1. Who we are
Where's The Fish ("we", "us", "our") runs wheresthefish.us. We are based in the United Kingdom and are responsible for the personal information described in this policy. You can reach us about anything in it at [email protected] or through the contact page.
2. What we collect
When you browse without an account
- Technical information your browser sends with every request: IP address, browser and device type, the pages you visit and the page you came from. Our web server and error monitoring keep this in logs.
- Anonymous, aggregated usage measurements from a cookieless analytics service (see section 8). These do not identify you.
- The map area you are looking at, sent to us so we can return the spots inside it. We do not store it against you.
- If you use the contact form: your name, email address and message, plus a reCAPTCHA score from Google that helps us block spam.
When you create an account
- Your email address and name. If you sign in with Google we also store the identifier Google gives us for your account so we can recognize you next time. We do not receive or store a password: sign-in links and codes are emailed to you and each one expires after a short time.
- Your angler profile: username, display name, bio, avatar, home county and the privacy defaults you choose. The username cannot be changed once set.
- Preferences: the species and conditions you care about, forecast calendar settings and saved-spot alert settings.
- Your saved spots ("My spots"), likes and the notifications the service sends you.
- Everything you log: catches (species, weight, length, method, bait, time, location, notes and photos), trip plans and their outcomes, session write-ups and reports, comments and replies, and feedback on forecasts.
- Usage events tied to your account (for example that you opened the planner or logged a catch) in our analytics, so we can see which features are used and fix what is not working.
When you subscribe to Premium
- Payment is handled by Stripe. Stripe collects your card details and billing address directly; we never see the full card number. We store your Stripe customer reference, the card type and last four digits, your subscription status and dates, and the events Stripe sends us about payments and renewals.
We do not ask for sensitive information such as health details, and please do not put any in your bio, notes or reports.
3. How we use it
- To sign you in and run your account.
- To store and show your catches, trips, reports, comments and profile, at the audience you choose.
- To take payment and manage your subscription, and to keep the tax and accounting records the law requires.
- To email you sign-in links and codes, receipts, the saved-spot forecast alerts and trip alerts you have turned on, and material changes to the service or our terms. Every alert email has a link to switch it off.
- To tell you in the app about likes, comments and replies on your content.
- To suggest a species from a photo, each time you ask us to.
- To produce aggregated, de-identified catch statistics for spots and species.
- To measure how the site is used, fix errors and improve features.
- To prevent spam, abuse and fraud, to enforce our terms and to comply with the law.
We do not send marketing email, and we do not use your information for automated decisions that have legal or similarly significant effects on you.
4. What is public
The service is a community of anglers, so by default the things you log are visible to everyone, including people without an account and search engines:
- your profile page (username, display name, bio, avatar, home county if set, and stats if you leave them on);
- your public catches with their photos, species, weight, date and the location at the precision you chose;
- your published trip reports and the comments you leave on other people's catches and reports;
- your username next to anything you like or comment on.
Your email address, Google identifier, payment details, private catches, unpublished trips, private notes, exact GPS positions and forecast preferences are never public.
You control the audience of each catch and report, and the default for new ones, from your profile settings. Some audience and location-precision options are part of Premium; the Premium page lists which. A profile with only a handful of public catches is marked so that search engines do not index it, and you can make your whole profile private.
5. Photos, locations and AI species ID
Photo metadata
Photos often carry hidden metadata: the time they were taken and, on most phones, a GPS position. When you upload a catch photo we read that metadata in your browser and on our server to pre-fill the time of the catch and suggest the nearest spot, and then we re-encode the image so the stored and published copy carries no metadata at all. You can switch metadata reading off in your profile settings, in which case we never look at it. The original file is not kept.
Location precision
A catch is placed on a spot from our catalog. When you publish it you choose whether other people see the spot, only the city, only the county, or no location. For session write-ups at a place not in our catalog you can drop a pin instead; the pin coordinate stays on our server and is never shown to anyone else, only the nearest city or the county at the precision you chose. We use location only to provide these features, never to infer anything else about you.
AI species identification
If you ask us to identify a species from a photo, we send the photo to OpenAI, a third-party AI provider, and show you its suggestion. We send only the image and a fixed instruction, never your name, email or location, and the photo is not used by the provider to train its models under the terms we hold with it. Use is limited to 5 identifications a calendar month on a free account and 50 on Premium, and we record how many you have used each month to enforce that.
6. Who we share it with
We disclose personal information only to the service providers we need to run the service, each acting on our instructions and not allowed to use it for their own purposes:
- Google (sign in with Google and reCAPTCHA on the contact form).
- Stripe (payments, subscriptions, invoices and the billing portal). Stripe also handles the payment information it collects under its own privacy policy.
- Resend (sending our email: sign-in links, receipts, alerts and notifications).
- OpenAI (photo species identification, as described in section 5, and the generation of our own site content, which involves no personal information).
- Cloudflare (content delivery, image resizing and the object storage that holds catch photos and avatars).
- Our hosting provider (the servers, database and backups the service runs on, located in the United States).
- Sentry (error monitoring, which receives technical details of a request when something goes wrong, including your user identifier if you were signed in).
- PostHog, running on infrastructure we control, and Umami (usage analytics, see section 8).
- Meta (Facebook and Instagram), only if you switch on "Feature my catches on our social media" in your angler profile settings. With that on, a public catch of yours may be posted on our own Facebook Page and Instagram account with its photo, species, weight, the place your privacy settings allow and your username. It is off by default, you can switch it off at any time, and a post already made stays up unless you ask us to take it down.
Our weather, sea-state and tide providers receive only spot coordinates, never anything about you. We may also disclose information where the law requires it, to enforce our terms or protect the safety of our users, or to a buyer if the service changes hands, in which case this policy continues to apply to it.
7. We do not sell or share your information
We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use it for targeted advertising. We run no advertising tags on this site. We do not disclose personal information to third parties for their own direct marketing. If that ever changes we will update this policy first and give you a way to opt out.
Because we neither sell nor share personal information, there is nothing to opt out of today. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out, which our practices already meet.
8. Cookies, analytics and local storage
We keep cookies to the minimum the service needs to work:
- Session and security cookies that keep you signed in, protect forms against forgery and remember one-off messages. These are strictly necessary and last for your session or until you sign out.
- Analytics. Umami measures page views without cookies or fingerprinting and cannot identify you. PostHog runs on infrastructure we control, so your usage data is not sold or passed to an analytics company; it uses browser storage to recognize the same visitor across page views and, once you sign in, ties events to your account so we can understand how features are used. It does not record your screen.
- Local storage in your browser keeps small conveniences on your device only: recent searches, which release announcement you have dismissed, and map preferences. Nothing in it is sent to us.
- Stripe sets its own cookies on the checkout and billing portal pages for fraud prevention.
You can clear or block cookies and site data in your browser settings. Blocking the session cookie will stop you signing in.
9. How long we keep it
- Account, profile and content information: for as long as you keep your account, then as described in section 10.
- Sign-in links and codes: each is single-use and expires after a short time; used and expired ones are removed.
- Server sessions: expire after a period of inactivity.
- Contact form messages: kept in our support mailbox for up to two years so we can follow up.
- Payment and subscription records: kept for six years after the last payment, as tax and accounting law requires.
- Server and error logs: up to 90 days.
- Analytics events: up to 12 months in identifiable form; aggregated statistics are kept indefinitely.
- Forecast data for spots is not personal information and is pruned on its own schedule.
- Backups: overwritten on a rolling basis within 30 days.
10. Deleting your account
You can delete your account yourself, immediately, from the account page. This removes your profile, catches, photos, trips, reports, comments, likes, saved spots, notifications, preferences and sign-in identifiers from the live service, cancels any Premium subscription straight away, and stops your public pages resolving. Photo files are purged from storage and backup copies are overwritten within 30 days.
What we keep after deletion:
- payment and invoice records at Stripe and in our accounts for the period tax law requires;
- aggregated statistics your catches contributed to, which no longer identify you;
- a minimal record (an email address or identifier) where an account was closed for breaking our terms, so the ban holds;
- anything in server logs until those logs age out on the schedule above.
You can also delete or make private individual catches, trips, reports and comments at any time without deleting the account. Deleting a comment removes replies to it.
11. Where your information is stored
The service, its database and its backups run on servers in the United States. We are based in the United Kingdom and the people who run the service access it from there, and some of the providers in section 6 process information in other countries. Wherever it is handled, it is protected as this policy describes.
12. Your privacy rights
Depending on the state you live in, you may have the right to:
- know and access the personal information we hold about you and get a copy of it in a portable format;
- correct anything inaccurate: most of it you can edit yourself from your profile and account pages;
- delete your information, which you can do yourself by deleting your account;
- opt out of the sale or sharing of your information, targeted advertising and profiling. We do none of these (see section 7);
- not be discriminated against for using any of these rights.
We honor these requests from every user, wherever you live. To make one that you cannot carry out yourself on the site, email [email protected] from the address on your account, so we can confirm the request is yours. You can use an authorized agent, who will need your signed permission, and we may still ask you to confirm your identity with us. We respond within 45 days; if we need longer (up to another 45 days) we will tell you why. If we turn down a request, you can reply to ask us to reconsider, and we will answer that appeal within 45 days. If you are still not satisfied, you can contact the attorney general of the state where you live.
13. California notice
If you live in California, the California Consumer Privacy Act gives you the rights in section 12 and requires us to describe the personal information we have collected in the last 12 months. The table below does that. We have not sold or shared any of it. The only sensitive personal information we collect is the precise location of the catches and sessions you log, which we use only to provide the service you ask for.
| Category | Examples | Source | Why | Disclosed to |
|---|---|---|---|---|
| Identifiers | Name, email address, username, Google account identifier, IP address, account and customer IDs | You, Google (if you sign in with Google), your device | Running your account, signing you in, billing, security, support | Hosting, email, payments, error monitoring and analytics providers |
| Commercial information | Subscription status and dates, payment events, card type and last four digits | You, Stripe | Taking payment, managing your subscription, tax and accounting records | Stripe |
| Internet or other electronic network activity | Pages viewed, features used, device and browser type, error reports | Your device | Measuring use of the site, fixing errors, preventing abuse | Hosting, error monitoring and analytics providers |
| Geolocation data | The spot or pin you log a catch or session at, the GPS position embedded in a photo (read and then removed) | You, your photos | Placing your catches and sessions, suggesting the nearest spot, the location you choose to show publicly | Hosting provider; the precision you choose is public |
| Audio, electronic or visual information | Catch photos and your avatar | You | Showing your catches and profile; species identification when you ask for it | Hosting and storage providers; OpenAI for species identification |
| Content you post and your preferences | Catches, trip plans, reports, comments, bio, saved spots, alert and forecast settings | You | Providing the service; aggregated catch statistics | Hosting provider; public content is visible to everyone |
How long we keep each kind of information is set out in section 9. California's "Shine the Light" law lets you ask whether we disclosed personal information to third parties for their own direct marketing; we do not.
14. Security
Everything is served over HTTPS. Sign-in links and codes are single-use and short-lived, and we hold no passwords that could leak. Card details never touch our servers. Uploaded images are re-encoded so they cannot carry hidden payloads or metadata, and free-text fields reject markup. Access to production systems is limited to the people who run the service. No system is perfectly secure, so if we learn of a breach that affects your personal information we will tell you as the law requires.
15. Children
The service is not aimed at children and you must be at least 16 to hold an account. We do not knowingly collect personal information from children under 13, or from anyone under 16 who has created an account. If you believe a child has created an account, email us and we will delete it. Photos of children in someone else's catch should only be posted with a parent's permission, and we will remove any that are reported to us.
16. Changes to this policy
We will update this policy when we add a feature that uses information in a new way, change a provider or the law changes. The date at the top shows the current version. For a material change we will tell you by email or with a notice on the site before it takes effect.
17. Contact
Questions, requests and complaints about your personal information go to [email protected] or through the contact page.
