Privacy Policy
Sea Spotter
Effective: 2026-06-11
Last updated: 2026-06-13
---
1. Who We Are and How to Contact Us
Sea Spotter is operated by Proinet sp. z o.o., ul. Konstantynowska 16, 95-200 Pabianice, Polska ("we", "us", "our").
For any privacy-related questions or to exercise your rights under this policy, contact us at: privacy@sea-spotter.com
---
2. Data We Collect
Account Data: When you register, we collect your email address, username, and a securely hashed password. Your password is never stored in plaintext. We also store a timestamp and version identifier recording when you accepted the Wildlife Ethics Guidelines, for audit purposes.
Location Data: When you submit a sighting, we collect the GPS coordinates of the sighting location, provided either by automatic GPS or manual map pin. We also read your device's current GPS position to determine which geographic region you are in (for push notifications) and to scope the map view on first launch. We do not continuously track your location in the background. You can revoke location permission at any time in your device settings.
Sighting Reports: Each report includes: species, GPS location, timestamp, optional individual count, optional free-text notes, and optional photographs. Sighting reports are public and visible to all App users.
Photographs: Photos you attach are uploaded to our secure cloud storage and are publicly accessible within the App. Do not include personally identifiable information in photographs unless you consent to it being public.
Push Notification Token: Your device generates a unique push token via Expo's notification service. We store this token solely to send you notifications about sightings in your subscribed geographic areas. You can disable notifications at any time in your device settings.
Notification Preferences: We store your notification preference settings (e.g., quiet hours) in your profile so they persist across devices.
Technical and Usage Data: We may collect aggregated, anonymised data about App usage — screen views, error logs, crash reports — to improve the Service. This data does not identify you personally.
---
3. Why We Use Your Data and Our Legal Basis
We use your data for the following purposes:
Providing and operating the App (account, map, sightings feed)
Data: account data, location, sightings
Legal basis: Contract — GDPR Art. 6(1)(b)
Recording ethics-agreement acceptance
Data: ethics agreement timestamp and version
Legal basis: Legal obligation / legitimate interest — GDPR Art. 6(1)(c)/(f)
Sending push notifications for nearby sightings
Data: location, push notification token
Legal basis: Consent — GDPR Art. 6(1)(a)
Improving the App and diagnosing errors
Data: anonymised usage and crash data
Legal basis: Legitimate interest — GDPR Art. 6(1)(f)
Preventing abuse and enforcing these Terms
Data: account data, usage patterns
Legal basis: Legitimate interest — GDPR Art. 6(1)(f)
Complying with legal obligations
Data: any relevant data
Legal basis: Legal obligation — GDPR Art. 6(1)(c)
---
4. Data We Share
We do not sell your personal data.
We share data only with the following service providers, under appropriate data processing agreements:
Supabase — database, authentication, file storage, and realtime data. Data transferred: account data, sightings, photos, push tokens. Location: EU (configurable per deployment).
Expo / EAS — app build infrastructure and push notification relay. Data transferred: push token, notification payload. Location: United States.
Mapbox — map tile delivery and geocoding. Data transferred: approximate viewport coordinates (not linked to your account). Location: United States.
RevenueCat (planned) — premium subscription billing management. Data transferred: account identifier, purchase metadata. Location: United States.
Sighting reports (location, species, timestamp, notes, photos) are public within the App and visible to all users. We may also disclose data if required by law, court order, or to protect the safety, rights, or property of our users or the public.
---
5. Data Retention
Account data (email, username, ethics record): retained until you delete your account.
Sighting reports: configurable per deployment; default 90 days from submission; minimum floor 60 days. Reports are automatically and permanently deleted by a scheduled database job.
Photographs: retained until the associated sighting is automatically deleted.
Push notification token: retained until account deletion or token refresh by your device.
In-app notification preferences: retained until account deletion.
Anonymised usage analytics: retained for up to 2 years.
Account deletion: when you delete your account from the Profile screen, your profile and all associated personal data — sightings, subscriptions, photos, push token — are permanently deleted via cascading database delete. Anonymised aggregate statistics derived before deletion may be retained.
---
6. Your Rights
If you are in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the GDPR (or UK GDPR):
Access: request a copy of the personal data we hold about you.
Rectification: ask us to correct inaccurate data.
Erasure: request deletion of your data. You can delete your entire account directly from the Profile screen at any time.
Portability: receive your personal data in a structured, machine-readable format.
Restriction: ask us to restrict processing in certain circumstances (e.g., while a dispute is pending).
Objection: object to processing based on legitimate interest.
Withdraw consent: withdraw consent for push notifications at any time via your device notification settings, or revoke location access in device settings.
To exercise any right (other than account deletion, which is self-serve), contact us at privacy@sea-spotter.com. We will respond within 30 days.
You also have the right to lodge a complaint with your national data protection authority.
---
7. Local Storage
The App does not use browser cookies. The following data is stored locally on your device:
Session token (JWT): keeps you logged in between launches.
Cached sighting data (last 24 hours): enables offline map browsing.
Species catalogue: enables offline species picker.
Offline submission queue: queues sightings for sync when network is unavailable.
This data remains on your device and is not shared with third parties. You can clear it by logging out or deleting the App.
---
8. Security
We implement industry-standard security measures, including:
• Encrypted data in transit (TLS 1.2+) for all API and WebSocket connections.
• Passwords are never stored in plaintext (bcrypt via Supabase GoTrue).
• Row-Level Security (RLS) on all database tables, enforced server-side.
• Storage access policies ensuring only owners and authenticated users can write sighting data.
No security measure is perfect. If you believe your account has been compromised, contact us immediately at contact@sea-spotter.com and change your password.
---
9. Children's Privacy
Sea Spotter is not directed at children under 13 (or under 16 where a higher threshold applies under local law). We do not knowingly collect personal data from children below the applicable age threshold. If you believe a child's account has been created without appropriate consent, please contact us and we will delete the account promptly.
---
10. International Data Transfers
Some of our service providers (Expo, Mapbox, and the planned RevenueCat integration) are based in the United States. When transferring personal data from the EEA or UK to the US, we rely on appropriate safeguards:
• Standard Contractual Clauses (SCCs) approved by the European Commission, and/or
• The provider's certification under an applicable data transfer framework (e.g., EU-U.S. Data Privacy Framework).
Supabase is deployed in the EU by default in our configuration; data stored there does not leave the EU unless you change the deployment region.
---
11. Third-Party Links and Features
The App may include links to third-party websites or social platforms. This Privacy Policy applies only to Sea Spotter. When you interact with third-party services, their own privacy policies apply.
---
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the App, our practices, or applicable law. Material changes will be communicated via an in-app notice or email before taking effect. The "Last updated" date at the top of this document indicates the most recent revision. Continued use of the App after a change takes effect constitutes your acceptance of the updated policy.
---
13. Contact
For all privacy-related enquiries, requests to exercise your rights, or to report a security concern:
privacy@sea-spotter.com
Proinet sp. z o.o.
ul. Konstantynowska 16, 95-200 Pabianice, Polska