Last updated 18 August 2026 · Also in Deutsch
Your photographs are corrected on your iPhone and never leave it. This website and the app both count what happens in them, without knowing who you are, and each keeps a random identifier so that a second visit is recognisable as a second visit. Both can be switched off. That is the whole of it; the detail is below.
Jerome Sommerfeldt, Deutschland. Reach the controller at BBR@jeromesommerfeldt.de, which is also the address for any of the requests below. Further details are in the Impressum.
These pages load nothing from a third party: the fonts are served from this domain, and there is no tag manager, no embedded video and no advertising network. Nothing here is sold, shared with a data broker, or used to build an advertising profile of you, on this site or anywhere else.
We count what people do here: pages opened, the demo run, and the App Store link followed. The events are sent to PostHog, whose EU service processes them for us under Art. 28 GDPR, on the legitimate-interest basis of Art. 6(1)(f) GDPR — knowing which parts of the page work.
To do it, the site stores a random identifier in this browser, in a cookie and in local storage. It is what lets us see that the same browser came back a week later, which is the difference between counting visits and counting people. There is no name, no account and no email address attached to it, and it is not shared with anybody or used to follow you onto another site.
With each event we send the page’s path, the country and city your IP address resolves to (PostHog derives those and then discards the address itself, so it is never stored), your browser, operating system and device type, and where you arrived from — the site that linked to you, and any campaign tag we ourselves put in that link. We also record which things on the page were clicked, and how the page performed while you were on it. We drop the query string from every address, including anything a search engine or another site appended to it, so nothing you typed or chose travels with an event. The photograph you put into the demo is never uploaded — it is corrected in this browser and we learn only that a correction happened. No recording of your screen is ever made.
The identifier is the only thing connecting one of your visits to the next, and under Art. 11 GDPR we cannot work out who you are from it: we hold nothing that links it to you, and we will not collect anything in order to be able to. So we cannot answer an access or erasure request for these events by looking you up. What you can do instead is stop it, here and now.
Delivering a page necessarily involves your IP address. Our hosting provider, acting as a processor under Art. 28 GDPR, records the usual access data: IP address, the page requested, the time, the referring page and your browser and operating system. We use it to serve the site and to investigate faults and abuse, on the legitimate-interest basis of Art. 6(1)(f) GDPR, and it is kept only as long as that requires.
Consent under § 25(1) TDDDG is required for storing information on your device, and we store an identifier, so the honest position is that we rely on that section without asking you first. We think a banner everybody clicks away to reach the page is worth less to you than a plain sentence and a working switch, so that is what this is. It also serves your right to object under Art. 21 GDPR, and it takes effect immediately.
We keep your message and address for as long as it takes to answer you and to handle any follow-up, under Art. 6(1)(b) and (f) GDPR.
Every part of the correction runs on your device. Your photos and videos are not uploaded, not copied to a server and not processed anywhere but on the iPhone in your hand. There is no account and no sign-in, and the app works with no network connection at all. Export creates a corrected copy in Photos or Files and leaves the source untouched. The app keeps a local list of what it has corrected; that list is a cache on your device and is never sent anywhere.
Because dive sites are sensitive, the app strips location from an exported file by default. You can switch that off if you want to keep it.
One feature uses location, and this is the whole of it. To put a place name beside a dive, the app sends that dive’s coordinate — the one already saved in the photo by your camera — to Apple’s geocoding service, which answers with the name of the town or the sea. Only a coordinate is sent, never the photograph and never anything identifying you; it happens only for a run the app has already recognised as a dive; each place is looked up once and the answer is then kept on your device. Turn off Location for the Camera app, or use a camera that records none, and no lookup ever happens — the dive is simply shown by its date and time instead.
The legal basis for that one lookup is Art. 6(1)(f) GDPR: a dive that names its place can be found again, and a dive that names only a time cannot. Apple is an independent recipient here and handles the request under its own privacy policy; that may involve transfer to the United States, covered by the European Commission’s adequacy decision for the EU-US Data Privacy Framework.
The app sends product analytics to PostHog, using their EU-hosted service as a processor under Art. 28 GDPR, so this data stays in the European Union.
Sent: which features you use, counts of how often, and settings you change. Above all, how far you move the intensity dial away from the automatic setting, because that number is the only way we can tell whether the automatic result is actually good. Along with it, the name of the screen you are on — from a fixed list such as “picker” or “video editor”, not a recording of what is on it.
Also sent: crash reports and technical diagnostics, such as the device’s thermal state or the reason an export was refused. They are how we find out a failure happened at all, and they carry the same fixed vocabulary as everything else.
Never sent to PostHog: your photos or any image data, filenames, the coordinates of your dives, your name or email address, and no identifier belonging to your phone rather than to this app — no advertising identifier, no serial number. Session recording is off, so no picture of your screen is ever transmitted. Automatic capture of tapped elements is off too, and deliberately: it would report controls by their label, and a dive’s heading is its place and its time.
The events carry a random identifier that is created the first time you open the app and stored on your device until you delete it. It stands for this copy of the app, not for you: there is no account and no name behind it, and it is not an identifier Apple or anyone else can match to your phone. What it does mean is that we can see that the same installation came back, which is how we count how many people actually use the app rather than how many times it was opened. The analytics component keeps two further technical identifiers on your device, which is how it batches events and survives being offline. Deleting the app removes all three.
Legitimate interest under Art. 6(1)(f) GDPR, namely understanding whether the automatic correction is good and whether people keep using the app. Because those identifiers are stored on your device, § 25(1) TDDDG applies and we do not ask you for consent first: we state plainly what is stored and give you one switch that stops it. That switch is put in front of you before the app asks for anything else.
On unless you turn it off, under Settings, Legal. Off means off: you are not asked again.
PostHog keeps the events for twelve months and deletes them afterwards. Crash reports are kept for the same period.
Apple handles the download itself and their privacy policy governs it. We receive only aggregate statistics from App Store Connect and hold no records about individual users.
Under the GDPR you may request access to your personal data (Art. 15), correction (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and portability (Art. 20). You may also complain to a supervisory authority (Art. 77).
You have the right to object at any time to processing of your data carried out on the basis of legitimate interests under Art. 6(1)(f) GDPR (Art. 21 GDPR). Here that means the usage statistics and the server logs. For the statistics you do not need to write to anyone: in the app the switch in Settings under Legal is that objection, and on this site it is the button above. Both take effect immediately.
The identifier is the only thing tying one event to the next, and it exists on your device and in our analytics and nowhere else. We hold nothing that connects it to your name, your email address or your phone, and we are not going to collect anything that would: under Art. 11 GDPR we cannot identify you from these events, and we will not acquire extra data in order to be able to. In practice that means we cannot answer an access or erasure request for them by looking you up. Turning the switch off stops the collection, and deleting the app removes the identifier, after which nothing new can be connected to what came before.
To exercise any of these, write to BBR@jeromesommerfeldt.de.
If what the app does with data changes, this page changes with it, and the date at the top changes too. We will not quietly widen what is collected under text that says otherwise.