The small print, in plain words

Privacy Policy

What Taħt il-Baħar knows about you, why it knows it, and what you can do about it.

Last updated: 23 September 2026

This policy describes the app as it is built today, not as a template says an app usually works. Where something might surprise you — session recordings, reviews carrying your name, a share link that needs no sign-in — it is spelled out rather than buried.

1. Who we are

Taħt il-Baħar ("we", "us", "our") is a dive planning companion for Malta, Gozo and Comino, operated from Malta. When you use the app we decide what happens to the data described here, which under the General Data Protection Regulation makes us the data controller for it.

Anything about privacy, including a request to see or delete what we hold: email privacy@tahtilbahar.com.

2. What we collect

Your account

  • Email address, which identifies the account and is where we send anything about it.
  • Password, if you sign in with one. It is stored only as a hash — we never hold the password itself and cannot read it.
  • Google account details, if you sign in with Google: the name, email address and account id Google hands us.
  • Sign-in records: when the account was created, when it last signed in, and the devices with a live session, so you can see them on the account page and sign them out.

Your diver profile

  • Display name, and a profile picture if you set one.
  • Certification level, as you state it. We do not check it with any agency.
  • A short bio, if you write one.
  • A home port, if you set one: a place name and its coordinates, used to sort sites by how far they are from where you usually start.

Dives you plan and log

  • The site, title, date and time, entry point and how you are getting in, planned depth and bottom time, gas, and any notes you write.
  • The conditions forecast as it stood when you planned, kept with the plan so the plan still makes sense when you read it back.
  • Whatever you log afterwards, and who was on the dive with you.
  • Buddy requests you send or accept, and your membership of a dive centre if you join one.
  • Share links you create: a plan and a long random token, which is what makes the link impossible to guess.

What you contribute to a site

Reviews (a rating, an optional comment, the date you dived) and sightings (a species, a date, an optional note). Both are public — see section 4.

If you register a dive centre

The centre's name, description, island and locality, address and the Google Maps link you paste, the coordinates read from it, phone number, email address, website and logo. These are business contact details and are published on the centre's page once it is approved. We also keep the approval record: the decision, when it was made, which administrator made it, and any note they left.

Technical and usage data

We use PostHog (on its EU servers) to see which parts of the app get used and to find out what broke when something breaks. It collects:

  • Pages opened and features used, with the type of device and browser.
  • Session recordings: a replay of how a screen was used. Everything typed into a field is masked before it leaves your device, so passwords and free text do not appear in a recording.
  • Console messages and unhandled errors from the app, and the server-side logs and error reports behind a request, which carry your user id so a problem can be traced to the session that hit it.
  • An approximate location — usually the city — which PostHog works out from the IP address your connection presents.

Until you sign in, none of this is attached to a person: signed-out visitors are counted without a profile being created. Once you sign in, events are linked to your account id, and only to that — we do not send your email address, your name or anything from your profile to PostHog.

Email we send you

Our email provider, Resend, keeps a record of each message sent to you — the address, the subject and whether it arrived — so a missing sign-in link can be chased. We send only messages the account needs: welcome, confirm your address, reset your password, a change of email, an account deleted confirmation, and the decision on a dive centre registration. There is no marketing list and no newsletter.

3. Why we use it

Every use has a lawful basis under the GDPR. These are ours.

What we do with itLawful basis
Creating your account and signing you inPerformance of a contract
Holding your profile, plans, logs, reviews and sightingsPerformance of a contract
Sharing a plan with the buddies, centre or link you choosePerformance of a contract
Publishing an approved dive centre's listingPerformance of a contract
Sending account, security and dive centre decision emailsPerformance of a contract
Checking a new password against known breachesLegitimate interest — keeping accounts from being taken over
Product analytics and session recordingsLegitimate interest — understanding what people use so the app gets better
Application and error logsLegitimate interest — finding and fixing faults
Reviewing a dive centre registration before it goes publicLegitimate interest — keeping the directory honest
Reading your device's locationConsent, given through your browser or phone, and revocable there
Keeping records we are required by law to keepLegal obligation

4. What is public and what is not

Worth knowing before you post

Reviews and sightings are public. Anyone, signed in or not, can read them on a site page along with the display name on your profile. Do not put anything in a review or a sighting note that you would not put on a noticeboard.

  • Your profile — display name, picture, certification level and bio — is visible to other signed-in divers. Your email address and your home port are not.
  • Dive plans are private by default. A plan is yours alone until you change its visibility to buddies, to your dive centre or to public, or add someone to it.
  • A share link works without a sign-in. The token is long and random so nobody can find it by guessing, but whoever holds the link can open the plan and can pass it on. Delete the link when you are done with it.
  • Dive centre listings are public once approved, including the address, phone number, email address and website given. A pending or rejected registration is visible only to the person who submitted it and to us.

5. Your location

The app can use your device's location for bearings to an entry point, the distance to a site, and sorting sites by what is nearest. Your browser or phone asks first, and you can refuse or withdraw that permission at any time in its settings — everything except the bearings keeps working without it.

Your position never leaves your device. The last fix is kept in your browser's local storage so the screen can draw immediately next time, and the bearings are worked out there too. We do not send it to our servers, we do not store it in your account, and we have no history of where you have been. Clearing the site's data in your browser erases it.

A home port you set yourself is different: that one you typed in, and it is saved with your profile so it is there on your other devices.

6. Sea conditions and maps

Forecasts are fetched by our servers, per dive site, on a schedule — never per diver. Copernicus Marine, Open-Meteo, the Oceanography Malta Research Group and aviationweather.gov are asked about a patch of sea, and receive nothing about you, not even your IP address. The sources are credited in full on the about page.

Map tiles are the exception: your browser fetches them straight from OpenFreeMap, which serves OpenStreetMap data, so their servers see your IP address and which tiles you asked for — the same as any image loaded from another site. The same is true of the two typefaces, which come from Google Fonts.

7. Who else sees your data

We do not sell personal data, and we do not share it with advertisers. There is no advertising in this app. These are the services that process some of it on our behalf, and nobody else:

ServiceWhat it doesPolicy
Supabase, through Lovable CloudThe database, sign-in and file storage behind the appsupabase.com/privacy
LovableHosting and deploymentlovable.dev/privacy
PostHog (EU cloud)Product analytics, session recordings, logs and error reportsposthog.com/privacy
ResendDelivering account emailresend.com/legal/privacy-policy
GoogleSigning in with Google, if you choose it, and the web fontspolicies.google.com/privacy
OpenFreeMapServing the map tiles your browser drawsopenfreemap.org
Have I Been PwnedTelling you a password has appeared in a breachhaveibeenpwned.com/Privacy

The breach check is worth explaining, because it sounds worse than it is: your password is hashed on your own device and only the first five characters of that hash are sent. Have I Been Pwned answers with every match for that prefix and the comparison happens locally. Your password, and the rest of its hash, never leave the device.

8. Where your data is kept

Your account, your plans and everything else in the database sit on Supabase infrastructure in the European Union. PostHog holds its analytics, recordings and logs on its EU servers.

Resend processes email in the United States, and Google processes a Google sign-in on its own infrastructure. Where data reaches a country outside the EEA it is covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard.

9. How long we keep it

WhatHow long
Account, profile, plans, logs, buddies and centre membershipsAs long as the account exists
Reviews and sightingsUntil you delete them, or the account goes
Share linksUntil you delete the link or the plan
Dive centre listing and its approval recordUntil the centre or its owner's account is deleted
Analytics, session recordings, logs and error reportsPostHog's own retention, currently one year for events and recordings
Email delivery records at ResendResend's own retention, a matter of months
Your last known positionIn your browser only, until you clear the site's data

Deleting your account removes it and everything hanging off it — profile, plans, logs, share links, reviews, sightings, buddy links and any dive centre you registered — from the database. It cannot be undone. Analytics already recorded stay under their own retention above, attached to an account id that no longer belongs to anyone.

10. Your rights

The GDPR gives you rights over your data, and for the two people ask for most, the app does it without going through us.

  • Access and portability. Account settings has a download that gives you everything we hold about you as one JSON file: account, profile, plans, participations, share links, reviews, sightings, buddies, memberships and centres.
  • Erasure. The same page deletes the account outright, after asking for your password or a fresh Google sign-in so nobody else can do it for you.
  • Rectification. Your profile, plans, reviews and sightings are all editable in the app. Anything you cannot reach, write to us.
  • Objection and restriction. You can object to anything we do on the basis of legitimate interest, analytics included, and ask us to limit what we do with your data while a question is open.
  • Withdrawing consent. Location permission is the only consent we rely on, and it is revoked in your browser or phone settings.

For anything you want us to do, email privacy@tahtilbahar.com. We answer within 30 days. If you think we have got it wrong you can complain to the Maltese Information and Data Protection Commissioner, or to the authority in your own EU country.

11. Cookies and local storage

We set no advertising cookies and run no ad trackers. What the app keeps in your browser is:

  • Your sign-in. The session token that keeps you signed in between visits.
  • Your last known position, so a screen needing a bearing can draw before the device answers again.
  • PostHog's identifier, which is how two visits are recognised as the same person rather than two.
  • A short-lived marker used when a Google sign-in bounces you back mid-deletion.

Clearing the site's data in your browser removes all of it and signs you out.

12. Keeping it safe

  • Everything travels over HTTPS.
  • Every table enforces its own row-level rules in the database, so a private plan is unreadable even to a request that goes around the app.
  • Passwords are stored only as hashes, and are checked against known breaches.
  • Deleting an account needs your password or a sign-in from the last five minutes.

No system is perfect. If you find a way to reach data that is not yours, please tell us at hello@tahtilbahar.com before telling anyone else.

13. Children

Taħt il-Baħar is not for children. You must be at least 16 to hold an account, which is the age Malta sets for consenting to online services on your own. We do not knowingly collect anything from anyone younger; if you believe a child has an account here, email privacy@tahtilbahar.com and we will remove it.

14. Changes to this policy

When the app changes, this policy changes with it, and the date at the top moves. If a change matters to you — a new recipient of your data, a new purpose — we will say so by email or in the app before it takes effect rather than leaving you to notice.

15. Contact us

This policy is governed by the law of Malta and by the General Data Protection Regulation. The terms of use cover the rest of what you can expect from the app, and it from you.