Privacy Policy
Last updated: September 10, 2026
1. Who we are
On The Fish ("we", "us", "our") is operated by Codaro Pty Ltd (ABN 68 682 118 529, ACN 682 118 529) and provides a platform for anglers to log catches, identify fish using AI, see general catch limits based on fishing location, view species eating guides, map fishing locations, create or join groups, and share moments with mates. We also operate a moderation programme, an optional affiliate programme, paid Pro subscriptions, and, where offered, a paid download of our native iOS app on the Apple App Store. You can use the service on the web at www.onthefish.app and in our native iOS app (App Store and TestFlight builds). The same account works across both. This policy explains what data we collect, how we use it, and your rights.
Contact: support@onthefish.app
2. Information we collect
- Account data: email, display name, username, avatar, password (hashed), onboarding preferences (such as fishing interests), and optional profile location.
- Catch data: photos, videos, species, notes, lure or bait, weather, date, and geolocation you choose to log, including GPS coordinates embedded in photo metadata (EXIF) when present, or a location you set manually on the map.
- Regulatory and eating information: when you identify a fish, we associate the identified species with general catch limit text for the jurisdiction inferred from your location, and species level eating quality information. These are stored in our database (including shared caches keyed by species and jurisdiction, not by individual user).
- Species descriptions: optional text summaries about species (including content fetched from Wikipedia and stored with attribution).
- Social and group data: mates (accepted friendships), groups you create or join, group names, descriptions, photos or videos, group invitations, group comments, catch sharing choices, reactions, and in-app notifications shown on the relevant dashboard tiles (for example comments on your catches appear under My Catches).
- Competition data: entries you submit (linked catch photos, consent confirmations, minor-safety confirmations, and timestamps), votes you cast in people's-choice competitions, competition-related notifications, and, if you win, information published in public results (which may include a location-redacted version of your winning catch).
- Feedback data: support threads you create, messages and optional image attachments, read/unread status, and admin replies (including push or in-app notifications when we respond).
- AI improvement feedback (optional): if you report that a species identification was wrong, we may store your catch reference, the AI suggestions shown, and your correction for moderator review and product improvement.
- Moderation data: content reports you submit (category, details, and the reported item), moderation actions taken on content or accounts, and account moderation status (such as suspended).
- Referral and billing data: subscription status, Pro plan expiry, Stripe customer and subscription identifiers, billing email, and, if you use a promotion or tracking code at checkout, which code was applied so we can attribute the signup for affiliate commissions. Payment card numbers for web subscriptions are collected and processed by Stripe; we do not store your full card details on our servers. If you purchase our iOS app as a paid download on the Apple App Store, Apple processes that payment; we receive purchase-related information from Apple as needed to provide the app (such as transaction status), not your full payment card details.
- Affiliate programme data (enrolled affiliates only): contact email, display name, tracking codes, redemption counts, commission records, payout history, and terms-acceptance records. Affiliates see aggregated signup and earnings data, not the personal profiles of individual customers who used their codes.
- Sign-in data: if you use Google, Sign in with Apple, or another supported OAuth provider, we receive basic profile information from that provider (such as email and name) according to your provider settings. Apple may process authentication data under its own privacy policy when you use Sign in with Apple.
- Technical and diagnostic data: device type, app or browser version, IP address, API usage, rate-limit counters, security and abuse-prevention logs, and, when you hit a blocking error in the web app or iOS app, details we log to help our team investigate (such as your user id, email, screen or page route, error message, API path, status code, client platform details, and optional stack trace).
- Push notifications (when enabled): on iOS, your device push token (via Apple Push Notification service, APNs), platform (iOS), app version, and related delivery metadata. Notifications are delivered through our infrastructure (including Amazon Web Services and SNS) when you opt in on a supported device.
- Native app storage (iOS): authentication tokens, cached catch data, and similar on-device storage needed for offline or faster access. This is not browser cookie storage; see section 2 above and our Cookie Policy (web only).
- Bot protection (sign in / sign up): we use Cloudflare Turnstile on email based authentication to reduce automated abuse; Cloudflare may process minimal technical data needed to run the challenge.
- Product analytics (web, with your consent): if you accept analytics cookies, PostHog may receive a user id, email, display name, pages viewed, in-app actions such as logging a catch, automatically captured interactions such as clicks on buttons and links, and error details. Google Analytics 4 may also receive pages viewed, device and browser information, approximate location derived from IP, and referral or campaign parameters. This does not apply to the native iOS app unless we add it later.
- Advertising and campaign measurement (web, with your consent): if you accept advertising cookies, the Meta Pixel loads and Meta Platforms receives page-view and event data linked to Meta's own identifiers, so we can measure our ad campaigns and show On The Fish ads on Facebook and Instagram. This does not apply to the native iOS app.
- Visit and campaign attribution: a first-party visit id and attribution id stored in your browser, the pages you visit, the referring website, your user agent, and any UTM or campaign parameters in the link you arrived on. Page-view attribution runs only if you accept analytics cookies; where a signup is linked to an affiliate's referral code we record that attribution regardless, because it is needed to pay commissions.
- Cookies and browser storage: authentication session storage, preference storage (for example theme and stay-signed-in choices), queued diagnostic reports, media crop-position preferences, and similar local app state. See our Cookie Policy.
3. How we use your data
- To operate the service: store your catches, show your map, connect you with mates, and send in-app notifications.
- To operate groups, including group membership, invitations, group media galleries, group comments, and catches shared with selected groups.
- To identify fish species using AI based on photos you upload.
- To infer fishing jurisdiction from photo GPS or your chosen location, and to show general catch limit information for that species and area.
- To provide species eating quality guides (ratings and preparation notes) linked to identified species.
- To fetch and display species description summaries (including from Wikipedia where you or we request them).
- To cache jurisdiction, catch limit, and eating information so repeat lookups are faster for all users.
- To provide paid Pro features, process subscriptions, attribute promotion-code signups to affiliates, calculate commissions, prevent fraud, and respond to billing enquiries.
- To operate moderation: review reports, hide or remove content, and suspend accounts that breach our terms.
- To send essential account emails (verification, password reset, security alerts, and affiliate onboarding where applicable).
- To operate competitions, including entries, voting, winner publication, related notifications, and promotional use of entries as described in our Terms of Service.
- To handle feedback and support requests you send us through the app.
- To deliver push notifications you have enabled on supported devices.
- To understand how the website is used and to improve it (PostHog and Google Analytics 4 on the web, if you accept analytics cookies).
- To measure and target our advertising, including measuring which campaigns lead to signups and showing our ads on Meta platforms (if you accept advertising cookies).
- To attribute signups to affiliate referral codes so we can calculate and pay commissions.
- To improve the product, diagnose errors, debug issues, and prevent abuse.
4. Privacy controls for catches
Every catch has a visibility setting: Private, Friends, or Public. You can also share a catch with selected groups that you belong to. Group members can see catches shared with their group. You can also hide the exact fishing spot at any time. You remain in control of what you share, and you can change or delete any catch, except that entering a competition grants the marketing licence in our Terms of Service, which continues after withdrawal or account deletion for promotional use already granted. Notifications about your catches, mates, groups, and competitions appear on the relevant parts of the app, not in a separate public feed.
5. Sharing with third parties
We do not sell your personal data. We share limited data with service providers that help us run the platform, including:
- Hosting, database, authentication, and file storage (including Supabase and Amazon Web Services).
- Email delivery for account and affiliate messages (Zoho Mail SMTP).
- AI model providers used to identify species and generate catch limit text, eating guides, and related descriptions (including Amazon Bedrock and, when configured, OpenAI or Google Gemini via Vertex AI).
- OpenStreetMap Nominatim for reverse geocoding when we need to resolve coordinates to a country or region (latitude and longitude are sent on cache miss; results are cached to reduce repeat lookups). See Nominatim usage policy.
- Wikipedia when you request a species summary (species name is sent to the Wikipedia API; we store the summary and attribution in our database). Wikipedia content is licensed under CC BY-SA 4.0.
- Stripe for payment processing and subscription management. Stripe receives the information needed to process your payment (such as email, billing details, and card information you enter at checkout). See Stripe's Privacy Policy.
- Apple when you download our paid iOS app from the App Store, use Sign in with Apple, or receive push notifications on iOS (APNs), subject to Apple's Privacy Policy.
- Google for optional sign-in (OAuth) and, if you accept analytics cookies, Google Analytics 4 on the website (page views and related measurement). See Google's Privacy Policy.
- Cloudflare for Turnstile bot protection on authentication flows.
- PostHog for product analytics on the website (page views, feature usage, and error tracking), loaded only if you accept analytics cookies. Data is processed in PostHog's European Union region. See PostHog's Privacy Policy.
- Meta Platforms (Facebook and Instagram) for advertising measurement and retargeting through the Meta Pixel, loaded only if you accept advertising cookies. Meta acts as an independent controller for its own advertising purposes. See Meta's Privacy Policy.
These providers are bound by contract or their own policies to protect your data and use it only to provide services to us.
6. Overseas recipients
We are an Australian company and our primary infrastructure is hosted in Australia (ap-southeast-2). Some of the providers above process data outside Australia, so using On The Fish involves disclosing personal information overseas:
- PostHog: European Union (Germany), for web product analytics.
- Google: United States and other countries where Google operates, for Google Analytics 4.
- Meta Platforms: United States and other countries where Meta operates, for advertising measurement.
- Stripe: United States and other countries where Stripe operates, for payments.
- Supabase and Amazon Web Services: primarily Australia, with some control-plane and support functions handled in the United States.
- Apple, Google, Cloudflare, Zoho, OpenStreetMap, and Wikipedia: United States, the European Union, and other countries, depending on the service.
We take reasonable steps to ensure these recipients handle your information consistently with Australian privacy law and their own obligations, including the GDPR where it applies.
7. Data retention
We keep your account, catch, group membership, and user-generated group data for as long as your account is active or as needed to provide the service. If you delete your account, your profile, catches, photos, and videos are removed or dissociated where deletion would affect other users' group content. Some logs and diagnostic reports may be retained for a limited period for security, reliability, legal, and abuse-prevention reasons. Species level catch limits, eating guides, and jurisdiction geocode caches may remain after account deletion because they are not tied to your personal account and may be reused to serve other users.
Billing, referral attribution, commission, and transaction records (such as subscription history, promotion codes used, and Stripe identifiers) may be kept for longer where required for tax, accounting, fraud prevention, affiliate payouts, or legal obligations, even after you delete your account or cancel a subscription.
Analytics and advertising data is kept on the provider's standard retention schedule: PostHog analytics events and person profiles for up to 12 months of inactivity, Google Analytics 4 event data for up to 14 months with Google identifiers lasting up to 2 years, and Meta Pixel identifiers for up to 90 days. Our own visit and attribution records are kept while they remain useful for measuring campaigns and paying affiliate commissions.
8. Cookies, analytics, and your choices
On the website, analytics and advertising cookies are switched off until you accept them. When you first visit we ask for your choice, and nothing beyond strictly necessary and preference storage is set until you accept. You can change or withdraw your choice at any time through Cookie Settings in the footer of any page, which stops further analytics and advertising collection. Full detail of each category is in our Cookie Policy.
9. Your rights
Depending on where you live, you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise most of these rights directly in the app, or by contacting us. For payment data held by Stripe, you may also contact Stripe or use the billing tools in your account. If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your local data protection authority; in Australia, you may complain to the Office of the Australian Information Commissioner.
10. Security
We use industry standard safeguards including encryption in transit, row level security on our database, scoped storage permissions, server-side validation, request size limits, rate limits for AI and other sensitive endpoints, role-based admin access, and moderation tools. Card payments are handled by Stripe using PCI compliant infrastructure. No system is perfectly secure, so please use a strong, unique password.
11. Children
On The Fish is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect data from children. Paid subscriptions must not be purchased by anyone who is not old enough to enter a binding contract in their jurisdiction.
12. Changes to this policy
We may update this policy from time to time. Material changes will be highlighted in the app or by email. The "Last updated" date at the top reflects the most recent revision.
13. Contact
Questions about privacy or billing data? Email support@onthefish.app.
Codaro Pty Ltd
ABN 68 682 118 529 · ACN 682 118 529
