Privacy Policy

FishTrip — Last updated: 7 July 2026

This Privacy Policy explains how FishTrip (“FishTrip,” “we,” “us”) collects, uses, and protects your personal data when you use the FishTrip mobile application and the services available at fishtrip.fun (together, the “Service”).

1. Who we are

Controller:Gregor Willenberg
Gellertstrasse 14
13127 Berlin Germany
Email: privacy@fishtrip.fun

2. What data we collect

CategoryExamplesSource
Account data Email address, display name, hashed password, Apple / Google user identifier You provide it when registering or signing in
Profile content Profile picture, language preference You provide it in the app
Trip & catch content Trip name, catch photos, fish species, length, weight, notes, voice messages You create it in the app
Precise location GPS coordinates attached to catches and shown on the map Requested only while the app is in use, with your consent
Photos & audio Images you capture or import, voice messages you record Camera, microphone, and photo library — with your permission
Device data Push notification token, device model, OS version, app version, language Sent automatically to deliver notifications and diagnose issues
Usage & log data Request timestamps, error messages, IP address Generated automatically when you use the Service
FishTrip does not currently use advertising identifiers, does not currently track you across other companies’ apps or websites, and does not sell your personal data. See §7 below on advertising we may introduce in the future.

3. How we use your data

4. Legal basis (GDPR)

5. Third-party services

We share only the minimum data needed to make the Service work.

ProviderPurposeData shared
Apple, Inc. Sign in with Apple, push notifications (APNs) Apple identifier, email (only if you share it), device push token
Google LLC Google Sign-In, Firebase Cloud Messaging (push infrastructure) Google identifier, email (during sign-in), FCM token
Fishial Recognition AI fish species detection from catch photos Anonymised photo bytes; no user identifier
Cloud infrastructure (fishtrip.fun/api) Hosting of the backend and object storage All data you enter into the app

We do not currently share your personal data with any other party for advertising or marketing purposes. See §7 below.

6. Reports and moderation data

FishTrip is a social platform, so we run a moderation programme to review user-generated content when it is flagged by other users. This section explains what data we collect through that programme, how we use it, and how long we keep it. The programme itself is described in §7 of our Terms of Service.

What we collect when you file a report

Legal basis: performance of the Service and our legitimate interest in keeping the community safe (Art. 6(1)(b) and (f) GDPR), and — for reports involving child safety or illegal activity — compliance with a legal obligation (Art. 6(1)(c)).

What we collect when you block someone

We store a symmetric record linking your account identifier to the blocked user's account identifier, plus a timestamp. That record is used to hide each side's content from the other and can be reviewed and removed at any time from Settings → Blocked Users.

Who can see reports and moderation actions

Audit log

Every moderation action taken on a report — assignments, status changes, content hides, removals, warnings, suspensions, and bans — is written to an immutable audit log. We keep this log so we can demonstrate the operation of our moderation programme to platform operators (Apple, Google) and to regulators. Individual entries are minimised: they contain the acting moderator's identifier, the action, the affected content or account identifier, and a timestamp.

Retention

Your rights

You retain all the rights listed in §9 of this policy over the data described in this section, including access, correction, and deletion. Requests to erase content you reported are subject to the retention rules above.

7. Advertising (planned)

FishTrip does not currently show advertising. We may introduce advertising in a future version of the Service to support ongoing development. Before we do, we will update this Privacy Policy and, where the advertising involves tracking, ask for your consent through:

We distinguish between two kinds of advertising:

If we begin using an advertising network, we will list the provider(s) in §5 above and describe what data is shared. You will always be able to manage your advertising choices in the app settings, and you will always be able to opt out of personalised advertising without losing access to the core Service.

8. International transfers

Some of our providers (e.g. Apple, Google, Fishial) may process data outside the European Economic Area. Where that happens, transfers are covered by the European Commission’s Standard Contractual Clauses or an adequacy decision.

9. Data retention

10. Your rights

Under the GDPR you have the right to:

To exercise any of these rights, email privacy@fishtrip.fun. We respond within one month.

11. Security

All traffic between the app and our servers uses TLS. Passwords are hashed using bcrypt; authentication uses JSON Web Tokens with automatic refresh. On your device, credentials are stored in the iOS Keychain or the Android Keystore. Despite these safeguards, no system is completely secure — if we become aware of a personal-data breach we will notify affected users and the relevant supervisory authority in line with Art. 33 GDPR.

12. Children

FishTrip is not directed at children under 13 (or the equivalent minimum digital-consent age in your country). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be communicated in the app or by email before they take effect.

14. Contact

Questions, requests, or complaints about this policy or your personal data:
privacy@fishtrip.fun