Data Processing

Last updated: draft — not yet published.

Draft — pending attorney review. This page is a placeholder used during development. It has not been reviewed by an attorney and must not be treated as final legal advice or a binding agreement until it is.

Who processes your data

Sparks Simple is the data controller for Dive Brief. We use the following subprocessors to run the product; each only receives the data it needs to perform its function.

  • Supabase — hosts our database, authentication, and file storage. All plan content, accounts, and attachments live here.
  • Stripe — processes subscription payments for paid tiers. Stripe receives billing/payment details directly; Dive Brief never stores full card numbers.
  • Resend— delivers transactional email (guest invitations, password resets). Resend receives the recipient's email address and the message content of that specific email.
  • Sentry — error monitoring, off by default and only active if the organization running this deployment has configured it. Error reports are scrubbed of coordinates, medical/emergency-contact fields, and other sensitive keys before being sent (see What we scrub below).
  • Google Analytics — aggregate marketing-site usage analytics, off by default and only active if configured. It does not run inside the authenticated app and never receives dive plan content.

What we scrub

Before any error report leaves the app, it is stripped of request cookies/headers and recursively redacted for a fixed list of sensitive field names — coordinates, medical notes, emergency contact details, certification numbers, phone numbers, storage paths, and free-text plan fields (objectives, procedures, hazards, access notes, and similar). This applies whether or not error monitoring is actively configured for a given deployment.

Data location and retention

Data is retained for as long as your account or organization exists, or as required for the organizational recordkeeping described in our Privacy Policy. You can export your data or delete your account at any time from account settings.

Contact

Questions about how a specific subprocessor handles data can be directed to Sparks Simple through the contact details on our website.