Privacy Policy

Spearfishing Copilot · Last updated 19 August 2026

Spearfishing Copilot tells you where and when conditions look good for a dive. Doing that needs your dive spots, your dive history and your location. Those are sensitive: a private spot’s coordinate is the whole secret. This page says exactly what is collected, where it goes, and how to remove it.

The short version. Your spots, dives, catches and photos are private to your account by default and are never published, sold, or shared with other users unless you explicitly make a spot public. There is no advertising and no data broker. You can delete everything from inside the app, and the deletion is immediate and permanent.

1. Who is responsible

Spearfishing Copilot (“the app”, “we”) is the controller of the personal data described here. Questions, requests and complaints: support@path.com.tr.

2. What we collect, and why

DataWhyWhere it comes from
Name, email address, profile photo, account identifierTo have an account, and to show you as signed inYour sign-in provider (Apple, Google) or the email address you register
Home area, maximum depth, target speciesTo rank spots and tailor the dive score to your experienceYou, during onboarding or in the profile screen
Dive spots you save, including coordinates and whether they are privateThe core function of the appYou
Dive log entries: date, duration, depth, visibility, conditions, notes, species caught, photosYour history, and to personalise future scores from your own resultsYou
Approximate or precise device locationTo find spots near you and to pre-fill where a dive happenedYour device, only while the app is open and only after you allow it
Push notification tokenTo alert you when conditions at a spot you follow look goodYour device, if you enable notifications
App usage events and crash reportsTo see which screens are used and to fix crashesFirebase Analytics and Firebase Crashlytics
Technical request logs (IP address, timestamp, endpoint)Security, abuse prevention and debuggingOur hosting provider, automatically

We do not collect contacts, health data, browsing history or advertising identifiers, and we do not track you across other apps or websites. The app shows no ads.

3. Legal basis

Where the GDPR or Turkey’s KVKK applies: account data, spots and dive logs are processed to perform the contract you enter into by using the app. Location is processed on the basis of the permission you grant in the operating system, which you can withdraw at any time in system settings. Security logging rests on our legitimate interest in keeping the service running and unabused. Analytics and crash reporting rest on your consent where consent is required; you can turn them off as described in section 7.

4. Who processes data on our behalf

ProcessorPurposeLocation
Google (Firebase Authentication, Storage, Cloud Messaging, Analytics, Crashlytics)Sign-in, photo storage, push notifications, usage and crash diagnosticsEU / United States
Neon (PostgreSQL)The database holding your profile, spots and dive logFrankfurt, Germany (eu-central-1)
VercelHosting for the API serving the appFrankfurt, Germany (fra1)

Two services that see coordinates but not your identity

To draw the map and to fetch a forecast, the app asks two public services for data about a location. These requests carry coordinates and your device’s IP address, but no account identifier, name or email, and they are made directly by your device:

A coordinate you ask about is not necessarily a coordinate you dive at, and neither service is told which is which.

5. Privacy between users

A spot is private unless you deliberately make it public. Private spots, your dive log, your catches and your photos are visible only to your account; the server enforces this on every read, not just the app’s interface. When a spot cannot be shown to you, the API answers as though it does not exist rather than confirming that something is there — for a private site, the coordinate is the secret worth protecting.

6. How long we keep it

Your account data, spots and dive log are kept until you delete them or delete your account. Deleting your account removes the profile and cascades to every dive, catch, photo record and private spot attached to it. Technical logs are kept for a short period by our hosting provider and then discarded. Backups roll off within 30 days.

7. Your choices and rights

8. Children

The app is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.

9. Security

Traffic runs over HTTPS. Sign-in tokens are issued by Apple, Google or Firebase and verified on every request against the issuing provider’s public keys; we never see or store your password. The database is reachable only over an encrypted connection with credentials held in the deployment environment. No system is perfectly secure, and we do not claim otherwise.

10. Changes

If this policy changes materially we will update the date at the top and, where the change affects how your data is used, tell you in the app before it takes effect.

11. Not a safety service

Conditions shown in the app are estimates from forecast data. They are not a guarantee of safety and must never replace your own assessment of the sea before you enter the water. See the Terms.