Privacy Policy
Last updated: April 18, 2026
1. Introduction
freediver.club (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our freediving tools and services.
2. Information We Collect
2.1 Personal Information
We may collect personal information that you voluntarily provide to us, including:
- Name and email address (if you create an account)
- Profile information and preferences
- Workout plans, training sessions, and related training data you create or import
- Communications with us
- Feedback and survey responses
2.2 Automatically Collected Information
When you visit our website, we automatically collect certain information, including:
- IP address and device information
- Browser type and version
- Pages visited and time spent on pages
- Referring website
- Usage patterns and interactions with our tools
3. How We Use Your Information
We use the collected information for the following purposes:
- Provide and maintain our freediving tools and services
- Improve and personalize your experience
- Analyze usage patterns to enhance our platform
- Communicate with you about updates and features
- Ensure security and prevent fraud
- Comply with legal obligations
4. Wearable Devices and Workout Data Collection
Users who complete freediver.club workouts on the Freediver.club app, Garmin, Suunto, Apple Watch, or other devices that are directly linked with the freediver.club ecosystem (where you log in with your freediver.club account) or indirectly linked through third-party systems such as Garmin or Suunto can expect their workout data to be collected by freediver.club. This information is used only for your workout analysis and will not be used for any other purpose without your explicit permission.
The information we store from your wearable devices may include:
- Number of completed workouts
- Lap and break times
- Heart rate (HR) interval data for charting in the Freediver.club app
- Other data that the wearable manufacturer provides
This data enables us to provide you with workout analysis and visualizations within the Freediver.club app. We will not use this data for marketing, advertising, or any purpose beyond your personal workout analysis unless you have given us explicit permission to do so.
5. Third-Party Services and Data Processing
We use several third-party services to operate our platform. Each service processes your data according to their own privacy policies and our agreements with them:
5.1 Auth0 (Authentication and Authorization)
Our authentication, authorization, and login credentials are handled by Auth0, a third-party identity management service operated by Auth0, Inc. When you create an account or log in to our platform:
- Auth0 processes your login credentials and authentication data
- Auth0 manages user sessions and access tokens
- Auth0 handles password security and account recovery
- Auth0 may collect additional information as outlined in their Privacy Policy
Auth0's collection and processing of your authentication data is governed by their own Privacy Policy and Terms of Service. We recommend reviewing Auth0's privacy practices at https://auth0.com/privacy.
5.2 Google Cloud Platform (Hosting and Data Processing)
Our website is hosted on Google Cloud Platform (GCP), a cloud infrastructure service operated by Google LLC. GCP processes your data in the United States and may collect:
- IP addresses and request logs
- Performance and error data
- Usage analytics for service optimization
Google Cloud's data processing is governed by their Privacy Policy available at https://cloud.google.com/terms/cloud-privacy-notice.
5.3 Supabase (Data Storage)
We use Supabase, operated by Supabase Inc., for data storage and database services. Your data is stored in databases located in the United States and may include:
- User account information and preferences
- Workout data and training records
- Application settings and configurations
- Usage data and analytics
Supabase's data processing is governed by their Privacy Policy available at https://supabase.com/privacy.
5.4 Amplitude (Data Tracking and Analytics)
We use Amplitude, operated by Amplitude Inc., to track website usage and analyze user behavior. Amplitude may collect:
- Page views and navigation patterns
- User interactions and engagement metrics
- Feature usage and tool interactions
- Device and browser information
Amplitude uses cookies and similar technologies. Amplitude's data processing is governed by their Privacy Policy available at https://amplitude.com/privacy.
5.5 Google Analytics (Website Analytics)
We use Google Analytics, operated by Google LLC, to collect and analyze website usage data. Google Analytics may collect:
- Page views and session duration
- Traffic sources and user demographics
- Device and browser information
- User behavior and interaction patterns
- Geographic location data (at country/region level)
Google Analytics uses cookies and similar technologies to collect this information. Google's data processing is governed by their Privacy Policy available at https://policies.google.com/privacy. You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.
6. Connected Services (AI, MCP, and Third-Party Integrations)
freediver.club provides integrations via the Model Context Protocol (MCP) to securely connect AI assistants (such as ChatGPT), as well as connections to third-party fitness tracking services.
6.1 AI Extension Data Boundaries & Minimization
To protect your privacy when using connected AI assistants, we strictly enforce the following boundaries:
- Data Minimization: We request and process only the absolute minimum information necessary to execute the tools or actions you authorize.
- No Chat Logging: We do not pull, reconstruct, store, or infer your full chat logs or conversational histories from any AI client.
- No Restricted Data: We never collect, process, or request Payment Card Information (PCI DSS), Protected Health Information (PHI), Government IDs, or authentication secrets via our AI integrations.
- Response Minimization: We return only the requested data to the AI. We do not inject unnecessary diagnostic telemetry, session IDs, or hidden tracking tags.
- No Surveillance: We do not engage in surveillance, tracking, or behavioral profiling based on your AI prompts or usage patterns.
6.2 AI Access Controls
- Explicit Authorization: Connecting an AI assistant requires completing an OAuth flow. You must review and grant explicit permission before any data is sent or received.
- Strict Scoping: Access tokens are strictly limited to your own account data.
- Revocable Defaults: You can instantly revoke all AI connections at any time via your Profile → Connected Services page. Revocations take effect immediately.
6.3 Training Center Coaching Access
A training center can only read your data through MCP if both of the following are true:
- You are an active athlete at that training center within freediver.club.
- You have explicitly enabled MCP Coaching Access for that training center in your Profile → Connected Services page.
This toggle is off by default. Turning it on grants the training center read access to your training data (workouts, dive logs, and related metrics) solely for coaching purposes. You can turn it off at any time and access is revoked immediately.
6.4 User-Controlled External Service Integrations
freediver.club integrates with external services such as Garmin and Suunto to sync your workout data. All such integrations are entirely opt-in and under your control:
- You must explicitly authorize each external service before any data exchange takes place
- A full list of your currently authenticated external services is available in your Profile → Connected Services page
- You can revoke access to any connected service at any time from that same page — revoking access immediately stops all future data synchronization with that service
- We only request the minimum data permissions required to provide the integration features you have chosen to enable
Data received from external services (e.g., dive logs, heart rate data, workout summaries) is stored in your account and used solely for your personal workout analysis within freediver.club.
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience and analyze website usage. These technologies help us:
- Remember your preferences and settings
- Analyze website traffic and usage patterns
- Provide personalized content and recommendations
- Improve our services and user experience
You can control cookie settings through your browser preferences. However, disabling certain cookies may affect the functionality of our website.
8. Information Sharing and Disclosure
We do not sell, trade, or otherwise transfer your personal information to third parties, except in the following circumstances:
- With your explicit consent
- To comply with legal obligations or court orders
- To protect our rights, property, or safety
- With trusted service providers who assist in operating our website (under strict confidentiality agreements), including:
- Auth0: For authentication, authorization, and user account management
- Google Cloud Platform: For website hosting and data processing (US-based)
- Supabase: For data storage and database services (US-based)
- Amplitude: For website usage analysis and performance monitoring
- Google Analytics: For website analytics and user behavior tracking
9. Data Retention
Your personal data is retained for as long as you hold an active account with freediver.club. You can delete your account at any time from your Profile page. Once account deletion is initiated, all personal information — including your profile, workout records, and Auth0 authentication profile — is erased automatically.
Anonymised usage and behaviour data (collected via Amplitude and Google Analytics) is not linked to your account and is not removed upon deletion, as it contains no personally identifiable information.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
11. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
- Access and review your personal information
- Correct inaccurate or incomplete information
- Delete your account and personal data — available directly from your Profile page. See Section 9 for details on what is removed.
- Object to or restrict processing of your information
- Data portability — you can request a structured export of your data via API access. To make this request, contact us at hello@freediver.club.
- Withdraw consent at any time
To exercise any of the above rights, contact us at hello@freediver.club.
12. Children's Privacy
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
13. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure that such transfers comply with applicable data protection laws and implement appropriate safeguards to protect your information.
Specifically:
- Google Cloud Platform: Processes data in the United States
- Supabase: Stores data in the United States
- Amplitude: Processes data in the European Union (EU) for GDPR compliance
- Google Analytics:Processes data globally in accordance with Google's data processing terms
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last updated” date. Your continued use of our services after such changes constitutes acceptance of the updated policy.
15. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: hello@freediver.club
Website: https://freediver.club
Changelog
April 18, 2026
Added strict privacy boundaries for AI integrations. Disclosed Amplitude and Google Analytics usage, updated infrastructure to Google Cloud, and clarified policies for data retention, account deletion, and data portability.
January 21, 2026
Added Section 4 “Wearable Devices and Workout Data Collection” describing workout data collection from the Freediver.club app, Garmin, Suunto, and Apple Watch
July 7, 2025
Initial publication of the Privacy Policy.