Privacy Policy

Effective as of 22 August 2026

This privacy policy is applicable to the I Saw a Fish app for mobile devices, together with any related services operated by Tomasz Ziębiński (collectively, the "Application"). Tomasz Ziębiński is hereinafter referred to as the "Service Provider". Your use of the Application is also governed by the Terms of Service.

Data Controller Information

Tomasz Ziębiński acts as the Data Controller responsible for the processing of your personal data.

For data protection inquiries and to exercise your GDPR rights, please contact the Data Controller using the contact information above.

What information does the Application obtain and how is it used?

The Application does not require a user account, and there is no registration or sign-in. The content you create in the Application — your dive logbooks and observations, the photos you add, your "bucket list", and your settings — is stored only locally on your device. The Service Provider operates no servers for this content and cannot access it.

The data that does leave your device is collected by third-party SDKs included in the Application (advertising, maps and billing), as described in the sections below. The Service Provider does not send marketing communications and does not collect your name, email address or contact details through the Application.

Legal basis for processing your personal data

Where the GDPR applies, the Service Provider relies on one or more lawful bases to process your personal data, including:

Cookies and similar technologies

The Application or its third-party SDKs may use cookies, SDKs, pixels, and similar technologies to support functionality, analytics, and service delivery. Where required by law, the Service Provider will obtain your consent before using non-essential tracking technologies.

Automated decision-making and profiling

The Service Provider does not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you. Any ad personalization is performed by Google as part of the advertising services described above, and is governed by Google's policies and your consent and ad-settings choices. Where automated decision-making or profiling applies, you have the right to request human review, express your point of view, and contest the decision, and to be informed of the logic involved where required by law.

What information does the Application collect automatically?

When the Application shows ads (the free version), the Google Mobile Ads SDK (AdMob) automatically collects and shares the following with Google for advertising, analytics and fraud prevention:

This data is collected by the Google Mobile Ads SDK and shared with Google; Google acts as an independent controller for this advertising data. The advertising ID is resettable and can be deleted by you (see "What are my opt-out rights?" below). The Application's own code does not read your device ID, account identifiers or contacts.

Does the Application collect precise real time location information of the device?

Location permission is optional — you can decline it and still use the Application. If you grant it, your device's precise location is used only for the following features:

When you view a map, the Google Maps SDK sends map-viewport information to Google to render the map (see the Google Maps section below). Separately, the advertising SDK may estimate your approximate location from your IP address, as described above.

Does the Application use Artificial Intelligence (AI) technologies?

The Application does not use Artificial Intelligence (AI) technologies to process your data or provide features.

Advertising and your consent

The free version of the Application displays ads through Google AdMob. Where required by law, the Application uses Google's User Messaging Platform (UMP) to present your privacy choices, which you can revisit at any time via Options → Manage privacy choices in the Application:

Separately, resetting or deleting your advertising ID and opting out of ad personalization (in your device's Android ad settings and via Google My Ad Center) makes the ads you see non-personalized

Subscriptions (Google Play Billing)

The optional Premium subscription is processed entirely by Google Play's billing system. The Service Provider never receives or stores your payment details (such as card numbers). The Application only checks with Google Play whether you currently hold an active subscription, in order to unlock Premium features and remove ads.

In-app announcements

The Application periodically downloads a small public announcement file from a third-party host (GitHub) to display occasional notices. This is a one-way download — no personal data about you is sent. As with any internet request, the host receives your device's IP address as part of delivering the file; it is not used by the Service Provider to identify, track, or locate you.

Do third parties see and/or have access to information obtained by the Application?

The Application includes third-party SDKs that receive data directly:

The Service Provider does not sell your data and does not transmit your on-device content (logbooks, observations, photos) to any third party. The Service Provider may disclose information:

Where the GDPR applies, the Service Provider enters into Data Processing Agreements (DPAs) with third-party service providers that process personal data on its behalf, as required by Article 28 of the GDPR. These DPAs impose the same data protection obligations on those service providers as described in this Privacy Policy.

International Data Transfers

The Service Provider or its third-party service providers may transfer personal data outside the European Economic Area (EEA). Where such transfers occur, the Service Provider will use an appropriate transfer mechanism required by GDPR Chapter V:

Countries outside the EEA may not provide the same level of data protection as the EEA. Where required by law, the Service Provider will apply appropriate safeguards and obtain any consent required for the transfer.

Please note that the Application utilizes third-party services that have their own Privacy Policy about handling data. The third-party services used by the Application are Google Play Services, Google AdMob, Google Maps Platform and Google Play Billing. Their data handling is governed by:

What are my opt-out rights?

You have several controls:

The Service Provider stores none of your personal content on its own servers, so there is no server-side copy to delete. For questions or to exercise your rights, contact the Service Provider at isawafishapp@gmail.com.

What is the data retention policy and how can you manage your information?

The Service Provider does not store any of your personal data on its own servers. Retention works as follows:

If you enable Android Auto Backup, Android may back up the Application database (excluding your photos) to your own Google Drive under your Google account's terms; the Service Provider cannot access it. Because the Service Provider holds no personal data of yours, deletion is performed through the on-device and Google/Android controls described in "What are my opt-out rights?". For any questions, contact isawafishapp@gmail.com.

How does the Application address children's privacy?

The Application is not directed to children under 13 years of age. The Service Provider does not knowingly collect personal information from children under 13, and does not solicit data from children or market the Application to them.

In the European Economic Area and the United Kingdom, the age of digital consent ranges from 13 to 16 depending on the country. Where the applicable local age is higher than 13, the Application should be used by a child below that age only with the consent of a holder of parental responsibility.

The Service Provider stores no personal data of yours on its own servers. If you are a parent or guardian and you believe a child has provided personal information without the required consent, please contact the Service Provider at isawafishapp@gmail.com and the Service Provider will take the necessary actions, including deleting any such data within its control.

How is your information kept secure?

Your content is kept in the Application's private, sandboxed storage on your device, which is not accessible to other apps. Data transmitted by the Application's third-party SDKs (advertising, maps, billing) is encrypted in transit using TLS. Because the Service Provider operates no servers for your personal content, there is no server-side store of it to be breached. However, no method of electronic storage or transmission can be guaranteed to be completely secure.

Data Breach Notification

The Service Provider does not store your personal data on its own servers, which limits the risk of a breach on its side. Should the Service Provider nonetheless become aware of a personal data breach that poses a risk to your rights and freedoms, it will notify the relevant supervisory authority within 72 hours, and, where the breach is likely to result in a high risk to your rights and freedoms, will notify you without undue delay, as required by applicable law. Breaches affecting data held by third-party providers (such as Google) are handled by those providers under their own policies.

How will you be informed of changes to this Privacy Policy?

The Service Provider may update this Privacy Policy from time to time. The Service Provider will notify you of material changes by posting the updated Privacy Policy with an effective date. Where required by law, the Service Provider will seek your consent to material changes before they take effect.

Previous versions of this Privacy Policy will be maintained and made available upon request by contacting the Service Provider at isawafishapp@gmail.com.

What are your GDPR data protection rights?

Under the GDPR, you have the following rights:

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. Contact details for each country's Data Protection Authority can be found at: https://digital-strategy.ec.europa.eu/en/library/list-personal-data-protection-competent-authorities

If you are located in the United Kingdom, you may contact the Information Commissioner's Office at https://ico.org.uk

What are your California privacy rights (CCPA/CPRA)?

If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information:

To exercise any of these rights, please contact the Service Provider at isawafishapp@gmail.com. The Service Provider will verify your request using the information you provide and respond within the timeframes required by law. You may designate an authorized agent to make a request on your behalf.

How do you give your consent?

Where processing is based on consent, you provide that consent by affirmatively opting in to the relevant feature or action. You may withdraw consent at any time without affecting processing carried out before withdrawal. Processing based on other lawful bases, including contract performance, legitimate interests, or legal obligations, is carried out as described above.

How can you contact the Data Controller?

If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at isawafishapp@gmail.com.

To request deletion of your personal data or to exercise any of your rights, contact the Service Provider using the details provided above. The Service Provider will respond within one month of receiving your request, extendable by up to two months where necessary due to the complexity or volume of requests, as permitted by applicable law.