Privacy
Shoal has no accounts, no analytics, and no server that stores your dives. Your dive log lives on your own device and in folders you choose. This page explains the exceptions — the handful of moments where something does leave your device, exactly what gets sent, and who receives it.
1. Who this is
Shoal is built and run by one person, in the United Kingdom. For anything on this page — questions, corrections, or a request about your data — write to luke@diveshoal.com.
2. The short version
- No account. You never create one, so there is nothing to identify you by.
- No analytics, no tracking, no advertising. Shoal contains no third-party tracking or advertising code of any kind.
- No Shoal server holds your dives. There is no backend and no database. Your dives are stored on your device and, if you enable it, written as plain files into a folder you pick.
- Your dive data is never sold or shared — there is no mechanism by which it could be.
- Some features need the internet, and those requests go from your device straight to the service concerned. Section 4 lists every one.
3. What Shoal stores, and where
Everything Shoal records is stored in one or more of these places, all of which are yours:
- Your browser or app's local storage on your device. Dive records, marine-life sightings, your settings, and the autocomplete suggestions built from your own past entries.
- A folder you choose, if you turn on folder sync. Shoal writes each dive as a plain Markdown file, plus small companion files for video links and dive-computer profiles. Shoal can only read and write inside the folder you pick.
- An Obsidian vault on the same computer, if you use that option. This talks to Obsidian over your machine's own loopback address (127.0.0.1) and never touches the internet.
If the folder you choose happens to be inside a cloud-storage folder — Google Drive, Proton Drive, iCloud — then that provider syncs those files as it would any other file on your computer. That is the provider's processing under their own privacy policy, not Shoal's.
4. What leaves your device
Shoal makes no background requests. Each row below happens only when you use the feature described, and the request goes directly from your device to that service — it does not pass through any Shoal server, because there isn't one. Every service listed receives your IP address as an unavoidable part of any internet request.
| Who | What they receive | When |
|---|---|---|
| OpenStreetMap tile servers | Which part of the map you are viewing, as map-tile requests | Whenever a map is shown |
| Nominatim (OpenStreetMap Foundation) | The exact coordinates of a pin you place, or the place/site text you type | When you drop a map pin, search for a site, or pick a country |
| Overpass API | A map area, to look up known dive sites within it | When you search for a dive site |
| Open-Meteo | The coordinates of the location you are planning for | When you use wind/sea forecasts on the Plan page |
| GitHub (raw.githubusercontent.com) | A request for a public community dive-site data file. No dive data is sent. | When you search for a dive site |
| iNaturalist open-data storage | Requests for species reference photographs, which reveal which species you are looking at | When you browse or search marine species |
| UK Hydrographic Office (Admiralty API) | Coordinates, to find the nearest tidal station, plus the API key you supplied | Desktop app only, when you view UK tide times |
| Google Drive | Only the files you explicitly choose to upload — see section 5 | Desktop app only, and only if you connect Drive |
| Cloudflare (hosting) | Standard web-server request logs: IP address, browser type, time, page requested | Whenever you load the app or this website |
The location services above receive the coordinates of a dive site — a place in the sea you are logging or planning for. They do not receive your dive log, your notes, your sightings, or any identifier that ties those coordinates to you.
5. Google Drive
Connecting Google Drive is optional, off by default, and currently available in the desktop app only. It exists so you can keep dive videos and photos in your own Drive rather than only on one machine.
- Shoal requests the
drive.filescope only. This is the narrowest Drive permission Google offers: it lets Shoal see and manage only the files Shoal itself creates. Shoal cannot see, list, read, or touch anything else in your Drive. - Your Google sign-in happens on Google's own pages. Shoal never sees your Google password.
- The resulting access token is stored in your operating system's own secure credential store (the macOS Keychain), not in the app's ordinary storage, and never leaves your machine.
- Shoal's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. That data is never used for advertising, never sold, and never transferred to anyone except as needed to provide the feature you asked for.
- You can disconnect at any time in Settings, and separately revoke Shoal's access from your Google Account permissions page.
6. Device permissions
- Location — used only at the moment you tap "use my location" to place a dive pin. The coordinates go into your own dive record. Shoal does not track your location in the background, and there is nowhere for such data to be sent.
- Bluetooth — used only to talk to a dive computer you pair yourself, in order to download your dives. This communication is between your device and your dive computer; nothing about it goes to the internet.
- Files and folders — Shoal can only see the specific folder you choose in the system picker. It has no access to the rest of your device.
7. What Shoal never does
- No advertising, and no advertising identifiers.
- No analytics, telemetry, crash reporting, or usage tracking.
- No third-party SDKs. The mapping and dive-physics libraries Shoal uses are bundled into the app itself and make no calls of their own beyond the map tiles listed above.
- No cookies used for tracking.
- No selling, renting, or sharing of personal data, and no profiling or automated decision-making.
8. Your data and your rights
Because your dive log is held on your own device and in your own folders, you already have direct control of it: you can read, edit, export, or delete any of it at any time, without asking anyone. Deleting the app's data through your browser or operating system removes Shoal's copy entirely; deleting the files in your synced folder removes the rest.
The limited personal data that does reach me is confined to the hosting logs described in section 4. Under UK data-protection law you have rights of access, rectification, erasure, restriction, objection, and portability over personal data held about you, and the right to complain to the Information Commissioner's Office. To exercise any of these, write to luke@diveshoal.com.
The third parties in section 4 are independent controllers of what they receive, and their own privacy policies govern it.
9. Children
Shoal is intended for certified divers and is not directed at children. It does not knowingly collect personal data from children.
10. Changes to this policy
If Shoal starts doing something new with data, this page changes in the same release — not afterwards. The date at the top is the date of the most recent change.
← Back to Shoal