MedFish
Choose language

Privacy Policy

Last updated: 29 August 2026

MedFish is a fishing log and marine map for the Mediterranean. This policy explains what we collect, why, and what control you have. It is written to be read, not to be survived.

The short version. We collect the account details you give us and the fishing data you choose to record. Your exact spot coordinates are private by default and are never published unless you explicitly choose to publish them. We do not sell your personal data. You can delete your account, and its data, from inside the app.

1. Who is responsible

The data controller is Louis Airaut, Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom. For any privacy question or request, contact privacy@medfish.online.

2. What we collect

Data Why we hold it
Email address and password To create and secure your account. Passwords are hashed by our authentication provider and are never visible to us.
Profile details — username, display name, bio, avatar, home port, preferred fishing style To identify you to other anglers. Everything except your username is optional.
Catches — species, size, weight, bait, notes, conditions, photos, date This is the log itself. You decide what to record and what to share.
Location data — device position, saved spot coordinates To centre the map, show conditions where you are, and sort shops and spots by distance. See section 3.
Photos To attach images to catches, set your avatar, and — if you list a paid spot — show buyers a photo of the fish before they pay. Accessed only when you pick or take a photo. We strip location and other metadata (including any GPS tag) from every image before it is uploaded, so a photo cannot reveal a position the rest of the app is protecting. A paid spot's photo is publicly readable, because it is what buyers are shown before purchase.
Messages To deliver direct messages between anglers and to shop or support accounts.
Shop details, if you register a shop — business name, address, contact, opening hours, inventory To list your shop on the map. This information is public by design.
Purchase and creator licence-fee records, if you subscribe, buy paid-location access, or license paid-location content to MedFish To grant purchases, reconcile Apple and Google financial reports, calculate variable creator licence fees from qualifying settled net unlock revenue, apply holds and adjustments, generate private statements, process payouts, and keep immutable accounting and audit evidence. In-app purchases are billed by the App Store or Google Play: card details are handled entirely by the store and never reach us.
Payout identity, tax and destination data, if you request creator payouts — date of birth, tax identifier, IBAN or PayPal email, masked destination, readiness status and transfer reference To review payout readiness, prevent duplicate destinations where necessary, meet accounting or compliance obligations, and process manual payouts. Protected values are encrypted with versioned keys; ordinary owner and administration screens show masked values only. Access is role-restricted, purpose-limited and audited. MedFish does not claim to perform government-identity or tax verification.
Activity between anglers — follows, likes, comments, saved spots To build your feed, show a catch's comments, and keep your saved spots on your map.
Safety records — accounts you block, reports you file To keep blocked accounts away from you, and so moderators can act on reports. A report records what was reported, by whom, and any reason you type.

3. Location — the part that matters

A fishing app that leaks your marks is worse than no app at all, so location is handled more carefully than anything else in MedFish.

You can revoke location permission at any time in your device settings. The app remains usable; the map simply opens on a default Mediterranean view instead of your position.

4. Legal basis for processing (GDPR)

5. Who else processes your data

We use a small number of established providers. They process data on our behalf, under contract, and only for the purposes below.

Provider Purpose
Supabase Database, authentication and photo storage. Data is hosted in the European Union.
Stripe Payment services for features that explicitly use Stripe. In-app purchases — MedFish Premium and paid spot unlocks — are billed by the App Store or Google Play, not Stripe. Creator licence-fee payouts to eligible contributors are made manually by SEPA transfer or PayPal to an approved destination.
RevenueCat Manages the MedFish Premium subscription, monthly or yearly, and paid spot unlocks bought through the App Store or Google Play. It receives your MedFish account identifier and the store's purchase receipt, and no catches, messages or spot coordinates.
Google Maps Renders the base map. Subject to Google's own privacy policy.
Open-Meteo, EMODnet Marine and weather data. These receive an approximate map position in order to return conditions, and no account information.
Google AdMob, in the free version of the app Serves the advertising that keeps the free tier free. Where required, we ask your permission before any ad request is made, and ads are non-personalised unless you agree otherwise. Ads are switched off while a MedFish Premium subscription is active.
WoRMS, OpenStreetMap Nominatim Species reference data and place-name lookup. These receive a search term or coordinate, and no account information.

We do not sell your personal data, and we do not give advertisers or data brokers your account, your catches, your messages or your spot coordinates. The free version of the app does show ads, which are served by Google AdMob as described above — we ask your permission first where the law requires it, and ads are switched off while a MedFish Premium subscription is active.

6. What other people can see

7. How long we keep it

We keep your account data for as long as your account exists. When you delete your account, your profile, catches, spots and messages are removed. An account with unresolved pending or available creator licence fees, a payout request, or a post-payout adjustment cannot be deleted until the accounting obligation is resolved. Purchase, licence, statement, settlement, refund, payout and audit records may then be retained separately for the period required by tax, accounting, fraud-prevention or other applicable law. Access to those retained records is restricted. Anonymised statistics that cannot identify you may also be retained.

8. Your rights

Under the GDPR you have the right to access, correct, delete, export, restrict or object to the processing of your personal data, and to withdraw consent at any time.

You can delete your account directly in the app — Settings → Delete my account. This is immediate and permanent. See the account deletion page for details and for how to request deletion if you can no longer sign in.

For any other request, email privacy@medfish.online. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

9. Children

MedFish is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.

10. Security

Data is encrypted in transit. Access to your data is enforced by database-level security rules, so the server refuses requests for data you are not entitled to rather than relying on the app to hide it. No system is perfectly secure, but we treat coordinates and messages as sensitive by default.

11. Changes

If we change this policy materially we will update the date above and notify you in the app before the change takes effect.

12. Contact

Louis Airaut
Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA
privacy@medfish.online