Privacy policy

Your fishing spots stay under your control.

This policy explains what SurfFishing.app processes, how approximate sharing differs from exact saved locations, how photos are cleaned, and what happens when you use Fish Identifier.

Effective August 26, 2026 · Version 2026-08-26

1. Data we collect and why

We process the information needed to authenticate you and operate features you choose to use. This can include your email address, username, optional profile details and avatar, account preferences, posts, comments, reactions, favorites, support requests, moderation reports, and technical security logs.

Public usernames, public profile details, public or approximate posts, comments, reactions, and media can be seen by other visitors. Your account email is not displayed in public posts.

2. Location privacy

Map posts keep an owner-only exact point and, when needed, a separate display point derived by trusted database logic. The public API does not return the exact point for an approximate or private post.

Only me

The post, exact point, and private media are available only to the owner through authenticated access.

Approximate

The public map displays a generalized grid area roughly one mile across. The exact saved point remains visible only to the owner. Generalization reduces precision but cannot guarantee that another person will never infer a location from the photo, text, surroundings, or other clues.

Public

The selected coordinate is intended for public display. Use this only for a location you are comfortable sharing.

Optional Fish Identifier location is stored only with the owner’s identification history and is not sent to the external recognition provider.

3. Photo and media processing

Uploaded community photos and avatars are decoded and re-encoded on the server before storage. This strips embedded EXIF, GPS, device, timestamp, thumbnail, and editing metadata from the delivered file. The raw upload is processed in memory and is not retained as the served original.

Public and approximate-post media uses a public delivery path. Private-post media uses a separate private bucket with owner-scoped access controls and short-lived signed URLs. Thumbnails are made only from the sanitized file.

Removing metadata does not remove visible clues inside an image. Review backgrounds, signs, landmarks, faces, vehicle plates, and reflections before posting.

4. Fish Identification Data

Fish Identifier accepts a photo and, optionally, a location. The optional location can be stored with your owner-only identification history but is not included in the provider recognition request.

When automatic recognition is configured and you choose Identify Fish, the original upload is placed in a private, service-only temporary bucket. Our self-hosted image processor decodes it, applies orientation, resizes it when needed, and produces a clean WebP without the original EXIF or other embedded metadata. The raw temporary object must be deleted successfully before the sanitized image can leave SurfFishing.app. If provider credentials are unavailable, the request stops before the image is staged or sent.

The sanitized image is then sent server-to-server to Fishial Recognition only to produce candidate species matches. SurfFishing.app does not intentionally retain the submitted photo after the request. Recognition results and optional location can remain in the requesting member’s owner-only history until account deletion.

Fishial’s public Recognition API documentation explains that the API receives image bytes, but it does not publish a recognition-upload-specific deletion period or a blanket commitment that API submissions are excluded from model improvement. Fishial’s general Privacy Policy says personal data is kept as necessary for stated purposes and usage data may be used for internal analysis. Do not submit a photo unless you are comfortable with that external processing.

5. Service providers and data destinations

SurfFishing.app uses a dedicated self-hosted Supabase deployment for authentication, database, storage, and server functions, plus a separate self-hosted image-sanitation service. Requested map areas, place-search text, or coordinates can be sent to Mapbox for map and place search, Open-Meteo for weather and marine forecasts, and NOAA for tides and official data. Live-camera requests can connect to the named camera provider when you open a stream. Fishial Recognition receives a sanitized fish image only when a signed-in member chooses Identify Fish; it does not receive the optional location.

Each third party applies its own privacy terms. We limit requests to the information needed for the feature and do not send your account password to these providers.

6. Retention

DataTypical retention
Account and profileUntil you delete the account, subject to limited operational backup cycles.
Active posts, comments, reactions, favorites, and mediaUntil you delete the item or account, or it is removed for safety, legal, or Terms enforcement reasons.
Removed posts, comments, and related post mediaHidden for a 30-day appeal window, then hard-deleted by the scheduled retention service. Report snapshots, moderation actions, and limited legal or safety records can remain after the content row is deleted.
Private mediaUntil the owner deletes the related media or account; delivery URLs expire after 10 minutes.
Authenticated support ticketsWhile the account exists and as needed to resolve and document the request.
Unauthenticated contact, abuse, and appeal requestsAs needed to respond, investigate, decide an appeal, and preserve a limited safety or legal record.
Fish Identifier uploadsThe raw temporary object is deleted before external transfer; SurfFishing.app discards the sanitized request bytes after Fishial responds. Fishial does not publish a fixed Recognition API image-retention period. Results can remain in owner-only history until account deletion.
Security, automated safety, and technical logsFor a limited operational period needed for reliability, abuse prevention, rate limiting, moderation, and incident investigation. Automated text screening does not intentionally store rejected submission text.
Deleted data in backupsNightly database dumps rotate after 14 days. VM recovery snapshots rotate as 7 daily, 4 weekly, and 6 monthly copies, so deleted data can remain in recovery copies until the relevant copy expires.

7. Your choices and rights

You can change profile visibility and location defaults, edit or remove content you own, and permanently delete your account from User Settings after re-authentication. Account deletion removes account-owned application rows and media under the service’s deletion workflow; limited backup copies age out under the backup schedule.

You may also request access, correction, deletion, or review of personal information. Identity verification may be required before fulfilling a request so one person cannot obtain or delete another person’s data.

8. Security and children

We use access controls, separate public and private media paths, scoped signed URLs, encrypted HTTPS transport, and service monitoring. No online system is perfectly secure, so do not upload information that is unnecessary for the service.

SurfFishing.app is not directed to children under 13. A parent or guardian can use the public contact channel to report content or request review without creating an account.

9. Contact

Use the public Support form for privacy requests, account-access problems, abuse, copyright, or content concerns. No sign-in is required. Signed-in members can also open an account-linked ticket inside the app.