Privacy Policy
Which data is collected on the site and in the mobile app, who it goes to, how long it is kept and what happens when you delete your account.
This translation is provided for information only. The binding text is the Turkish version.
This page tells you which data is collected on the Piscatorium website and in its mobile app, who it goes to and how long it is kept. The legal bases and the full list of your rights are in the Personal Data Protection Notice.
No account is needed to read the site only, and no location permission is asked for. When you open an account, log a catch or use the mobile app, the data collected grows; below, each case and when it comes into play is written out separately.
The data collected
For everyone
- Session cookie. Needed for verifying forms against forgery (CSRF). The site does not work without it.
- Server access logs. IP address, browser information and the requested address; kept by the hosting infrastructure. Their purpose is debugging and abuse detection.
- Analytics. If analytics is on, page usage is measured; if it is off, the analytics code is never sent to your browser. The cookie table below shows this live.
If you join the waiting list
- Your email address. Only to send the announcement. It is not added to a marketing list and is not given to third parties.
- IP address and browser information. Kept in order to tell automated sign-up attempts apart; not used for any other purpose.
If you open an account
- Name, email address and password hash. The password itself is never kept in the clear anywhere. We do not send a verification link to your email address.
- Your profile address. It is a short name derived from your name and it appears in the public address of your profile.
- Your profile photo, if you upload one. It is re-encoded on upload and its embedded metadata (GPS included) is dropped. You can turn off showing it on the profile.
- The version of the text you accepted and the time of acceptance. Kept as proof of your consent.
- If you signed in with Google or Facebook, the name, email and account ID coming from that service.
Your profile is public. Your name, your profile photo and the catch logs you share publicly can be seen by everyone, visitors who are not signed in included. There is at present no setting that hides the profile completely.
If you log a catch
- Location. The location of every catch log is held at three separate precisions: the exact coordinates you enter, the approximate point derived from them, and the option of not being shown at all. As you share the log you decide which one is visible; the default is hidden.
- Photos. They are re-encoded on the server and all embedded metadata is dropped — the GPS coordinates, the device model and the serial number included. The profile photo goes through the same process.
- Date, time, species, technique, tackle and your notes, plus the weather, sea and moon/sun data at the moment of the log.
If you use the community features
Your comments, your likes, the people you follow, the people you block and the reports you send are recorded. Commenting and liking are only possible on catch logs shared publicly.
If you use the mobile app
- Location permission — only while the app is open. Your location is not tracked in the background.
- Photo permission — to pick catch and profile photos.
- Notification permission — if you grant it, your device’s notification token is stored. If you do not, the app keeps working.
- Crash and usage logs. If the app crashes, a technical log is sent; those logs are not associated with your account.
- Advertising. Ads are shown to free users. The ads are not personalized; the ad network still sees your device’s advertising identifier and IP address.
If you move to Pro membership
Your subscription status and your start and end dates are stored, and your user identifier is sent to the subscription infrastructure. Your card details never reach us; payment is completed in the system of the store you downloaded the app from.
Administrator accounts
The name, email address and password hash of panel users are stored.
Cookies
| Cookie | Purpose | Duration |
|---|---|---|
| piscatorium-session | Session and form security (CSRF). Required. | 120 minutes |
| XSRF-TOKEN | Verifying form submissions against forgery. Required. | 120 minutes |
| cerez_onayi | Remembering your cookie choice. Required. | 1 year |
| _ga, _ga_* | Google Analytics — visitor counting. Not required. | 2 years |
| _clck, _clsk | Microsoft Clarity — heatmaps and session recording. Not required. | _clck 1 year · _clsk 1 day |
This list is not hard-coded: it is generated from the current configuration of the site. If analytics is off, the analytics cookie does not appear in the list and is never sent to your browser either.
When you sign in, a persistent session cookie is also issued; it keeps your session open when you close and reopen your browser and it lives at most 400 days.
Third parties
We do not send data outside on your behalf. The services below come into play as a requirement of running the site and the app:
Google Analytics 4
- What for:
- How much each page is read
- Data it sees:
- Cookie identifier, pages visited, device and approximate location
GA4 does not store your full IP address. The admin panel is excluded from measurement.
Microsoft Clarity
- What for:
- Heatmaps and session recording — clicks, scrolling and mouse movement
- Data it sees:
- Cookie identifier, pages visited, click and scroll activity, device and browser information, IP address
Text on the page is masked by default; what you type into form fields is not recorded. The admin panel is excluded from measurement.
Ahrefs Web Analytics
- What for:
- Page view and referring site measurement
- Data it sees:
- IP address, page visited, referring address, browser information
Does not use cookies. The admin panel is excluded from measurement.
Esri (World Imagery)
- What for:
- Satellite imagery tiles on the map
- Data it sees:
- Your IP address and which map tile you are viewing
The tile request goes directly from your browser; our server does not relay it.
OpenStreetMap
- What for:
- The street base layer of the map
- Data it sees:
- IP address and tile requests
Only when you select the “Street” base layer.
EMODnet Bathymetry
- What for:
- Sea depth layer
- Data it sees:
- IP address and tile requests
Only when you turn on the depth layer.
The site is also published behind a content delivery network; that network sees the IP address and the browser information of every request that reaches the site.
Weather and sea data is not taken directly from a third party: our server collects it and serves it to your browser from our own address. The fonts come from our own server too, so no font request goes out.
Retention periods
- Your account and content: until you delete your account.
- Catch photo files: thirty days at the latest after the account is deleted.
- Waiting list: until the announcement is sent; deleted on request thereafter.
- Session records: dropped after 120 minutes of inactivity.
- Persistent session cookie: at most 400 days.
- Administrator accounts: until the account is closed.
Deleting your account
You can delete your account from the account screen in the mobile app; the operation cannot be undone. Your account and your content are closed to access, your profile photo is removed from disk immediately and your catch photos within thirty days at the latest; your likes, follows, notifications and comments are permanently deleted. The details are in the Personal Data Protection Notice.
Your rights
To leave the waiting list, to delete your account, to access your data or to ask for it to be corrected, writing to the address on the contact page is enough. Your rights and the application process are set out in detail in the Personal Data Protection Notice.
Last updated:
Piscatorium