phone, but it does not touch anything in the cloud: uninstalling never signs you out or deletes anything remotely, so if you were signed in, your sessions and account remain there until you delete them from within the app (see the next three paragraphs) or delete your account entirely.
If you have never signed in, that is the whole story for your dive data specifically: nothing is held elsewhere for us to delete, and there is no data-access request for you to make about it. Deleting your dive data is entirely in your hands. (This is about the app. If you separately subscribed to this website's email list, that is a different address book with its own removal route — see section 7 — regardless of whether you have ever signed in to the app at all; the two are unrelated.)
If you are signed in, deleting a session — one at a time, or all at once via Delete all data — already reaches the cloud. Each delete writes a marker that this phone, and every other phone signed into the same account, applies on its next sync, removing that session from the cloud (and from those other phones) too. There is no separate "local-only" delete for a session while you are signed in. The one exception is workouts: workout deletes do not sync yet, so a deleted workout can still come back on a later pull, including on the phone you deleted it from.
Deleting your account is a separate, additional action from deleting sessions, for when you want the account itself gone rather than just its current contents. Open Settings → Account and choose Delete account. It asks you to confirm and sign in again, then permanently deletes your account and every dive, pool session and workout stored in the cloud for it, in one step, without waiting for a sync; this cannot be undone, and it does not touch any other signed-in phone's own local copy of that data. If you signed in with Apple, deleting also makes a best-effort attempt to revoke inDepth's access on your Apple ID — this is best-effort because our app cannot confirm from the client whether Apple's revoke succeeded, so check Settings → [your name] → Sign-In & Security → Apps Using Apple ID afterwards if you want to confirm inDepth is no longer listed there. The confirmation dialog also offers to erase this phone's own local copy of everything at the same time, if you want a completely clean slate rather than just the cloud copy.
The one case with no cloud effect at all is a delete made while signed out. It writes no marker, so if this phone later signs into a cloud account that still has that session, the delete can be silently undone by the sign-in itself, which then pulls the session back down. Whether a delete reaches the cloud depends on whether you were signed in at the moment you made it, not on which button you pressed.
The one thing none of the buttons above reach, signed in or not, is a Garmin Saved Location written when you marked a spot — that one belongs to your watch, so delete it there (see section 2).
7. This website
in-depth.app is hosted on Firebase Hosting (Google). Like any web host, it writes standard server request logs — IP address, timestamp, requested URL, browser user agent — which Google retains under its own policies for security and operational purposes. The site also runs Google Analytics 4, through Firebase Analytics, which sets its own cookies and records page views and a small number of interaction events on the site. We use it to see which pages get read, not to build an advertising profile of you. Beyond that, there is no advertising network and no third-party tracker of any kind.
Email list
The forms on this site (the newsletter box on the home page, the "Hear about important updates" box on /install, and the "Tell me when it's supported" box on /depth) each sign you up to one or more of three separately-chosen subscriptions — ticking one never ticks another:
- inDepth newsletter — roughly monthly notes on new inDepth features, real session data, and whatever freediving itself taught me;
- Important app updates — a handful of emails a year about important updates to the watch apps: a new release worth installing, or a fix that matters. Nothing else;
- Watch support updates — a one-off email if we add support for the Garmin watch model you told us you use. This isn't a program to join, just a "let me know" list for unsupported watches.
Submitting any of these forms does not create or touch any app account, and signing in to the app does not add you to this list; it is also never joined to any dive data. That is a separate claim from section 1's "if you sign in, cloud backup uploads your dive data" — that dive data exists in our own Firebase project for signed-in accounts, and this list, held separately by Resend, is never cross-referenced or combined with it.
The list is held by Resend (resend.com), the email provider we use to store subscribers and send these emails, based in the United States. That means your email address is transferred to and stored in the US, a third country outside the EU/ EEA/UK. Resend offers EU data residency only as a paid add-on we do not subscribe to, so Resend's own account data and logs for us — the account we, not you, hold with them — stay in the US regardless of where you are. Resend acts as our processor and is contractually bound to use the data only to send mail on our behalf.
What we store per subscriber: the email address; the original, unchanging record of the consent you first gave — a timestamp, a version tag for that consent, and which page you signed up on — plus a separately-tracked timestamp, version tag and page for your most recent submission, if you ever fill in one of these forms again; and, only if you typed one, the watch model you entered on the /depth form. We do not store your browser's user-agent string with your subscription — an earlier version of this form did, and this policy used to say so, but that field has been removed. (Like any web host, Firebase Hosting's own server logs still capture the user-agent of every request to this site, subscribe or not — see the first paragraph of section 7 — but it is not stored alongside, or as part of, your subscription.) The subscribe endpoint also keeps a rate-limit counter — a one-way hash of your IP address plus a request count, not the address itself — to stop abuse of the forms; we never use it to look anyone up, it is not linked to your subscription, and it has roughly an hour's life before the next request from that address starts a fresh one.
Every newsletter and update email we send carries an unsubscribe link that leads to a preference page (hosted by Resend) where you can drop any single one of the three subscriptions, or all of them at once, at any time. The one exception is the single welcome email sent when you first subscribe — it's a one-to-one message rather than a broadcast, so instead of that link it carries a List-Unsubscribe header and asks you to reply to it, or write to support@in-depth.app, to be removed. That address works as a removal route for any of these subscriptions at any time, whether or not you use the preference page; unlike the preference page, a request by email is handled by hand, and we will act on it within 30 days.
We do not sell, rent or share this list, and we do not use it for any marketing beyond what you signed up for. Each subscription is kept until you unsubscribe from it. What "unsubscribe" does depends on which button you use, and the two cases work differently on purpose:
- Dropping all mail, or using the "unsubscribe from everything" option on the preference page, is remembered: your address stays on file afterwards as a suppression entry specifically so a later, unrelated signup — from any of our forms, by you or anyone else typing that address — cannot silently re-subscribe you. A plain subscribe form has no way to override that, on purpose.
- Dropping just one of the three subscriptions (the preference page also offers this) is not remembered the same way, and can be reversed: since each subscription is opted into separately and never on by default, later signing up again for that one specific subscription is a fresh, deliberate action, not a form silently undoing your earlier choice — so it re-subscribes you to that one, as intended.
If you would rather your address were deleted outright — including the suppression entry, if you unsubscribed from everything — ask at support@in-depth.app; we will do that manually, with the tradeoff that a later, unrelated signup with the same address would then have no record that you had opted out before.
8. Children's privacy
inDepth is not directed at children, and freediving is not a children's activity. The apps do not collect anything automatically from anyone, children included. Someone could choose to submit feedback, as described in section 1, but we do not knowingly collect feedback, sign-in data, or cloud-backup data from a child. This website's email forms (section 7) are not directed at children either, are not age-gated, and work the same way for anyone who submits one; we do not knowingly collect an email address from a child through them, and will remove any such signup on request at support@in-depth.app.
9. Changes to this policy
If this policy changes, the updated version will be posted at this URL with a new "last updated" date at the top. Material changes will also be noted in the release notes of the app version they apply to.
10. Contact
Questions about this policy, or about privacy generally:
support@in-depth.app