Privacy Policy
Fishician® ("Fishician", "we", "us") is an aquarium companion application that helps hobbyists manage aquariums, track fish and water parameters, get AI-assisted care suggestions, and participate in an aquarium community. This policy explains what personal data we collect, why, how long we keep it, and the rights you have over it — including rights under the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).
1. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account identifiers | Email address, display name, hashed password, optional avatar | You, at registration |
| Aquarium records | Tanks, fish, equipment, water test logs, maintenance tasks, photos you add | You, in the app |
| Community content | Posts, comments, photos, videos, group and forum activity, direct messages | You, in community areas |
| AI requests | Text and images you submit to AI features (e.g. fish health scan), and the responses | You, when using AI tools |
| Security and device data | Session tokens, IP-derived security events, sign-in history, two-factor settings | Generated when you use the service |
| Preferences | Cookie/privacy choices, display settings | You |
We do not knowingly collect data from children under 13, and accounts are limited to users 13 and older.
2. Why we process it (legal bases)
- Provide the service (contract): aquarium tracking, community features, AI tools you request, support.
- Security and abuse prevention (legitimate interest / legal obligation): authentication, rate limiting, fraud and abuse detection, audit logs.
- Content moderation (legitimate interest / legal obligation): automated and manual review of community content for safety.
- Product improvement (consent where required): optional, privacy-conscious analytics you can decline.
- Advertising: Fishician does not currently load third-party advertising scripts. If this changes, this policy and the available consent controls will be updated before advertising is enabled.
3. Cookies and similar technologies
Strictly necessary cookies and local storage keep you signed in, protect your account, remember settings you request, and support recovery-safe app functions; they cannot be switched off while using those features. Optional analytics is controlled from the cookie banner or Privacy Choices inside the app (Settings → Privacy). Advertising storage is not available and remains disabled. We honor the Global Privacy Control (GPC) browser signal as an opt-out of sale/share.
Fishician does not currently load Google AdSense or another third-party advertising script. Privacy Choices therefore controls optional analytics, while advertising storage remains disabled. If advertising is enabled in the future, Fishician will update this policy and provide the consent and opt-out controls required for the relevant regions before loading an ad script.
4. Advertising and affiliate links
Fishician does not currently display programmatic ads. It does include affiliate links to participating retailers. Affiliate links do not send retailers your Fishician account data; the retailer sets its own cookies on its own site. See our Advertising & Affiliate Disclosure.
5. Who we share data with
- Infrastructure: Cloudflare, Inc. (hosting, storage, AI inference) processes data on our behalf.
- Email delivery: transactional email providers for verification and security codes.
- AI processing: AI requests are processed by models run on Cloudflare Workers AI and, for some features, Google's Gemini API. Operational AI logs are redacted of common emails, phone numbers, and identifiers before storage. When you explicitly save an AI result, the saved-history record retains the prompt or upload context you supplied so you can understand and reopen that result; you can delete individual saved results or your account.
- Legal: where required by law or to protect users and the service.
We do not sell personal information, and we do not share it for cross-context behavioral advertising without your consent. The Privacy Choices "Do not sell or share" toggle records a CCPA/CPRA opt-out regardless.
California notice at collection
During the preceding 12 months, Fishician may have collected the categories described in Section 1: identifiers, internet or network activity used for security, user-generated aquarium and community content, approximate device/security information, and preferences. We use those categories for the purposes in Section 2 and disclose them only to the service providers described above or when legally required. We do not sell personal information, do not knowingly sell or share information about consumers under 16, and do not offer financial incentives for personal information.
6. Data retention
| Data | Retention |
|---|---|
| Account, aquarium, and local recovery data | While your account is active; deleted or scrubbed when you delete your account. A recovery copy stored in your browser remains under your browser/device control and can be removed by clearing site data. |
| Community posts you delete | Removed from the service on deletion |
| Security event logs | Up to 365 days, then automatically purged |
| AI analysis logs | Up to 90 days, then automatically purged |
| Saved AI results | Saved results remain account data until you delete the individual result or your account, subject to disclosed in-product history limits. Legacy outcome fields from the discontinued health follow-up interface, if present on an older saved result, are deleted with that result or account and are not collected by the current interface. |
| Backups and legal-hold records | Rotated on a limited disaster-recovery schedule or retained only as needed for security, fraud prevention, legal claims, or legal compliance; deleted data is not restored into the live service except for disaster recovery. |
7. Your rights
Depending on where you live (GDPR for EU/UK, CCPA/CPRA for California, and similar state laws), you may have the right to:
- Access / know what personal data we hold about you;
- Export your data in a portable format (in-app: Settings → Account → Export data);
- Correct inaccurate data (edit in-app, or ask us);
- Delete your data (in-app: Settings → Account → Delete Account — immediate, permanent, self-service);
- Opt out of sale/share and targeted advertising (Privacy Choices toggle or GPC);
- Object or restrict certain processing, and not be discriminated against for exercising rights.
To exercise any right, use the in-app controls or email privacy@fishician.app. We respond within the timelines required by applicable law (30 days GDPR, 45 days CCPA, extendable where permitted). We may need to verify your identity via your account email. Authorized agents may submit CCPA requests with proof of authorization. If you are in the EU/UK you may also lodge a complaint with your supervisory authority.
8. International transfers
We operate on Cloudflare's global network; data may be processed in the United States and other countries. Where GDPR applies, transfers rely on appropriate safeguards such as standard contractual clauses implemented by our processors.
9. Security
Protections include HTTPS everywhere, HttpOnly session cookies, PBKDF2-hashed passwords, optional two-factor authentication (TOTP or email codes), 2FA-enforced admin access, parameterized database queries, origin-checked requests, automated content moderation, and audit logging of security events. No system is 100% secure; report concerns to support@fishician.app.
10. Changes and contact
We will post updates to this page and, for material changes, notify you in the app. Contact: privacy@fishician.app.