Effective date: 28 August 2026 Last updated: 28 August 2026
Fish Pilot ("the app") is provided by Devello ("we", "us"). We are the data controller for the personal data described in this policy.
Questions about this policy, or about your data: contact@devello.co.
This policy covers the Fish Pilot mobile application on iOS and Android, and the server-side services that support it. It does not cover websites, services or apps operated by anyone else, including the third parties listed in section 7 — each of those has its own privacy policy.
Fish Pilot creates an anonymous account the first time you open it. You can browse, get predictions, and log catches without providing an email address, a name, or any other identifying detail.
If you later choose to sign in with Google, Apple, or an email address and password, that anonymous account is upgraded in place — your existing catches and saved locations stay with you and are not lost.
Why: to give you an account that persists across sessions and devices, to sign you in, and to keep your data attached to you rather than to a device.
Your experience level, the types of water you fish, the species you are interested in (which you type yourself), the species you have saved as favourites, your home state, and your preferred units of measurement.
Why: to tailor what the app shows you. Providing these is optional — the onboarding questions can be skipped.
Fish Pilot uses your location to produce fishing predictions, to find nearby water bodies, and to show you the map.
Your location is used to request weather, nearby water bodies, and predictions. Those requests go through our servers, never directly from your phone to a third party.
When you log a catch, we store what you enter: species, date and time, the location, and optionally a photo, water body name, weight, length, bait, lure, method, personal notes, and the fishing conditions at the time.
This is stored privately to your account. Section 5 explains the only circumstances in which any of it becomes visible to other people, and exactly what is and is not included.
When you use the in-app fishing assistant, the text of your question is sent to Google's Gemini API, together with context assembled by our server: your coordinates, the current conditions, the current prediction for that spot, and your stated experience level and preferred species.
We do not store the text of your questions. Our server logs record only how long the question was, never what it said.
When you search for a place, the text you typed is sent to our geocoding provider so it can be matched against place names. Our server logs record only the length of the search, never the text.
If you subscribe, purchases are handled by the Apple App Store or Google Play. We never see or handle your card or payment details.
We use RevenueCat to manage subscriptions. Your account identifier is sent to RevenueCat, and RevenueCat tells us which products and entitlements are active on your account, and when they expire.
If you allow notifications, your device's push token, its platform (iOS or Android), and when it was last seen are stored so we can send you alerts. Notifications we have delivered are also kept in an in-app inbox.
We collect product analytics — a fixed, closed list of events describing how the app is used (screens viewed, onboarding steps completed, a purchase completed, a fish identification finishing, and similar). These events are deliberately built to carry no free text and no personal content. Your account identifier is attached to them.
We also collect crash reports — stack traces and device and operating system information — so we can fix faults. Your account identifier is attached to these too, so a crash can be traced to the account that experienced it.
We do not use any advertising SDK, we do not access your device's advertising identifier, and we do not show ads.
Your privacy preference settings are stored on your device only and are never sent to us.
This is the part worth reading closely.
By default, nothing. Every catch you log is private unless you decide otherwise, and the app's default for a new catch is the most private setting.
For each individual catch, you choose one of three levels:
| Your choice | What other people can see |
|---|---|
| Private (the default) | Nothing. No shared record exists at all. |
| Approximate | A version of the catch with the location deliberately blurred to a grid roughly 5.5 km across, so it shows the general area or water body, not the spot. |
| Public | The catch with its exact location. This is an explicit choice you make for that catch. |
For a catch shared at either level, what is published is a fixed list: species, date and time, the location at the precision you chose, water body name, weight, length, bait, lure, method, and the photograph.
Your personal notes are never published. They are excluded permanently and by design, because free text can contain an address, a companion's name, or a description of the exact spot, and no automated check could reliably tell.
Three further guarantees:
You can change a catch's privacy level at any time. Setting it back to private removes the shared version.
| Purpose | Legal basis |
|---|---|
| Providing the app, your account, and your catch log | Performance of a contract (Art. 6(1)(b)) |
| Location, predictions, fish identification, the assistant | Performance of a contract, and your consent for device location access (Art. 6(1)(a)/(b)) |
| Subscriptions and purchase records | Performance of a contract; legal obligation for records we must retain (Art. 6(1)(b)/(c)) |
| Analytics and crash reporting | Legitimate interests — understanding how the app is used and keeping it working (Art. 6(1)(f)) |
| Publishing a catch you chose to share | Your consent, given per catch (Art. 6(1)(a)) |
| Security, fraud prevention, and enforcing usage limits | Legitimate interests (Art. 6(1)(f)) |
We do not sell your personal data, and we do not share it with data brokers.
We use the following providers to run the app:
| Provider | What it receives | Why |
|---|---|---|
| Google Firebase | Your account, profile, catches, photos, notifications, analytics and crash reports | Authentication, database, file storage, server functions, push notifications, analytics, crash reporting |
| Google — Gemini API | Coordinates and conditions for a prediction; the text of an assistant question along with your stated preferences; a photograph for fish identification | Generating predictions, answering questions, identifying fish. We use the paid tier of the Gemini Developer API. Under Google's terms for that tier, the content we send — including your photographs and the text of your questions — is not used to train or improve Google's models. |
| RevenueCat | Your account identifier and purchase state | Managing subscriptions |
| Apple App Store / Google Play | Purchase transactions | Payment processing |
| Amplitude | Product analytics events and your account identifier | Product analytics. Only present in app builds where an Amplitude key was included at build time |
| Open-Meteo | A coordinate | Weather data |
| OpenStreetMap / Overpass | A coordinate | Finding nearby water bodies |
| OpenStreetMap Nominatim | The text of a place search | Converting place names to coordinates |
| Mapbox | Map tile requests and the map SDK's own usage telemetry, sent from your device | Rendering the map |
Your phone never contacts the weather, water body, geocoding or AI services directly. Those requests are made by our servers.
Other users of Fish Pilot can see catches you have chosen to share, as described in section 5.
We may also disclose data where we are legally required to, or to establish or defend legal claims.
Our providers operate globally, so your data may be processed outside your country, including in the United States.
You can delete your account from within the app. Deletion is permanent and removes:
your shared catches, your public catch photos, your original catch photos, your profile photo, your entire user record including your catch log and saved locations, your notification settings and push tokens, and finally your login credentials. If you signed in with Apple, your Apple sign-in token is revoked with Apple as the first step.
Two things to be aware of:
Depending on where you live, you may have the right to access the data we hold about you, correct it, delete it, restrict or object to its processing, receive a copy in a portable format, and withdraw a consent you previously gave.
If you are in California, you additionally have the right to know what personal information is collected, used and disclosed; to delete it; to correct it; and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioural advertising.
The fastest route to deletion is the in-app account deletion described in section 10. For anything else, contact us at contact@devello.co. You also have the right to complain to your local data protection authority.
Fish Pilot is not directed at children and is intended for adults. You must be at least 18 years old to use it. We do not knowingly collect data from anyone below that age. If you believe a child has provided us data, contact us and we will delete it.
Data is encrypted in transit. Access to your catch log, your photos and your account is restricted to you by server-side security rules, and requests to our servers are authenticated. No system is perfectly secure, but we take reasonable measures to protect your data.
Fish Pilot's fishing scores, species suggestions and fish identifications are estimates, not guarantees. The app is built to say so: it will not present a prediction as a certainty, and a fish identification is a suggestion for you to confirm or correct. Do not rely on it for safety decisions, and always check local regulations and licensing yourself.
We may update this policy. When we do, we will change the "last updated" date above, and for significant changes we will notify you in the app.