Privacy Policy

Catching Alpha · Updated September 18, 2026

Catching Alpha is a personal fishing log. Your data exists to power your log and your insights — it is not sold, shared for advertising, or used to profile you. This page explains exactly what the app collects, where it goes, and how to delete it.

What we collect

  • Account: your email address and a password, used only to sign you in. Passwords are handled by AWS Cognito; we never see them.
  • Catches: photos you choose to add, plus details you enter — species, length, lure, and the catch's location and time. When you upload a photo, the app reads its embedded EXIF data (GPS position and capture time) on your device to place the catch for you.
  • Tracks and trips: if you start a track, the app records your GPS position while the trip is active — including in the background with the screen off, if you grant "Always" location access. Tracking only runs when you start it and stops when you end the trip.
  • Saved spots: POIs and zones you save on the map.
  • Conditions: when you log a catch, the app automatically attaches the weather, tide, and water conditions at that place and time (this is the point of the app).

What we don't do

  • No advertising, and no selling or renting your data to anyone.
  • No third-party analytics or tracking SDKs in the app.
  • No access to your contacts, and no reading of your photo library beyond the photos you explicitly pick.
  • Your catches, spots, and tracks are visible only to your account. There is no social feed and no public sharing.

Where your data lives

Your cloud records and photos are stored in Amazon Web Services (AWS) in the United States: your records in DynamoDB and your photos in S3, both scoped to your account — the backend enforces per-user isolation, so one user's data is never readable by another. Data is encrypted in transit and at rest by AWS. No method of storage or transmission is 100% secure, so we cannot guarantee absolute security.

The app also keeps account-specific data on your device, including pending photo imports, recorded tracks, and data waiting to sync. It uses third-party software and services, including AWS for accounts and storage and Google Maps for the map. We do not add advertising or analytics SDKs.

The app is operated from the United States. If you use it from elsewhere, your data is transferred to and processed in the US.

Third-party services

To fetch conditions, our AWS backend sends the relevant coordinates or station identifiers, dates and times, and requested measurements to the services below. These condition requests do not include your catch photos, account email, or account identifier.

  • OpenWeather and Open-Meteo — weather at a location
  • NOAA and the National Weather Service — tides, water temperature, weather, and nautical chart data (U.S. government services)
  • USGS — river and water-level data (a U.S. government service)
  • Google Maps — the map itself; Google's own privacy policy applies to map usage

Google Maps loads directly in the app and receives map requests for the area you view, along with technical information such as your IP address and browser or device information. Other map-layer requests may also go directly to their providers. Their privacy policies apply to those requests.

If you choose Sign in with Apple or Google, that provider handles sign-in and shares the account information needed to authenticate you with AWS Cognito. This is separate from requests for maps and fishing conditions.

Location access

Location is used to center the map, stamp catches, show nearby conditions, and record tracks. Background ("Always") access is requested only so tracks keep recording with your screen locked; iOS shows an indicator whenever this is active. You can limit or revoke location access anytime in iOS Settings — the app still works for logging, with locations set by hand.

Keeping and deleting your data

We keep your data for as long as your account exists — it's your log. You can delete individual catches, trips, spots, and photos in the app at any time. To erase everything, use Settings → Delete account inside the app: this permanently deletes every catch, photo, track, zone, and saved spot, and then the login itself. There is no undo.

Photos are removed immediately. Deleted records disappear from the app immediately and from AWS's automated recovery backups within 35 days; we never restore deleted data except to recover from a system failure.

Children

Catching Alpha is not directed at children under 13, and we do not knowingly collect data from them.

Changes

If this policy changes in a way that matters, the date at the top will change and the app will point to the updated page.

This website

The Catching Alpha website is hosted by AWS Amplify. Requests to the website are processed by AWS and may include technical information such as your IP address, browser information, and the requested page. This website does not use advertising, analytics scripts, contact forms, or accounts. Email links open your email application; information you send is used to respond to your request.

Contact

Questions or requests: catchingalpha.app@gmail.com