# Privacy Policy, BC Fish Map

**Last updated: July 26, 2026**

BC Fish Map (the "App") is operated by **33knots** ("we", "us", "our"). Contact: **thirtythreeknots@gmail.com**.

**Short version:** a fisherman's spots and catches are sacred. The App works with no account at all. Your
spots, catches, sonar imports and licence copy stay **on your device** and are never uploaded. We run **no
analytics, no ad trackers and no profiling**, and we never sell your data. Two things do leave your device,
and only if you choose them: an optional account (sign-in), and beta tester feedback when you press Send.

---

## 1. The core App collects nothing

There is **no account and no login required to use the App**, and nothing you create in it is transmitted
to us.

Stored **only on your device**, in browser storage or on-device IndexedDB:

- **My Spots** and your **catch log**, including any notes you add.
- **Imported sonar depth logs and GPS tracks** (GPX / CSV). These stay on the device and are drawn only for
  you. They are never uploaded, never merged into anyone else's map, and never shared.
- **My Licence**: your licence number(s) and, if you add one, a **photo of your licence**. The photo never
  leaves the device. That whole feature makes no network requests of any kind.
- **My Species** favourites, your settings (mode, theme, alert preference), and whether you finished
  onboarding.

Clearing the App's data deletes all of it permanently. We hold no copy, so there is nothing for us to
return, correct or delete.

## 2. Optional account (sign-in)

Signing in is **optional** and the App is fully usable without it. It exists so your beta comments can carry
your name, and for future paid features.

Sign-in is handled by **Clerk**, a third-party authentication provider, using **Sign in with Apple** or
**Sign in with Google**. If you sign in:

- **Clerk receives** your email address and the identity information Apple or Google returns to it, and
  creates an account record on Clerk's systems, under **Clerk's own privacy policy**:
  <https://clerk.com/legal/privacy>.
- **We receive** your Clerk user id and email, and use them only to attribute your feedback and, in future,
  your entitlements. We do not use them for marketing.
- The Clerk sign-in code is loaded from the **jsDelivr** public CDN when you open the sign-in screen.

If you never sign in, none of the above happens.

## 3. Beta tester feedback (Guide Class), beta testers only

This section applies **only** to the invite-only beta build, and **only** when you deliberately send a
comment. It does not exist in the public App.

When you tap Send on a comment, this is uploaded to our **Cloudflare D1** database:

- the **comment text** and the category you picked,
- a **screenshot of the map** as it looked,
- the **exact coordinates of the spot you tapped**, and the screen position of the tap,
- which **panel was open**, the **selected species**, and a short **snippet of the verdict card** on screen,
- your **browser user agent**, theme, mode and the **app version**,
- your **invite code**, and your Clerk user id if you are signed in.

**Nothing is sent unless you press Send.** Closing the comment window discards the capture. If you are
offline the comment is held on your device and retried later, and you can clear it by clearing App data.

Redeeming an invite code also stores a tester record: the **code**, your **Clerk user id** and **email** if
you are signed in. We use all of this only to fix the App, and we delete it when the beta ends.

## 4. Location

Your location is used **on your device** to centre the map and work out local conditions. We never collect,
transmit or store a track of where you are or where you fish.

Two narrow exceptions, both about the point you are looking at rather than where you are:

- Weather and tide lookups send that point's coordinates to the providers in Section 6.
- In the beta, a comment you choose to send includes the coordinates of the spot you tapped (Section 3).

## 5. Closure alerts (optional, opt in)

If you turn on closure and opening alerts, your browser creates an anonymous **push subscription**: a random
endpoint URL and cryptographic keys. We store **only that**, so we can send you DFO closure and opening
notices. It contains **no name, no email, no account link and no location**, and we store nothing alongside
it. Turn alerts off to stop them; ask us and we will delete the stored subscription. We never share it.

Alerts are still being switched on. Until they are, the button in the App says so and nothing is stored.

## 6. What third parties receive when the App fetches data

To work, your device requests data directly from these services. Each one necessarily sees your device's
**IP address** and what was requested, under **their own privacy policies**, not ours. We do not receive or
store any of it.

- **Esri / ArcGIS Online**: basemap, satellite and hillshade tiles. The tiles requested reveal the **map area
  you are viewing**.
- **Fisheries and Oceans Canada (DFO)**: nautical chart tiles, tide predictions (IWLS), fishery notices and
  regulation pages. Tide lookups send **the coordinates of the point you are checking**.
- **Open-Meteo**: weather and marine forecast. Sends **the coordinates of the point you are checking**.
- **Environment and Climate Change Canada**: river levels and marine forecasts.
- **jsDelivr**: serves the Clerk sign-in library, only if you open sign-in.
- **Windy.com**: only if you tap "Open in Windy". That link deliberately carries a **rounded, roughly
  1 km area**, not your precise spot.

The App is **offline first**. Once loaded, the regulations and map work with no connection, which keeps
these requests to a minimum.

## 7. What we do not do

- **No analytics.** In the public App: no Google Analytics, no Meta pixel, no product-analytics SDK, no
  session recording. (The invite-only beta build is the one exception, disclosed in full just below.)
- **No advertising and no profiling.** We do not build a profile of you or track you across apps or sites.
- **We never sell, rent or trade your data.**
- We do not upload your spots, catches, tracks, sonar imports or licence photo. Ever.

### Guide Class beta builds only: usage analytics (added 2026-07-30)

The invite-only **beta** build, and only that build, records how the app is used: screens viewed, features
tapped, session length and coarse device info, using **PostHog**. It exists so tester feedback can be
matched to what testers actually did, and every tester accepts it in the agreement shown before the beta
opens. The public App contains none of this: the analytics code ships with an empty key and only a beta
build can activate it. No session recording, no ad networks, and beta usage data is never sold. Leave the
beta and it stops; ask us (same email as section 9) and we delete your beta usage data.

## 8. Children

The App is intended for a general audience and is not directed at children under 13. We do not knowingly
collect personal information from children.

## 9. Deleting your data

- **On your device** (spots, catches, tracks, sonar imports, licence copy and photo, settings): clear the
  App's data in your browser or device settings, or delete the installed app. That is a permanent deletion
  and we never had a copy.
- **Beta feedback rows and tester record**: email **thirtythreeknots@gmail.com** from the address you signed
  in with, or quote your invite code, and we will delete them.
- **Your account**: email the same address and we will delete your Clerk account and everything linked to
  it. There is **no in-app account deletion button yet**. We will add one before the App is released on any
  app store, because the stores require it and because you should not have to email anyone to leave.
- **Push subscription**: turn alerts off, or ask us and we will delete it.

## 10. Security

Data on your device is protected by your device and browser. Network requests use HTTPS. No method of
transmission or storage is perfectly secure, and you use the App at your own risk.

## 11. Changes

We may update this Policy. Material changes are reflected in the "Last updated" date and the changelog below.

## 12. Contact

Questions about privacy? Contact **thirtythreeknots@gmail.com**.

---

## Changelog

- **2026-07-26**: rewritten so every statement matches the App as built today. Added the optional Clerk
  account, the Guide Class beta feedback disclosure (including the screenshot, the exact tapped coordinates
  and the user agent), invite-code redemption, sonar imports and the licence photo as device-only stores,
  and the Windy link. Corrected the CDN name (jsDelivr, not unpkg) and named Open-Meteo and DFO IWLS
  directly. Added a real deletion section, including the honest note that in-app account deletion is planned
  and not yet built.
- **2026-06-24**: first version.

---

> **Not legal advice.** This is a good-faith description of the App's actual data practices as built. Have it
> reviewed by a qualified lawyer before commercial launch, and keep it in sync with the App: if you add
> analytics, new accounts, payments or any new data flow, this Policy must be updated first.
