Oceanus Privacy Policy
Effective Date: September 17, 2026
This Privacy Policy describes how LiJordan ("we", "us", or "our") collects, uses, and protects your personal information when you use the Oceanus mobile application ("App") and the profile and species links we host at oceanus.lijordan.com.
By using Oceanus, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Account Information
When you create an account or log in via Google or Apple, we may collect:
- Email address (stored only in Firebase Authentication, not duplicated in our Firestore database)
- Display name
- Profile photo URL
- Nickname (optional, user-chosen; 3–20 characters using lowercase letters, digits, dot, or underscore)
1.2 Device Information
We automatically collect:
- Device type and operating system version
- App version
- Anonymous usage analytics
1.3 Camera Data
When you use the marine species identification feature, we access your device's camera to capture images. These images are processed to identify species and provide information. We do not store these images on our servers after processing, unless you explicitly save identified species to your collection.
1.4 Species Detection Data
Information generated from the species detection feature:
- Identified marine species names and IDs
- Detection timestamps
- First discovery flags
- Image references (if saved to collection)
1.5 Garmin Integration Data
If you connect your Garmin account, we receive activity data from your Garmin devices to enhance your experience. This includes data from:
Diving Activities (Garmin Descent series):
- Dive start time, duration, and end time
- Maximum and average depth
- Water temperature
- Depth profile data (depth samples over time)
- Gas mix information
- Device information (model, serial number)
- GPS coordinates of dive entry point
Fishing Activities:
- Fishing session start time and duration
- GPS location and route data
- Weather conditions (if recorded)
- Water temperature (if available)
- Device information
This data is used solely to display your activity history within the app, link species discoveries to specific activities, and visualize species habitats on maps based on activity locations.
1.6 AI Dive Story Feature
When you use the AI Dive Story feature in the dive log share sheet (a Premium-only feature):
- The photo you select from your device is sent to Google's Vertex AI (Gemini 2.5 Flash Image) to generate a transformed cinematic underwater scene
- Selected dive log statistics (location name, max depth, dive time, water temperature, date) are included in the generation prompt
- Google processes these inputs solely to produce the generated image; we do not retain the source photo on our servers
- The resulting AI-generated image is stored locally on your device under the app's Documents directory until you regenerate or delete it
- We store an anonymous monthly usage counter (number of generations per calendar month) in Firebase Firestore under your account, used only to enforce the per-user monthly generation limit
1.7 Cloud Sync Data
If you sign in with your Google or Apple account, the following data is synced to Firebase Firestore:
- Your profile information (display name, profile photo URL, nickname, user type)
- Your detection history
- Your favorite species
- Your discovered species collection
- Your dive and fishing logs (if imported from Garmin)
- Your follow relationships (the accounts you follow and the accounts that follow you)
- Your leaderboard standing — an "Ocean Score" recalculated once a day from the number of species you have identified, your total identifications, your unlocked achievements and your longest activity streak, together with your rank among participating users (see Section 3.2)
Your email address is stored only in Firebase Authentication and is not duplicated in our Firestore database.
1.8 Push Notification Tokens
If you enable push notifications, we store a per-device record so we can deliver messages to your device:
- The push notification token issued by Apple Push Notification service (APNs) via Firebase Cloud Messaging (FCM), or by FCM directly on Android
- Your device's language code (used to send notifications in your preferred language)
- A technical platform identifier ("ios" or "android")
Notification tokens are stored only for the purpose of delivering push notifications. They are not used for advertising or cross-device tracking. See Section 4 for details on how notifications work and how to opt out.
1.9 Device Location (Sky Conditions)
Oceanus can show today's sunrise and sunset times, the moon phase, and whether the tide is running spring or neap on your profile screen. Working these out requires knowing roughly where you are.
- What we access: your approximate location only. On Android the app requests the coarse location permission; on iOS it requests "While Using the App" access and asks the system for kilometre-level accuracy. The app never requests precise location.
- When: only after you turn on Settings → Conditions → "Use location for conditions", which is off by default, and only while your profile screen is open. Normally at most one position request is made per day.
- Where it goes: nowhere. Sunrise, sunset, moon phase and tide type are computed entirely on your device using offline astronomical formulas, with no network request. Your coordinates are never sent to our servers, never stored in our cloud database, and never shared with any third party — including our advertising and analytics providers.
- What is stored: the app keeps the last position on the device itself, rounded to roughly one kilometre, together with the date it was taken, so that opening your profile again on the same day needs no new position request. This is held in the device's local app storage, is not synced between your devices, and is removed when you uninstall the app or clear its data.
- How to stop it: turn the setting off, which stops all location access and removes the feature from your profile; or revoke the location permission in your device settings, which also stops access.
Location never leaves your device. This feature adds no data to your account, to our servers, or to any third-party service. It is the only part of Oceanus that uses your device's current position, and it is off until you turn it on.
2. How We Use Your Information
The information collected is used to:
- Provide marine species identification using AI technology
- Generate AI-enhanced cinematic dive story images from photos you select (Premium feature)
- Store and display your species collection and discoveries
- Sync your dive logs and fishing logs from Garmin devices
- Link species sightings to specific dives or fishing trips
- Visualize species habitats on maps based on activity locations
- Improve the accuracy of species identification
- Provide a unique, user-chosen identifier (nickname) so you can be referenced consistently within the app
- Enable social features: user search, following other users, and viewing others' public profiles
- Calculate your Ocean Score and rank, and display the global leaderboard to signed-in users, unless you have opted out
- Send push notifications about events relevant to your account (for example, when someone starts following you)
- Show today's sunrise, sunset, moon phase and tide type on your profile, computed on your device from your approximate location (see Section 1.9)
- Sync your data across devices
- Display relevant advertisements
- Process in-app purchases and subscriptions
- Communicate important updates
3. Public Profile and Social Features
When you sign in, certain information becomes visible to any other signed-in user of the app:
- Your display name, profile photo, nickname, and chosen user type (Diver, Fisher, Strider)
- Your follower count and following count
- Your identity in other users' followers/following lists after you follow or are followed by them
- If you take part in the global leaderboard: your rank, your Ocean Score, and the aggregate counts behind it (see Section 3.2)
3.1 Species Seen and Dive Log Visibility
Two further parts of your profile can be shown to other signed-in users, and you control who sees each of them from Settings → Privacy:
- Species seen — your "species seen" progress and the list of marine species you have identified, with their images
- Dive log — your dive entries, including date and time, dive site name, GPS coordinates, maximum and average depth, duration, water type and temperature, visibility, equipment details, your written notes, the species linked to each dive, and the depth profile chart
Each of the two has its own independent setting with four levels:
- Everyone — any signed-in user of the app
- Friends — only users you follow who also follow you back (a mutual follow)
- Followers — only users who follow you
- Nobody — only you
Defaults. Species seen defaults to Everyone. Your dive log defaults to Followers, meaning that unless you change it, users who follow you can see your dive entries, including the GPS coordinates of your dive sites and any notes you have written. If you would rather keep this private, set the dive log to Nobody in Settings → Privacy. These settings are enforced on our servers, not only in the app.
Because dive log entries can contain precise location data and free-text notes, we recommend reviewing this setting before adding dives, and avoiding personal details in dive notes and site names if you share your log.
3.2 Global Leaderboard
Once a day we rebuild a global leaderboard and publish the top 100 participants, which every signed-in user of the App can see. Each published entry contains your display name, profile photo, nickname, user type, rank, Ocean Score, and the four aggregate counts the score is built from: species identified, total identifications, unlocked achievements, and longest activity streak. If you are ranked outside the top 100, your own rank and score are still calculated and shown to you inside the App, but your entry is not published on the board.
Only totals are published. Individual detections, their dates, their photos, your dive log, and any location data are never part of a leaderboard entry, regardless of your other visibility settings.
Defaults and opt-out. Participation is on by default for signed-in users. You can turn it off at any time in Settings → Privacy → "Take part in the leaderboard". When you opt out, your entry is removed from the published board at the next daily rebuild and your stored rank and score are deleted from your profile. Deleting your account removes your entry from the board immediately.
3.3 Profile Links
Sharing a profile from the App produces a link of the form https://oceanus.lijordan.com/u/{your account id}. You choose whether and where to post it; once posted it is outside our control, the account id in it cannot be changed or rotated, and deleting your account is the only way to break the link.
The same link is printed as a QR code on the profile card you can design in the App, and on the Apple Wallet pass described in Section 3.4. A QR code carries no information beyond that link, but it can be photographed from a screen or a printout by anyone who can see it — treat showing the card as posting the link.
The link does not bypass Section 3.1. Opening it requires a signed-in Oceanus account, and what the viewer then sees is exactly what your visibility settings allow. The link preview shown in messengers is the generic Oceanus icon and name — it does not reveal whose profile it points to — and the page is marked noindex, so profiles are not indexed by search engines. Visitors without the app get a page offering the App Store and Google Play.
Opening the link records a standard web server log entry with Google Firebase Hosting (IP address, browser user agent, timestamp, referring page). These logs are used for security and operations only; they are not linked to your Oceanus account or used for advertising.
We recommend not using personally identifying information in your display name or nickname if you prefer to remain anonymous. You can change your nickname at any time from the Profile screen. Follow relationships are stored as records in our cloud database that indicate which accounts you follow and which accounts follow you; unfollowing removes both records. Deleting your account removes all of this information along with your other data.
Private data — your detection history, favorites, individual achievements, streak history, notification tokens, and email address — is not visible to other users under any setting. The leaderboard is the only place where they are used, and only as the aggregate counts described in Section 3.2, never as individual records.
3.4 Apple Wallet Card (iOS)
On iOS you can add your profile card to Apple Wallet. The pass is built and signed on our servers, because a Wallet pass is only valid with a signature the App cannot produce on its own. The App sends only which card of your deck you picked; everything printed on the pass is read server-side from your own account:
- Your display name, nickname and diver type
- The year your account was created
- Your Ocean Score, species seen, identifications and leaderboard rank — the same aggregate figures described in Section 3.2
- A QR code containing your profile link (Section 3.3)
The finished pass is handed to Apple Wallet and stored on your device. We do not operate a pass update service, so Apple does not send us your device identifier and we cannot see, change or remove a pass once it is added — the pass is yours to delete from Wallet. A pass can be shown on a locked screen and can be shared onward by whoever holds it, so what it displays is as public as you choose to make it. Passes already added are not affected by later changes to your visibility settings or by deleting your account; the profile link on them stops working, as described in Section 3.3.
4. Push Notifications
The app can send push notifications (for example, when another user follows you). This feature is optional and requires your explicit consent:
- Data we store per device: see Section 1.8.
- When we collect: after you tap "Enable notifications" and grant the system permission prompt.
- How we use it: only to deliver push notifications to your device. We do not use notification tokens for advertising, cross-device tracking, or any other purpose.
- How to opt out: at any time, disable notifications in your device's Settings → Notifications → Oceanus. You can also revoke permission by deleting the app. When you sign out, we delete the notification token associated with the signed-out device. When you delete your account, all your notification tokens are deleted.
5. Third-Party Services
We use the following third-party services:
- Google Firebase: Authentication, Firestore database, Cloud Functions, Analytics, Crashlytics, and App Check
- Google Gemini AI / Vertex AI: Powers marine species identification, information retrieval, and AI Dive Story image generation. Photos and prompts you submit are processed by Google solely to produce results returned to the app; Google does not retain them for model training under the Vertex AI data processing terms.
- Firebase Cloud Messaging (FCM) and Apple Push Notification service (APNs): Delivers push notifications to your device. See Section 4.
- AdMob (Google Ads): Displays advertisements. On iOS, AdMob may use Apple's Advertising Identifier (IDFA) to personalise them and to measure advertising performance across apps and websites owned by other companies — that is, for tracking as Apple defines it. iOS asks for your permission first through the system prompt, and the identifier is used only if you allow it; declining leaves the advertising non-personalised, and you can change your answer at any time in Settings → Privacy & Security → Tracking. On Android the equivalent role is played by the Advertising ID, which you can reset or delete in the system settings.
- Google UMP: Manages user consent for personalized advertising
- Amplitude Analytics: App analytics and user behavior analysis
- Google Play Billing (Android) and Apple StoreKit (iOS): Processes in-app purchases and subscriptions
- Garmin Connect API: Syncs dive logs and fishing activity data (with your explicit consent)
- Firebase Hosting: Serves our website and the profile/species links, and keeps standard access logs (see Section 3.3)
Important: We do not sell, trade, or share your personal data with third parties for marketing purposes. Data shared with third-party services is used solely to provide app functionality. Public profile information, follow relationships, leaderboard entries, and — subject to the visibility settings you choose — your species seen and dive log (see Section 3) are visible to other signed-in users of the app as part of the app's normal functionality.
6. Data Security
We protect your data using:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of data at rest in Firebase Firestore
- Firebase App Check to prevent unauthorized access
- Secure OAuth 2.0 authentication for Garmin integration
However, no method of data transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. You can request deletion of your data at any time.
8. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and all associated data (including follow relationships and notification tokens)
- Portability: Request your data in a portable format
- Withdraw Consent: Disconnect Garmin integration at any time; disable push notifications in your device's Settings; turn off Settings → Conditions → "Use location for conditions" to stop all location access; leave the global leaderboard in Settings → Privacy, which removes your entry at the next daily rebuild
- Opt-out: Sign out to stop cloud synchronization (this also removes the current device's push notification token)
9. US State Privacy Rights
Residents of California, Virginia, Colorado, Connecticut, Utah, and other US states with privacy legislation have additional rights:
- Right to Know: Request information about collected personal data
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out of Sale: We do not sell your personal information
- Right to Non-Discrimination: We will not discriminate for exercising your rights
- Right to Correct: Request correction of inaccurate information
To exercise these rights, contact us at contact@lijordan.com. We respond within 45 days as required by law.
10. Children's Privacy
Oceanus is intended for users aged 18 and older. We do not knowingly collect data from children under 18.
11. Updates to This Policy
We may update this Privacy Policy from time to time. Updates will be reflected on this page with a new "Effective Date."
12. Contact Us
For questions about this Privacy Policy:
- Email: contact@lijordan.com
- Company: LiJordan, Poland