MedFish
EN IT

Privacy Policy

Last updated: 10 August 2026

MedFish is a fishing log and marine map for the Mediterranean. This policy explains what we collect, why, and what control you have. It is written to be read, not to be survived.

The short version. We collect the account details you give us and the fishing data you choose to record. Your exact spot coordinates are private by default and are never published unless you explicitly choose to publish them. We do not sell your personal data. You can delete your account, and its data, from inside the app.

1. Who is responsible

The data controller is [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COUNTRY]. For any privacy question or request, contact privacy@medfish.online.

2. What we collect

Data Why we hold it
Email address and password To create and secure your account. Passwords are hashed by our authentication provider and are never visible to us.
Profile details — username, display name, bio, avatar, home port, preferred fishing style To identify you to other anglers. Everything except your username is optional.
Catches — species, size, weight, bait, notes, conditions, photos, date This is the log itself. You decide what to record and what to share.
Location data — device position, saved spot coordinates To centre the map, show conditions where you are, and sort shops and spots by distance. See section 3.
Photos To attach images to catches and set your avatar. Accessed only when you pick or take a photo.
Messages To deliver direct messages between anglers and to shop or support accounts.
Shop details, if you register a shop — business name, address, contact, opening hours, inventory To list your shop on the map. This information is public by design.
Purchase records, if you buy access to a paid spot To grant you access and to pay the spot owner. Card details are handled entirely by our payment processor and never reach us.

3. Location — the part that matters

A fishing app that leaks your marks is worse than no app at all, so location is handled more carefully than anything else in MedFish.

You can revoke location permission at any time in your device settings. The app remains usable; the map simply opens on a default Mediterranean view instead of your position.

4. Legal basis for processing (GDPR)

5. Who else processes your data

We use a small number of established providers. They process data on our behalf, under contract, and only for the purposes below.

Provider Purpose
Supabase Database, authentication and photo storage. Data is hosted in the European Union.
Stripe Payment processing for paid spot access and shop payouts. Card data goes directly to Stripe and is never stored by MedFish.
RevenueCat Manages in-app purchases and subscriptions, where offered.
Google Maps Renders the base map. Subject to Google's own privacy policy.
Open-Meteo, EMODnet Marine and weather data. These receive an approximate map position in order to return conditions, and no account information.
WoRMS, OpenStreetMap Nominatim Species reference data and place-name lookup. These receive a search term or coordinate, and no account information.

We do not sell your personal data, and we do not share it with advertisers or data brokers.

6. What other people can see

7. How long we keep it

We keep your account data for as long as your account exists. When you delete your account, your profile, catches, spots and messages are removed. Transaction records are retained where accounting law requires it, and anonymised statistics that cannot identify you may be retained.

8. Your rights

Under the GDPR you have the right to access, correct, delete, export, restrict or object to the processing of your personal data, and to withdraw consent at any time.

You can delete your account directly in the app — Settings → Delete my account. This is immediate and permanent. See the account deletion page for details and for how to request deletion if you can no longer sign in.

For any other request, email privacy@medfish.online. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

9. Children

MedFish is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.

10. Security

Data is encrypted in transit. Access to your data is enforced by database-level security rules, so the server refuses requests for data you are not entitled to rather than relying on the app to hide it. No system is perfectly secure, but we treat coordinates and messages as sensitive by default.

11. Changes

If we change this policy materially we will update the date above and notify you in the app before the change takes effect.

12. Contact

[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
privacy@medfish.online