Privacy & Data Protection
Last updated: July 26, 2026
This page explains what data DiveScan (the "App") processes, why, and where it lives. We've tried to write it in plain language rather than pure legal boilerplate. Where German/EU law requires specific disclosures (GDPR), those are covered below.
Who is responsible
The data controller for DiveScan is:
Matthias BrechtZur Adlerseige 7
93105 Tegernheim
Germany
Email: mb@brecht.me
The short version
- Your dive data (dive logs, photos of pages, sites, notes) is stored in your own private iCloud database — not on our servers.
- A scanned page is sent to Anthropic's Claude API purely to extract the data on it. It is not used to train models and is not stored by us.
- Our own server only ever tracks how many scan credits you have left — never the contents of a dive.
- Payments are handled entirely by Apple. We never see your card details.
- There is no advertising and no analytics SDK that profiles you.
What data is processed, and why
1. Scanned pages (AI extraction)
When you scan or import a page, the image is sent to Anthropic's Claude API (api.anthropic.com) so its vision model can read the handwriting and structured fields on the page. This is done under our instructions as a data processor. Anthropic's own privacy practices for its API are described at anthropic.com/legal/privacy. The extracted result is returned to your device; we do not keep a copy of the image on our servers.
2. Your digital logbook
Dives, dive sites, notes, and the original scan you choose to keep are stored using Apple's SwiftData framework with CloudKit's private database — meaning the data is tied to your own iCloud account and synced only between your own devices. We do not have access to it, and it never touches our servers.
3. Account & scan credits
To meter free and purchased scan credits, the App creates a lightweight account (via Supabase) that records your remaining credit balance and purchase history. This account intentionally does not store any dive data — its only job is the number on the "Scan credits" screen. Apple's DeviceCheck is used to tie the initial free scans to your device, to prevent the free trial from being reset by reinstalling the App.
4. Purchases
Scan credit packs are bought through Apple's In-App Purchase system (StoreKit). Apple processes the payment and is the merchant of record; we receive a signed transaction confirming what was bought, never your payment details.
Legal basis (GDPR Art. 6)
- Contract performance — processing scans and metering credits is necessary to provide the scanning service you're using.
- Legitimate interest — DeviceCheck-based trial metering, to prevent abuse of free scans.
Recipients / sub-processors
- Anthropic PBC (Claude API) — processes scanned page images to extract dive data.
- Apple Inc. — iCloud (private database sync), StoreKit (purchases), DeviceCheck (fraud prevention).
- Supabase Inc. — hosts the account/credit-metering backend.
Some of these providers may process data outside the EU/EEA (e.g. in the United States). Where that happens, it is covered by their respective Standard Contractual Clauses or equivalent safeguards.
Data retention
Your dive data stays in your private iCloud database for as long as you keep it in the App. Account and purchase records are retained as long as needed to maintain your credit balance and to satisfy accounting/legal obligations. Scanned images are not retained by our servers beyond the extraction request itself.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing based on legitimate interest. Since your dive data lives in your own iCloud account, you can delete it directly in the App at any time. For anything related to your account or credit balance, contact mb@brecht.me. You also have the right to lodge a complaint with your local data protection supervisory authority.
Security
Data in transit to Anthropic and our backend is encrypted (TLS). Any API key you enter yourself is stored in the iOS Keychain, never in plain preferences or hardcoded in the App.
Children
DiveScan is not directed at children under 16.
Changes to this policy
If how DiveScan handles data changes materially, this page will be updated with a new "last updated" date above.
Contact
Questions about this policy or your data: mb@brecht.me.