Version: v5
Effective Date: August 17, 2026
Last Updated: August 17, 2026
This Privacy Policy ("Policy") describes how Chlorofishy ("Operator," "Chlorofishy," "we," "us," "our") — a trade name under which an individual sole proprietor offers the Service, with notice address at 530 W Ojai Ave, Suite 201, Ojai, CA 93023 — collects, uses, stores, shares, and protects information about you when you access or use the Chlorofishy ocean data visualization platform, including the website at chlorofishy.com, the Chlorofishy mobile application for iOS and Android, all associated APIs, and related services (collectively, the "Service"). The Operator's legal name will be disclosed on lawful request, including in response to a verified data-subject identity-of-controller request under GDPR Article 13(1)(a) made to [email protected].
This Policy is incorporated into and subject to the Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service. Use of cookies, mobile-app local storage, and similar technologies is further described in the Cookie Policy. By using the Service, you acknowledge that you have read and understood this Policy.
Controller / responsible party. Chlorofishy (operated by an individual sole proprietor) is the controller of personal information processed in connection with the Service. Upon any assignment to a successor entity (such as a limited liability company later formed to operate the Service), references to Operator shall mean the assignee, and you will be notified of the change as described in Section 13.
When you create an account, subscribe, configure alerts, or otherwise interact with the Service, we may collect:
When you access or use the Service, we collect certain information automatically:
$is_emulator flag, and similar non-identifying device characteristics auto-captured by PostHog. Operator does not collect Apple IDFA, Google AAID, or any other device advertising identifier. No GPS, no precise location, and no contacts/photos data is collected.chlorofishy_guest_tos (the version of the Terms you accepted as a guest), chlorofishy_pending_signup_method (a short-lived stash used to attribute a signed_up event), and chlorofishy_cookie_consent (your analytics-consent record). These values do not leave the device except as part of normal authentication or consent-mirror traffic described elsewhere in this Policy.chlorofishy_lv) that lets us later connect the visit to your account if you sign up, so we can measure whether an advertising channel produced signups — no advertising click identifier or first-party identifier is retained if you have declined Marketing cookies or sent a Global Privacy Control signal, though the campaign is still counted. This data is never sent to PostHog or any advertising platform; it is used solely for our own first-party measurement of which channels drive visits. See Section 7.6 for retention.The Service uses IP-derived approximate geolocation only. When you load the web Service, Vercel injects approximate latitude and longitude headers (x-vercel-ip-latitude, x-vercel-ip-longitude) derived from the IP address; the Service uses these headers (via the /api/geolocate route) to center the map on the nearest supported fishing region. This geolocation is approximate (typically city-level), is not stored after the request completes, and is not GPS. You can disable IP-based geolocation by clearing cookies or using a VPN; the Service will fall back to a default region. The Mobile App does not request location permission.
We may create aggregated or anonymized data from information we collect. Such data does not identify you personally and may be used for any lawful purpose, including product improvement, analytics, research, and commercial purposes.
The Service is built on top of third-party infrastructure, payment, analytics, email, and authentication providers. Each vendor named below is bound by its own privacy policy and data-processing agreement, and is contractually limited to processing personal information on Operator's behalf. Operator does not sell your personal information.
| Vendor | Role | Personal Information Processed | Region |
|---|---|---|---|
| Stripe, Inc. | Payment processing; subscription management; PCI-DSS card vault | Billing name, billing address, payment-card details (collected directly by Stripe), email, transaction history, subscription state | United States |
| Supabase, Inc. | Authentication; database; account records | Email, hashed password, auth tokens, profile preferences, alert configurations, ToS acceptance state, cookie-consent mirror | United States |
| Cloudflare, Inc. | Content delivery network; R2 object storage for tiles, value grids, buoy snapshots, and alert screenshots | IP address, request metadata; no account or auth data flows to Cloudflare | Global edge; data centers principally in the United States |
| Vercel, Inc. | Frontend hosting; serverless functions; Vercel Analytics; Vercel Cron (account-deactivation hard-delete); IP-based geolocation headers | IP address, request metadata, approximate IP-derived latitude/longitude | United States |
| PostHog, Inc. | Product analytics; session replay (when enabled); autocapture of clicks and page interactions (post-consent) | Supabase user ID, email, signup date, default region, units, named events (e.g., viewed_pass, set_alert, clicked_upgrade), automatically captured page interactions and click events (autocapture, post-consent), device/browser metadata. Hosted at us.i.posthog.com; cookies set under ph_phc_* prefix. Fires only after analytics opt-in. | United States |
| Loops, Inc. | Alert notification email delivery; subscription enrollment acknowledgment and conversion confirmation emails | Email address; alert data (alert name, layer type, observed value, capture time, screenshot URL, deep link); subscription details (plan name, amount, billing interval, trial end date) for acknowledgment emails | United States |
| Apple Inc. | Sign in with Apple; (when applicable) App Store distribution and in-app purchases | Auth handshake; Apple may provide an obfuscated relay email when "Hide My Email" is enabled; for App Store IAP, payment data is processed by Apple, not Operator | United States / Global |
| Google LLC | Google Sign-In; (when applicable) Google Play Store distribution and in-app purchases | Auth handshake (email, name, profile ID); for Play Store IAP, payment data is processed by Google, not Operator | United States / Global |
| Google LLC (Google Ads) | Advertising conversion measurement (Google Ads conversion tracking via gtag.js), subject to Google Consent Mode v2 | Ad-click identifier (gclid) when present in the URL, page URL, referrer, timestamp, device/browser metadata, a per-checkout transaction reference, and — at the moment a subscription checkout completes — the email address associated with your account in hashed form, supplied so that Google can match the conversion to the ad click that preceded it (see Section 6.4). The ad_personalization signal is governed by the Marketing / Advertising consent category: it is denied where that category is off, where a Global Privacy Control signal is present, or by default for visitors in the EEA, UK, or Switzerland who have not opted in, and granted otherwise. Cookies are set where the Marketing / Advertising consent category is enabled and no GPC signal is present (Sections 6.4, 6.5); where those signals are denied, Google may receive limited cookieless signals (see Section 6.4). | United States |
| Meta Platforms, Inc. | Advertising measurement and remarketing (Meta Pixel; Meta Conversions API) | Hashed email address, event data, advertising click identifiers, IP address, browser user agent (shared only upon Marketing consent) | United States (EU–U.S. Data Privacy Framework certified) |
| RevenueCat (only if/when in-app purchases are enabled) | Mobile in-app purchase orchestration | App-installation identifier, entitlement state, App Store / Play Store transaction metadata | United States |
| NOAA, NASA, EUMETSAT, NDBC | Public-domain ocean and satellite data sources | No user personal data is transmitted to these sources. They provide raw satellite and buoy data only. | United States / Europe |
Notice of changes. Operator may add or change subprocessors from time to time. Material additions will be posted to this Section 4 before they take effect, and may additionally be notified by in-app notice or by email to the address associated with your account. Where applicable law requires a specific notice period, a specific form of notice, or your consent before such a change may take effect, Operator will comply with that requirement. Continued use of the Service after the effective date constitutes acceptance; if you object to a new subprocessor, you may cancel your Subscription and stop using the Service.
We do not sell your personal information. We do not share your personal information with third parties for cross-context behavioral advertising. We share information only in the limited circumstances described below.
We share information with the vendors listed in Section 4, each of which acts as our subprocessor, contractually obligated to use the information only to provide services to Operator and prohibited from using it for their own independent purposes (subject to each vendor's own privacy policy as it relates to data they collect from you directly, such as Stripe's PCI-scope card data).
When you use Sign in with Google, Sign in with Apple, or magic-link email, Operator exchanges authentication tokens with the relevant provider as necessary to issue you a session. Sign-in events fire a signed_up analytics event subject to your analytics-consent choice.
We may disclose your information if required to do so by law, regulation, legal process, subpoena, or governmental request, or if we believe in good faith that disclosure is necessary to (a) comply with applicable law or legal process, (b) protect the rights, property, or safety of Operator, our users, or others, (c) enforce the Terms of Service, or (d) detect, prevent, or address fraud, security, or technical issues. Where permitted, Operator will give you notice before disclosure.
If Operator is involved in a merger, acquisition, sale of assets, bankruptcy, reorganization, or formation of a successor business entity, your information may be transferred as part of that transaction. The new entity will continue to be bound by this Policy (as it may then be amended by notice to you). See Section 13 (Changes to This Policy) and Section 19 of the Terms of Service.
We may share information in other circumstances with your express consent.
A complete inventory of cookies, web local-storage keys, and mobile SecureStore keys is maintained in the Cookie Policy. In summary:
These are required for the Service to function and are not subject to consent. They include the Supabase authentication cookie (sb-*-auth-token), the cookie-consent record cookie (cookie_consent), and the guest ToS gate cookie (guest_tos). On mobile, the equivalent values are stored in the device's secure storage as described in Section 2.2.
These remember your preferences (selected layers, last camera, default region, units). Mobile-app preferences are stored on-device with optional server mirror via your authenticated Supabase profile.
Analytics technologies (including PostHog cookies under the ph_phc_* prefix and Vercel Analytics request beacons) are disabled by default and only fire after you actively grant consent through the cookie banner or in-app consent gate. No analytics events, identifiers, or session replay are sent before you opt in. Analytics consent also activates PostHog session replay recording, which captures your interactions with the Service (clicks, navigation, and page activity) to help us understand usage patterns and diagnose issues. PostHog will not record your session before you opt in, and you may withdraw analytics consent at any time to stop recording — after which the Service will opt the analytics SDK out and clear analytics cookies. This Section covers PostHog and Vercel Analytics specifically; Google Ads conversion measurement is governed by Section 6.4, including its distinct pre-consent behavior under Google Consent Mode.
The Service uses Google Ads conversion tracking (gtag.js) to measure whether a visit resulted in a completed subscription checkout. Where you have consented to Marketing cookies, Operator uses remarketing, audience-building, and interest-based advertising through Google Ads and Meta Platforms, including the Meta Pixel and Meta Conversions API. These services receive event data (such as page views, account creation, and purchases), advertising click identifiers, and, for conversion matching, a hashed (SHA-256) version of your email address. Operator never transmits your email address in readable form to any advertising service. Ad personalization is controlled by your Marketing consent choice: if you decline Marketing cookies, or if your browser sends a Global Privacy Control signal, ad personalization is set to denied, no advertising identifiers are collected, and none of these services load or receive data. Operator uses no advertising networks other than those described in this Section. The tag loads via Google Consent Mode v2 with region-scoped defaults. If Google identifies you by IP address as located in the European Economic Area, the United Kingdom, or Switzerland, advertising storage is denied unless you affirmatively opt in through the Marketing / Advertising category in the cookie banner. Outside those jurisdictions, advertising storage is enabled by default and you may switch it off at any time through that same category or by transmitting a Global Privacy Control signal. Where advertising storage is denied, Google receives only limited, cookieless conversion signals and the conversion is modeled rather than directly measured. Where a checkout completes and advertising storage is enabled, the Service additionally supplies the email address associated with your account to Google in hashed form, so that Google can match the conversion to the ad click that preceded it; hashing occurs in your browser and Google does not receive the address in readable form. See Section 11.3 for how this interacts with your CCPA/CPRA sale-or-share rights.
Some browsers transmit "Do Not Track" (DNT) signals or Global Privacy Control (GPC) signals. When the Service detects a GPC signal, it automatically treats analytics and advertising consent as declined — including Google Ads conversion cookies and PostHog/Vercel Analytics — for that browser, regardless of any previously stored consent choice; the affected cookies are not set and no data is sent to those vendors while the signal is present. The Service does not act on DNT signals separately from GPC. Industry standards for DNT remain non-uniform; we will update this Policy as standards evolve.
When you arrive at the Service from a link carrying a recognized advertising or campaign identifier (a Google, Meta, Microsoft Advertising, or Reddit Ads click identifier, or a utm_* campaign parameter), Operator records that visit server-side — the landing page, referring page, browser user agent, the campaign identifier, and a timestamp — so Operator can measure how many visits an advertising channel produced, not only how many of those visits converted into a signup. This measurement is first-party: none of this data is sent to PostHog, Google, Meta, Microsoft, Reddit, or any other third party, and it is never used to build advertising audiences or target advertising to you. Operator's service providers, including its database host, process this data on Operator's behalf as described in Section 5. Because it does not involve reading or writing browser storage, this record is created for a tagged visit regardless of your Analytics or Marketing cookie consent choice. Operator relies on its legitimate interest in measuring the effectiveness of its own advertising as the lawful basis for this record.
A separate first-party cookie (chlorofishy_lv), gated by the Marketing / Advertising consent category described in Section 6.4, lets Operator connect a landing record to your account if you later sign up, so an advertising channel's contribution to signups can be measured. If you decline Marketing cookies, or if your browser sends a Global Privacy Control signal, this cookie is not set, the advertising click identifier is removed from the stored record before it is written, and the visit cannot be connected to any account you later create — though the visit is still counted toward that campaign. See Section 7.6 for retention and the Cookie Policy for the full cookie inventory.
We retain your account data while your account is active. If you delete your account, the deletion initiates a thirty (30) day soft-delete grace period during which you may sign in to cancel the deletion. After the grace period, a daily Vercel Cron job hard-deletes your account and associated personal data, subject to the exceptions in Section 7.2.
Per-alert tile screenshots are stored short-term in Cloudflare R2 with HMAC-signed URLs that expire after a limited period. Screenshots are deleted on a rolling cycle (typically within thirty (30) days of creation).
Server access logs containing IP addresses and request data are retained for no more than ninety (90) days for security monitoring and debugging.
PostHog event data is retained per the PostHog data-retention configuration (currently the default rolling retention applied to the PostHog project). Operator may delete a User's analytics record on request; analytics events received before opt-in did not occur (see Section 6.3).
Campaign landing records described in Section 6.6 are retained for twelve (12) months from the visit. At that point, Operator removes the advertising click identifier, the first-party cookie value, the user agent, and the referring page from the record, while keeping the visit's campaign label, landing date, and whether it was later connected to a signup — so historical measurement (e.g., how many visits from a channel converted last year) does not change after old records are anonymized. This is a longer window and a different mechanism than Section 7.4's ninety (90) day general server-log retention, because campaign records serve a distinct purpose (year-over-year advertising measurement, not security monitoring) and are anonymized rather than deleted outright.
We implement reasonable administrative, technical, and physical safeguards, including:
No method of transmission over the Internet or electronic storage is completely secure. While we take reasonable steps to protect your information, we cannot guarantee its absolute security. You are responsible for maintaining the confidentiality of your account credentials.
The Service is not directed to individuals under eighteen (18). Operator does not knowingly collect personal information from children under thirteen (13). If we learn that we have collected such information, we will take prompt steps to delete it. Contact [email protected] if you believe a child under thirteen has provided personal information.
The Service is operated from the United States and our subprocessors are principally located in the United States. If you are located in the European Economic Area ("EEA"), United Kingdom, or Switzerland, your personal information will be transferred to and processed in the United States and other jurisdictions whose laws may not provide the same level of data protection as your home country.
For such transfers, Operator and its subprocessors rely on one or more of the following mechanisms, as applicable: (a) Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum); (b) the recipient's certification under the EU–U.S. Data Privacy Framework ("DPF") or the UK Extension thereto, where the recipient is so certified (e.g., Stripe, Vercel, Cloudflare, where listed); or (c) other lawful transfer mechanisms permitted by applicable law. Contact [email protected] for information about the specific transfer mechanism applicable to your data.
Regardless of location, you may:
If you are in the EEA, UK, or Switzerland, you have these rights under the General Data Protection Regulation ("GDPR") and equivalent UK and Swiss legislation:
Lawful bases for processing.
| Purpose | Lawful Basis |
|---|---|
| Account creation and management | Performance of contract |
| Subscription billing | Performance of contract |
| Providing Service features | Performance of contract |
| Transactional communications | Performance of contract |
| Alert notifications | Performance of contract / legitimate interest |
| Security and fraud prevention | Legitimate interest |
| Service improvement and analytics (post opt-in) | Consent |
| Marketing communications | Consent (opt-out available) |
| Legal compliance | Legal obligation |
To exercise these rights, contact [email protected]. We will respond within thirty (30) days, or within the timeframe required by law, and may verify your identity before processing the request.
Data Protection Contact. [email protected]. Operator has not appointed a Data Protection Officer; we will appoint one if and when required by Article 37 of the GDPR.
If you are a California resident, the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA") provides additional rights.
Categories of personal information collected (in the preceding twelve (12) months):
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Name, email address, IP address, account ID, device identifiers (non-advertising) | Yes |
| Customer records | Billing name, billing address (held by Stripe) | Yes (via processor) |
| Commercial information | Subscription history, transaction records, entitlements | Yes |
| Internet/electronic activity | Map and feature interactions, alert configurations, browsing within the Service | Yes |
| Geolocation data | Approximate IP-derived location; map regions viewed | Yes (approximate, not GPS) |
| Inferences | Usage patterns, feature preferences | Yes |
| Sensitive personal information | None (we do not collect government IDs, precise geolocation, biometrics, financial-account numbers, race, religion, health, sexual orientation, etc.) | No |
Sale or sharing for cross-context behavioral advertising. Operator does not sell personal information for monetary consideration. Operator shares the following categories of personal information with advertising partners (Google LLC and Meta Platforms, Inc.) for cross-context behavioral advertising as defined by the CCPA/CPRA: identifiers (hashed email address, advertising click identifiers, cookie identifiers, IP address) and internet activity (pages visited, actions taken on the Service). This sharing occurs only with your Marketing consent and is subject to your right to opt out described below. The Service honors any Global Privacy Control (GPC) signal it detects as a valid opt-out request, automatically disabling advertising cookies for that browser (Section 6.5).
Your California rights.
To exercise these rights, contact [email protected]. We will respond within forty-five (45) days as required by law and may verify your identity by matching information you provide against information in our records.
Authorized agents. You may designate an authorized agent by providing signed written authorization. We may still verify your identity directly.
Shine the Light. Under California Civil Code §1798.83, California residents may request information about personal information disclosed to third parties for direct-marketing purposes. Operator does not disclose personal information to third parties for their direct-marketing purposes.
If you are a resident of Virginia (Consumer Data Protection Act), Colorado (Colorado Privacy Act), Connecticut (Connecticut Data Privacy Act), Utah (Utah Consumer Privacy Act), Texas (Texas Data Privacy and Security Act), or another U.S. state with a comparable comprehensive privacy law, you have rights to access, correct, delete, and obtain a portable copy of your personal data, to opt out of targeted advertising and the sale of personal data, and (in some states) to appeal a denied request. Operator does not sell personal data for monetary consideration. Operator engages in targeted advertising with consent as described in Sections 6.4 and 11.3, and residents of states providing an opt-out right for targeted advertising may exercise it through the "Do Not Sell or Share My Personal Information" link in the site footer or by sending a Global Privacy Control signal. To exercise these rights, contact [email protected]; we will respond within the timeframe required by your state's law (typically 45 days).
Users in other jurisdictions may have additional privacy rights under local law. Contact [email protected] to discuss any rights that apply to you.
This Section applies in addition to the rest of this Policy when you use the Mobile App.
For Apple App Store privacy nutrition labels and Google Play Data Safety disclosures, refer to the listings on the App Store and Play Store (when published). Operator's listings will be consistent with this Policy.
We may update this Policy from time to time. We will indicate updates by changing the "Last Updated" date. For material changes (such as adding a new subprocessor that materially expands data sharing, changing the categories of personal information collected, or changing data-retention practices), we will provide notice before the change takes effect by a method reasonably calculated to reach you, which may include posting the revised Policy on the Service, displaying an in-app notice, or sending email to the address associated with your account. Where applicable law requires a specific notice period, a specific form of notice, or your consent before a change may take effect, we will comply with that requirement. Continued use of the Service after the effective date constitutes acceptance of the revised Policy. If you do not agree, your sole remedy is to stop using the Service and delete your account.
The Service may contain links to third-party websites or services not operated by Operator (including links to NOAA, NASA, OpenFreeMap, and similar). This Policy does not apply to those third-party services. Review their privacy policies before providing them with your information.
For questions, concerns, or requests regarding this Policy or our data practices:
For GDPR-related inquiries, please include "GDPR Request" in the subject line. For California or other U.S. state privacy requests, please include "State Privacy Request" in the subject line.
This Privacy Policy (Version v4) was last updated on August 1, 2026.