CatchID Privacy Policy

Original policy effective date: July 14, 2026

Last updated: September 18, 2026

App name: CatchID

Package: com.catchid.app

Developer/operator: Pete Colley

Privacy contact: colley.apps@gmail.com

1. Overview

CatchID helps users identify fish from photographs and keep a personal catch log on their Android device.

When you ask CatchID to identify a fish, the app sends the selected or newly captured photograph to the CatchID backend so the identification request can be processed. CatchID also lets you save catch details locally in the app, such as the photo, species result, date, location text, bait, and weight.

You can record catches and use your CatchID journal on your device without signing in. Identification and adding a photo are optional. If you choose Journal Protection, CatchID uses Google sign-in and Firebase to back up your journal and catch photos and make protected data available to restore with the same Google account. Backup requires a working connection and successful completion; pending changes are not yet backed up.

Fish identifications are suggestions and can be wrong.

2. Information You Choose to Provide

Fish Identification Photographs

When you request an identification, a user-selected or newly captured photograph is sent securely to the CatchID backend. The backend sends the image and the instructions needed for identification to the OpenAI API so that CatchID can provide the requested result.

The current backend code processes uploaded images for the request and does not write uploaded images to a CatchID database, upload folder, or file-storage service after the request completes. CatchID explicitly sends store: false on OpenAI Responses API requests, does not use background responses or persistent OpenAI objects, and does not store or log OpenAI response IDs. OpenAI standard abuse-monitoring records may still remain for up to 30 days, subject to legal and security exceptions.

CatchID application logs are designed not to include photographs, Base64 image data, prompts, or raw OpenAI provider responses.

Saved Catch Information

If you save a catch, CatchID stores the catch record locally on your device in app-private storage. A saved catch record may include:

  • a generated catch ID;
  • the local photo URI used by the app;
  • the creation timestamp;
  • location text entered by you;
  • bait, lure, or fly text entered by you;
  • weight value and weight unit entered by you;
  • species name, if one is saved;
  • identification source;
  • confidence label;
  • a local synced flag.

Journal Protection account and backup data

When you enable Journal Protection, Google and Firebase process your sign-in information, including your account identifier and the email address supplied by Google. CatchID associates your protected journal with a Firebase user identifier; it does not separately copy a Google display name or profile photograph into the journal. Google and Firebase may process provider profile information as part of sign-in. Firebase stores the catch details you save, including dates, species, locations you enter, bait, methods, weights and identification details, together with identifiers and information needed to process changes. Catch photos are stored as processed copies. Device-local photo addresses are not included in the journal backup.

We use this information to authenticate you and back up and restore your journal and photos. Cloud journal records and photos are restricted to the authenticated owner by access rules. They are not a public catch feed. The operator and service providers may access data where necessary to administer the service, provide support, handle deletion requests or meet legal obligations. Transfers use encrypted connections. Backup is not end-to-end encrypted against the service operator.

Sharing and Feedback

If you use Android sharing from CatchID, the app creates a share card and opens the Android share sheet. The content is sent only to the app or service you choose. CatchID does not automatically send shared catch cards to the CatchID backend.

If you report a wrong result, CatchID opens an email draft in your chosen email app addressed to CatchID support. The draft may include result details and app version information so you can send feedback. You decide whether to send the email and whether to attach or include any photo.

3. Technical and Diagnostic Information

The CatchID backend handles technical metadata needed to operate and troubleshoot the identification service, such as a per-request correlation ID, app version and build number, request outcome, response status, request duration, provider and model name, and safe error information.

CatchID backend logs are designed not to include photographs, Base64 image data, exact catch locations, catch notes, bait or other free text, email addresses, API credentials, prompts, raw provider responses, raw request bodies, tokens, or stack traces containing sensitive data.

4. Firebase Analytics

CatchID uses Firebase Analytics to understand bounded app usage and feature reliability. Firebase Analytics collection is enabled in release builds.

CatchID deliberately sends only typed, bounded app events and parameters, such as identification started, identification completed, identification failed, result viewed, identify-another selected, save-catch selected, catch editing/deletion/sharing, journal migration and verification outcomes, and insights screen usage.

CatchID does not deliberately send fish species names, photographs, image URIs, exact catch locations, bait, weight, notes, email addresses, prompts, raw provider responses, tokens, API keys, arbitrary user identifiers, Firebase user IDs, or Firebase user properties to Firebase Analytics.

Firebase Analytics may also automatically process app, device, session, approximate geography, and app-instance information as described by Google. CatchID disables advertising ID collection and ad-personalisation signals in the app manifest and does not use Firebase Analytics for advertising or ad personalisation.

5. Firebase Crashlytics

CatchID uses Firebase Crashlytics to receive crash and non-fatal diagnostic reports. Crashlytics collection is enabled in release builds.

Crashlytics may collect crash stack traces, relevant application state, device/app metadata, a Crashlytics installation UUID, Firebase installation information, Firebase Sessions quality metadata, and Analytics breadcrumb logs where applicable.

CatchID's developer-defined Crashlytics custom keys are limited to bounded diagnostic values: operation, error category, failure stage, safe code, local correlation ID where applicable, backend correlation ID where applicable, app version, and app build.

CatchID does not deliberately attach photographs, image URIs, species names, exact catch locations, bait, weight, notes, prompts, raw provider responses, request bodies, tokens, API keys, Firebase user IDs, Firebase user properties, or arbitrary exception messages as Crashlytics custom keys.

6. Why Information Is Used

  • providing fish identification requested by you;
  • saving and displaying your personal catch journal locally on your device;
  • authenticating you and backing up and restoring your journal and photos when you choose Journal Protection;
  • letting you share a catch card or send feedback when you choose to do so;
  • maintaining security and reliability;
  • diagnosing technical failures;
  • understanding bounded app usage and app health;
  • preventing abuse and managing service performance.

CatchID does not sell personal data and does not use collected data for advertising or ad personalisation.

7. Service Providers

Render

Render hosts the CatchID backend in Virginia, US East. The backend receives identification requests, calls OpenAI, returns identification results, and writes privacy-safe operational logs. The Render workspace plan is Hobby, the service instance is Free, dashboard logs are retained for 7 days, and no external Render log or metrics streams are configured.

OpenAI

The CatchID backend uses the OpenAI API to process identification images and request content on behalf of CatchID. The OpenAI API key is kept on the backend and is not included in the Android app. OpenAI model-feedback sharing, evaluation/fine-tuning sharing, and API input/output sharing are disabled for CatchID. CatchID explicitly sends store: false on OpenAI Responses API requests and does not claim Zero Data Retention. Standard abuse-monitoring records may still remain for up to 30 days, subject to legal and security exceptions.

Firebase / Google

CatchID uses Firebase Authentication for optional Google sign-in, Cloud Firestore for protected journal records, and Cloud Storage for catch-photo backup and restore. CatchID also uses Firebase Analytics and Firebase Crashlytics for bounded analytics and diagnostics. Firebase processes the account, backup and SDK information needed to provide these services.

Android Platform and Selected Apps

CatchID uses Android system features such as the camera, document picker, app-private storage, browser intent for the privacy policy, email intent for feedback, and share sheet for sharing. If you choose a third-party app from Android's share sheet or email chooser, that app handles the content under its own terms and privacy policy.

8. Data Retention

Your local journal remains on your device until you remove it or Android removes the app data. Clearing app storage or uninstalling CatchID does not delete an existing protected cloud journal. Deleting a protected catch removes it from the journal and queues deletion of its cloud content and photo; the cloud change requires a successful connection. Minimal deletion markers and change receipts remain to prevent an older device or delayed retry from restoring a deleted catch. These records retain identifiers and revision information rather than the deleted catch details or photo. Account-wide deletion is a separate request.

CatchID keeps app-private copies of journal photos, including photos selected from a gallery or taken with the camera. Gallery originals remain controlled by your selected gallery or document provider. Share-card images are generated in the app cache.

Deleted backup photos may remain recoverable to authorized service administrators for seven days from deletion under the current Cloud Storage soft-delete policy. They cannot be permanently purged during that period. This seven-day period begins at object deletion and is separate from active removal and the time needed to verify and fulfil your request. An expected expiry date does not mean that expiry has already been observed. We do not restore those photos as part of normal service after an account-deletion request. Other provider records may have separately disclosed retention requirements; account removal is not a claim that every provider copy disappears immediately.

Render Hobby dashboard logs are retained for 7 days and are intended to contain privacy-safe operational metadata only. No external Render log or metrics streams are configured.

CatchID sends store: false on OpenAI Responses API requests, but OpenAI standard abuse-monitoring records may still remain for up to 30 days, subject to legal and security exceptions.

Firebase Analytics and Crashlytics data retention is controlled through Firebase/Google settings and service behaviour.

9. Deletion and User Control

You can delete individual catches inside CatchID. You can also remove CatchID's locally stored data using Android's application storage controls.

To request deletion of your CatchID sign-in account and its protected journal and photos, use Request account and cloud-data deletion in About & Support or email colley.apps@gmail.com from the Google email address used for Journal Protection, with the subject CatchID account and cloud-data deletion. You do not need to reinstall CatchID to send a request. We will send a confirmation message to the email address registered for Journal Protection and ask you to reply confirming the request. If you cannot access that address, contact us so we can assess how to verify ownership. Do not send passwords, sign-in or verification codes, tokens or photographs.

After verifying ownership, we stop the CatchID account from accessing its protected cloud data and remove its sign-in account, cloud catch records, photos, deletion markers and change receipts. We check the result before confirming active account and cloud-data removal. We separately explain any retained records, why they remain and when their retention is expected to end. A minimal account-erasure security record may be needed to prevent old sessions or uploads from restoring erased data; it does not contain your catch details or photos.

We aim to acknowledge deletion requests within three working days and normally complete removal of the active CatchID account and protected cloud journal within seven calendar days after verifying ownership. We confirm completion after checking the result. If we need further information or more time, we will explain why and respond within the applicable legal deadline.

We normally delete routine deletion-request correspondence 90 days after closing the request. We retain a minimal record of the request and its outcome for 12 months to demonstrate how it was handled. That record does not contain your catch details or photographs. Specific unresolved complaints or legal obligations may require limited information to be retained longer; we document the reason and review its continued necessity.

We may retain a minimal account-blocking record to prevent erased data from being recreated by old account sessions or delayed operations. We review its necessity after 30 days and at least every 90 days thereafter, and remove it when it is no longer needed.

The 12-month period starts when the request is closed. The first account-block review is 30 days after completed erasure; this is a necessity review, not an automatic deletion date. The block is separate from the completion record and contains no catch details or photos. These operator-record periods do not set the retention periods for separate provider logs, Analytics or Crashlytics records.

A CatchID deletion request does not delete your Google account, gallery originals or copies held only on your devices. Previously connected devices may still show local catches and pending work; account deletion does not remotely clear them. To remove local CatchID data and queued work, use Android Settings to clear CatchID's app storage on each device, or uninstall it. These local steps do not delete cloud backups and are not required to submit a cloud-deletion request. Photos and copies in a gallery, email app or share destination must be managed there. Creating another CatchID account is separate; an existing journal is not automatically moved to it.

See the CatchID Data Deletion page for request information.

For other data processed outside your device, email colley.apps@gmail.com, describe the data or activity and give an approximate date. Do not send unnecessary sensitive content. We assess records we and our service providers can identify, request applicable provider deletion and explain any verified retention limits.

10. Security

CatchID uses HTTPS/TLS for identification requests to the backend. The backend calls OpenAI over HTTPS. Firebase states that listed Firebase Android SDK end-user data is encrypted in transit using HTTPS. API credentials are kept on the backend rather than in the Android app.

No system can be guaranteed completely secure.

11. Data Sharing

CatchID does not sell personal data.

CatchID provides information to service providers needed to operate the app, process identification requests, maintain reliability, prevent abuse, and meet legal obligations. These providers are not used by CatchID to independently market to users.

12. Children

CatchID is not specifically directed at children.

13. International Processing

Production journal records and backup photos are configured for storage in London (europe-west2). This does not mean all account, support, analytics, diagnostic or provider processing is confined to the UK. Service providers may process information in other countries under their contractual and legal safeguards.

14. Changes to This Policy

CatchID may update this policy when the app, service providers, data practices, or legal requirements change. The "Last updated" date will be changed when the policy is updated.

15. Contact

For privacy questions, contact:

Pete Colley
colley.apps@gmail.com