Privacy policy
Last updated: 27 September 2026
Nextdive is an online dive logbook for divers, buddies and dive schools. This policy explains which data we keep, why, who can see it and what your rights are. In short: we only keep what your logbook needs, we sell nothing, we show no ads and we use no tracking.
1. Who is responsible?
The data controller is Dylan Prins, reachable at prins.dylan@outlook.com. You can get in touch there with any question about your data.
2. What data do we keep?
- Account: name, username and a hash of your password (never the password itself). If you sign in with Microsoft or Google, we keep the account ID and email address they pass on to us and, for Google, the link to your profile photo.
- Profile: profile photo (if you upload one or use your Google photo), certifications, the number of dives logged before Nextdive, your visibility setting and display settings.
- Dives: date and time, duration, depth, temperature, gas, tank and pressures, dive site, place and country, dive computer, notes, training details, gear and the buddies you tag. Buddies without a Nextdive account are kept only as the name you type.
- Buddies and dive schools: your buddy connections, memberships and roles at dive schools, sign-ups for group dives, buddy teams, rental gear and whether you are a club member.
- Imported files: a file you import (FIT, UDDF, Subsurface, PDF, CSV or zip) is only read. We keep the dive data from it, not the file itself.
- Technical data: a session cookie to keep you signed in, and server logs (including IP address, time and requested page) for security and troubleshooting. When you sign in to the Nextdive app, we keep a hash of its sign-in tokens and the device name, until you sign out or they expire (at most 90 days unused).
We do not ask for health data (such as heart rate), payment details or location history.
3. Why, and on what legal basis?
- To provide your logbook, statistics, buddy and dive school features: performance of the contract (Art. 6(1)(b) GDPR).
- Connections with Garmin or Suunto: your consent (Art. 6(1)(a)), which you withdraw at any time by disconnecting.
- Security, preventing abuse and fixing errors (server logs), and names of buddies without an account: legitimate interest (Art. 6(1)(f)). If someone wants their name removed from your logbook, we do so.
4. Who can see your data?
- You see and manage all your data.
- Buddies you tag on a dive see that dive and can copy it to their own logbook. Your profile with statistics and recent dives is visible according to your own setting: everyone, only buddies (default) or nobody.
- Dive schools you are a member of see your name, role, sign-ups, buddy team and rental gear, and your certification according to your visibility setting.
- The administrator can view and manage accounts, only for support and administration.
We never sell or rent out your data and never share it with ad networks or data brokers.
5. Service providers
- Microsoft Azure (hosting, database and logs), in the EU (Sweden). A data processing agreement with Microsoft applies.
- Microsoft and Google, only if you sign in with them. Nextdive only receives your account ID, name, email address and (Google) profile photo.
- Open-Meteo: when you type a place for a dive, your browser looks up suggestions at open-meteo.com. Only the typed text goes there, no account data.
6. Connections with Garmin and Suunto
You can choose to connect your Garmin Connect or Suunto account, so new dives land in your logbook automatically. For this:
- The connection is only made when you explicitly give consent on the Garmin or Suunto sign-in page. We never see your password there.
- We only fetch dive activities and keep the same dive data as for a manual import (see section 2). Other activities and health data are not stored.
- We only read. We never send data to Garmin or Suunto.
- Your Garmin or Suunto data, and your account ID there, are used only within Nextdive. We never pass them on to other services, ad networks or data brokers.
- If you disconnect (in Nextdive or at Garmin/Suunto), we stop fetching immediately and delete the access tokens. You choose whether dives imported so far stay in your logbook or are deleted.
7. How long do we keep data?
As long as your account exists. If you delete your account (Profile → Delete account), your account, dives, gear, photo and connections are deleted immediately. Database backups are overwritten within 7 days, server logs after 30 days.
8. Security
All connections use HTTPS. Passwords are hashed with scrypt, the database is only reachable by the app and the app uses no database passwords but a managed identity. Access tokens for Garmin and Suunto are stored encrypted.
9. Cookies
Nextdive only uses functional cookies: a session cookie (at most 30 days) to keep you signed in and, when you sign in with Microsoft or Google, a sign-in cookie from Azure. No analytics or tracking cookies, and so no cookie banner.
10. Your rights
You have the right to access, rectify, erase, restrict, object to and port your data. Much of this you can do yourself: export all your dives as CSV (Dives → Export), change your details and delete your account. For anything else, contact us as in section 1; we reply within a month. If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority or the supervisory authority in your own EU country.
11. Changes
When this policy changes, we update the date at the top. We announce important changes in the app before they take effect.