Privacy Policy
Last updated: June 2026
1. Controller
Michael Pawlik
Sperberweg 6c
50997 Cologne
Germany
Email: support@4fish.app
A data protection officer is not legally required.
2. Scope and website
This privacy policy applies to the website 4fish.app as well as to the 4Fish app. Some sections concern only the website, others only the app.
The website is a static product and information page. The website has no user account, no login, no newsletter, no contact form, no web shop, no checkout and no entry or validation of promo codes. The website does not request your location, does not load map or weather data and does not store any user input in LocalStorage or IndexedDB.
3. Website hosting
The website 4fish.app is hosted by ALL-INKL.COM. When the website is accessed, the host processes technically necessary access data, in particular the requested page, date and time of access, browser and device information, referrer URL and the IP address.
IP addresses are fully anonymized. Log data is deleted after 90 days. ALL-INKL.COM is engaged as a processor on the basis of a data processing agreement.
4. Cookies, tracking and analytics
As things stand, the website uses no cookies of its own and no analytics, marketing or tracking services. In particular, no Google Analytics, no Meta Pixel and no comparable tracking services are currently used.
If we use analytics services in the future, this will only be done after updating this privacy policy accordingly and, where required, after obtaining your consent.
5. Email contact
If you contact us by email, we process the data you transmit, in particular your email address, name if provided, the content of the message and technical mail metadata. The processing is carried out in order to handle your request.
The mailbox is operated at ALL-INKL.COM. Emails are deleted as soon as they are no longer required for processing, unless statutory retention obligations apply.
6. Social media and external links
We maintain online presences on Instagram, YouTube, Facebook and TikTok and link to these profiles. Our website also contains links to external offers, in particular to the Google Play Store and the Apple App Store.
When you simply visit our website, no data is transmitted to these providers, as no social media plugins, feeds, videos or embedded content are loaded. Only when you click on a corresponding link do you leave our website. The respective provider is responsible for the subsequent data processing.
No payments are accepted on the website itself. There is no web shop and no checkout. Purchases and subscriptions are made exclusively via the app stores or within the app.
7. Local data storage in the app
All data you enter — in particular catches, sessions, spots, GPS coordinates, photos, audio recordings and notes — is stored exclusively locally on your device (in the device's local database, e.g. IndexedDB). This content is not transmitted to our servers or to third parties; we have no access to it. You can delete this data at any time by removing the app data on your device.
Note: Locally stored data may be lost when the app is uninstalled, the device is reset, or app/website data is deleted on the device. Therefore, back up important data yourself.
8. Legal bases
Where personal data is processed, this is done on the basis of Art. 6 (1) (a) GDPR (consent, in particular for access to location data), Art. 6 (1) (b) GDPR (provision of the features you request and processing of the subscription) and Art. 6 (1) (f) GDPR (legitimate interest in the technical provision of map, weather and place services and in preventing misuse).
You can revoke consent you have given at any time with effect for the future, e.g. in your device settings.
9. Location data
With your express consent, the app accesses location data (GPS) in order to save catch locations, display spots on the map, retrieve weather data for your location and determine place names.
Location data is stored locally. It is only transmitted in the context of the external services listed below.
10. Weather data (Open-Meteo)
To retrieve current and historical weather data, location coordinates are transmitted to Open-Meteo. The app uses Open-Meteo's paid customer/commercial plan for this (customer-api.open-meteo.com and customer-archive-api.open-meteo.com); the requests additionally contain an API key that identifies our contract with Open-Meteo — this is not a personal identifier of the app user.
Provider: OpenMeteo GmbH, Hintere Schilligmatte 6, 6463 Bürglen (UR), Switzerland (an EU adequacy decision exists for Switzerland)
Data transmitted: GPS coordinates, IP address
Legal basis: Art. 6 (1) (b) and (f) GDPR
Note: The service uses a globally distributed server infrastructure; transmission to servers outside the EU/EEA cannot be ruled out. According to Open-Meteo's terms of use, log files containing the IP address and request URL are deleted after 90 days; under the paid plan, aggregated usage statistics that can no longer be traced back to individual requests are additionally retained.
Responsibility: Open-Meteo acts as an independent controller within the meaning of Art. 4 No. 7 GDPR. No data processing agreement exists, and none is required in this constellation.
More information: open-meteo.com/en/terms
11. Maps, place lookup and geocoding (MapTiler)
MapTiler is used for map display (street map and satellite view) and for converting GPS coordinates into place names (reverse geocoding). The map data displayed is based on OpenStreetMap data but is delivered via MapTiler's infrastructure.
Provider: MapTiler AG, Höfenstrasse 14, 8590 Romanshorn, Switzerland (an EU adequacy decision exists for Switzerland)
Data transmitted: GPS coordinates, IP address, technical request data (map section, zoom level)
Legal basis: Art. 6 (1) (b) and (f) GDPR
MapTiler processes this data as an independent controller within the meaning of Art. 4 No. 7 GDPR.
More information: maptiler.com/privacy-policy
12. Photos and audio recordings / device permissions
Photos and audio recordings are stored exclusively locally; they are not transmitted to us or to third parties. For individual features, the app requests device permissions (location, camera, microphone, storage). You can change these permissions at any time in your device settings.
13. Purchase and subscription processing via the app stores
Purchases and subscriptions are processed via the Apple App Store or Google Play. In doing so, Apple and Google process payment, account and device data under their own responsibility. Their privacy policies apply (apple.com/legal/privacy and policies.google.com/privacy). We do not receive any payment data from the stores.
14. Purchase and subscription management (RevenueCat)
We use RevenueCat for the technical validation of purchases and for managing subscriptions. The service sits between the app and the billing systems of the app stores (Google Play Billing, Apple StoreKit).
Provider: RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA
Data processed: a pseudonymous user identifier assigned by RevenueCat, purchase and transaction data (transmitted by the store), app version, platform/operating system, country and the IP address. Name and email address are not transmitted.
Purpose: validation of purchases, provision and management of the premium subscription and prevention of misuse
Legal basis: Art. 6 (1) (b) GDPR (performance of the subscription contract); insofar as the processing serves fraud or misuse prevention, additionally Art. 6 (1) (f) GDPR
Data processing agreement: RevenueCat processes this data as a processor on the basis of a data processing agreement (Data Processing Addendum) and may engage sub-processors in doing so.
Third-country transfer: As RevenueCat is based in the USA, data is transferred to a third country. The transfer is safeguarded by standard contractual clauses pursuant to Art. 46 GDPR, which form part of the data processing agreement.
More information: revenuecat.com/privacy
15. Storage period
Locally stored content remains on your device until you delete it. For the external services, the storage period is governed by their respective policies.
16. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to revoke consent you have given. Since we do not store any personal data on our own servers, these rights primarily concern the transmissions to external services listed above; apart from that, your data remains under your sole control on your device.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).
Contact for data protection matters: support@4fish.app
17. Changes to this privacy policy
We reserve the right to amend this privacy policy. The current version is available at: 4fish.app/datenschutz-en.html