Privacy Policy — Piscary
Publisher: Morgane Garnier — sole trader (micro-enterprise), trading as KreaRise SIREN: 994 232 130 Registered office: 18 chemin de Meaux, 93360 Neuilly-Plaisance, France Contact: contact@piscary.app Last updated: July 7, 2026 App version: 1.0.0
Piscary is a bilingual (French / English) mobile fishing logbook. This policy describes, honestly and specifically to this app, what data we process, why, where it is stored, and what your rights are. We are established in the European Union and apply the General Data Protection Regulation (GDPR).
Core principle: an account is required, but the app still works offline
As of version 1.0, an account is required to use Piscary. Account creation relies on Supabase (see “Third-party services”) and requires a verified email address.
The app is still local-first: your data is first saved on your device — so you can log a catch with no connection, at the water’s edge — then synced to your account when a network is available. In practice, your catch journal, your photos, your statistics, your challenges and badges, and your gear are kept locally (both for offline display and as an upload queue) and synced to our servers.
Data we process
1. Data stored locally on your device (cache & offline)
This data is kept in the app’s private storage (the app sandbox Piscary
folder) for offline display and as an upload queue; it is also synced to your
account (see section 3):
- Catch journal: species, fish name, date and time, notes, length, weight, technique, place name (private and public), and the location privacy setting.
- Catch photos: saved as files in the app’s
photos/folder. - Catch location: GPS coordinates (latitude / longitude) attached to a catch when you add them.
- Gear: rods, reels and combos you enter (names and optional photos).
- Settings: language, display preferences, challenge and badge progress, local alert setting.
2. Location
- Catch location: with your permission, the app reads your current position (“balanced” accuracy, ~100 m) to pre-fill a catch’s place. These coordinates are stored locally. If you are signed in and share the catch, they are transmitted according to the catch’s privacy setting (see below).
- Fishing-spot location: the coordinates of a point you look up are sent to Open-Meteo to retrieve weather, tides and river flow, in order to compute the fishing-conditions score.
- Reverse geocoding: to turn coordinates into a human-readable place name (city, region), the app first uses the device operating system’s geocoder (via Apple / Google depending on platform), processed locally by the OS. When that is unavailable, the coordinates may be sent as a fallback to OpenStreetMap Nominatim (see “Third-party services”). No place name is sent to our servers without an account.
- Fishing-spot search: when you type a place name to find a spot, that text is sent to OpenStreetMap Nominatim and/or Open-Meteo to return matching coordinates.
Catch location privacy — for each catch, you choose:
- Private: the location is not shared with others (you always keep your own exact coordinates).
- Public: your exact location is shared with the audience you chose for the catch.
3. Data processed on our servers (account required)
Because an account is required to use the app, the following data is processed on our servers. Authentication and storage are powered by Supabase (see “Third-party services”).
- Account: email address and password (authentication is handled by Supabase; the password is hashed server-side and we never have access to it in plain text).
- Profile: display name / username, avatar (profile photo), total points.
- Synced catches: the catches you sync (species, name, date, notes, length, weight, technique, place name, and coordinates according to each catch’s chosen privacy setting) are stored in the Supabase database.
- Catch photos: uploaded to Supabase Storage (bucket
catch-photos) only when you are signed in. Photos are resized (max 1920 px) and compressed before upload. - Synced gear: rods, reels and combos.
- Social features: if you publish a catch as “public” or “friends”, your username, avatar and the catch become visible to the chosen audience. We also process likes, comments, and friendships (requests / acceptances).
- Moderation: if you report content or block a user, we record your identifier, the identifier of the targeted content or user, and the reason you give, in order to handle the report.
- Account deletion: see “Your rights” (immediate and permanent erasure).
4. Advertising (free users)
The app shows advertising via Google AdMob, in the “App Open” format (open screen), only to free users: Piscary Pro subscribers see no ads.
- Ads are non-personalized only: no profile-based ad targeting, no cross-app tracking (in the sense of Apple’s “App Tracking Transparency” feature), no access to the IDFA on iOS, and no App Tracking Transparency prompt.
- To serve these ads, the Google AdMob SDK may process device / advertising
identifiers and technical information (device model, IP address,
diagnostics and anti-fraud signals). This data is processed by Google as the
advertising provider (see Google’s privacy policy:
policies.google.com/privacy). - Consent (GDPR): if you are in the EEA or the UK, a consent form (Google UMP / consent management platform) is presented before any ads are loaded.
5. Piscary Pro subscription (optional)
The app offers a Piscary Pro subscription, managed via RevenueCat on top of the App Store (Apple) or Google Play.
- RevenueCat processes purchase / subscription data and an identifier linked to your account (pseudonymous) to manage your entitlements and to restore your purchases.
- The payment itself is handled by Apple or Google depending on your platform: we never have access to your card details.
6. What we do NOT do
- No personalized advertising and no cross-app tracking: the ads shown are strictly non-personalized and are not used to track you from one app to another.
- No third-party behavioral or advertising analytics (no Google Analytics, Firebase Analytics, Facebook SDK, etc.). The only diagnostic tool is Sentry, used for crash / stability reporting (technical data, no personal data — see “Third-party services”), never to track your behavior.
- No selling of data, no data brokers.
- No remote “push” notifications: the only notifications are local (an ideal-fishing-window alert scheduled on the device); no notification token is sent to any server.
Purposes of processing
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Journal, photos, gear (local) | Provide the fishing logbook | Service provision / legitimate interest |
| Spot location | Compute fishing conditions (weather, tides) | Consent (location permission) |
| Catch location | Locate your catches | Consent |
| Email + password | Create and secure your account | Contract performance (the account you request) |
| Synced profile, catches, photos | Sync and sharing you enable | Contract performance / consent |
| Likes, comments, friendships | Social features you use | Consent |
| Reports / blocks | Community safety and moderation | Legitimate interest |
| Non-personalized advertising (free users) | Fund the free version of the app | Legitimate interest; consent (UMP form) in the EEA / UK |
| Purchase / subscription data | Manage the Piscary Pro subscription and restore purchases | Contract performance |
| Crash / technical diagnostics (Sentry) | App stability and bug fixing | Legitimate interest |
| Email address (Resend) | Deliver the account confirmation email | Contract performance |
Third-party services
Piscary communicates with eight families of external services:
-
Open-Meteo (
open-meteo.com) — weather, marine and hydrology service. Receives only geographic coordinates of a point you look up, in order to return weather, tides and river flow. No account identifier and no direct personal data is transmitted to it. See Open-Meteo’s policy on their site. -
OpenFreeMap (
openfreemap.org) — map tile provider (cartography). When you view a map, the app downloads tiles for the geographic area you are viewing. No account identifier and no direct personal data is transmitted. Map data comes from OpenMapTiles / OpenStreetMap. -
Supabase — database, authentication and file-storage host, used only if you have an account. Piscary’s Supabase project is hosted in the European Union (EU) region.
-
Google AdMob — advertising network, used only for free users, to serve non-personalized ads. May process device / advertising identifiers and technical information (see “Advertising”). See Google’s privacy policy (
policies.google.com/privacy). -
RevenueCat — management of the Piscary Pro subscription (entitlements, purchase restoration), on top of the App Store / Google Play. Processes purchase / subscription data and an identifier linked to your account (pseudonymous, see “Piscary Pro subscription”).
-
Sentry — crash and error reporting for app stability, active only in the released app. Receives technical diagnostics (crash stack traces, device model and OS version, app version, and in-app navigation breadcrumbs = screen names). Configured without personal data (no user IP, no user identifier) and hosted in the European Union (EU) region. Used to fix bugs, never for advertising or behavioral tracking.
-
Resend — transactional email delivery provider used to send the account confirmation email (through Supabase). Processes your email address for the sole purpose of delivering that email. See Resend’s policy (
resend.com). -
OpenStreetMap / Nominatim (OSM Foundation) — geocoding service used to turn a place name you type into coordinates (fishing-spot search) and, as a network fallback when the device geocoder is unavailable, to turn coordinates into a place name. Receives the place name you search or the coordinates of the looked-up spot. See the OSMF privacy policy (
osmfoundation.org).
Attribution — weather, marine and hydrology data is provided by Open-Meteo under the CC BY 4.0 license; map data by OpenFreeMap / OpenMapTiles / © OpenStreetMap. All are credited within the app.
International transfers — Supabase and Sentry process data in the European Union. Google (AdMob), RevenueCat, Resend and the app stores (Apple / Google) may process data outside the EU (notably the United States); these providers rely on appropriate safeguards, such as the EU Standard Contractual Clauses.
Storage location and retention
- Local data: kept on your device until you delete it in the app or uninstall the app. Uninstalling clears the app’s local storage.
- Account data (Supabase): kept in the EU region for as long as your account exists. When you delete a catch in the app and sync, the deletion is propagated to the server.
- Inactive accounts: to respect storage limitation, an account with no sign-in for 36 months may be deleted (or anonymized) after a prior warning email.
- Account deletion: when you delete your account, erasure is immediate and permanent server-side (see “Your rights”).
Your rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability of your data.
- Edit your data: your profile, catches and gear can be edited directly in the app.
- Delete your account: in the app, Profile → Settings → Danger zone →
Delete account. This triggers a server function (Supabase Edge Function
delete-account) that immediately and permanently erases your authentication account, profile, catches, photos, comments, likes, friendships and reports. You may also write to contact@piscary.app to exercise this right. Note: any Piscary Pro subscription is not cancelled by deleting your account; you must manage or cancel it directly through your store (App Store or Google Play). - Access / portability: write to contact@piscary.app; we will provide the account data concerning you.
- Complaint: you may lodge a complaint with the CNIL (the French supervisory authority) or the authority in your country of residence.
Transparency note: account deletion is immediate and permanent: it runs directly in the app (Profile → Settings → Danger zone → Delete account) via a server function, with no manual intervention or processing delay. Emailing contact@piscary.app remains an option if you prefer. Your local data (on the device) is erased as soon as you delete the relevant items or uninstall the app.
Children
Piscary is not directed at children under 15 and does not knowingly collect data about them. If you believe a child has provided us with personal data, contact contact@piscary.app for its removal.
Security
Exchanges with Supabase and Open-Meteo use HTTPS (encryption in transit). Access to account data is protected by Supabase Row Level Security: you can only access your own data and content shared with you. The authentication session is stored locally on the device.
Changes
This policy may be updated. The “Last updated” date at the top of this document indicates the version in force. For any question: contact@piscary.app.