1. About this policy
Aqua AI is currently in development. Available features may differ by build. Google, Apple and email sign-in are planned; the current account implementation uses Firebase guest authentication. Store subscriptions and native analytics depend on the integrations enabled in your build. We will update this policy before introducing materially different processing.
This policy covers our processing as the app operator. Apple, Google and other providers may separately process information under their own policies when you use their accounts, stores or services.
2. Information we process
Account information. The app creates a persistent Firebase guest identifier and stores authentication credentials on your device. Guest use is pseudonymous: our systems can associate records with your identifier. When email, Google or Apple sign-in is made available, we process the account identifier, email and any name provided through the selected method. Apple may provide a private relay email. We do not receive your Google or Apple password; email authentication credentials are handled by Firebase Authentication.
Aquarium content. Photos you select or take; aquarium and livestock names; equipment, dimensions, species, notes, dates and water readings; associations between records; AI results; and your edits and corrections. Results may contain observations about aquatic life. Avoid including people, children, documents, addresses, passwords or other sensitive personal information in photos and text.
Purchase information. Apple or Google processes store payments. RevenueCat and Aqua AI process account-linked product and transaction identifiers, entitlement status, purchase and renewal dates, expiry, cancellation and refund information to manage access. We do not ask for or receive your full payment-card number through the app.
Technical and support information. Providers may process IP addresses, app and device information, request times, authentication and security signals, operational errors and service usage. Our backend can store request identifiers, image fingerprints and processing results to prevent duplicate requests. If you contact us, we receive your email and the information you provide.
3. Photos and AI processing
An online scan sends a resized or compressed copy of your selected photo through our server to Google Gemini Developer API. Keeping a photo on your device does not mean that online analysis stays on the device. Selecting a photo for an online scan starts AI analysis without a separate confirmation dialog. Camera and photo-library permissions are managed separately by your device.
Saved profile photos are currently stored locally. Cloud records may contain a local photo reference, but this is not a downloadable photo backup. AI results, profiles and correction histories may be stored under your user identifier. Editing or removing a local result does not necessarily remove the original cloud prediction; request account/data deletion to address those copies.
Catalog enrichment can send the entered item name, original prediction, scientific hint and existing general catalog information to Gemini. General species or equipment information may enter a shared catalog. Account-linked profiles and correction histories are separate records. Do not include personal information in item names.
Google’s Gemini data use depends on the applicable service arrangement. For unpaid services, Google may use inputs and outputs to improve products and machine learning, and human reviewers may examine content. Paid-service terms state that prompts and responses are not used to improve Google products, while allowing limited safety-related logging. We do not promise zero provider retention. Development service configuration may change; do not submit sensitive, confidential or personal information for AI processing. Before public app release we will identify the applicable production arrangement in this policy. See the Gemini API terms linked below.
4. Why we use information
We use information to authenticate users, provide requested scans and catalog information, store aquarium records, manage subscriptions, provide support, prevent misuse, protect accounts, process privacy requests and meet legal obligations.
Where European or UK data protection law applies, we rely on performance of a contract for requested account, scan and subscription services; legitimate interests for proportionate security, fraud prevention and support; legal obligations for required records; and consent for optional analytics or other processing where consent is required. You can withdraw consent without affecting the lawfulness of earlier processing.
AI outputs support aquarium decisions. They are not intended to make decisions about people producing legal or similarly significant effects.
5. Usage analytics and permissions
Usage analytics is enabled automatically when native Firebase Analytics is configured in your build. In this version, we collect app interactions and scan performance, such as app opens, premium-screen views, scan success/failure, processing time, image size and scan category. Firebase may additionally process installation identifiers, device/app information and session data. We do not set your Firebase account UID as an analytics user ID.
Our analytics events exclude photos, file paths, free-text notes, email addresses and full AI responses. Advertising identifier collection is disabled in the app configuration, and we do not use advertising SDKs or sell personal information or share it for cross-context behavioral advertising. We must reassess this policy before introducing advertising or tracking.
This version does not include an in-app analytics switch. Contact us about privacy rights or deletion requests. Account deletion disables this integration and resets local analytics data when the native SDK is available; previously uploaded events are subject to the analytics service retention and deletion process.
Camera and photo-library permissions allow you to take or select an image. You can change them in device settings. We do not request access to contacts, microphone or precise GPS location. Content inside a photo can nevertheless reveal a location or other personal information.
6. Providers, disclosures and transfers
We use Google/Firebase for authentication, database and backend services; Google Gemini for online analysis and catalog enrichment; RevenueCat for subscriptions; Apple and Google for store payments and supported sign-in; and hosting/security infrastructure for the website. Information is shared as needed for these functions. We may also disclose information when legally required, to address fraud or security threats, or in a business transfer subject to applicable protections and notice.
We operate from the United States and our providers may process information there and in other countries where they operate. Applicable provider data-processing terms, transfer safeguards and any local requirements depend on the service and your location. Contact us for information about the safeguards applicable to your data. We do not represent that all data stays in your country.
Relevant provider information is linked below. Provider policies supplement this notice; they do not remove our responsibilities as the operator.
7. Retention and deletion
We retain account and saved aquarium records while needed to provide your account and requested history, or until a verified deletion request is processed. Original predictions and corrections can form part of that history. Local files remain until deleted from the device or cleared by the app. Device backups may have a separate lifecycle. Uninstalling does not automatically erase cloud records.
Account deletion covers the Firebase account, private aquarium records, predictions, corrections, catalog links, associated processing jobs and our RevenueCat customer profile. General species facts that contain no personal information may remain. Store providers may retain transaction records under their own legal obligations. We retain only limited records needed for security, legal obligations or disputes, for as long as that purpose requires.
We aim to complete verified deletion requests within 30 days and follow shorter legal deadlines where applicable. If a lawful extension is needed, we will explain it. A request being received is not confirmation that deletion is complete. The in-app request flow, when connected, provides a private receipt for checking completion without emailing support. During development, use the account deletion page if the in-app service is not yet connected.
After completion, the connected app clears its local records and photos on this device when it checks your request. Other devices and operating-system backups may need separate cleanup. We retain a minimal deletion receipt and account-blocking record for up to 90 days to confirm completion and prevent queued writes recreating records. Provider backup deletion can take additional time under the provider’s documented cycle.
Support correspondence is ordinarily reviewed for deletion 12 months after the issue closes. Operational/security records are retained only as long as reasonably necessary for their purpose. Analytics retention is governed by the configured analytics service; its final production retention setting will be disclosed before launch.
8. Requests and privacy rights
Use Privacy & account → Delete account in a connected app build, or the account deletion page linked below. You can also email benbaler@gmail.com about access, correction, deletion, a portable copy, restriction or objection to processing. Rights and exceptions depend on applicable law. We verify ownership proportionately; do not send passwords, authentication tokens or full payment details.
We respond within applicable legal deadlines and explain any lawful limitation. Where available, you may appeal a decision or complain to your local data protection authority. We will not unlawfully discriminate against you for exercising privacy rights.
Deleting your account does not cancel an Apple or Google subscription. Manage or cancel it separately in your store account. You may request deletion without first canceling a subscription.
9. Teenagers and children
Aqua AI’s selected audience is people aged 13 and older. The service is not intended for children under 13. Teenagers may need a parent or guardian’s authorization under applicable law; a minimum age of 13 does not override a higher local consent requirement.
If you believe a child under 13 provided personal information, contact benbaler@gmail.com so we can investigate and arrange appropriate deletion. We do not use this policy as a substitute for any legally required parental consent.
The app remains in development. Public access by teenagers depends on compatible provider terms and appropriate privacy controls; this policy is not a statement that those release requirements have been satisfied.
10. Website, security and changes
The informational website has no scan upload, account registration, payment form or advertising tracker. If you choose Allow analytics, the site loads Google Analytics to measure page views, scrolls, outbound-link clicks, referral source and general browser, device and approximate-location information. We do not send photos, account identifiers, email addresses or free-text content through the website analytics tag. Advertising storage, Google signals and ad personalization are disabled.
Your analytics choice is stored in your browser. You can reopen Privacy choices on the website and choose No thanks to stop analytics on later visits from that browser. Google and our hosting and security infrastructure may process IP addresses, request logs and security cookies. An email link opens your email application; nothing is sent until you send the message. External links are subject to the destination’s policies.
We use safeguards appropriate to our services, but no system guarantees absolute security. Protect your device and credentials and keep copies of important aquarium records. The app is not a secure vault or a guaranteed backup.
We will update the effective date when this policy changes and provide appropriate notice of material changes. Where new processing requires consent, a policy update alone will not replace it. Contact Ben Baler at benbaler@gmail.com for privacy or support inquiries.
Contact Ben Baler
Email: benbaler@gmail.com. An email link opens your mail app; you review and send the message yourself.