CatchID Privacy Policy
1. Overview
CatchID helps users identify fish from photographs and keep a personal catch log on their Android device.
When you ask CatchID to identify a fish, the app sends the selected or newly captured photograph to the CatchID backend so the identification request can be processed. CatchID also lets you save catch details locally in the app, such as the photo, species result, date, location text, bait, and weight.
CatchID does not currently provide user accounts, cloud catch-history storage, subscriptions, or cross-device catch-log synchronisation.
2. Information You Choose to Provide
Fish Identification Photographs
When you request an identification, a user-selected or newly captured photograph is sent securely to the CatchID backend. The backend sends the image and the instructions needed for identification to the OpenAI API so that CatchID can provide the requested result.
The current backend code processes uploaded images for the request and does not write uploaded images to a CatchID database, upload folder, or file-storage service after the request completes. CatchID explicitly sends store: false on OpenAI Responses API requests, does not use background responses or persistent OpenAI objects, and does not store or log OpenAI response IDs. OpenAI standard abuse-monitoring records may still remain for up to 30 days, subject to legal and security exceptions.
CatchID application logs are designed not to include photographs, Base64 image data, prompts, or raw OpenAI provider responses.
Saved Catch Information
If you save a catch, CatchID stores the catch record locally on your device in app-private storage. A saved catch record may include:
- a generated catch ID;
- the local photo URI used by the app;
- the creation timestamp;
- location text entered by you;
- bait, lure, or fly text entered by you;
- weight value and weight unit entered by you;
- species name, if one is saved;
- identification source;
- confidence label;
- a local synced flag.
CatchID currently has no user account system, no cloud catch-history database, and no cross-device synchronisation. The operator cannot remotely view your locally saved catch log through a CatchID account or server-side catch database.
Sharing and Feedback
If you use Android sharing from CatchID, the app creates a share card and opens the Android share sheet. The content is sent only to the app or service you choose. CatchID does not automatically send shared catch cards to the CatchID backend.
If you report a wrong result, CatchID opens an email draft in your chosen email app addressed to CatchID support. The draft may include result details and app version information so you can send feedback. You decide whether to send the email and whether to attach or include any photo.
3. Technical and Diagnostic Information
The CatchID backend handles technical metadata needed to operate and troubleshoot the identification service, such as a per-request correlation ID, app version and build number, request outcome, response status, request duration, provider and model name, and safe error information.
CatchID backend logs are designed not to include photographs, Base64 image data, exact catch locations, catch notes, bait or other free text, email addresses, API credentials, prompts, raw provider responses, raw request bodies, tokens, or stack traces containing sensitive data.
4. Firebase Analytics
CatchID uses Firebase Analytics to understand bounded app usage and feature reliability. Firebase Analytics collection is enabled in release builds.
CatchID deliberately sends only typed, bounded app events and parameters, such as identification started, identification completed, identification failed, result viewed, identify-another selected, and save-catch selected.
CatchID does not deliberately send fish species names, photographs, image URIs, exact catch locations, bait, weight, notes, email addresses, prompts, raw provider responses, tokens, API keys, arbitrary user identifiers, Firebase user IDs, or Firebase user properties to Firebase Analytics.
Firebase Analytics may also automatically process app, device, session, approximate geography, and app-instance information as described by Google. CatchID disables advertising ID collection and ad-personalisation signals in the app manifest and does not use Firebase Analytics for advertising or ad personalisation.
5. Firebase Crashlytics
CatchID uses Firebase Crashlytics to receive crash and non-fatal diagnostic reports. Crashlytics collection is enabled in release builds.
Crashlytics may collect crash stack traces, relevant application state, device/app metadata, a Crashlytics installation UUID, Firebase installation information, Firebase Sessions quality metadata, and Analytics breadcrumb logs where applicable.
CatchID's developer-defined Crashlytics custom keys are limited to bounded diagnostic values: operation, error category, failure stage, safe code, local correlation ID where applicable, backend correlation ID where applicable, app version, and app build.
CatchID does not deliberately attach photographs, image URIs, species names, exact catch locations, bait, weight, notes, prompts, raw provider responses, request bodies, tokens, API keys, Firebase user IDs, Firebase user properties, or arbitrary exception messages as Crashlytics custom keys.
6. Why Information Is Used
- providing fish identification requested by you;
- saving and displaying your personal catch log locally on your device;
- letting you share a catch card or send feedback when you choose to do so;
- maintaining security and reliability;
- diagnosing technical failures;
- understanding bounded app usage and app health;
- preventing abuse and managing service performance.
CatchID does not sell personal data and does not use collected data for advertising or ad personalisation.
7. Service Providers
Render
Render hosts the CatchID backend in Virginia, US East. The backend receives identification requests, calls OpenAI, returns identification results, and writes privacy-safe operational logs. The Render workspace plan is Hobby, the service instance is Free, dashboard logs are retained for 7 days, and no external Render log or metrics streams are configured.
OpenAI
The CatchID backend uses the OpenAI API to process identification images and request content on behalf of CatchID. The OpenAI API key is kept on the backend and is not included in the Android app. OpenAI model-feedback sharing, evaluation/fine-tuning sharing, and API input/output sharing are disabled for CatchID. CatchID explicitly sends store: false on OpenAI Responses API requests and does not claim Zero Data Retention. Standard abuse-monitoring records may still remain for up to 30 days, subject to legal and security exceptions.
Firebase / Google
CatchID uses Firebase Analytics and Firebase Crashlytics for bounded analytics and diagnostics. Firebase may process automatic SDK data needed to provide these services.
Android Platform and Selected Apps
CatchID uses Android system features such as the camera, document picker, app-private storage, browser intent for the privacy policy, email intent for feedback, and share sheet for sharing. If you choose a third-party app from Android's share sheet or email chooser, that app handles the content under its own terms and privacy policy.
8. Data Retention
Saved catch records remain on your device until you delete them in CatchID, clear CatchID app data, uninstall the app, or Android otherwise removes the app data. CatchID does not maintain a server-side database of users' catch histories.
Camera photos captured through CatchID may remain in the app's private files area. Share-card images are generated in the app cache. Gallery photos remain controlled by your selected gallery or document provider; CatchID stores the URI string and retained permission where applicable.
Render Hobby dashboard logs are retained for 7 days and are intended to contain privacy-safe operational metadata only. No external Render log or metrics streams are configured.
CatchID sends store: false on OpenAI Responses API requests, but OpenAI standard abuse-monitoring records may still remain for up to 30 days, subject to legal and security exceptions.
Firebase Analytics and Crashlytics data retention is controlled through Firebase/Google settings and service behaviour.
9. Deletion and User Control
You can delete individual catches inside CatchID. You can also remove CatchID's locally stored data using Android's application storage controls.
CatchID currently has no user account to delete. Because catch records are stored locally on your device, the operator cannot remotely view or delete those records from your device.
You may contact colley.apps@gmail.com with privacy questions or deletion requests for data that CatchID or its service providers may process. Some provider records may be retained for security, abuse prevention, legal, or service-operation reasons, and CatchID cannot promise deletion outside its control where provider retention or legal requirements apply.
10. Security
CatchID uses HTTPS/TLS for identification requests to the backend. The backend calls OpenAI over HTTPS. Firebase states that listed Firebase Android SDK end-user data is encrypted in transit using HTTPS. API credentials are kept on the backend rather than in the Android app.
No system can be guaranteed completely secure.
11. Data Sharing
CatchID does not sell personal data.
CatchID provides information to service providers needed to operate the app, process identification requests, maintain reliability, prevent abuse, and meet legal obligations. These providers are not used by CatchID to independently market to users.
12. Children
CatchID is not specifically directed at children.
13. International Processing
CatchID's service providers may process information in countries outside your own country. Processing by those providers is subject to their contractual and legal safeguards. Specific provider processing regions have not all been confirmed.
14. Changes to This Policy
CatchID may update this policy when the app, service providers, data practices, or legal requirements change. The "Last updated" date will be changed when the policy is updated.
15. Contact
For privacy questions, contact:
Pete Colley
colley.apps@gmail.com