Privacy Policy
Last updated: 2026-09-24
FishCap is built to keep your data with you. No accounts, no in-app login, no third-party analytics SDKs, no ad tracking, and no server of ours holding your catch log. Here is the detail.
1. Where your records live
Catches, photos, cutouts, species, measurements, spots and weather are stored on your device and synced through your own iCloud private database — space under your own Apple ID — to your other devices. Sync is on by default and free. We cannot access your iCloud private database; that data is protected by Apple's account and encryption mechanisms and never passes through our servers.
2. What happens during a cloud identification
When a photo is sent
After you take a photo or choose one from your library, the app first makes the cutout on your device and then automatically sends the photo for identification — there is no separate button to tap. No request is sent when:
- your device is offline;
- the app already knows this device's free identifications are used up and you are not subscribed;
- the on-device check finds neither a fish nor a subject to cut out (you can still send it yourself with "Identify anyway").
Tapping "Identify" on a saved catch that was never identified also sends one request.
What is sent
- That one photo — the cut-out fish on a plain grey background, or the original photo when no subject was found, as a JPEG no larger than 1024 px on the long edge.
- An optional coarse region code (
na/eu/au/jp/cn/global) and a freshwater / saltwater hint, used only to reorder candidate species. - Your app language, which only affects the language of the returned text.
- Identifiers — an anonymous device identifier (a token derived via Apple App Attest), used to verify the device is genuine and count the free allowance; an optional RevenueCat anonymous app user ID, used to check subscription status; and the random ID of that catch record, so that a network retry is not charged twice.
GPS coordinates are never sent. Location EXIF from the photo is not sent with the request either.
Who processes it, and for how long
The request goes to FishCap's own Cloudflare Worker proxy, which forwards it to Google's Gemini model. FishCap's proxy does not store the photo: it is held in memory only while that one request is processed and is discarded once it has been passed to Google. So that a network retry does not consume your allowance twice, a successful identification result (candidate species, a one-line note and any length estimate — not the photo) is cached for your device, under the catch record's random ID, for up to 24 hours.
Under Google's terms for the paid Gemini API, Google does not use these requests and responses to improve or train its models, but it may log request content for a limited period solely to detect violations of its prohibited use policy and for legally required disclosures. That processing is governed by Google's terms and privacy policy.
3. What we keep on the server
- Allowance counters — keyed to the anonymous device identifier: the time of each identification (deleted after about 25 hours; used for the hourly and daily limits) and a lifetime count. No name, email, Apple ID, phone number, IP address or location.
- Subscription-status cache — RevenueCat's answer to whether an anonymous app user ID currently holds an active subscription, keyed to that RevenueCat anonymous app user ID (not the device identifier) and deleted automatically after about 10 minutes.
- Identification-result cache — see section 2: up to 24 hours, no photo.
- Aggregate usage stats — when the model names a fish that is not in our species list, the guessed name, region code and freshwater / saltwater hint are recorded in aggregate form (Cloudflare Analytics Engine) so we know which species to add. No photos, no device identifiers.
- Operational logs — the log lines our code writes contain timings, the model, the top species and its confidence, the region and water hints, the subscription tier, failure reasons and request trace ids. Never the photo, a coordinate or an IP address. They are kept briefly for troubleshooting and abuse prevention.
- Cloudflare and IP addresses — every request, including requests to this website, passes through Cloudflare. Cloudflare processes your IP address to deliver the request and as part of its request logging (Workers Logs), which Cloudflare keeps for a limited period under its own policies. On the two device-registration endpoints the IP address is also used, transiently, as the key for an anti-abuse rate limit. FishCap's own stored data (the allowance counters and the caches) contains no IP addresses.
We do not keep your catch log, spots, photos or photo library, or anything that could be traced back to you personally.
4. Location
With your permission, the app uses precise location on-device to record a spot, reverse-geocode it, and fetch the weather at that moment. Those results are written only into your own records and your own iCloud and are never sent to FishCap's servers or any third party (an identification request carries only the coarse region code described in section 2). You can turn location access off at any time in iOS Settings; logging still works, it simply won't fill in a place or the weather.
5. Photos
The camera and the system photo picker are used only for the photos you choose. Photos stay on your device and in your own iCloud. Apart from the identification request described in section 2, they are not uploaded anywhere. Share cards are rendered locally and handed to the system share sheet; they hide location by default and never include coordinates or GPS EXIF.
6. Weather
Weather comes from Apple WeatherKit. Fetching local conditions requires sending a location to Apple's weather service; that processing is governed by Apple's privacy policy. The result is stored only in your own records.
7. Purchases and subscriptions
Purchases run through Apple In-App Purchase; we never see your payment method, your name or your Apple ID. Receipts are processed by RevenueCat to determine subscription status, using a RevenueCat anonymous app user ID — we do not give them an email address or anything else that identifies you.
8. Tracking and analytics
FishCap contains no third-party analytics or advertising SDKs. It does not read the IDFA, does not track you across apps or websites, and does not link your data with data from other sources. In the app's privacy manifest (PrivacyInfo.xcprivacy), NSPrivacyTracking is false and the tracking-domains list is empty.
9. What we "collect", in Apple's terms
- Photos (not linked to you, not used for tracking) — when a photo is sent for identification, to provide that feature.
- Purchase history (not linked, not tracking) — to restore your subscription after a reinstall or on a new device.
- Device ID (not linked, not tracking) — the anonymous App Attest–derived device identifier, used to count the free allowance, and the RevenueCat anonymous app user ID, used to check subscription status.
Precise location is not collected: coordinates stay on your device and in your private iCloud and are never sent to us or a third party. The widget contains no networking code at all and only reads a local snapshot shared with the app.
10. Children
FishCap is not directed at children under 13 and we do not knowingly collect information from them.
11. Your choices and deleting data
- Delete a record — delete the catch in the app; the deletion syncs to your iCloud.
- Delete everything — delete the app and remove FishCap's iCloud data in iOS Settings → your Apple Account → iCloud.
- Permissions — camera, photos, location and notifications can be revoked at any time in iOS Settings.
- Server-side records — the allowance counter is keyed to an anonymous device identifier, the subscription-status cache deletes itself after about 10 minutes and the result cache after at most 24 hours; none of them holds personal information. If you want the records associated with your device removed, email willisshan66@gmail.com and we will delete them (which also clears that device's free-allowance count).
- Depending on where you live you may have rights to access, correct, delete or export personal data. Because what we hold is minimal and not linked to your identity, the steps above usually cover it.
12. International processing
Identification requests are handled on Cloudflare's global network and forwarded to Google's model service, so that processing — including Cloudflare's handling of IP addresses — may happen outside your country. Everything else stays on your device and in your iCloud.
13. Changes to this policy
If this policy changes we update the "Last updated" date at the top of this page, and material changes to how data is handled are surfaced in the app.
14. Contact
FishCap · willisshan66@gmail.com