Privacy Policy
Last updated: 7 September 2026
The short version. We collect only what the app needs to work. We show no ads, we never sell your data, and analytics and crash reports are off unless you turn them on. Your data is stored in the European Union, and you can export or delete everything yourself from inside the app.
1. Who we are
FishandBeer is operated by FNBgroup OÜ (the "Company"), a company registered in Estonia under registry code 17563256, with its registered address at . The Company is the data controller for personal data collected through the App. Data-protection contact: legal@fishandbeer.app.
2. What we collect
We collect only what the App needs to work. This is the full list.
- Account: a user identifier, your display name, the sign-in provider you used (Apple or Google) and the email address it shares with us, and your language preference. We also keep a one-time record of when your account was created and which sign-in provider you used, which we use in aggregate to understand signups.
- Date of birth: collected at sign-up, used to verify you meet the minimum age and to gate the beer features to the legal drinking age. Kept for the life of your account and never shown to anyone. The field is protected against casual change; if the date on your account is wrong, email legal@fishandbeer.app from your account email and we will verify and correct it.
- Profile: optional bio and profile photo, plus your privacy settings (profile and catch visibility, both public by default; see the end of this section).
- Catches: species, measurements, timestamp, notes, photos, optional beer count, and the location you log. If you log with GPS we store the coordinates. On your profile and the public feed, other people see your catch location only at county/city level, never the exact coordinates. Two sharing choices are more precise, and both are yours to make per catch: sharing a catch with a fishing group shows the group an approximate location (rounded to about 1 km), and sharing a catch's location directly with a friend shows that friend the exact spot. If you request catch verification, this also includes the proof photos you take for it, which a moderator reviews.
- Trips: trip name, participants, start and end times, and beer counters.
- Social: friend connections, follows, trip invites, likes, guesses, blocks, and reports you send or receive.
- Fishing groups: groups you create or join (group name, owner, and member list), invites you send and receive, and the fishing spots and catches you choose to share with a group. A spot you share includes its exact coordinates, name, category, colour, and note, together with your display name. A catch you share includes its details, photo, county, and an approximate location (rounded to about 1 km), together with your display name. Only members of that group can see what you shared, nothing is shared until you share it, and you can un-share any spot or catch at any time. Shared copies are deleted when you un-share them, when you leave or are removed from the group, when the group is deleted, and when your account is deleted.
- Device: a push-notification token (only if you grant push permission), an app-generated installation identifier, platform, OS version, and app version.
- Subscription: your entitlement state and renewal dates from validating your App Store or Google Play purchase. We never receive your payment details.
- Support: emails you send us, used to answer you and resolve your issue.
- Feedback: messages you send us through the in-app feedback form, where available, with their category and your app version, used to improve the App; genuinely useful feedback may be rewarded with Premium time.
- Feature progress: achievement and badge progress, daily reward claims and streaks where those features are available, and per-day usage counters for limited features (such as guesses), kept only to run those features and erased with your account.
- Usage statistics: only if you opt in, app usage events (for example that a catch was logged or a species page was viewed) tied to your user identifier alone, used to understand how the App is used and improve it. Off by default; see sections 4 and 6.
- Technical: your IP address and request logs, processed to keep the service secure and running (see section 4) and deleted or anonymised within 30 days.
Who can see your data.
- Your profile is public by default: your display name, profile photo, a title you equip, catch statistics (such as species counts and totals), and your achievement badges are visible to everyone, including on leaderboards and in discovery suggestions. The list of your recent catches on your profile and your personal bests are shown only to accepted friends, with any showcase catch you pin shown first. You can hide the Statistics, Personal bests, Achievements, Catches, and Beer sections one by one in Settings → Account → Edit profile → Profile sections.
- A new catch is also public by default, with its photo and county/city-level location, including on the public feed.
- You can change either default, or any single catch, at any time: set your profile to friends-only or private in Settings → Privacy, pick a visibility when logging or editing a catch, and change the catch default in Settings → Privacy.
- A spot or catch you share with a fishing group is visible to every member of that group, including people who join it later, together with your display name. You can un-share it at any time, and leaving a group or being removed from one removes everything you shared into it.
Photos you upload can show other people. You are responsible for having their permission (see the Terms), and a person appearing in a photo can contact us at legal@fishandbeer.app to exercise their data-protection rights, including having the photo removed.
Map markers you place and personal notes you write on the Home screen are stored only on your device, not on our servers, unless you share a marker with a fishing group. An unshared marker is not part of your account data, is not covered by account deletion or the data export, and is lost if the App is removed from the device. When you share a marker with a group, a copy of that marker (its exact coordinates, name, category, colour, and note, together with your display name) is stored on our servers so the group can see it. That copy is included in your data export and is deleted when you un-share it, when you leave or are removed from the group, when the group is deleted, and when your account is deleted.
3. What we don't do
- No advertising and no advertising identifiers.
- We do not sell personal data.
- No behavioural tracking and no advertising analytics. Usage statistics are off by default and collected only if you opt in (sections 4 and 6); crash reports are likewise off by default and sent only if you opt in. We do keep a few anonymous, app-wide counts (for example how many catches are logged across the whole app) to understand overall usage, plus the one-time signup record described in section 2.
- No AI training on your content and no AI profiling. The automated analysis we do is limited to two things: an on-device species suggestion from your catch photo (which never leaves your device) and, when the check is enabled, an automated safety scan of photos you share publicly (see the AI features page).
4. Why we process it (legal bases)
- Contract (GDPR Art. 6(1)(b)): providing the App's features: saving and syncing catches, trips, social features, and Premium features you paid for.
- Legitimate interest (Art. 6(1)(f)). Our specific interests are: keeping the App and its users secure (abuse prevention, rate limiting, app-integrity checks); keeping the shared feed free of illegal and objectionable content (moderation of reports and, when enabled, the automated image safety check); sending service communications; answering your support emails, handling the feedback you send us, and using both to fix problems and improve the App; and understanding overall usage through anonymous app-wide counts and the one-time signup record. You can object to any of these (section 9).
- Consent (Art. 6(1)(a)): the beer counter, push notifications, usage statistics, crash reports, and marketing messages. Each is opt-in, off by default, and can be withdrawn at any time as easily as it was given; withdrawing the usage-statistics consent stops collection immediately.
- Legal obligation (Art. 6(1)(c)): verifying that you meet the minimum age (in conjunction with Art. 8 GDPR and, for the beer features, the drinking-age laws that apply to you), responding to lawful requests, handling illegal-content notices, and retaining records where the law requires.
Account data (your user identifier, display name, date of birth, and the sign-in email) is required to create and sync your account; without it the App cannot work and no account can be created. Everything else (photos, GPS location, the beer count, crash reports, and marketing) is optional, and the App works if you leave it off.
The beer counter. The beer count is a personal tally you choose to keep. It is off by default, opt-in with its own separate choice, and age-gated. Some regulators may treat a log of alcohol consumption as health data. Whether or not it legally is, we handle it as if it were: we process it only with your explicit consent (Art. 6(1)(a) and, to the extent it is health data, Art. 9(2)(a)), we never analyse it, and we never use it to infer anything about your health.
Others see your beer count only in these places, each under your control: trip participants see your counter during a shared trip; a catch you share can show its per-catch amount; and your profile total is visible to profile viewers unless you turn that section off in Settings → Account → Edit profile → Profile sections. You can turn the whole feature off at any time in Settings → Preferences; recorded entries are erased with your account, and you can ask us to erase them earlier at legal@fishandbeer.app.
If we ever want to use your data for a new purpose not described here, we will tell you first and, where the law requires it, ask for your permission.
5. Where your data lives
We keep your data on Google Cloud / Firebase servers in the European Union (database: multi-region eur3, Belgium and Netherlands; file storage and server functions: europe-west1, Belgium). Personal data leaves the European Economic Area only where a processor below requires it, and then only under EU-approved safeguards: an EU adequacy decision (such as the EU-US Data Privacy Framework) or Standard Contractual Clauses. If an adequacy decision we rely on is ever invalidated, we will move the affected transfers to Standard Contractual Clauses or stop them. You can request a copy of the safeguards used for any transfer by emailing legal@fishandbeer.app with the subject "SCC copy".
6. Processors we use
These are the service providers that process personal data for us. Each is bound by a data-processing agreement: it may process your data only on our instructions, for the purpose listed, and must protect it to at least the standard described in this policy. We update this list before adding a processor, and announce material changes in the App.
- Google / Firebase: sign-in, database, file storage, push delivery, and app integrity checks. Data is stored in the EU (section 5); any processing in the United States is covered by the EU-US Data Privacy Framework, to which Google is certified.
- Google Cloud Vision: the automated safety scan of photos you share publicly, when that check is enabled. Receives only the shared photo, and only when you make a catch public. Google states that images sent to this service are processed in memory and not stored. Any US processing is covered by the EU-US Data Privacy Framework.
- RevenueCat: subscription validation. Receives your user ID and purchase receipt. Based in the United States; the transfer is covered by Standard Contractual Clauses in our data-processing agreement with them.
- Sentry: crash reports, only if you opt in (Settings). We configure crash reports to remove names, emails, locations and similar fields before sending. Crash events are retained at Sentry for 90 days and then deleted automatically; they are not linked to your account data. US processing is covered by the EU-US Data Privacy Framework, to which Sentry is certified. While we verify a new release, the App may also send a small number of one-time technical status events through the same opt-in channel (for example whether subscriptions, push notifications, and app integrity checks are working); they follow the same scrubbing and retention as crash reports.
- PostHog: usage statistics, only if you opt in (asked at sign-up, toggleable in Settings → Privacy). Receives app usage events tied to your user identifier alone: no location (we disable even the IP-derived kind), no name, email, birth data, measurements, or photos. Data is hosted on PostHog's EU cloud, inside the European Union. Events are kept for up to 24 months, then deleted; the analytics identity stored on your device is cleared when you sign out.
- Expo (EAS): push-notification delivery and app updates. Receives your push token and basic device info. Processing takes place in the United States, under Standard Contractual Clauses in our data-processing agreement with Expo.
- Sanity: delivery of the curated species and waters knowledge base to our servers. Receives no personal data.
Apple and Google Play handle your subscription payment as independent controllers, not as our processors: your payment relationship is with them, under their own privacy policies.
7. Retention and deletion
We keep your data while your account is active.
- Deleting your account (Settings → Danger zone → Delete account) disables it and starts a 30-day grace window during which you can restore it by signing in again.
- After 30 days your account, catches, trips, photos, social connections, and everything you shared into fishing groups are permanently erased; residual copies in routine backups are purged on the normal backup cycle, within a further 30 days. Catches you delete individually sit in Recently deleted for 30 days before they are removed.
- You can also request deletion of your account and associated data without using the App by emailing legal@fishandbeer.app with the subject "Delete my account" from the address linked to your account, or through the account-deletion page on our website. If you signed in with Apple and chose to hide your email, write from any address, tell us your display name, and we will verify you another way (for example through a message sent to the relay address on your account).
- If you asked for catch verification, the request record is removed 180 days after a moderator resolves it.
What survives deletion, and for how long:
- Billing records are kept for 7 years, as the accounting law of Estonia requires; once your account is deleted, we keep them with your user identifier removed.
- Support emails are kept for up to 24 months after the issue is closed, including after account deletion.
- Feedback you sent through the in-app form is erased with your account, so it does not survive deletion. While your account is active it is kept for up to 24 months, and you can email us to have it deleted sooner.
- Security and moderation audit logs are kept in de-identified form for up to 12 months (24 months for deletion events).
- Moderation reports and the statements of reasons for moderation decisions are kept in pseudonymised form (your identifiers are replaced) so that moderation history stays intact for the safety of other users. Statements of reasons are deleted after 180 days; pseudonymised reports are kept for up to 24 months.
- Crash reports you opted into sit at Sentry under its own 90-day retention (section 6) and are not part of your account data.
- The same goes for usage statistics you opted into: they stay at PostHog under the analytics retention (section 6, at most 24 months) rather than being erased with the account; email us to have your analytics data deleted sooner.
- Data exports you request are written to a private file whose download link is valid for 1 hour; requesting a new export deletes the previous one immediately, and the file is stored with your account data and erased with your account. Treat the link like a password and do not share it: anyone with the link can download the file while it is valid.
8. How we protect your data
Your data is encrypted in transit and at rest on Google Cloud. Per-user access rules limit what each account can read and write, photos are re-encoded on upload so embedded metadata is stripped, and staff access follows least privilege and is logged. No method of storage or transmission is 100% secure, so we cannot promise absolute security. If a breach affects you, we will notify you and the supervisory authority as the GDPR requires.
9. Your rights
Under the GDPR you can access your data, correct it, export it in a machine-readable form (portability), delete it, restrict its processing, object to processing based on legitimate interest, and withdraw any consent at any time without affecting past processing. The Your data & GDPR page explains each right and the exact place in the App where you can exercise it yourself. For anything not covered in-app, email legal@fishandbeer.app: we respond within one month. Complex requests can take up to two further months, and we will tell you if we need the extra time. Requests are free.
10. Children and age
You must be at least the digital age of consent in your country to create an account: 13 in most of the countries the App launches in, 14 in Lithuania, and up to 16 in some EEA countries; 13 elsewhere unless local law sets it higher. We check this at sign-up using the date of birth you enter; if the check fails, no account is created and anything already stored is removed. The beer features are additionally gated to the legal drinking age where you live (18 by default); they record a personal tally and nothing in the App encourages drinking.
We don't knowingly collect the data of anyone below the applicable minimum age. If you are a parent or guardian and believe a child has an account, email legal@fishandbeer.app and we will erase it.
11. Changes to this policy
We will announce material changes in the App before they take effect and ask you to review them. The date at the top shows the current version.
12. Contact and complaints
Privacy questions: legal@fishandbeer.app with the subject "Privacy". We have not appointed a Data Protection Officer (our processing does not require one); privacy matters are handled at that address.
You have the right to lodge a complaint with a data-protection supervisory authority (GDPR Art. 77): either the authority of your country of residence or the supervisory authority in Estonia, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, +372 627 4135, aki.ee. We would appreciate the chance to resolve the issue directly first, but that is your choice, not a requirement.
13. US residents: your state privacy rights
If you live in California or another US state with a comprehensive privacy law (for example Virginia, Colorado, Connecticut, Texas, Oregon), you have the right to: know and access the categories and specific pieces of personal information we collect; delete it; correct it; opt out of the sale or sharing of personal information and of targeted or cross-context behavioural advertising; limit the use of sensitive personal information; and not be treated differently for exercising these rights.
Do Not Sell or Share My Personal Information. We do not sell your personal information and we do not share it for cross-context behavioural advertising, as "sell" and "share" are defined under the CCPA and similar laws. We also do not use or disclose sensitive personal information beyond the purposes permitted by those laws, so no separate opt-out link is required.
Sensitive information. We treat precise geolocation as sensitive personal information. We collect exact GPS coordinates when you log a catch with location turned on, and we use them only to provide the features you enabled. That is why asking us to "limit the use of sensitive information" would not change anything: the limit is already how the App works. When your catches are shown to other people on your profile or the public feed, their location is generalised to county/city level. Sharing a catch with a fishing group reveals an approximate location (rounded to about 1 km), and sharing a catch's location directly with a friend reveals the exact spot; both happen only when you choose them for that catch. A fishing spot you share with a group shows its members the exact coordinates you chose to share. You can log catches without location at any time.
Categories (for US law). Mapping section 2 to the statutory categories: identifiers (user ID, email, display name); commercial information (subscription status); precise and coarse geolocation (catch location); visual information (catch photos); and internet/device activity (app and OS version, and opt-in analytics or crash data). We disclose these to service providers (cloud hosting, subscription validation, opt-in usage analytics, crash reporting, push delivery, and automated image safety scanning of public photos) for the business purposes in sections 4 and 6 only. We have not sold or shared any category in the preceding 12 months.
Exercising your rights. Use the in-app export and delete tools (Settings), or email legal@fishandbeer.app with the subject "US Privacy Request". We will confirm receipt within 10 days and respond within 45 days, extendable once by a further 45 days with notice. You may use an authorised agent with proof of authorisation. We verify requests using the email linked to your account and will not discriminate against you for exercising your rights.
Opt-out preference signals. Because we do not sell or share personal information or run targeted advertising, there is nothing for a Global Privacy Control signal to opt out of. The App is a native mobile application and does not process browser-based signals.