Android early accessTest Piscary before everyone else — leave the Gmail address of your Google Play account.

Only to add you to the test, then deleted. Privacy

Privacy Policy — Piscary

Publisher: Morgane Garnier — sole trader (micro-enterprise), trading as KreaRise SIREN: 994 232 130 Registered office: 18 chemin de Meaux, 93360 Neuilly-Plaisance, France Contact: contact@piscary.app Last updated: September 16, 2026 App version: 1.0.2

Piscary is a bilingual (French / English) mobile fishing logbook. This policy describes, honestly and specifically to this app, what data we process, why, where it is stored, and what your rights are. We are established in the European Union and apply the General Data Protection Regulation (GDPR).

Core principle: an account is required, but the app still works offline

As of version 1.0, an account is required to use Piscary. Account creation relies on Supabase (see “Third-party services”) and requires a verified email address.

The app is still local-first: your data is first saved on your device — so you can log a catch with no connection, at the water’s edge — then synced to your account when a network is available. In practice, your catch journal, your photos, your statistics, your challenges and badges, and your gear are kept locally (both for offline display and as an upload queue) and synced to our servers.

Data we process

1. Data stored locally on your device (cache & offline)

This data is kept in the app’s private storage (the app sandbox Piscary folder) for offline display and as an upload queue; it is also synced to your account (see section 3):

2. Location

Catch location privacy — for each catch, you choose:

3. Data processed on our servers (account required)

Because an account is required to use the app, the following data is processed on our servers. Authentication and storage are powered by Supabase (see “Third-party services”).

4. Advertising (free users)

The app shows advertising via Google AdMob, in the “App Open” format (open screen), only to free users: Piscary Pro subscribers see no ads.

5. Piscary Pro subscription (optional)

The app offers a Piscary Pro subscription, managed via RevenueCat on top of the App Store (Apple) or Google Play.

6. Usage measurement (anonymous statistics)

To learn which features are actually used, and where the app is hard to use, we measure its usage with PostHog, hosted in the European Union.

7. What we do NOT do

Purposes of processing

Data Purpose Legal basis (GDPR)
Journal, photos, gear (local) Provide the fishing logbook Service provision / legitimate interest
Spot location Compute fishing conditions (weather, tides) Consent (location permission)
Catch location Locate your catches Consent
Email + password Create and secure your account Contract performance (the account you request)
Synced profile, catches, photos Sync and sharing you enable Contract performance / consent
Photo submitted to “Identify a fish” Identify the species from a photo (not kept) Service provision
Visual signatures of your catches Improve species recognition Consent (dedicated setting, off by default)
Likes, comments, friendships Social features you use Consent
Device notification token Tell you about a like, a comment or a new follower Consent (notification permission)
Reports / blocks Community safety and moderation Legitimate interest
Non-personalized advertising (free users) Fund the free version of the app Legitimate interest; consent (UMP form) in the EEA / UK
Purchase / subscription data Manage the Piscary Pro subscription and restore purchases Contract performance
Crash / technical diagnostics (Sentry) App stability and bug fixing Legitimate interest
Email address (Resend) Deliver the account confirmation email Contract performance

Third-party services

Piscary communicates with the following families of external services:

  1. Open-Meteo (open-meteo.com) — weather, marine and hydrology service. Receives only geographic coordinates of a point you look up, in order to return weather, tides and river flow. No account identifier and no direct personal data is transmitted to it. See Open-Meteo’s policy on their site.

  2. Apple (Apple Maps, on iOS) and Google (Google Maps, on Android) — map display and reverse geocoding. The map is rendered by the operating system’s mapping service: when you view a map, the device requests the cartography for the area you are viewing from Apple (iOS) or Google (Android). The same services turn coordinates into a place name. Piscary transmits no account identifier to them; what these services collect falls under their own policies (apple.com/legal/privacy, policies.google.com/privacy).

  3. Supabase — database, authentication and file-storage host, used only if you have an account. Piscary’s Supabase project is hosted in the European Union (EU) region.

  4. Google AdMob — advertising network, used only for free users, to serve non-personalized ads. May process device / advertising identifiers and technical information (see “Advertising”). See Google’s privacy policy (policies.google.com/privacy).

  5. RevenueCat — management of the Piscary Pro subscription (entitlements, purchase restoration), on top of the App Store / Google Play. Processes purchase / subscription data and an identifier linked to your account (pseudonymous, see “Piscary Pro subscription”).

  6. Sentry — crash and error reporting for app stability, active only in the released app. Receives technical diagnostics (crash stack traces, device model and OS version, app version, and in-app navigation breadcrumbs = screen names). Configured without personal data (no user IP, no user identifier) and hosted in the European Union (EU) region. Used to fix bugs, never for advertising or behavioral tracking.

  7. Resend — transactional email delivery provider used to send the account confirmation email (through Supabase). Processes your email address for the sole purpose of delivering that email. See Resend’s policy (resend.com).

  8. Public hydrology networks — to show a river’s flow and level (and its temperature where that measurement exists): Hub’Eau / Eaufrance (France), queried directly by the app — it therefore sees your connection’s IP address; U.S. Geological Survey (United States) and Environment Agency (England), queried by our servers. They receive coordinates or a gauging station identifier, never an account identifier.

  9. PostHog — app usage measurement (see “Usage measurement”). Receives the screens opened, lifecycle events, a closed list of actions, and your account identifier (pseudonym). Hosted in the European Union (eu.i.posthog.com). Receives none of the text you type, no coordinates, no photos. Can be turned off in Settings. See posthog.com/privacy.

  10. OVH (OVH SAS, server located in Gravelines, France) — hosts the image-analysis server for species recognition. Receives the photo you submit (or, if you consented to improvement, a catch photo) for the time needed to compute a visual signature, and keeps neither the photo nor the signature. No account identifier is sent to it.

  11. Expo (expo.dev) — remote notification delivery. Receives your device’s notification token and the notification text — which contains the other angler’s username and, for a comment, an excerpt of it — then relays them to Apple (APNs) or Google (FCM) notification services. Receives neither your email address, nor your photos, nor your coordinates. See expo.dev/privacy.

Attribution — weather, marine and hydrology data is provided by Open-Meteo under the CC BY 4.0 license; place and waterway names come from OpenStreetMap (via Overture Maps) under the ODbL license. Both sources are credited within the app; the map on screen carries the Apple Maps (iOS) or Google Maps (Android) notice.

International transfers — Supabase, Sentry, PostHog and OVH process data in the European Union. Google (AdMob, Google Maps), Apple (Apple Maps), RevenueCat, Resend, Expo and the app stores (Apple / Google) may process data outside the EU (notably the United States); these providers rely on appropriate safeguards, such as the EU Standard Contractual Clauses.

Storage location and retention

Your rights

Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability of your data.

Transparency note: account deletion is immediate and permanent: it runs directly in the app (Profile → Settings → Danger zone → Delete account) via a server function, with no manual intervention or processing delay. Emailing contact@piscary.app remains an option if you prefer. Your local data (on the device) is erased as soon as you delete the relevant items or uninstall the app.

Children

Piscary is not directed at children under 15 and does not knowingly collect data about them. If you believe a child has provided us with personal data, contact contact@piscary.app for its removal.

Security

Exchanges with Supabase and Open-Meteo use HTTPS (encryption in transit). Access to account data is protected by Supabase Row Level Security: you can only access your own data and content shared with you. The authentication session is stored locally on the device.

Changes

This policy may be updated. The “Last updated” date at the top of this document indicates the version in force. For any question: contact@piscary.app.