Last updated 12 August 2026 · Also in Deutsch
Your photographs are corrected on your iPhone and never leave it. This website sets no cookies and counts what happens on it without knowing who you are. The app sends anonymous usage statistics, which you can switch off. That is the whole of it; the detail is below.
Jerome Sommerfeldt, Deutschland. Reach the controller at BBR@jeromesommerfeldt.de, which is also the address for any of the requests below. Further details are in the Impressum.
These pages are static files. They set no cookies, write nothing to your browser’s storage, and load nothing from a third party: the fonts are served from this domain, and there is no tag manager, no embedded video and no advertising network.
We count what people do here: pages opened, the demo run, and the App Store link followed. The events are sent to PostHog, whose EU service processes them for us under Art. 28 GDPR, on the legitimate-interest basis of Art. 6(1)(f) GDPR — knowing which parts of the page work.
This site stores nothing on your device to do it. Each event carries an identifier that exists only in the memory of the open tab: it lets us see that one visit moved from this page to that one, and it is gone when you reload or close the tab. It is never written down, so a second visit cannot be recognised as yours, and no profile is built on PostHog’s side.
With each event we send the page’s path, whether you are on a phone, a tablet or a computer, and where you arrived from — the site that linked to you, and any campaign tag we ourselves put in that link. We drop the rest of the address, including anything a search engine or another site appended to it, and we never send anything you typed or chose. The photograph you put into the demo is never uploaded — it is corrected in this browser and we learn only that a correction happened.
Because no identifier outlives the tab, there is nothing we could look up, correct or erase for you under Art. 15 to 17 GDPR: no event here is connected to a person, including you.
Delivering a page necessarily involves your IP address. Our hosting provider, acting as a processor under Art. 28 GDPR, records the usual access data: IP address, the page requested, the time, the referring page and your browser and operating system. We use it to serve the site and to investigate faults and abuse, on the legitimate-interest basis of Art. 6(1)(f) GDPR, and it is kept only as long as that requires.
Consent under § 25(1) TDDDG is required for storing information on your device or reading what is already there. This site does neither, so there is nothing to ask you about. A banner would need to store your dismissal to remember it, which would create the very thing it claimed to avoid.
We keep your message and address for as long as it takes to answer you and to handle any follow-up, under Art. 6(1)(b) and (f) GDPR.
Every part of the correction runs on your device. Your photos and videos are not uploaded, not copied to a server and not processed anywhere but on the iPhone in your hand. There is no account and no sign-in, and the app works with no network connection at all. Export creates a corrected copy in Photos or Files and leaves the source untouched. The app keeps a local list of what it has corrected; that list is a cache on your device and is never sent anywhere.
Because dive sites are sensitive, the app strips location from an exported file by default. You can switch that off if you want to keep it.
One feature uses location, and this is the whole of it. To put a place name beside a dive, the app sends that dive’s coordinate — the one already saved in the photo by your camera — to Apple’s geocoding service, which answers with the name of the town or the sea. Only a coordinate is sent, never the photograph and never anything identifying you; it happens only for a run the app has already recognised as a dive; each place is looked up once and the answer is then kept on your device. Turn off Location for the Camera app, or use a camera that records none, and no lookup ever happens — the dive is simply shown by its date and time instead.
The legal basis for that one lookup is Art. 6(1)(f) GDPR: a dive that names its place can be found again, and a dive that names only a time cannot. Apple is an independent recipient here and handles the request under its own privacy policy; that may involve transfer to the United States, covered by the European Commission’s adequacy decision for the EU-US Data Privacy Framework.
The app sends product analytics to PostHog, using their EU-hosted service as a processor under Art. 28 GDPR, so this data stays in the European Union.
Sent: which features you use, counts of how often, and settings you change. Above all, how far you move the intensity dial away from the automatic setting, because that number is the only way we can tell whether the automatic result is actually good. Along with it, the name of the screen you are on — from a fixed list such as “picker” or “video editor”, not a recording of what is on it.
Also sent: crash reports and technical diagnostics, such as the device’s thermal state or the reason an export was refused. They are how we find out a failure happened at all, and they carry the same fixed vocabulary as everything else.
Never sent to PostHog: your photos or any image data, filenames, your location, or anything that identifies you or your device. Session recording is off, so no picture of your screen is ever transmitted. Automatic capture of tapped elements is off too, and deliberately: it would report controls by their label, and a dive’s heading is its place and its time.
The events themselves carry no lasting identifier: a random one is created when the app starts and discarded when it closes, so one session's events cannot be tied to the next, and no profile is built on PostHog's side. The analytics component does keep two technical identifiers on your device, which is how it batches events and survives being offline. Deleting the app removes them.
Legitimate interest under Art. 6(1)(f) GDPR, namely understanding whether the automatic correction is good. Because those two identifiers are kept on your device, this is something you can and should be able to refuse outright, which is what the switch is for - and it is put in front of you before the app asks for anything else.
On unless you turn it off, under Settings, Legal. Off means off: you are not asked again.
PostHog keeps the events for twelve months and deletes them afterwards. Crash reports are kept for the same period.
Apple handles the download itself and their privacy policy governs it. We receive only aggregate statistics from App Store Connect and hold no records about individual users.
Under the GDPR you may request access to your personal data (Art. 15), correction (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and portability (Art. 20). You may also complain to a supervisory authority (Art. 77).
You have the right to object at any time to processing of your data carried out on the basis of legitimate interests under Art. 6(1)(f) GDPR (Art. 21 GDPR). Here that means the usage statistics and the server logs. For the statistics you do not need to write to anyone: the switch in Settings under Legal is that objection, and it takes effect immediately.
Because there is no account, and because the events carry no identifier that outlives a session, nothing links them to a person: we cannot look up records about you, and there are none to delete. The two identifiers that do persist stay on your device and go when the app does.
To exercise any of these, write to BBR@jeromesommerfeldt.de.
If what the app does with data changes, this page changes with it, and the date at the top changes too. We will not quietly widen what is collected under text that says otherwise.