Privacy Policy

Last updated: 7 September 2026

The short version. We collect only what the app needs to work. We show no ads, we never sell your data, and analytics and crash reports are off unless you turn them on. Your data is stored in the European Union, and you can export or delete everything yourself from inside the app.

1. Who we are

FishandBeer is operated by FNBgroup OÜ (the "Company"), a company registered in Estonia under registry code 17563256, with its registered address at . The Company is the data controller for personal data collected through the App. Data-protection contact: legal@fishandbeer.app.

2. What we collect

We collect only what the App needs to work. This is the full list.

Who can see your data.

Photos you upload can show other people. You are responsible for having their permission (see the Terms), and a person appearing in a photo can contact us at legal@fishandbeer.app to exercise their data-protection rights, including having the photo removed.

Map markers you place and personal notes you write on the Home screen are stored only on your device, not on our servers, unless you share a marker with a fishing group. An unshared marker is not part of your account data, is not covered by account deletion or the data export, and is lost if the App is removed from the device. When you share a marker with a group, a copy of that marker (its exact coordinates, name, category, colour, and note, together with your display name) is stored on our servers so the group can see it. That copy is included in your data export and is deleted when you un-share it, when you leave or are removed from the group, when the group is deleted, and when your account is deleted.

3. What we don't do

4. Why we process it (legal bases)

Account data (your user identifier, display name, date of birth, and the sign-in email) is required to create and sync your account; without it the App cannot work and no account can be created. Everything else (photos, GPS location, the beer count, crash reports, and marketing) is optional, and the App works if you leave it off.

The beer counter. The beer count is a personal tally you choose to keep. It is off by default, opt-in with its own separate choice, and age-gated. Some regulators may treat a log of alcohol consumption as health data. Whether or not it legally is, we handle it as if it were: we process it only with your explicit consent (Art. 6(1)(a) and, to the extent it is health data, Art. 9(2)(a)), we never analyse it, and we never use it to infer anything about your health.

Others see your beer count only in these places, each under your control: trip participants see your counter during a shared trip; a catch you share can show its per-catch amount; and your profile total is visible to profile viewers unless you turn that section off in Settings → Account → Edit profile → Profile sections. You can turn the whole feature off at any time in Settings → Preferences; recorded entries are erased with your account, and you can ask us to erase them earlier at legal@fishandbeer.app.

If we ever want to use your data for a new purpose not described here, we will tell you first and, where the law requires it, ask for your permission.

5. Where your data lives

We keep your data on Google Cloud / Firebase servers in the European Union (database: multi-region eur3, Belgium and Netherlands; file storage and server functions: europe-west1, Belgium). Personal data leaves the European Economic Area only where a processor below requires it, and then only under EU-approved safeguards: an EU adequacy decision (such as the EU-US Data Privacy Framework) or Standard Contractual Clauses. If an adequacy decision we rely on is ever invalidated, we will move the affected transfers to Standard Contractual Clauses or stop them. You can request a copy of the safeguards used for any transfer by emailing legal@fishandbeer.app with the subject "SCC copy".

6. Processors we use

These are the service providers that process personal data for us. Each is bound by a data-processing agreement: it may process your data only on our instructions, for the purpose listed, and must protect it to at least the standard described in this policy. We update this list before adding a processor, and announce material changes in the App.

Apple and Google Play handle your subscription payment as independent controllers, not as our processors: your payment relationship is with them, under their own privacy policies.

7. Retention and deletion

We keep your data while your account is active.

What survives deletion, and for how long:

8. How we protect your data

Your data is encrypted in transit and at rest on Google Cloud. Per-user access rules limit what each account can read and write, photos are re-encoded on upload so embedded metadata is stripped, and staff access follows least privilege and is logged. No method of storage or transmission is 100% secure, so we cannot promise absolute security. If a breach affects you, we will notify you and the supervisory authority as the GDPR requires.

9. Your rights

Under the GDPR you can access your data, correct it, export it in a machine-readable form (portability), delete it, restrict its processing, object to processing based on legitimate interest, and withdraw any consent at any time without affecting past processing. The Your data & GDPR page explains each right and the exact place in the App where you can exercise it yourself. For anything not covered in-app, email legal@fishandbeer.app: we respond within one month. Complex requests can take up to two further months, and we will tell you if we need the extra time. Requests are free.

10. Children and age

You must be at least the digital age of consent in your country to create an account: 13 in most of the countries the App launches in, 14 in Lithuania, and up to 16 in some EEA countries; 13 elsewhere unless local law sets it higher. We check this at sign-up using the date of birth you enter; if the check fails, no account is created and anything already stored is removed. The beer features are additionally gated to the legal drinking age where you live (18 by default); they record a personal tally and nothing in the App encourages drinking.

We don't knowingly collect the data of anyone below the applicable minimum age. If you are a parent or guardian and believe a child has an account, email legal@fishandbeer.app and we will erase it.

11. Changes to this policy

We will announce material changes in the App before they take effect and ask you to review them. The date at the top shows the current version.

12. Contact and complaints

Privacy questions: legal@fishandbeer.app with the subject "Privacy". We have not appointed a Data Protection Officer (our processing does not require one); privacy matters are handled at that address.

You have the right to lodge a complaint with a data-protection supervisory authority (GDPR Art. 77): either the authority of your country of residence or the supervisory authority in Estonia, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, +372 627 4135, aki.ee. We would appreciate the chance to resolve the issue directly first, but that is your choice, not a requirement.

13. US residents: your state privacy rights

If you live in California or another US state with a comprehensive privacy law (for example Virginia, Colorado, Connecticut, Texas, Oregon), you have the right to: know and access the categories and specific pieces of personal information we collect; delete it; correct it; opt out of the sale or sharing of personal information and of targeted or cross-context behavioural advertising; limit the use of sensitive personal information; and not be treated differently for exercising these rights.

Do Not Sell or Share My Personal Information. We do not sell your personal information and we do not share it for cross-context behavioural advertising, as "sell" and "share" are defined under the CCPA and similar laws. We also do not use or disclose sensitive personal information beyond the purposes permitted by those laws, so no separate opt-out link is required.

Sensitive information. We treat precise geolocation as sensitive personal information. We collect exact GPS coordinates when you log a catch with location turned on, and we use them only to provide the features you enabled. That is why asking us to "limit the use of sensitive information" would not change anything: the limit is already how the App works. When your catches are shown to other people on your profile or the public feed, their location is generalised to county/city level. Sharing a catch with a fishing group reveals an approximate location (rounded to about 1 km), and sharing a catch's location directly with a friend reveals the exact spot; both happen only when you choose them for that catch. A fishing spot you share with a group shows its members the exact coordinates you chose to share. You can log catches without location at any time.

Categories (for US law). Mapping section 2 to the statutory categories: identifiers (user ID, email, display name); commercial information (subscription status); precise and coarse geolocation (catch location); visual information (catch photos); and internet/device activity (app and OS version, and opt-in analytics or crash data). We disclose these to service providers (cloud hosting, subscription validation, opt-in usage analytics, crash reporting, push delivery, and automated image safety scanning of public photos) for the business purposes in sections 4 and 6 only. We have not sold or shared any category in the preceding 12 months.

Exercising your rights. Use the in-app export and delete tools (Settings), or email legal@fishandbeer.app with the subject "US Privacy Request". We will confirm receipt within 10 days and respond within 45 days, extendable once by a further 45 days with notice. You may use an authorised agent with proof of authorisation. We verify requests using the email linked to your account and will not discriminate against you for exercising your rights.

Opt-out preference signals. Because we do not sell or share personal information or run targeted advertising, there is nothing for a Global Privacy Control signal to opt out of. The App is a native mobile application and does not process browser-based signals.