Privacy Policy
Last updated 26 July 2026
The short version
FishnIQ is a fishing app. The most sensitive thing it holds is where you fish, and we treat it that way: the exact coordinates of your catches, saved spots and GPS tracks are end-to-end encrypted with a key that stays on your devices, so not even we can read them — and they are never shown to other users, in any form.
We do not sell your data, we do not run third-party advertising trackers, and we do not build an advertising profile of you.
This policy describes what the app actually does today, not what we might do. If that changes, this page changes with it.
Your exact spots are end-to-end encrypted
The precise coordinates of your catches, saved spots and recorded GPS tracks are encrypted on your device before they ever reach us. The key that unlocks them is derived from a recovery code that stays on your devices and is never sent to us. As a result we cannot read your exact fishing locations — not our staff, not with full access to our database, and not with the database's own encryption key. If we were ordered by a court to produce them, we could hand over only unreadable ciphertext, because we do not hold the key.
What we can see, and store in readable form, is a coarse area of roughly 40 km around each location. That is enough to work out the tide, weather and solunar forecast for the right region, and far too coarse to identify a fishing spot. Your exact position is never stored anywhere we can read it.
A privacy promise is only worth the parts that are true, so the honest limits:
- Only the coordinates are encrypted. The name you give a spot, the species and length of a catch, and any photo are not — so treat a spot's name and a catch photo as things we can see (and, if you choose to share a catch, other anglers can too).
- This protects your data on our servers. It cannot protect a phone that is unlocked in someone else's hands, and anyone you give your recovery code to can read your spots. Keep that code safe: we cannot reset it, and without it your exact history cannot be recovered — by us or by you.
- This applies from the moment your device sets up encryption. Locations you logged before that are re-encrypted, losslessly, the next time you open the app.
Your fishing locations
When you log a catch or save a spot, its exact coordinates are end-to-end encrypted on your device (see above) and are readable only by you, on your own devices.
No feature shares them with another user. Not exactly, not approximately, and not "the general area". We previously showed crew members a map of each other's catches rounded to a roughly 2 km grid, and we removed it — because repeated catches at one spot always round to the same point, which identifies it well enough to matter.
Two consequences worth being explicit about:
- Photos you attach to a catch are re-encoded before storage, which removes all embedded metadata including any GPS coordinates your camera recorded.
- A photo still shows whatever it shows. If a picture contains a recognisable dock, bridge or shoreline, sharing that catch shares that view. We cannot strip that, and you should assume anything you publish can be recognised by someone who knows the water.
We may later add an option to share a specific spot or catch location deliberately. If we do, it will be off by default and per-item — never a blanket setting, and never retroactive to things you logged before it existed.
What we store about you
- Your account: a handle, display name, the provider you signed in with (Google or Apple), and your email address.
- Your fishing data: catches (species, length, time, optional photo, and coordinates that are end-to-end encrypted — we store only ciphertext plus a coarse ~40 km region), saved spots, trips, GPS tracks, and crew memberships.
- Usage analytics: which screens you open and which features you use, tied to your account. No IP address is recorded with these and no device fingerprint is taken.
- Security records: sign-ins, failed sign-ins, and administrative actions, with the IP address they came from.
- Billing state, if you subscribe: your Stripe customer and subscription identifiers. We never see or store your card details.
What is shared with other users
When you log a catch it appears in the public feed and on your public profile, showing the species, length, photo, time and your handle. It does not include where you were.
Your handle and public profile are visible without signing in. Your email address is never shown to another user.
Services we send data to
Running the app requires sending some data to other companies. This is the complete list:
- Open-Meteo — weather and sea state. Receives your coordinate rounded to two decimal places (roughly 1 km), which is coarser than the ~11 km resolution of the weather model itself.
- NOAA — US tide predictions. Receives a tide station identifier only. Your coordinate is never sent; the nearest station is worked out on our own server.
- Photon (Komoot) — place search. Receives the text you type into the search box.
- Google (Gemini) — AI fish identification, only when you use it. Receives the photo you chose to identify. Your location and identity are not sent.
- Stripe — payments, only if you subscribe. Receives your email address and an account identifier. Card details go directly to Stripe and never reach us.
- Google and Apple — sign-in. We verify the token they issue; nothing about you is sent to them by us.
- OpenFreeMap — the background map. Your browser fetches map tiles directly from them, so they receive your IP address and the area of the map you are looking at. This is how essentially every map application works, and we have chosen not to route it through our servers. It does not include your catches or your saved spots.
- Cloudflare — sits in front of the site and therefore handles all traffic to it.
Our AI coach receives conditions — solunar rating, moon phase, tide and pressure — and never receives your coordinates or your identity.
How long we keep things
- Your catches, spots and trips: until you delete them or close your account.
- Usage analytics: 180 days.
- Security and administrative records: 365 days.
- Billing records: 90 days in our systems; Stripe keeps its own records for as long as the law requires them to.
- Web server logs: 30 days. Coordinates are stripped from these before they are written.
Analytics and your choice
We record which screens you open and which features you use, so we can tell what is worth building. It is tied to your account so we can honour your choice about it.
You can turn analytics off in your account settings. When it is off, nothing is recorded — the choice is enforced on our server, not just hidden in the app.
We do not use Google Analytics, advertising pixels, or any third-party tracking script.
Deleting your account
You can delete your account from your account settings. It is immediate and it is not reversible.
Deleting removes your catches, spots, trips, photos, notification settings and analytics records, and cancels any active subscription immediately — including any paid time still remaining, which is not refunded. If you own a crew that other people are in, ownership passes to the longest-standing member rather than deleting their crew along with your account.
One exception, stated plainly: security records of sign-ins and administrative actions are kept for up to 365 days after deletion. They exist to investigate abuse, and removing them on request would defeat that. They contain an account identifier and an IP address, not your fishing data.
Children
FishnIQ is not for children under 13, and we do not knowingly collect anything from them. Where local law sets a higher minimum age for using a service like this without a parent's consent — 16 in some European countries — that higher age applies instead.
We do not ask for a date of birth. Accounts are created through Google or Apple sign-in, both of which have their own minimum ages.
If you believe a child has created an account, email [email protected] and we will delete it and everything attached to it. You do not need to prove anything to us; we will act on a credible report.
Your rights
Depending on where you live you may have the right to access, correct, export or delete your data, and to object to certain processing. Account deletion is available in-app; for anything else, contact us and we will respond within the time your local law requires.
[CONFIRM: whether a GDPR representative or a specific state-law disclosure is required, based on where users actually are. The app has users in the United States and South East Asia.]
Contact
FishnIQ is operated by FishnIQ, 1 Sandy Cove Rd, Sarasota, FL 34242, USA.
Privacy questions: [email protected]
Questions about anything here: [email protected]