Privacy Policy
Effective as of 22 August 2026
This privacy policy is applicable to the I Saw a Fish app for mobile devices, together with any related services operated by Tomasz Ziębiński (collectively, the "Application"). Tomasz Ziębiński is hereinafter referred to as the "Service Provider". Your use of the Application is also governed by the Terms of Service.
Data Controller Information
Tomasz Ziębiński acts as the Data Controller responsible for the processing of your personal data.
- Name: Tomasz Ziebinski
- Address: Tyniecka 43/61, 30-323 Kraków, Poland
- Email: isawafishapp@gmail.com
For data protection inquiries and to exercise your GDPR rights, please contact the Data Controller using the contact information above.
What information does the Application obtain and how is it used?
The Application does not require a user account, and there is no registration or sign-in. The content you create in the Application — your dive logbooks and observations, the photos you add, your "bucket list", and your settings — is stored only locally on your device. The Service Provider operates no servers for this content and cannot access it.
The data that does leave your device is collected by third-party SDKs included in the Application (advertising, maps and billing), as described in the sections below. The Service Provider does not send marketing communications and does not collect your name, email address or contact details through the Application.
Legal basis for processing your personal data
Where the GDPR applies, the Service Provider relies on one or more lawful bases to process your personal data, including:
- Contract performance: processing necessary to provide the Application or fulfil a contract with you.
- Consent: where you have given explicit consent to processing, including for marketing, analytics, or optional features. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
- Legitimate interests: where processing is necessary for the Service Provider's specific legitimate interests, such as maintaining network and information security, preventing fraud and abuse, or improving the Application's core functionality through analytics, provided those interests are not overridden by your data protection rights or fundamental freedoms.
- Legal obligation: to comply with laws or government requests.
Cookies and similar technologies
The Application or its third-party SDKs may use cookies, SDKs, pixels, and similar technologies to support functionality, analytics, and service delivery. Where required by law, the Service Provider will obtain your consent before using non-essential tracking technologies.
Automated decision-making and profiling
The Service Provider does not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you. Any ad personalization is performed by Google as part of the advertising services described above, and is governed by Google's policies and your consent and ad-settings choices. Where automated decision-making or profiling applies, you have the right to request human review, express your point of view, and contest the decision, and to be informed of the logic involved where required by law.
What information does the Application collect automatically?
When the Application shows ads (the free version), the Google Mobile Ads SDK (AdMob) automatically collects and shares the following with Google for advertising, analytics and fraud prevention:
- Device and other identifiers — the Android advertising ID, the app set ID, and, if applicable, identifiers related to Google accounts signed in on the device;
- App activity — in-app interactions such as app launches, taps and ad views;
- App info and performance — diagnostic information such as app launch time, responsiveness and energy usage;
- IP address, which may be used to estimate your approximate (coarse, city-level) location.
This data is collected by the Google Mobile Ads SDK and shared with Google; Google acts as an independent controller for this advertising data. The advertising ID is resettable and can be deleted by you (see "What are my opt-out rights?" below). The Application's own code does not read your device ID, account identifiers or contacts.
Does the Application collect precise real time location information of the device?
Location permission is optional — you can decline it and still use the Application. If you grant it, your device's precise location is used only for the following features:
- Dive geotagging: you can attach your current (or a chosen) location to a dive logbook. The coordinates are stored locally on your device and are not sent to the Service Provider.
- "Locate me" search: your location is used to match your area to a marine region. This is processed on your device and is not stored.
When you view a map, the Google Maps SDK sends map-viewport information to Google to render the map (see the Google Maps section below). Separately, the advertising SDK may estimate your approximate location from your IP address, as described above.
Does the Application use Artificial Intelligence (AI) technologies?
The Application does not use Artificial Intelligence (AI) technologies to process your data or provide features.
Advertising and your consent
The free version of the Application displays ads through Google AdMob. Where required by law, the Application uses Google's User Messaging Platform (UMP) to present your privacy choices, which you can revisit at any time via Options → Manage privacy choices in the Application:
- European Economic Area, United Kingdom and Switzerland: you are asked to consent before personalized-advertising data is processed. If you do not consent, the Application does not show ads.
- Certain U.S. states: you can opt out of the sale or sharing of your personal information for targeted advertising. In this case ads are still shown, but are non-personalized.
Separately, resetting or deleting your advertising ID and opting out of ad personalization (in your device's Android ad settings and via Google My Ad Center) makes the ads you see non-personalized
Subscriptions (Google Play Billing)
The optional Premium subscription is processed entirely by Google Play's billing system. The Service Provider never receives or stores your payment details (such as card numbers). The Application only checks with Google Play whether you currently hold an active subscription, in order to unlock Premium features and remove ads.
In-app announcements
The Application periodically downloads a small public announcement file from a third-party host (GitHub) to display occasional notices. This is a one-way download — no personal data about you is sent. As with any internet request, the host receives your device's IP address as part of delivering the file; it is not used by the Service Provider to identify, track, or locate you.
Do third parties see and/or have access to information obtained by the Application?
The Application includes third-party SDKs that receive data directly:
- Google AdMob — receives the identifiers, app-activity, diagnostic and IP information described above and acts as an independent controller of that data for advertising, analytics and fraud prevention.
- Google Maps Platform and Google Play Billing — act as service providers, processing data (map viewport, subscription status) to deliver the mapping and billing functions you request.
- GitHub (the host of the in-app announcement file) — when the Application downloads that file, GitHub receives your device's IP address as part of delivering it, as with any internet request. No other data is sent.
The Service Provider does not sell your data and does not transmit your on-device content (logbooks, observations, photos) to any third party. The Service Provider may disclose information:
- as required by law, such as to comply with a subpoena, or similar legal process;
- when they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request;
- with their trusted services providers who work on their behalf, do not have an independent use of the information the Service Provider discloses to them, and have agreed to adhere to the rules set forth in this privacy statement.
Where the GDPR applies, the Service Provider enters into Data Processing Agreements (DPAs) with third-party service providers that process personal data on its behalf, as required by Article 28 of the GDPR. These DPAs impose the same data protection obligations on those service providers as described in this Privacy Policy.
International Data Transfers
The Service Provider or its third-party service providers may transfer personal data outside the European Economic Area (EEA). Where such transfers occur, the Service Provider will use an appropriate transfer mechanism required by GDPR Chapter V:
- Adequacy decisions by the European Commission
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Other safeguards or derogations recognized under GDPR Chapter V, including consent where legally permitted
Countries outside the EEA may not provide the same level of data protection as the EEA. Where required by law, the Service Provider will apply appropriate safeguards and obtain any consent required for the transfer.
Please note that the Application utilizes third-party services that have their own Privacy Policy about handling data. The third-party services used by the Application are Google Play Services, Google AdMob, Google Maps Platform and Google Play Billing. Their data handling is governed by:
What are my opt-out rights?
You have several controls:
- Uninstall the Application to stop all further data collection and remove the content stored on your device.
- Withdraw advertising consent (where the consent prompt applies) via Options → Manage privacy choices in the Application.
- Reset or delete your advertising ID and opt out of ad personalization in Android Settings → Google → Ads, and via Google My Ad Center.
- Deny or revoke the location permission in your device settings.
The Service Provider stores none of your personal content on its own servers, so there is no server-side copy to delete. For questions or to exercise your rights, contact the Service Provider at isawafishapp@gmail.com.
What is the data retention policy and how can you manage your information?
The Service Provider does not store any of your personal data on its own servers. Retention works as follows:
- Your on-device content (logbooks, observations, photos, settings): retained on your device until you delete it within the Application or uninstall the Application.
- Advertising data collected by AdMob: retained by Google in accordance with Google's policies.
- Subscription status: held by Google Play.
If you enable Android Auto Backup, Android may back up the Application database (excluding your photos) to your own Google Drive under your Google account's terms; the Service Provider cannot access it. Because the Service Provider holds no personal data of yours, deletion is performed through the on-device and Google/Android controls described in "What are my opt-out rights?". For any questions, contact isawafishapp@gmail.com.
How does the Application address children's privacy?
The Application is not directed to children under 13 years of age. The Service Provider does not knowingly collect personal information from children under 13, and does not solicit data from children or market the Application to them.
In the European Economic Area and the United Kingdom, the age of digital consent ranges from 13 to 16 depending on the country. Where the applicable local age is higher than 13, the Application should be used by a child below that age only with the consent of a holder of parental responsibility.
The Service Provider stores no personal data of yours on its own servers. If you are a parent or guardian and you believe a child has provided personal information without the required consent, please contact the Service Provider at isawafishapp@gmail.com and the Service Provider will take the necessary actions, including deleting any such data within its control.
How is your information kept secure?
Your content is kept in the Application's private, sandboxed storage on your device, which is not accessible to other apps. Data transmitted by the Application's third-party SDKs (advertising, maps, billing) is encrypted in transit using TLS. Because the Service Provider operates no servers for your personal content, there is no server-side store of it to be breached. However, no method of electronic storage or transmission can be guaranteed to be completely secure.
Data Breach Notification
The Service Provider does not store your personal data on its own servers, which limits the risk of a breach on its side. Should the Service Provider nonetheless become aware of a personal data breach that poses a risk to your rights and freedoms, it will notify the relevant supervisory authority within 72 hours, and, where the breach is likely to result in a high risk to your rights and freedoms, will notify you without undue delay, as required by applicable law. Breaches affecting data held by third-party providers (such as Google) are handled by those providers under their own policies.
How will you be informed of changes to this Privacy Policy?
The Service Provider may update this Privacy Policy from time to time. The Service Provider will notify you of material changes by posting the updated Privacy Policy with an effective date. Where required by law, the Service Provider will seek your consent to material changes before they take effect.
Previous versions of this Privacy Policy will be maintained and made available upon request by contacting the Service Provider at isawafishapp@gmail.com.
What are your GDPR data protection rights?
Under the GDPR, you have the following rights:
- Right of Access: You can request access to your personal data.
- Right to Rectification: You can request correction of inaccurate data.
- Right to Erasure: You can request deletion of your personal data (the "right to be forgotten").
- Right to Restrict Processing: You can request that the Data Controller limits how they use your data.
- Right to Data Portability: You can request a copy of your data in a structured, commonly used, machine-readable format.
- Right to Object: You can object to processing based on legitimate interests. You have an absolute right to object to processing for direct marketing purposes at any time.
- Right to Withdraw Consent: Where processing is based on your consent, you can withdraw it at any time. Withdrawal is as simple as toggling preferences in the Application's settings or contacting the Data Controller.
- Rights Regarding Automated Decision-Making: You have rights related to automated decisions that affect you.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. Contact details for each country's Data Protection Authority can be found at: https://digital-strategy.ec.europa.eu/en/library/list-personal-data-protection-competent-authorities
If you are located in the United Kingdom, you may contact the Information Commissioner's Office at https://ico.org.uk
What are your California privacy rights (CCPA/CPRA)?
If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information:
- Right to Know: You can request disclosure of the categories and specific pieces of personal information the Service Provider has collected about you.
- Right to Delete: You can request deletion of personal information the Service Provider has collected from you, subject to certain exceptions.
- Right to Correct: You can request correction of inaccurate personal information.
- Right to Opt-Out: You can opt out of the sale or sharing of your personal information for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: You can limit the use of your sensitive personal information to essential purposes.
- Right to Non-Discrimination: The Service Provider will not discriminate against you for exercising any of your CCPA/CPRA rights.
To exercise any of these rights, please contact the Service Provider at isawafishapp@gmail.com. The Service Provider will verify your request using the information you provide and respond within the timeframes required by law. You may designate an authorized agent to make a request on your behalf.
How do you give your consent?
Where processing is based on consent, you provide that consent by affirmatively opting in to the relevant feature or action. You may withdraw consent at any time without affecting processing carried out before withdrawal. Processing based on other lawful bases, including contract performance, legitimate interests, or legal obligations, is carried out as described above.
How can you contact the Data Controller?
If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at isawafishapp@gmail.com.
To request deletion of your personal data or to exercise any of your rights, contact the Service Provider using the details provided above. The Service Provider will respond within one month of receiving your request, extendable by up to two months where necessary due to the complexity or volume of requests, as permitted by applicable law.