1. Data Controller
FjordSpot is operated by Cato Tangen (private individual) from the Bergen area, Norway. Contact: cato.tangen@gmail.com
2. What Data We Collect
- Account: Email address and optional username upon registration.
- Location data: GPS coordinates and map selections you register or choose in the app for analysis and display. Precise location is stored with the catches and spots you register, linked to your account, until you delete them. We do not track your location in the background.
- Catch data: Species, weight, length, photo, notes, and position you voluntarily register.
- Saved locations: Coordinates and names you save as fishing spots. Your saved locations are private and not visible to other users. Access may occur in limited cases for operations, security, backup, or troubleshooting, but is not used for sharing or publication.
- Error reporting: Pseudonymized error reports are sent to Sentry (EU region) for troubleshooting. For signed-in users, reports are linked to an internal user ID (never your name or email) so we can follow up on errors affecting your account.
- Security logs: We store technical logs related to login, security, and abuse prevention for a limited period.
- Usage statistics: When a page is opened, we store its address (without parameters), the page you came from and your browser's technical identifier (user agent). We do not store your IP address or your account with this. Page views are recorded once you have accepted the terms, and on the information pages (including terms, privacy, help and changelog) also without that.
- Push notifications: If you turn on push notifications, we store the subscription your browser creates (an address at your browser's push service and encryption keys) and your browser's user agent, linked to your account. When you turn notifications off in the app, we try to delete the subscription on our side. If that deletion fails, it may remain until you delete your account. Subscriptions that the push service reports as expired during a delivery are removed, and everything is deleted when you delete your account. Beyond this, there is no fixed deletion deadline.
- IP address: We use your IP address to limit the number of requests and prevent abuse. The counters for this only apply within a time window of at most one hour.
- Photos for AI species identification: Photos you take for species identification are sent to Anthropic (Claude) as a data processor for interpretation. On a successful identification, FjordSpot stores a downscaled copy of the image on our own server in Norway to improve species recognition; the legal basis is legitimate interest (Art. 6(1)(f)), the copy is never shared publicly and is deleted when you delete your account. Photos you add to a catch are stored by FjordSpot on our own server in Norway, privately and access-controlled, until you delete the catch or your account. In line with its privacy policy, Anthropic may retain data for up to 30 days for abuse and safety monitoring before deletion.
- Voice-controlled catch logging: Your browser's built-in speech recognition converts your speech to text. Depending on your browser, this may use the browser vendor's speech service for transcription (Google in Chrome, Apple in Safari). The text is sent to FjordSpot and on to Anthropic (Claude) for interpretation, together with up to four alternative interpretations from the speech recognition. To get place and species names right, we also send the names of up to 30 of your saved spots and up to 10 species you have logged recently — the audio recording itself is never sent to Anthropic. The audio recording is stored by FjordSpot on our own server in Norway and is automatically deleted after 90 days.
- Solo-fishing contact: If you use the Solo Fishing feature, we collect the name and email address of the contact person you provide so we can notify them of missed check-ins or expired sessions. This information is used solely for this feature and is deleted when the session ends.
3. Purpose and Legal Basis
Contract (GDPR Art. 6(1)(b))
We process personal data necessary to provide the service, including for:
- Creating and operating user accounts
- Login and authentication
- Storing catches and fishing spots
- Map analysis and habitat assessment (HSI)
Legitimate interest (GDPR Art. 6(1)(f))
- Security and abuse prevention
- Troubleshooting and technical stability
- Improving the service and habitat model
- Usage statistics (page views without IP address or account)
Consent (GDPR Art. 6(1)(a))
- Push notifications for fishing conditions
4. Use of Location Data in the Habitat Model
To improve the habitat analysis, we may use aggregated or de-identified location data from user activity. This means that coordinates are separated from user identity and may be used at an area or grid level. Such data is not used to display or share your private fishing spots with other users.
5. Data Sharing
We do not sell personal data. Service providers that process data on our behalf:
- Sentry (EU): Error reporting and performance monitoring.
- Cloudflare: CDN and DDoS protection. Traffic passes through Cloudflare.
- Resend (USA): Sending emails (password reset, verification, Solo-fishing notifications). Emails are sent from Resend's EU region (Ireland), but Resend states that its primary processing takes place in the USA. The transfer is based on the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses (SCC).
- Anthropic (USA): AI interpretation of photos for species identification and text from voice logging (transcript, alternative interpretations and the names of saved spots and recently logged species) — the audio recording itself is never sent to Anthropic. Transfer to the USA occurs under EU Standard Contractual Clauses (SCC). In line with its privacy policy, Anthropic may retain the data for up to 30 days for abuse and safety monitoring before deletion.
Other external services:
- Google / Apple (browser speech recognition): Speech-to-text in voice-controlled catch logging (only when you use the feature). Your browser may send the audio to the browser vendor's speech service for transcription (Google in Chrome, Apple in Safari).
- Your browser's push service (for example Google in Chrome and Android): Delivers push notifications if you have turned them on. The push service sees the subscription address and technical delivery information (such as time and message size). The notification content itself is end-to-end encrypted and cannot be read by the push service.
- Kartverket / GeoNorge: Map and depth data. Map tiles load directly in your browser, so Kartverket receives your IP address and which part of the map you are viewing. We send no account information.
- Esri / ArcGIS (USA): Satellite imagery in the map. These also load directly in your browser, so Esri receives your IP address and which part of the map you are viewing. We send no account information.
- Miljødirektoratet (Norwegian Environment Agency): Marine habitat layers in the map. These tiles load directly in your browser when you enable the layer, so Miljødirektoratet receives your IP address and which part of the map you are viewing. We send no account information.
- Norwegian Meteorological Institute: Weather data. Fetched by our own server, not by your browser — no personal data is sent.
Where third parties process personal data on our behalf, this is done as data processors under data processing agreements where required.
6. Storage and Security
- Primary service data is stored on servers in Norway. Certain technical service providers may process limited data as part of operations, security, email, or error reporting.
- Passwords are stored as secure hash values (bcrypt) and never in plaintext.
- All traffic is encrypted with HTTPS/TLS.
- CSP, CSRF protection, and rate limiting are implemented.
- Daily backups with 30-day retention.
7. Retention Period
Account data is retained as long as you have an active account. Inactive accounts are deleted after 24 months — you are notified by e-mail about one month in advance, and a single sign-in is enough to keep the account. Catch data and saved locations are deleted when you delete your account. Audio recordings from voice-controlled catch logging are automatically deleted after 90 days. Pseudonymized error reports are deleted no later than 90 days after they last occurred. Security logs are retained for up to 90 days. Page views in the usage statistics are deleted by a nightly cleanup once they are older than 13 months.
8. Your Rights
Under the GDPR, you have the right to:
- Access: Request a copy of your data.
- Rectification: Correct inaccurate information.
- Erasure: Request that your data be deleted. You can delete your account and all associated data directly in the app under Settings → Data → Delete account. Alternatively, contact support@fjordspot.no.
- Data portability: Export your data. Where available, data can also be exported directly from the app (GPX export).
- Objection: Object to processing based on legitimate interest.
- Restriction: Ask us to restrict the processing of your data, for example while we check whether it is accurate or whether an objection should be upheld.
- Withdraw consent: For push notifications, at any time.
Contact us at support@fjordspot.no to exercise your rights. You may also file a complaint with the Norwegian Data Protection Authority (Datatilsynet).
9. Cookies
FjordSpot only uses necessary cookies and similar technologies for login, session management, and security. We do not use third-party tracking cookies or advertising cookies.
10. Children
FjordSpot has no age restriction. We encourage children to use the app together with an adult, especially when fishing and near the sea. Parents or guardians are responsible for children's use of the service. If we become aware that personal data has been registered in violation of applicable regulations, we will attempt to delete or restrict the processing.
11. Changes
We may update this policy. In the event of significant changes, we will notify you in the app or on the website before the changes take effect.
