Privacy Policy — Piscary

Publisher: Morgane Garnier — sole trader (micro-enterprise), trading as KreaRise SIREN: 994 232 130 Registered office: 18 chemin de Meaux, 93360 Neuilly-Plaisance, France Contact: contact@piscary.app Last updated: July 7, 2026 App version: 1.0.0

Piscary is a bilingual (French / English) mobile fishing logbook. This policy describes, honestly and specifically to this app, what data we process, why, where it is stored, and what your rights are. We are established in the European Union and apply the General Data Protection Regulation (GDPR).

Core principle: an account is required, but the app still works offline

As of version 1.0, an account is required to use Piscary. Account creation relies on Supabase (see “Third-party services”) and requires a verified email address.

The app is still local-first: your data is first saved on your device — so you can log a catch with no connection, at the water’s edge — then synced to your account when a network is available. In practice, your catch journal, your photos, your statistics, your challenges and badges, and your gear are kept locally (both for offline display and as an upload queue) and synced to our servers.

Data we process

1. Data stored locally on your device (cache & offline)

This data is kept in the app’s private storage (the app sandbox Piscary folder) for offline display and as an upload queue; it is also synced to your account (see section 3):

2. Location

Catch location privacy — for each catch, you choose:

3. Data processed on our servers (account required)

Because an account is required to use the app, the following data is processed on our servers. Authentication and storage are powered by Supabase (see “Third-party services”).

4. Advertising (free users)

The app shows advertising via Google AdMob, in the “App Open” format (open screen), only to free users: Piscary Pro subscribers see no ads.

5. Piscary Pro subscription (optional)

The app offers a Piscary Pro subscription, managed via RevenueCat on top of the App Store (Apple) or Google Play.

6. What we do NOT do

Purposes of processing

DataPurposeLegal basis (GDPR)
Journal, photos, gear (local)Provide the fishing logbookService provision / legitimate interest
Spot locationCompute fishing conditions (weather, tides)Consent (location permission)
Catch locationLocate your catchesConsent
Email + passwordCreate and secure your accountContract performance (the account you request)
Synced profile, catches, photosSync and sharing you enableContract performance / consent
Likes, comments, friendshipsSocial features you useConsent
Reports / blocksCommunity safety and moderationLegitimate interest
Non-personalized advertising (free users)Fund the free version of the appLegitimate interest; consent (UMP form) in the EEA / UK
Purchase / subscription dataManage the Piscary Pro subscription and restore purchasesContract performance
Crash / technical diagnostics (Sentry)App stability and bug fixingLegitimate interest
Email address (Resend)Deliver the account confirmation emailContract performance

Third-party services

Piscary communicates with eight families of external services:

  1. Open-Meteo (open-meteo.com) — weather, marine and hydrology service. Receives only geographic coordinates of a point you look up, in order to return weather, tides and river flow. No account identifier and no direct personal data is transmitted to it. See Open-Meteo’s policy on their site.

  2. OpenFreeMap (openfreemap.org) — map tile provider (cartography). When you view a map, the app downloads tiles for the geographic area you are viewing. No account identifier and no direct personal data is transmitted. Map data comes from OpenMapTiles / OpenStreetMap.

  3. Supabase — database, authentication and file-storage host, used only if you have an account. Piscary’s Supabase project is hosted in the European Union (EU) region.

  4. Google AdMob — advertising network, used only for free users, to serve non-personalized ads. May process device / advertising identifiers and technical information (see “Advertising”). See Google’s privacy policy (policies.google.com/privacy).

  5. RevenueCat — management of the Piscary Pro subscription (entitlements, purchase restoration), on top of the App Store / Google Play. Processes purchase / subscription data and an identifier linked to your account (pseudonymous, see “Piscary Pro subscription”).

  6. Sentry — crash and error reporting for app stability, active only in the released app. Receives technical diagnostics (crash stack traces, device model and OS version, app version, and in-app navigation breadcrumbs = screen names). Configured without personal data (no user IP, no user identifier) and hosted in the European Union (EU) region. Used to fix bugs, never for advertising or behavioral tracking.

  7. Resend — transactional email delivery provider used to send the account confirmation email (through Supabase). Processes your email address for the sole purpose of delivering that email. See Resend’s policy (resend.com).

  8. OpenStreetMap / Nominatim (OSM Foundation) — geocoding service used to turn a place name you type into coordinates (fishing-spot search) and, as a network fallback when the device geocoder is unavailable, to turn coordinates into a place name. Receives the place name you search or the coordinates of the looked-up spot. See the OSMF privacy policy (osmfoundation.org).

Attribution — weather, marine and hydrology data is provided by Open-Meteo under the CC BY 4.0 license; map data by OpenFreeMap / OpenMapTiles / © OpenStreetMap. All are credited within the app.

International transfers — Supabase and Sentry process data in the European Union. Google (AdMob), RevenueCat, Resend and the app stores (Apple / Google) may process data outside the EU (notably the United States); these providers rely on appropriate safeguards, such as the EU Standard Contractual Clauses.

Storage location and retention

Your rights

Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability of your data.

Transparency note: account deletion is immediate and permanent: it runs directly in the app (Profile → Settings → Danger zone → Delete account) via a server function, with no manual intervention or processing delay. Emailing contact@piscary.app remains an option if you prefer. Your local data (on the device) is erased as soon as you delete the relevant items or uninstall the app.

Children

Piscary is not directed at children under 15 and does not knowingly collect data about them. If you believe a child has provided us with personal data, contact contact@piscary.app for its removal.

Security

Exchanges with Supabase and Open-Meteo use HTTPS (encryption in transit). Access to account data is protected by Supabase Row Level Security: you can only access your own data and content shared with you. The authentication session is stored locally on the device.

Changes

This policy may be updated. The “Last updated” date at the top of this document indicates the version in force. For any question: contact@piscary.app.