Your data & GDPR

Last updated: 7 September 2026

Your data belongs to you. Almost every GDPR right is a switch inside the app; the few that need us take one email. The same text lives in the app under Settings → Legal.

The short version

Your data belongs to you. The App is built so you can exercise almost every GDPR right yourself, directly in the App; the few that need us (like correcting your date of birth, or objecting to processing) take one email. This page lists each right and where to find it. The data controller is FNBgroup OÜ (the "Company"), registry code 17563256, registered address . Data-protection contact: legal@fishandbeer.app.

Access and portability (Art. 15 & 20)

Get a machine-readable copy (JSON) of your profile, catches, trips, beer log, social connections, fishing groups (your memberships and the spots and catches you shared into them) and settings from the App at Settings → Privacy → Export my data. The download link works for 1 hour and only the newest export is kept, so treat the link as private and do not share it. Email us for anything not included and we will provide everything the GDPR entitles you to. To protect other users, the export leaves out data that identifies them, for example who you blocked or reported.

Rectification (Art. 16)

Correct your data yourself: profile details under Settings → Account → Edit profile, and any catch by opening it and choosing Edit. Your date of birth is protected against casual change, so it cannot be edited in-app: if it is wrong, email legal@fishandbeer.app from the address linked to your account and we will verify and correct it. Anything else you cannot edit in-app, we will correct on request.

Erasure (Art. 17)

Delete individual catches at any time (they go to Recently deleted for 30 days, then are removed). Delete everything at Settings → Danger zone → Delete account: your account is disabled immediately, held for a 30-day grace window in case you change your mind, then permanently erased. A small amount of data survives where the law requires or allows it, some of it only in de-identified or pseudonymised form; the Privacy Policy, section 7, lists exactly what and for how long.

Withdrawing consent (Art. 7)

Everything consent-based is a switch you control:

Objection and restriction (Art. 18 & 21)

You can object to any processing we base on legitimate interest, including the automated image safety check applied to your public photos. Separately, you can ask us to restrict processing while we verify a correction you contested, where processing is unlawful but you prefer restriction to erasure, where you need the data preserved for legal claims, or while we assess an objection you have raised. Email legal@fishandbeer.app and tell us what you object to or want restricted; we will stop unless the law requires otherwise, and we will explain either way. If a photo of yours was withheld by the safety check, you can also have a person review it: email support@fishandbeer.app with the subject "Appeal".

Automated decision-making (Art. 22)

No decision with legal or similarly significant effect is made about you by automated means alone. One automated safeguard exists: when the image safety check is enabled, a public photo can be automatically withheld from public view if the check flags it. Your catch still posts, you keep the photo, and if it happens we tell you, with the reasons and how to challenge it; a person then reviews it. That is a content-visibility measure, not a decision about you or your account; account decisions are always made by a person.

Making a request by email

For anything the App cannot do directly, email legal@fishandbeer.app from the address linked to your account (so we can verify it is really you). If you signed in with Apple and chose to hide your email, write from any address, tell us your display name, and we will verify you another way (for example through a message sent to the relay address on your account). We respond within one month; for complex requests the GDPR allows a two-month extension, and we will tell you if we need it. Requests are free.

Complaints

If you believe we have handled your data unlawfully, you can lodge a complaint with the data-protection authority in your country of residence or with the supervisory authority in Estonia: the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, +372 627 4135, aki.ee. We would appreciate the chance to resolve it directly first, but that is your choice, not a requirement.