Privacy Policy
Last updated: 6 October 2026
This privacy policy explains, in accordance with Articles 13 and 14 GDPR, which personal data we process when you use the Wall of Fish app (iOS, Android) or our website, for what purposes, on which legal basis, who receives it and what rights you have. In short: we only process what your fishing log needs. No ads, no tracking or analytics SDKs, no selling of data. In case of discrepancies, the German version prevails.
1. Controller
[Vorname Nachname][Straße Hausnummer]
[PLZ] [Ort]
Deutschland
Email: [kontakt@walloffish.com]
See also our imprint. We have not appointed a data protection officer because the legal requirements for doing so (Section 38 BDSG) are not met. For any privacy question, contact us at the email address above.
2. Data we process
- Account data: name and email address from Google or Apple sign-in (with Apple possibly an anonymous relay address), an internal user ID and your account identifier at the sign-in provider.
- Profile data: nickname, optionally a profile picture (avatar), region, units, language and your visibility settings.
- Catch data: species, length, weight, time, water name, notes, assignment to walls and per-catch visibility.
- Location data (optional): coordinates and accuracy of the catch location, see section 4.
- Photos (optional): catch photos and profile picture, see section 5.
- Weather data for the catch (temperature, air pressure, wind etc.), derived from location and time.
- Social data: buddy requests and connections, blocks, memberships in shared walls (crews), invitations.
- Technical data: IP address, date and time, requested URL, browser or app version, operating system, session token.
- Purchase data (once Pro is available): your subscription status and the App Store or Google Play transaction ID. We do not receive payment details.
3. Purposes and legal bases
3.1 Account, sign-in and providing the app
We process account, profile, catch and social data to provide your log, your walls, buddies and shared walls, and to sync them across your devices. The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR). Catches are first stored locally on your device and synced with your account once you are signed in and online.
3.2 Sign in with Google or Apple
When you use “Sign in with Google” or “Sign in with Apple”, the app redirects you to that provider. We receive an account identifier, your name and your email address (with Apple, a relay address if you choose); we do not store a password. The provider processes the sign-in itself as an independent controller under its own privacy policy. Our legal basis is Art. 6(1)(b) GDPR. We run authentication ourselves (Better Auth on our servers); no further authentication service provider is involved.
3.3 Location and photos
We only process location data and photos with your consent (Art. 6(1)(a) GDPR; for access to device features also Section 25(1) TDDDG). You give it through your operating system's permission prompt and by taking or selecting photos. You can withdraw consent at any time with effect for the future: revoke the permission in your system settings, remove the location or photo from a catch, or delete the catch. Withdrawal does not affect the lawfulness of processing before it. Details in sections 4 and 5.
3.4 Security and abuse prevention
To protect our systems and your account we process technical data (in particular IP address, time, request, session data) in server logs, for rate limiting and for investigating attacks and abuse (e.g. spam, unauthorised access). The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR).
3.5 Contact and support
If you write to us, we process your message and contact details to handle your request (Art. 6(1)(b) GDPR where it concerns your account, otherwise Art. 6(1)(f) GDPR).
3.6 Purchases (Pro)
Once a Pro subscription is offered, it is purchased and billed exclusively through Apple's App Store or Google Play, which are independently responsible for it. We only receive which subscription is active and a transaction ID to unlock Pro features (Art. 6(1)(b) GDPR).
3.7 Push notifications (planned)
If we introduce notifications (e.g. buddy requests), we will only send them with your consent via the system prompt (Art. 6(1)(a) GDPR). This involves transmitting a device token via Expo (650 Industries, Inc., USA) and Apple Push Notification service or Firebase Cloud Messaging (Google). You can withdraw at any time in your system settings.
3.8 Cookies and local storage
On the website we only set strictly necessary cookies: a session cookie for sign-in and a cookie for your language. In the app we store catches, settings and cached images locally on your device. This storage is strictly necessary for the service you request (Section 25(2) no. 2 TDDDG). We do not use analytics, marketing or tracking cookies.
4. Location data
- Only while logging: the app only requests your location while you record a catch (“While Using the App” permission). There is no background tracking and no movement profile. Without permission the location stays empty and you can type the water name manually.
- Exact only for you: we store the exact coordinates and their accuracy. Only you can see them.
- Visibility to others: by default, buddies and members of shared walls see no location (“Hidden”). Optionally you can share a position rounded to about 1 km (“Coarse”). Exact coordinates are never shown to other users; the same rule applies to the water name. Locations are never shown publicly.
- Place name: the app determines the place name using your operating system's geocoding feature, which sends the coordinates to Apple (iOS) or Google (Android) under their privacy policies.
- Weather: to add weather data to a catch we send the coordinates rounded to four decimal places (about 10 m) and the time to the weather service Open-Meteo, which for technical reasons also receives the IP address of the requesting system. No account or profile data is transmitted.
- Export and deletion: your coordinates are part of the data export (section 9). You can remove the location from any catch; it is deleted along with the catch or your account.
5. Photos
- The app only accesses your camera or photo library when you take or select a photo. With limited access it only sees the photos you have shared.
- Metadata is removed: before uploading, the app creates resized copies on your device (display size and thumbnail). EXIF metadata, including GPS position, camera details and capture time, is stripped in the process. The original never leaves your device.
- Catch photos are kept in non-public storage and are only delivered via time-limited signed links, and only to people allowed to see the catch (you, your buddies if shared, members of a shared wall you assigned the catch to).
- Your profile picture (avatar) is visible to other users who see you as a buddy or wall member and is delivered without a signature. Choose it accordingly.
- Please do not upload photos in which other people can be identified without their consent.
6. Recipients and processors
We do not share your data with third parties for advertising and we do not sell it. We use the following service providers. Processors only process data on our instructions under a contract pursuant to Art. 28 GDPR.
- Vercel Inc., USA (hosting of website and server)
- Processor. Server functions run in an EU region where configurable; delivery via a global network. Processes all data passing through our servers, including server logs.
- Neon Inc., USA (database)
- Processor. The database (PostgreSQL) is hosted in region eu-central-1 (Frankfurt am Main, Germany) and holds account, profile, catch and social data.
- Cloudflare, Inc., USA (image storage and delivery)
- Processor. Photos and profile pictures are stored in Cloudflare R2 [location: EU jurisdiction — confirm before publication]; delivery runs over Cloudflare's global network, where they may be cached.
- Google (Google Ireland Limited, Ireland / Google LLC, USA)
- Independent controller for “Sign in with Google”, geocoding on Android and Google Play (purchases, app distribution).
- Apple (Apple Distribution International Ltd., Ireland / Apple Inc., USA)
- Independent controller for “Sign in with Apple”, geocoding on iOS and the App Store (purchases, app distribution).
- Open-Meteo (weather service)
- Receives rounded coordinates, time and, for technical reasons, the IP address (section 4). [Verify operator, seat and role before publication.]
- Expo / 650 Industries, Inc., USA (planned, push notifications)
- Processor for delivering notifications, once introduced.
Other users only see your data according to your settings: confirmed buddies and members of shared walls see your nickname, avatar, region, wall progress and shared catches. There is currently no public profile.
Authorities only receive data where we are legally obliged to provide it.
7. Transfers to third countries
Some providers are based in the USA or may process data there. We base such transfers on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) where the recipient is certified under it, and otherwise on the Commission's standard contractual clauses (Art. 46(2)(c) GDPR). [Verify certification or clauses per provider before publication.] You can request a copy of the safeguards from us.
8. Retention
- Account, profile, catches, social data: until you delete them or your account. After account deletion the data is deleted without undue delay; residual copies in backups are overwritten within [30] days at the latest.
- Photos: removed from storage immediately when you delete the photo, the catch or your account. Cached copies in the delivery network remain reachable only via links already issued, which expire within 24 hours at the latest.
- Server logs: 30 days, unless a specific security incident requires longer retention for investigation.
- Support requests: until resolved, then up to [12] months for follow-up questions.
- Statutory retention obligations (e.g. under commercial and tax law) remain unaffected; in that case processing is restricted.
9. Your rights
You have the following rights regarding your data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR): you can export your catches including coordinates and photos in a common, machine-readable format [export feature in the app — until it ships, by email request].
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
- Objection (Art. 21 GDPR): where we process data based on legitimate interests, you may object at any time on grounds relating to your particular situation.
Deleting your account: you can delete your account at any time directly in the app (“You” tab, “Account” section) or request deletion by email. This removes your profile, catches, photos, buddy connections and memberships. Walls you created for others are deleted as well or [transferred to another member — define rule].
Right to lodge a complaint: you can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence, place of work or place of the alleged infringement. The authority competent for us is [data protection authority of the provider's German federal state].
10. Obligation to provide data, automated decisions
You are under no legal or contractual obligation to provide data. Without an account, however, you cannot sync or use buddies and shared walls; without location or photo permission only those features are missing. We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
11. Children and minimum age
Wall of Fish is intended for people aged 16 and over. Younger people may not create an account. If we learn that an account was created by someone under 16 without parental consent, we will delete it.
12. Changes to this policy
We update this policy when the app, our service providers or the law change. The version published here applies; we will inform you about material changes in the app. New processing that requires consent only starts once you have consented.
Note: This text is a draft and should be reviewed by a lawyer before publication.