The app collects nothing
The app at first-minutes.com/app/ has no account, no login, no analytics and no third-party code of any kind. It makes no request to any server except this one, and only to refresh its own phone numbers and first-aid content.
Everything you type — your name, the casualty's details, the dive profile, the call log, the dive centre's plan — stays in the browser on your device. None of it is transmitted. No server sees it. There is nowhere for us to look at it even if we wanted to, which is the point: the app has to work on a boat with no signal, and anything that needed a server would fail exactly when it mattered.
If you allow it, the phone's GPS is read on the phone, to name the nearest town and show you a position you can read to an operator. The position is never sent anywhere. You can refuse, and the app says so on screen and never asks again.
This is enforced rather than promised. The Content-Security-Policy this site sends
for /app/ permits no external origin at all, and the build fails if a
third-party host appears anywhere in the app's source.
The website counts visits, if you let it
On this website — not the app — we would like to know whether anybody is finding it. We use Google Analytics 4 for that, and nothing from Google is loaded until you press “Yes, count visits”. Not the script, not a cookie, not a request. If you decline, or if you never answer, this website contacts Google zero times.
If you do say yes, Google Analytics receives
- Which pages you looked at, when, and in what order.
- The site or search that sent you here, if any.
- Your approximate location — country, and usually region — worked out from your IP address. The IP address itself is anonymised before storage.
- Your device type, screen size, browser and language.
- A cookie (
_ga) holding a random identifier, so a second visit is not counted as a second person. It lasts two years.
Advertising features are switched off and cannot be switched on from here: advertising storage, ad personalisation and ad user data are all set to denied permanently. We do not advertise, and we do not sell, share or transfer this data to anyone. Google processes it as our processor, and their own terms apply on top.
Cloudflare hosts this site and, like any host, keeps short-lived request logs for security and abuse handling. Cloudflare's own page-count tag was switched off on 8 September 2026, so nothing is injected into these pages at the edge: what loads is what you chose above, and nothing else.
You can change your mind at any moment. Your choice is stored in this
browser only, under fm.consent; clearing site data forgets it and you will
be asked again.
The dive centre plan builder
The plan builder fills a printable sheet and a QR square as
you type. What you type stays in your browser, saved under fm.eap so you can
come back to it.
Nothing is sent to us until you press save. You can fill the whole plan in, print both pages and laminate them without any part of it reaching us. The QR square carries the plan itself, in the part of a web address that browsers never transmit to a server — so a diver scanning your printed sheet loads the plan from the paper, not from us, and that is true whether or not you ever save one here.
This changed on 13 September 2026. Until then we held only a hash of your plan and could not have handed it back. Centres asked to edit a plan from a second computer, which is not possible without us holding the plan, so now we do — and the section below says exactly what that means.
If you give your plan an address
There is one optional step that does involve us. You can verify an email address and
get a permanent address for the plan — coral-anchor-lantern-marble —
printed on both pages, so a laminated sheet has a stable name, you can open the plan on
any computer to change a number, and the address stays the same when you do.
It is optional and it is not a login. Ignore it entirely and the builder
works as it always has, on this device alone.
If you do use it, this is everything we store
- The email address you verified.
- The address we issued for the plan.
- The plan itself — every line you typed, page two included: the centre's name, the town, the numbers, the hospital, the chamber, the oxygen, the evacuation route, the coordinates, the roles and the date. This is the part that changed on 13 September 2026, and it is the whole point of the feature: it is what comes back when you open the plan somewhere else.
- The dates the address was created and last updated.
Who can read it
Anyone who has the address can read the plan. That is deliberate: the address is printed on the sheet, and the QR square beside it already carries the same numbers to any phone that scans it — a plan is a thing a dive centre hands to divers, not a secret.
The address itself says nothing about you. It is four words drawn at random when you save — not built from your centre's name, your town or your country — so the line printed on your sheet tells a stranger nothing and cannot be guessed from anything they already know. There are about three million million of them, and we limit how fast anyone can try one.
Only the email address it is registered to can change or delete it, and only with a six-digit code we send to that address at the time.
We accept the plan's own fields and nothing else — a closed list, each one length-capped, anything unrecognised refused. We do not store an IP address against your plan, we set no cookie here, and there is no profile of you behind any of it.
Where it is, and who else touches it
The site and the database run on Cloudflare, who host them for us and process what is stored on our instructions.
Plans are stored in the European Union. The database was created under Cloudflare's EU jurisdiction on 13 September 2026, which restricts where it runs and where its data is kept to the EU. It replaced one in Cloudflare's Asia-Pacific region — a database's jurisdiction can only be chosen when it is created — and the two records that existed by then were copied across and the old database deleted.
Email is delivered by Resend, a US company, as our processor. Two messages go to you: the six digits when you ask for them, and — from 13 September 2026, on every save — a copy of the plan itself, with its address, so the address exists somewhere you control and not only in a browser and on a sheet. That copy passes through Resend to reach your inbox, and it means the plan leaves the EU to be delivered to you. If you would rather it did not, delete the plan here and use the file export in the builder instead, which sends nothing anywhere.
The six-digit code we email you is stored hashed, never in the clear, expires after ten minutes, allows five attempts, and is deleted the moment it is used. The email itself is sent through Resend, who process it as our processor in order to deliver that one message.
Deleting it
There is a delete button in the plan builder itself, beside the address. It asks for the same six digits and then removes the row — the plan, the address and the email it was registered to, all of it, not a flag saying deleted. You can also write to hello@first-minutes.com from the address you verified and we will do it for you.
Your printed sheets keep working either way: the QR square carries the plan, so a diver scanning the paper never needed us. What stops working is the address on the sheet, which is why the builder also lets you keep a copy of the plan as a file.
We keep what is listed above until you delete it. We do not have a retention timer on a dive centre's emergency plan: a plan nobody has touched for two years is still the plan on that wall.
If you write to us
The contact form on the front page sends your message to hello@first-minutes.com through Resend, who process it as our processor in order to deliver that one message. We keep no copy of it. What you wrote lives in that inbox and nowhere else, exactly as it would if you had emailed us yourself — which you can, and it is the same address.
One thing is stored, for one hour: a one-way SHA-256 hash of the address you typed, with the second it was sent. It exists so that “three messages an hour from one address” can be counted at all, and it is deleted by the next request that looks after the hour is up. The address itself never reaches the database, and a hash cannot be turned back into one.
The form also carries a field you cannot see, left empty by people and filled in by automated senders. If it arrives with anything in it the message is discarded and nothing is stored or sent.
Your rights
Because the app stores nothing about you, there is nothing for us to give you, correct or delete. For the website, if you consented to analytics you may withdraw it above. If you asked for a plan code, we hold the email address you verified — write from that address and we will tell you exactly what is stored against it, or delete it. If you only used the contact form, there is nothing to ask for: an hour after you sent it, the hash is gone and the message is in an inbox like any other email.
Under UK and EU data protection law you have the right of access, rectification, erasure, restriction, objection and portability, and the right to complain to your national supervisory authority. Write to the address below and we will answer.
Who to write to
First Minutes is made by Donarun Das, a technical diving instructor, as an individual rather than a company. For anything on this page, or a number that has changed: hello@first-minutes.com
Place names and coordinates come from GeoNames, used under CC BY 4.0 and modified: filtered to selected towns, coordinates rounded to three decimals.