Legal

Privacy.

What we collect, what we do with it, and how to remove it.

What we collect

We collect your account details (username, email if you provide one) and your activity (sightings, comments, dive logs, site suggestions). Server logs (IP, timestamp, user agent) are retained for 30 days. **None of this is highly protected.** Only your password is treated as private (stored hashed). All other data — including site comments and contribution history — may be disclosed to any official, legal, or governmental entity on lawful request. See the Terms for the full disclosure language.

Cookies

Session cookies (httpOnly JWT) for authentication. A `locale` cookie for language preference. A theme preference key in localStorage. No third-party analytics, no advertising trackers.

Your rights

Export your data via the profile page. Delete your account and contributions via account settings. Email [email protected] for assistance.