Introduction
Welcome to Odyssea ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our mobile application.
Odyssea is operated by Tatsapat Saerejittima, an independent app developer based in Bangkok, Thailand, who acts as the data controller for the personal data described in this policy. Contact details are in the "Contact Us" section below.
Information We Collect
Information You Provide Directly
- Account Information: Your name, email address, and user ID when you create an account or sign in via Google or Apple
- Dive Log Data: Information about your dives including date, time, location, depth, duration, and dive site details
- Personal Profile: Your name, certification details, agency information, and certification numbers
- Photos: Profile photos and dive-related images you attach to your dives, trips, and wildlife sightings. When you are signed in, these are backed up to your account as described under "Cloud Hosting"
- Dive Buddy Information: Names and details of dive buddies you add to your logs
Automatically Collected Information
- Dive Site Coordinates: The coordinates of dive sites you attach to a dive log, taken from our reference data, entered by you, or contained in dive-computer files you choose to import. The App does not access your device's GPS location
- Google Sign-In Service Data: When you use Google Sign-In, Google may collect your IP address and use it to estimate general location for fraud prevention. The SDK also sends technical sign-in metadata such as SDK, platform and operating-system versions
- Device Information: App version, operating system version, and device model, for troubleshooting purposes
- Crash & Diagnostic Data: Crash reports, error diagnostics, and app performance data via Sentry, associated with a pseudonymous user identifier (never your name or email) to help us fix bugs
- Purchase Information: If you subscribe to Odyssea Pro, the subscription product, purchase date, renewal status, and a store transaction identifier, received from Apple or Google via our subscription provider (RevenueCat). We never receive your payment card details
Information from Third-Party Services
- Google Sign-In / Apple Sign-In: When you authenticate, we receive your name, email address, and a unique account identifier from the provider. We do not receive your password.
- Apple authentication credentials: During Apple sign-in or confirmation for account deletion, we briefly receive an identity token, a one-time authorization code, and a nonce (a random value that binds the sign-in request to its response). Our backend exchanges the code with Apple and retains each distinct Apple refresh token, encrypted at rest, so it can remove your Apple sign-in access when you delete your account. These Apple refresh tokens are separate from your Odyssea session tokens and are never sent back to the app.
- Apple App Store / Google Play: When you subscribe to Odyssea Pro, the store processes your payment and shares the purchase receipt with our subscription provider (RevenueCat) so we can unlock Pro features on your account.
How We Use Your Information
We use the information we collect to:
- Create and manage your account and dive certification cards
- Store and synchronize your dive log history across your devices
- Provide and maintain the cloud sync and photo backup service
- Verify and manage your Odyssea Pro subscription
- Enable export and sharing of your dive data
- Monitor app stability and fix crashes
- Improve app functionality and user experience
- Provide customer support
- Comply with legal obligations
Data Storage and Security
Local Storage
- Your data is stored locally on your device using a SQLite database for offline access
- The app works fully offline; an internet connection is only needed for account features and sync
Server Storage
- When you create an account, your dive logs, profile, and related data are synchronized to our servers hosted on secure cloud infrastructure
- Server data is stored in a PostgreSQL database with encrypted connections
- Your data is associated with your user account and is not shared with other users
- Photos and images you attach to your dives are stored as files in private cloud object storage (separate from the database above) so they can be restored to your other devices. Free accounts back up a reduced-size copy; Odyssea Pro backs up the full-resolution original. The copy on your device is never modified
Security Measures
- All data transmitted between the app and our servers is encrypted via TLS/HTTPS
- Authentication tokens are stored securely on your device using platform-provided secure storage
- API access is protected by API key validation and JWT authentication
- Regular security updates and patches
Notifications
- Dive and trip reminders are scheduled locally on your device
- We do not use a push-notification service, and no data leaves your device to deliver a reminder
- You can turn reminders off at any time in Settings or in your device's notification settings
Data Synchronization
When you are signed in, the following data is synchronized between your device and our servers:
- Dive logs and dive cards
- Trip information, travel legs, accommodation, planned dives, and expenses
- Reviews and wildlife sightings
- User profile information
- Photos and images attached to your dives, trips, sightings, and profile
We store your backed-up photos so you can restore them; we do not use them for analytics, advertising, or any other purpose. If we ever offer to use specific photos (for example, wildlife-sighting photos for species research), we will ask for your explicit, separate consent first.
Reference data (dive areas, dive sites, wildlife information) is managed by Odyssea and distributed to all users. Your personal data is only accessible to you.
Your Privacy Rights
Depending on your location, you may have the following rights:
General Rights
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and all associated data
- Export: Download your data in a portable format (JSON)
- Opt-out: Use the app without creating an account (local-only mode)
Account Deletion
You can delete your account at any time through the app (Settings > Account > Delete Account), or by emailing us from the address linked to your account. Upon deletion:
- Your account is immediately deactivated and signed out on every device
- For Apple-linked accounts, we request removal of your Apple sign-in access and automatically retry temporary failures. If a usable Apple credential is unavailable, the app may ask you to confirm with Apple or explicitly agree to remove access yourself. Cancelling Apple confirmation does not delete your account. Pending and manual-removal results include instructions at Apple Account under Sign-In & Security > Sign in with Apple > Odyssea
- Your personal data on our servers is scheduled for permanent deletion after the 30-day restoration window
- Signing in before permanent cleanup restores your account and synced data; after permanent cleanup, deletion cannot be undone
- Local data on your device remains until you uninstall the app or delete it in Settings
- An active Odyssea Pro subscription is not cancelled by deleting your account; cancel it in your Apple ID or Google Play subscription settings
GDPR Rights (European Users)
If you are in the European Economic Area (EEA), you have additional rights under GDPR:
- Right to data portability
- Right to restrict processing
- Right to object to processing
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority
PDPA Rights (Thailand)
We are established in Thailand, so the Personal Data Protection Act B.E. 2562 (2019) applies to our processing. Under the PDPA you have the right to access and obtain a copy of your personal data, to have it corrected, erased, or restricted, to object to processing, to receive it in a portable format, to withdraw consent at any time, and to lodge a complaint with the Personal Data Protection Committee (PDPC). Where your data is transferred outside Thailand to the processors listed below, we do so on the basis that it is necessary to provide the service you asked for and under contractual safeguards with those processors.
CCPA Rights (California Users)
If you are a California resident, you have rights under CCPA:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to say no to the sale of personal information (we don't sell data)
- Right to non-discrimination for exercising your rights
Data Retention
- We retain your data for as long as your account is active
- After account deletion, server-side data is scheduled for permanent deletion after the 30-day restoration window
- Encrypted Apple refresh tokens are kept while your account is active for later revocation. During deletion, they are retained until revocation succeeds or reaches a terminal manual-removal outcome, or until scheduled hard purge after the 30-day restoration window. Token material is removed at that point; related revocation records and deletion-recovery receipts are removed by hard purge. Signing in before permanent cleanup restores your account and cancels the deletion request
- Crash and diagnostic reports held by Sentry are pseudonymous and expire under Sentry's standard retention period (currently 90 days)
- Your RevenueCat customer record (app user identifier and purchase history) is retained by RevenueCat so that Store purchases can be restored; email us if you want it erased as well
- You can export your data before deleting your account
- Local data on your device persists until you uninstall the app or manually delete it
Children's Privacy
Odyssea is intended for users aged 16 and older. We do not knowingly collect personal information from anyone under 16. If you are a parent or guardian and believe a child under 16 has provided us personal information, please contact us and we will delete it.
Third-Party Services
Authentication Providers
- Google Sign-In: Subject to Google's Privacy Policy
- Apple Sign-In: Subject to Apple's Privacy Policy
We receive your name, email, and account identifier from these providers, together with the authentication credentials needed to verify sign-in. For Apple, we briefly receive the identity token, one-time authorization code, and nonce, exchange the code on our backend, and retain distinct encrypted Apple refresh tokens for account-deletion revocation as described under "Data Retention". We do not receive your provider password.
Google Sign-In may also collect your IP address and use it to estimate general location for fraud prevention, independently of the profile fields returned to Odyssea. The SDK sends technical service metadata and declares analytics as well as authentication functionality; Google's handling of that data is governed by its privacy policy. This does not require device GPS permission.
Subscriptions (RevenueCat)
- We use RevenueCat (RevenueCat, Inc.) to manage Odyssea Pro subscriptions purchased through the Apple App Store or Google Play
- RevenueCat receives your Odyssea user identifier (or an anonymous identifier if you are not signed in), the purchase receipt issued by the store, and basic device information (platform, app version) in order to validate purchases and unlock Pro features across your devices
- Payments are processed entirely by Apple or Google under their own terms and privacy policies; neither we nor RevenueCat receive your payment card details
- Subject to RevenueCat's Privacy Policy
Crash Reporting (Sentry)
- We use Sentry (Functional Software, Inc.) to collect crash reports, error diagnostics, and performance data
- Reports are associated with a pseudonymous user identifier so we can gauge how many users a bug affects; we do not attach your name or email
- This data is used only to identify and fix bugs and improve app stability
- Subject to Sentry's Privacy Policy
Cloud Hosting
- When you create an account, your synced data is stored on cloud servers operated by DigitalOcean, LLC on our behalf
- Subject to DigitalOcean's Privacy Policy
- Photo and image files you back up are stored on Cloudflare R2 object storage, operated by Cloudflare, Inc. on our behalf, in a private bucket. Access is granted only to you, through short-lived, authenticated links
- Subject to Cloudflare's Privacy Policy
Camera and Photo Library Access
- We request access to your photo library to save dive cards you export and to let you pick photos for your profile, dives, trips, and sightings
- We request access to the camera only when you choose to take a photo inside the app
- Photos are only accessed when you explicitly pick, take, save, or share them; we do not scan or access other photos in your library
Location
- The App does not request or use your device's GPS location
- When you use Google Sign-In, Google may use your IP address to estimate general location for fraud prevention, independently of the disabled map feature
- Dive site coordinates come from our reference data or from values you enter, are stored with your dive logs, and are synced to your account if you are signed in
International Data Transfers
- Our cloud servers and processors (DigitalOcean, Cloudflare, RevenueCat, Sentry, Google, Apple) may store and process data in data centers outside Thailand and outside your country of residence
- Where required, we rely on appropriate safeguards (such as the providers' Standard Contractual Clauses) for these transfers, in compliance with applicable data protection laws
Changes to This Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by:
- Updating the "Last Updated" date at the top of this policy
- Asking you to review and accept the updated policy the next time you open the app while signed in
- For material changes, requesting your consent again if required by law
Contact Us
If you have questions, concerns, or requests regarding this privacy policy or your personal data, please contact the data controller:
Data Controller: Tatsapat Saerejittima (independent developer) Address: 444 Condolette Ize, Petchburi Rd., Ratchathewi, Bangkok 10400, Thailand Email: support@exploreodyssea.app Response Time: We will respond to privacy requests within 30 days
Legal Basis for Processing (GDPR)
For European users, our legal basis for processing your personal data is:
- Consent: You have given explicit consent for specific purposes (e.g., creating an account)
- Contract: Processing is necessary to provide the app services, including cloud sync
- Legitimate Interest: To improve and maintain the app functionality and stability
- Legal Obligation: To comply with applicable laws
Cookies and Tracking
- Odyssea does not use cookies
- We do not use advertising trackers
- We do not run analytics on your dives, photos or activity in the App
- Google Sign-In processes technical service metadata and declares analytics as described under "Authentication Providers"
- Crash reporting via Sentry is limited to technical error data
Your Consent
By using Odyssea, you consent to this privacy policy. When you sign in, we record the version of this policy you accepted and the time of acceptance so we can honor your choices and tell you when the policy changes. If you do not agree with this policy, please do not use the app. You may use the app without creating an account to avoid server-side data storage.
How to Exercise Your Rights
To exercise any of your privacy rights:
- Export Data: Settings > Data Management > Export All Data
- Delete Account: Settings > Account > Delete Account
- Delete Local Data: Settings > Data Management > Delete All Data
- Contact Us: Email support@exploreodyssea.app
We will respond to your request within 30 days and may require verification of your identity.
Odyssea - Your Personal Dive Companion