Privacy Policy

Effective date: 2026-05-11

This Privacy Policy describes what data Aquarium Coach (the iOS app, hereafter "we" or "the app") collects, why, who else sees it, and the choices you have. It is written in plain English on purpose. If anything is unclear, email us at amtyurin@gmail.com.

Contents
  1. The short version
  2. Data we collect
  3. Who else sees your data
  4. Where your data lives
  5. How long we keep your data
  6. Encryption and security
  7. Your rights and choices
  8. Children
  9. Changes to this Policy
  10. Contact
  11. Apple App Store disclosures

1. The short version

2. Data we collect

2.1 Photos

When you tap "Scan Strip" or "Tank Health Scan", the app sends a photo (compressed to ≤1280px, JPEG) to our backend at aquariumcoach-api.cpmtek.com. Our backend forwards it to Anthropic's Claude API for AI analysis, then receives the AI's parsed response (text only). We log the AI's text response for debugging, but we do NOT persist the image bytes after the API call returns.

2.2 Apple User ID (only if you Sign in with Apple)

If you choose Sign in with Apple, we receive an opaque identifier (Apple calls it the "user" or "sub" claim) that uniquely identifies you to our app. This identifier:

We do NOT receive your real Apple ID, your real email (unless you choose to share it), or your name (unless you choose to share it).

2.3 Optional: name and email (only if you share via Sign in with Apple)

When you Sign in with Apple, Apple lets you choose:

If you share name/email: we display your name in Settings on your device. We do NOT store the email on our backend. We never sell or share these to anyone.

2.4 In-app reminders, livestock, equipment, tank notes

Everything you log in the app — tank names, gallons, livestock species, equipment install dates, water-change reminders, test result history, AI scan readings — lives:

  1. On your device (encrypted SwiftData storage)
  2. In your private iCloud database (only if you've enabled iCloud sync), encrypted by Apple under your Apple ID

This data is NEVER sent to our backend. We don't have access to it. If you turn off iCloud sync, it stays solely on your device.

2.5 Crash and performance diagnostics

The app may collect anonymized crash reports and performance metrics (frame rate, memory usage, etc.) to help us identify bugs. These reports do NOT include photos, tank data, or your identifier. They are aggregated and used only to fix bugs.

If you opt out of "Share with App Developers" in iOS Settings → Privacy & Security → Analytics & Improvements, we receive no diagnostics at all.

2.6 In-app purchases

When you buy Pro Monthly, Pro Yearly, or Pro Lifetime, the transaction is processed entirely by Apple. Apple sends us a signed notification (App Store Server Notifications V2) telling us the transaction occurred so we can grant the entitlement. We receive:

We do NOT receive your credit card number, billing address, or any other payment information. Apple handles all of that.

2.7 What we do NOT collect

We never collect: your location, contacts, health/fitness data, browsing or search history, audio recordings, biometric data, financial account info, contacts, calendar events, photos other than ones you explicitly submit for scanning, advertising identifiers (IDFA), tracking IDs of any kind. We don't use any third-party analytics SDK that tracks you across other apps (no Google Analytics, no Facebook SDK, no Mixpanel, no Segment).

3. Who else sees your data

3.1 Anthropic

Photos you submit for AI scanning are sent to Anthropic for analysis. Their privacy policy: https://www.anthropic.com/legal/privacy. We use Anthropic's API in standard mode — they may retain submissions briefly for abuse monitoring per their published policy but do NOT use submissions to train their models when accessed via the paid API.

3.2 Apple

Apple handles:

Apple's privacy policy: https://www.apple.com/legal/privacy/

3.3 Cloudflare

Network traffic from your device to our backend transits Cloudflare's edge (we use Cloudflare Tunnel for network ingress). Cloudflare may log connection metadata (IP address, timestamp, request size). They do not see request bodies (encrypted in transit). Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/

3.4 We never sell or share data with anyone else

We do NOT sell any data. We do NOT share data with advertisers, data brokers, marketing platforms, social media platforms, or any other third party not listed above.

4. Where your data lives

DataStorage location
Tank, livestock, equipment, reminders, test historyYour device (SwiftData) + your private iCloud database (if enabled). NEVER on our backend.
Sign in with Apple identifier (only if signed in)Our backend's Postgres database, hosted on cpmtek-controlled hardware
AI scan response text logsOur backend's Postgres database, retained ~30 days then auto-purged
Pro entitlement recordsOur backend's Postgres database, retained indefinitely (needed for billing reconciliation)
Photo bytes during AI scanningRAM only, during the ≤30 second API call. Then discarded.

Our backend is currently hosted on a small Kubernetes cluster on cpmtek-managed hardware. As we scale, this may move to a managed cloud provider (AWS, GCP, or DigitalOcean). Your data remains within the United States and EU regions only.

5. How long we keep your data

TypeRetention
On-device data (SwiftData)Until you delete the app or tap Settings → Delete all local data
iCloud-synced dataPer Apple's iCloud retention. Deleted from your iCloud when you delete the app or sign out.
AI scan response logs~30 days, then auto-purged by a scheduled job
Sign in with Apple ID + Pro entitlement stateUntil you request deletion (see §7), or 7 years after your last sign-in (whichever is earlier), to satisfy tax record-keeping for the IAP revenue
Photo bytesNever persisted past the AI call (~30 seconds in memory)

6. Encryption and security

We do not yet have a SOC 2 or ISO 27001 certification. This may change as we grow.

7. Your rights and choices

7.1 Access and portability

7.2 Deletion

7.3 Opt out of analytics

iOS Settings → Privacy & Security → Analytics & Improvements → Share with App Developers → toggle OFF. We will receive no diagnostics from your device.

7.4 Use the app without an account

You can use the app without ever signing in. All your data stays on your device + your private iCloud (if you've enabled it). You will:

7.5 GDPR / CCPA / EU-UK rights

If you're in the EU, UK, or California, you have additional rights under GDPR / UK GDPR / CCPA respectively, including:

To exercise any of these, email amtyurin@gmail.com. Our legal basis for processing is "performance of a contract" (delivering the app you've installed) for app data, and "legitimate interest" (running the app's anti-abuse systems) for diagnostics.

8. Children

Aquarium Coach is rated 9+ in the App Store. It is not directed at children under 13. We do NOT knowingly collect personal data from children under 13. If you are a parent or guardian and believe we have collected personal data from a child under 13, email amtyurin@gmail.com and we will delete it.

9. Changes to this Policy

We may update this Privacy Policy as the app evolves. When we do:

10. Contact

Questions about this policy or about data we hold about you:

amtyurin@gmail.com

11. Required Apple App Store disclosures

Per Apple's App Privacy nutrition labels (visible on the App Store listing):

Data collectedLinked to your identityUsed to track youPurpose
PhotosNoNoApp Functionality
User IDYesNoApp Functionality
Crash DataNoNoApp Functionality
Performance DataNoNoApp Functionality, Analytics

Everything else is Not Collected.