Waterlogged Fishing Journal — Privacy Policy
Effective date: August 1, 2026
Waterlogged Fishing Journal (“Waterlogged,” “we,” “us”), operated by Christopher Kurtz, is a fishing-log app that helps you record catches and find conditions. We built it privacy-first: by default your data lives on your own device, your fishing spots are yours, and we don’t sell data or run ad tracking. This policy explains what we collect, how it’s used, and your choices.
- You can use Waterlogged without an account — your data stays on your device.
- If you create an account, your catches sync to private, per-user storage so they follow you across devices. Only you can see them.
- To show weather, tides, and water data, the app sends location coordinates to public data services (Open-Meteo, NOAA, USGS) from your device.
- We don’t sell your data, show ads, or use behavioral tracking.
- You can export or delete your data — including your whole account — at any time, in the app.
1. Information we collect
a. Data you create in the app
- Catch records: species, date and time, depth, notes, and the location (latitude/longitude) of a catch.
- Photos you add (and, if present, the time and GPS location stored in the photo’s EXIF data, which the app reads on your device to help fill in the catch).
- Environmental conditions attached to a catch (weather, tide, water temperature, salinity, barometric pressure, moon phase), retrieved for the catch’s time and place.
- Saved spots and free-text journal entries.
b. Account information (only if you create an account)
- Your email address and password, and an optional display name. Authentication is handled by our backend provider (Supabase); we never store your password in plain text.
- When you sign up or reset a password, we send the necessary emails through our email delivery provider (Resend), which processes your email address to deliver them. We send transactional email only (confirmations, password resets) — no marketing.
- During sign-in and sign-up, a Cloudflare Turnstile check helps block bots; it sends limited device and browser signals to Cloudflare to tell humans from automated abuse. It does not track you across sites.
c. Information collected automatically
- Minimal technical data needed to operate the app (e.g., your device’s network requests to our services and data sources include your IP address, as with any internet app). We do not run third-party analytics or advertising SDKs.
2. How your location is used — and who receives it
Location is the heart of a fishing log. The app uses your coordinates to record where a catch happened, power the on-device “hotspot” engine (which runs on your device), and fetch conditions for that point.
To fetch conditions, your device requests data from these services, which have their own privacy practices:
- Apple Weather (WeatherKit) — weather, forecasts, and minute-by-minute precipitation. These requests go through our own weather relay (hosted on Cloudflare), which passes along only the coordinates being queried — never your identity or account.
- Open-Meteo — backup weather and historical conditions (requested directly from your device)
- NOAA / National Ocean Service — tides and water temperature (directly)
- USGS — salinity, river flow, water temperature (directly)
Direct requests come from your device, so those services may receive your IP address and the coordinates being queried. We don’t control their data practices; please review their policies.
3. Where your data is stored
- On your device (default). Catches, photos, and spots are saved locally. If you never sign in, this information is not sent to us.
- In your account (if you sign in). Your data syncs to our backend provider, Supabase (hosted database and file storage). Every record is isolated to your account using row-level security, so other users cannot access it. Photos are kept in a private storage area accessible only to you.
- The app itself is delivered from Cloudflare infrastructure (hosting/CDN).
4. Spot location encryption
Waterlogged encrypts your spot coordinates on your device before they are saved to your account, using a key derived from your password and a one-time recovery phrase. Because of this, we cannot read your spot locations — not our staff, and not anyone who might gain access to the database. The trade-off: if you lose both your password and your recovery phrase, your encrypted spots cannot be recovered by anyone, including us. We provide a data-export option so you can keep your own backup.
5. How we use information
We use your information only to provide the app’s features (logging, syncing, conditions, hotspots), maintain your account and keep your data secure, send the transactional emails needed to operate your account, and diagnose problems and improve reliability. We do not use your information for advertising, and we do not sell or rent it.
6. Sharing
We share information only:
- with service providers that operate the app on our behalf, under obligations to protect it: Supabase (database, authentication, and photo storage), Cloudflare (site hosting/CDN and the Turnstile bot check), and Resend (delivery of account emails);
- with the public data services in Section 2, as needed to fetch conditions;
- if required by law (e.g., a valid legal request); or
- in connection with a business transfer (e.g., merger or acquisition), with notice to you.
7. Data retention and deletion
- You can delete any catch, spot, or journal entry in the app at any time.
- You can delete your account in the app (Settings → Account → “Delete my account…”), which permanently removes your account and all synced data — records and photos — from our backend. Data stored locally on your device stays on your device until you delete it there or uninstall the app.
- You can export your log (Settings → “Download my data”) to keep your own copy.
8. Security
We protect your data with encryption in transit (HTTPS/TLS), encryption at rest at our hosting provider, per-user access controls (row-level security), private photo storage, and — for spot coordinates — on-device end-to-end encryption (see Section 4). No method of storage or transmission is 100% secure, but we work to protect your information and limit what we can access.
9. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise most of these directly in the app; for anything else, contact us below. We do not sell personal information or use it for cross-context behavioral advertising (relevant to California/CCPA). We honor applicable rights under laws such as the CCPA and GDPR.
10. Children’s privacy
Waterlogged is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the app evolves. We’ll post the new version here and update the “Effective date.” Material changes will be communicated in the app where appropriate.
12. Contact us
Questions or requests: support@waterloggedfishing.com
Waterlogged Fishing Journal — Christopher Kurtz, Florida, United States.