Gilli ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application ("the App"). This policy applies to all users in the European Economic Area (EEA), United Kingdom, and worldwide.
By using Gilli, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Email address, display name, profile photo (via Google Sign-In)
- Fishing Logs: Catch data (species, location, date, time, weather conditions, photos, notes)
- Tackle Box: Lure inventory, tackle notes
- Trip Plans: Fishing trip details, participants, locations
- Social Features: Friend requests, club memberships, activity feed posts, comments
- User Preferences: Units, language, environment mode (marine/freshwater)
1.2 Information Collected Automatically
- Location Data: Precise GPS coordinates when logging catches, viewing maps, or planning trips (only when you grant location permission)
- Device Information: Device model, operating system version, unique device identifiers
- Usage Data: App features used, screens viewed, session duration
- Performance Data: Crash logs, error reports (via Firebase Crashlytics)
1.3 Information from Third-Party Services
- Google Maps: Map tiles, geocoding data (processed on Google's servers)
- Weather Services: Marine and freshwater conditions from external APIs
- Firebase Services: Authentication, database, storage (hosted in EU region: europe-west3)
2. How We Use Your Information
2.1 Core Functionality
- Provide fishing condition predictions and intelligence
- Display maps, weather, tide, and water quality data
- Log and organize your catches, trips, and tackle
- Enable social features (clubs, challenges, activity feed)
2.2 Personalization
- Recommend lures and fishing spots based on your history
- Provide species-specific insights for your region
- Deliver notifications for trip briefings and weather alerts
2.3 Analytics & Improvement
- Understand app usage patterns to improve features
- Diagnose and fix technical issues
- Measure performance and reliability
3. Data Storage and Security
3.1 Where Your Data is Stored
- Firebase Firestore: EU region (europe-west3, Frankfurt, Germany)
- Firebase Storage: EU region (for photos and attachments)
- Local Device Storage: Cached data for offline functionality
3.2 Security Measures
We implement industry-standard security measures:
- Encryption in Transit: TLS/HTTPS for all data transmission
- Encryption at Rest: Firebase encrypts stored data
- Access Controls: Role-based security rules in Firestore
- Authentication: Secure Google Sign-In (OAuth 2.0)
4. Data Sharing and Disclosure
4.1 Third-Party Service Providers
We share data with the following services to operate the App:
| Service | Purpose | Data Shared |
|---|---|---|
| Google Firebase | Authentication, database, storage | Email, user ID, profile data, catches, photos |
| Google Maps | Map display, geocoding | Location coordinates, device info |
| Weather APIs | Marine/freshwater conditions | Location coordinates (anonymized) |
4.2 Social Features
When you use social features (clubs, activity feed, challenges):
- Public Profile: Display name, avatar, and badge are visible to other users
- Catches: Shared with club members or friends based on your privacy settings
- Location Data: Shared only when you explicitly post a catch or trip
4.3 No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties.
5. Your Rights (GDPR & Data Protection)
If you are in the EEA or UK, you have the following rights:
5.1 Right to Access
Request a copy of all personal data we hold about you.
5.2 Right to Rectification
Correct inaccurate or incomplete data.
5.3 Right to Erasure ("Right to be Forgotten")
Request deletion of your account and all associated data.
5.4 Right to Data Portability
Receive your data in a structured, machine-readable format (JSON).
5.5 Right to Object
Object to processing of your data for specific purposes.
5.6 Right to Withdraw Consent
Withdraw consent for location tracking, notifications, or analytics at any time.
How to Exercise Your Rights:
- In-App: Settings → Account → Delete Account or Export Data
- Email: contact@pelagiclabs.io
We will respond to requests within 30 days as required by GDPR.
6. Data Retention
- Active Accounts: Data retained while your account is active
- Deleted Accounts: Data permanently deleted within 90 days of account deletion
- Backup Retention: Backups are purged within 30 days of deletion
7. Children's Privacy
Gilli is not intended for users under 13 years of age (16 in the EEA). We do not knowingly collect data from children. If we discover a child's account, we will delete it immediately.
8. Location Data
8.1 How We Use Location
- Catch Logging: Record GPS coordinates of fishing spots
- Map Display: Show your position on the map
- Condition Predictions: Provide localized weather, tide, and ecology data
- Trip Planning: Calculate distances and routes
8.2 Location Permissions
You can revoke location permission at any time in your device settings. Some features (maps, predictions) will be unavailable without location access.
8.3 Location Data Sharing
Location data is never shared publicly by default. Shared only when you:
- Post a catch to a club feed
- Share a trip with friends
- Report a hatch (approximate location only)
9. International Data Transfers
Your data is stored in the EU region (europe-west3, Frankfurt). If you are outside the EU, your data may be transferred to and processed in the EU under Standard Contractual Clauses (SCCs) and Firebase GDPR compliance.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted in the App with a new "Last Updated" date. Continued use of the App after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy, contact us:
- Email: contact@pelagiclabs.io
- Company: Pelagic Labs
12. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Consent: Location data, photos, optional analytics
- Contract: Providing app functionality (catches, trips, predictions)
- Legitimate Interest: Improving app performance, preventing fraud
- Legal Obligation: Compliance with laws and regulations