1. Who we are
Fria LLC ("we", "us", or "our") provides Catcharium: Fish ID & Log and this website. We are responsible for the personal information we process to provide these services. This policy explains what information is handled, why, who receives it, and the choices available to you.
Contact: support@fria.ai.
2. Information we handle
Cloud-account and backup details below apply when Account & backup is available in your version and connects to the service. A pending or failed backup is not a completed backup. Earlier versions keep the catch journal locally and send photos for recognition without creating a private photo archive on our backend; AI-provider processing and retention still apply.
- Anonymous account and device information. In versions with Account & backup, Firebase Authentication automatically creates or restores an anonymous account. Its user ID links your private records. We store your profile handle, first-use and activity times, app preferences, a random installation ID, system region, locale, preferred languages, time zone, device model, operating-system version, and app version/build. System region describes your settings, not your physical location.
- Profile photo and username. You can choose a profile photo for private account backup. The app crops and re-encodes it to remove embedded camera metadata before upload. Profile photos are not submitted for fish recognition. Custom usernames are checked for uniqueness without revealing another account's identity; the default name catcher is shared.
- Catch journal and cloud backup. Saved catch photos, fish cutouts, species and identification results, capture dates, length measurements or corrections, badges, and preferences are stored locally and, where cloud backup is available, uploaded to your anonymous account. The operating system may also include local app data in device backups according to your Apple settings.
- Submitted scans. A resized photo and its capture or import time are sent for identification. In versions with cloud backup, all submitted scan attempts are also archived privately with their result or failure status, including scans you dismiss or do not save as catches. Interrupted submissions can be archived when connectivity returns without automatically running recognition again. Anything visible in the image is included. Images are re-encoded before upload to remove embedded camera metadata.
- Purchase and app identifiers. RevenueCat creates a separate anonymous app user ID and processes purchase records, product identifiers, entitlement status, and technical information. In versions with cloud backup, we associate that ID with your account for purchase support. A Pro scan sends that ID and an Apple-signed transaction to our backend to verify paid access. These identifiers are pseudonymous, not a guarantee that information can never be associated with a person.
- Service and security data. Our infrastructure processes IP addresses, request times and identifiers, response/error status, model choice, latency, and aggregate call/token counts to operate the service and diagnose failures.
- Support messages. If you email us, we receive your email address, message, and attachments. The app prepares an editable support email with app/device versions and available account identifiers; you decide whether to send it and may remove those details.
Catcharium does not require a named account or email sign-in. We do not receive your full payment card details from Apple.
3. Camera, photos, and location
Camera access is used to capture the photo you choose to identify. The system photo picker lets you select particular images without giving Catcharium unrestricted access to your library. Subject cutouts and supported depth-based length measurements are processed on the device.
The current app does not request GPS permission or collect your precise device location. Network providers may infer a general area from your IP address, and a photo can itself reveal a place. You can change camera permission in iOS Settings and stop submitting images at any time.
4. Why we process information
We use information to identify fish, return results, provide and restore Pro access, prevent fraud and excessive requests, maintain reliability, understand subscription performance using RevenueCat purchase reports, respond to support and privacy requests, and meet legal obligations. Local journal data supports your collection and preferences. Where cloud backup is available, backed-up data also supports recovery to the same anonymous account.
Where applicable data protection law requires a legal basis, we rely on performing our contract with you for requested features, our legitimate interests in a secure and reliable service and customer support, compliance with legal obligations, and consent where required. You may withdraw consent for optional processing without affecting earlier lawful processing.
We do not sell personal information, share it for cross-context behavioral advertising, or use advertising SDKs or an advertising identifier in Catcharium.
5. Cloud processing and service providers
We disclose only the information needed for the relevant service to providers acting under applicable service and data protection terms:
- Google Cloud / Firebase: hosts the recognition backend, operational logs, and aggregate service counters. Versions with Account & backup also use Firebase for anonymous authentication and private user/scan/catch records and images. Our primary recognition service and the resources configured for private records and images are in Northern Virginia, United States. An older regional endpoint redirects recognition requests to the US service. See Firebase privacy and security.
- Alibaba Cloud Model Studio (Qwen): processes photos and capture/import times for free recognition using its US inference service. See Model Studio privacy information.
- OpenAI: processes photos and capture/import times for verified Pro recognition. Purchase proofs and RevenueCat IDs are used by our backend for authorization and are not included in the image prompt sent to the AI provider. See OpenAI API data controls.
- Apple and RevenueCat: process purchases, renewals, refunds, restoration, access verification, and subscription analytics. Apple sends purchase-status notifications to RevenueCat. See Apple's privacy policy and RevenueCat's privacy policy.
- Vercel: hosts these public web pages and processes connection and security logs, such as IP address and browser/request information. See Vercel's privacy notice.
We do not use submitted photos to train our own AI models. Our AI providers' published API policies describe how they handle training and retention; these are cloud services, so processing is not confined to your device. We require service providers processing information on our behalf to protect it consistently with this policy and applicable law.
We may also disclose information when reasonably necessary to comply with law, protect people and the service, or complete a business transfer subject to appropriate protections. We do not publish your catch journal or photos as a public feed. If you choose to share or copy a catch card, its image, species, date, and length are included; the recipient or app you choose then handles that content under its own practices.
6. Storage and retention
Profile photos: your current profile photo is retained privately until replaced or your account is deleted. Replaced or interrupted avatar uploads become eligible for cleanup after 24 hours; service interruptions or in-progress operations can delay removal. Account deletion also removes profile photos and releases the custom username.
Saved catches: local copies support offline use. Where cloud backup is available, we retain saved catches, their photos and cutouts, and their linked scans until you delete them or your account. Deleting a catch removes it locally and queues the corresponding cloud deletion. After the service accepts the request, its catch record is removed and cleanup removes its related scan and stored app photos. Cleanup can take additional time while in-progress requests finish or failed operations are retried. Earned badges and minimal deletion markers may remain so deleted content does not reappear. Original images in Apple Photos, shared copies, and your device backups are managed separately.
Other scans in versions with cloud backup: scans not saved as catches, including failed or dismissed recognition attempts, become eligible for cleanup 90 days after creation of their server record. The scheduled cleanup removes their records and images; service interruptions or pending operations can delay completion. This retention rule applies to our private scan archive, not to earlier versions that do not create one or to AI providers' own records. Local pending uploads are removed after successful archival. Our backend does not intentionally log image bodies or purchase proofs.
Account deletion: in versions with Account & backup, an accepted deletion request blocks further account writes and queues deletion of private user records, images, and the Firebase anonymous account. The app then clears its local journal and signs out. Cloud cleanup continues after acceptance, waits for requests already in progress, and retries interruptions. Minimal deletion-job records can remain while cleanup and status checks complete. An offline request is saved locally and submitted when the app can reconnect; keep the app installed until the request is accepted. A minimal deletion-request status is retained for up to 24 hours after completion to handle retries, then removed. Removing the app alone does not request cloud deletion.
Providers and other records: AI providers handle submitted content under their linked policies; our retention periods do not override theirs. Firebase Authentication has separate security-log and backup retention after an account-deletion request, as explained in Firebase's privacy information. Operational logs follow hosting retention settings. Aggregate service counters may remain for usage and cost monitoring. Purchase records and support correspondence are retained as needed for their purposes and applicable legal obligations. In-app account deletion does not automatically erase Apple's or RevenueCat's purchase records; contact us for related privacy requests.
7. Your choices and privacy requests
You can delete individual catches from their detail screen and manage permissions in iOS Settings. Versions with Account & backup also offer account and data deletion in Settings. Cloud recovery requires valid credentials for the same anonymous account; switching devices, clearing credentials, or reinstalling may make the old account inaccessible. Account linking is not currently offered. Backups and original photos are managed separately through Apple. Removing the app does not cancel a subscription or automatically erase purchase records.
For access, correction, deletion, a copy of information, or other applicable privacy rights, email support@fria.ai with the subject "Catcharium privacy request". The in-app Support link can include your Firebase and RevenueCat user IDs to help us locate account and subscription records. Do not send your Apple password or full payment card information. We may need proportionate verification before fulfilling a request.
Depending on where you live, you may have rights to portability, restriction, objection to processing, withdrawal of consent, an appeal of a privacy decision, and a complaint to your local data protection authority. We will respond within applicable legal deadlines and will not discriminate against you for exercising your rights. Some records may need to be retained for legal, security, or transaction reasons; we will explain applicable limitations.
8. Security and international processing
We use HTTPS for requests, authenticated access to private records and photos, and administrative access controls for backend systems. No storage or transmission method can be guaranteed completely secure.
Fria LLC is based in the United States. Our providers may process information in the United States and other countries where they operate. The US configuration of our Google and Qwen services does not establish a US-only residency guarantee for every provider. Where required, international transfers are subject to legally recognized safeguards, such as contractual protections.
9. Children and this website
Catcharium is not directed to children under 13, or a higher minimum age where required by local law. We do not knowingly collect personal information from children below that age. A parent or guardian who believes a child has submitted personal information can contact us to request its removal.
This policy website does not include advertising pixels, analytics scripts, or nonessential cookies. Hosting providers may process ordinary security and connection data as described above. External links lead to services with their own privacy policies.
10. Changes and contact
We may update this policy as our services or legal requirements change. The effective date at the top identifies the current version. For material changes, we will provide an appropriate notice and obtain additional consent where required.
Questions about Catcharium privacy: support@fria.ai. You can also visit our support page.