1. Data we collect and why
We process the information needed to authenticate you and operate features you choose to use. This can include your email address, username, optional profile details and avatar, account preferences, posts, comments, reactions, favorites, support requests, moderation reports, and technical security logs.
Public usernames, public profile details, public or approximate posts, comments, reactions, and media can be seen by other visitors. Your account email is not displayed in public posts.
2. Location privacy
Map posts keep an owner-only exact point and, when needed, a separate display point derived by trusted database logic. The public API does not return the exact point for an approximate or private post.
Only me
The post, exact point, and private media are available only to the owner through authenticated access.
Approximate
The public map displays a generalized grid area roughly one mile across. The exact saved point remains visible only to the owner. Generalization reduces precision but cannot guarantee that another person will never infer a location from the photo, text, surroundings, or other clues.
Public
The selected coordinate is intended for public display. Use this only for a location you are comfortable sharing.
Optional Fish Identifier location is stored only with the owner’s identification history and is not sent to the external recognition provider.
3. Photo and media processing
Uploaded community photos and avatars are decoded and re-encoded on the server before storage. This strips embedded EXIF, GPS, device, timestamp, thumbnail, and editing metadata from the delivered file. The raw upload is processed in memory and is not retained as the served original.
Public and approximate-post media uses a public delivery path. Private-post media uses a separate private bucket with owner-scoped access controls and short-lived signed URLs. Thumbnails are made only from the sanitized file.
Removing metadata does not remove visible clues inside an image. Review backgrounds, signs, landmarks, faces, vehicle plates, and reflections before posting.
4. Fish Identification Data
Fish Identifier accepts a photo and, optionally, a location. The optional location can be stored with your owner-only identification history but is not included in the provider recognition request.
When automatic recognition is configured and you choose Identify Fish, the original upload is placed in a private, service-only temporary bucket. Our self-hosted image processor decodes it, applies orientation, resizes it when needed, and produces a clean WebP without the original EXIF or other embedded metadata. The raw temporary object must be deleted successfully before the sanitized image can leave SurfFishing.app. If provider credentials are unavailable, the request stops before the image is staged or sent.
The sanitized image is then sent server-to-server to Fishial Recognition only to produce candidate species matches. SurfFishing.app does not intentionally retain the submitted photo after the request. Recognition results and optional location can remain in the requesting member’s owner-only history until account deletion.
Fishial’s public Recognition API documentation explains that the API receives image bytes, but it does not publish a recognition-upload-specific deletion period or a blanket commitment that API submissions are excluded from model improvement. Fishial’s general Privacy Policy says personal data is kept as necessary for stated purposes and usage data may be used for internal analysis. Do not submit a photo unless you are comfortable with that external processing.
5. Service providers and data destinations
SurfFishing.app uses a dedicated self-hosted Supabase deployment for authentication, database, storage, and server functions, plus a separate self-hosted image-sanitation service. Requested map areas, place-search text, or coordinates can be sent to Mapbox for map and place search, Open-Meteo for weather and marine forecasts, and NOAA for tides and official data. Live-camera requests can connect to the named camera provider when you open a stream. Fishial Recognition receives a sanitized fish image only when a signed-in member chooses Identify Fish; it does not receive the optional location.
Each third party applies its own privacy terms. We limit requests to the information needed for the feature and do not send your account password to these providers.
6. Retention
| Data | Typical retention |
|---|---|
| Account and profile | Until you delete the account, subject to limited operational backup cycles. |
| Active posts, comments, reactions, favorites, and media | Until you delete the item or account, or it is removed for safety, legal, or Terms enforcement reasons. |
| Removed posts, comments, and related post media | Hidden for a 30-day appeal window, then hard-deleted by the scheduled retention service. Report snapshots, moderation actions, and limited legal or safety records can remain after the content row is deleted. |
| Private media | Until the owner deletes the related media or account; delivery URLs expire after 10 minutes. |
| Authenticated support tickets | While the account exists and as needed to resolve and document the request. |
| Unauthenticated contact, abuse, and appeal requests | As needed to respond, investigate, decide an appeal, and preserve a limited safety or legal record. |
| Fish Identifier uploads | The raw temporary object is deleted before external transfer; SurfFishing.app discards the sanitized request bytes after Fishial responds. Fishial does not publish a fixed Recognition API image-retention period. Results can remain in owner-only history until account deletion. |
| Security, automated safety, and technical logs | For a limited operational period needed for reliability, abuse prevention, rate limiting, moderation, and incident investigation. Automated text screening does not intentionally store rejected submission text. |
| Deleted data in backups | Nightly database dumps rotate after 14 days. VM recovery snapshots rotate as 7 daily, 4 weekly, and 6 monthly copies, so deleted data can remain in recovery copies until the relevant copy expires. |
7. Your choices and rights
You can change profile visibility and location defaults, edit or remove content you own, and permanently delete your account from User Settings after re-authentication. Account deletion removes account-owned application rows and media under the service’s deletion workflow; limited backup copies age out under the backup schedule.
You may also request access, correction, deletion, or review of personal information. Identity verification may be required before fulfilling a request so one person cannot obtain or delete another person’s data.
8. Security and children
We use access controls, separate public and private media paths, scoped signed URLs, encrypted HTTPS transport, and service monitoring. No online system is perfectly secure, so do not upload information that is unnecessary for the service.
SurfFishing.app is not directed to children under 13. A parent or guardian can use the public contact channel to report content or request review without creating an account.
9. Contact
Use the public Support form for privacy requests, account-access problems, abuse, copyright, or content concerns. No sign-in is required. Signed-in members can also open an account-linked ticket inside the app.
