PRIVACY POLICY
BlueEscape App (Android · gr.mytilini.fishing)
This Privacy Policy replaces any previous version as from the date of its publication. English translation of the Greek Privacy Policy; the Greek text is the binding version and prevails in case of divergence.
1. Data controller
The data controller is Nikolaos Tsalikis, a natural person (the “Publisher”). Contact: TsNickGr@gmail.com.
2. Core principle — what stays on your device
Your journal, photographs, spots and notes are stored exclusively on your device. Your device also stores the record of your acceptance of the Terms of Use and of your consent to the service beginning — date, time and the version number of the Terms then in force — which is not sent to any server.
Some data leaves the device only at the moment it is needed and only for the described purpose: the photograph when you request recognition, the audio when you use voice entry, the purchase token for verifying your subscription, the coordinate for country determination, tide and wind data, and technical error reports.
Only the following are held on a server: the hashed device identifier for abuse prevention, the records relating to your subscription, and technical error reports. Each is described in detail below, together with its retention period.
3. Data categories, purposes and legal bases
3.1 Photograph for recognition
Purpose: recognition of the species you actively request. Legal basis: Article 6(1)(b) GDPR (performance of a contract). The photograph follows the route: device → our server (Cloudflare) → artificial-intelligence provider (Google/Gemini). The App never communicates directly with the provider; the access key is held exclusively on the server. This route applies both to single-catch recognition and to multi-species recognition from a single photograph. The photograph is not stored by the Publisher and is transmitted only at the moment of recognition. It involves a transfer outside the EEA (see section 6).
3.2 Voice-entry audio
Purpose: recording a catch by speaking. It is optional and activated by an express action of yours; legal basis: Article 6(1)(a) GDPR (consent). The audio is processed by Google’s speech-recognition service via the operating system, in the same way as voice typing, and is governed by Google’s terms. The Publisher does not store or send the audio. Voice entry does not constitute recognition: the speech is converted to text and matched locally against the device catalogue. If it fails, the recognised text is stored locally on your device to improve matching and remains on the device.
3.3 Device identifier (abuse prevention)
Purpose: solely the security of the service and the prevention of abusive use and circumvention of its limits. The right to use the subscription derives from the Google account via Google Play Billing and not from the identifier; the identifier does not serve functionality but is kept only as a safeguard against abuse. Legal basis: Article 6(1)(f) GDPR (legitimate interest in the security of the service and the prevention of abuse).
The identifier is never transmitted in readable form. It is subjected to a one-way hash on your device before being sent, so that the server never receives the original value, and it is hashed again on the server with a secret key that is not contained in the App. The hash is irreversible: not even the Publisher can recover your device’s original identifier from it. The second layer is applied because the Android identifier is of limited length and a plain hash could be reversed by exhaustively trying all possible values.
Records that use the hashed identifier to control the frequency of requests are retained for sixty (60) seconds and are then automatically deleted.
For the sake of transparency, it is noted that despite the hashing this value still allows a device to be singled out and is therefore treated as personal data. It is not used for functionality, profiling, statistics or advertising.
3.4 Purchase token and subscription records
Purpose: verifying your subscription so as to activate the Recognition Service and enforce the quantitative recognition limit. Legal basis: Article 6(1)(b) GDPR (performance of a contract).
The purchase token is sent from the device to our server and transmitted to the Google Play Developer API for verification. The server holds records linked to the purchase receipt which serve the verification of the subscription and the enforcement of the limit; one of them links the purchase receipt to your hashed device identifier.
Retention: the record linking the purchase receipt to the device is automatically deleted one hundred and eighty (180) days after your last use of the App.
The remaining records linked to the purchase receipt are automatically deleted at the latest thirty-seven (37) days after the end of the billing period to which they relate. If the App communicates with our servers after expiry, the verification records are created anew and are deleted at the latest seven (7) days after that last communication.
The purchase token itself is deleted from your device as soon as Google confirms that the subscription is no longer active.
3.5 Location
Location serves three distinct purposes.
(a) Tide service. Optional, activated by an express action on your part; legal basis: Article 6(1)(a) GDPR (consent), revocable at any time. The coordinate is transmitted to the TideCheck service without rounding. This is deliberate: the time of high tide differs materially over short distances — open sea and an enclosed bay may be a few kilometres apart — and an inaccurate time would be more harmful to you than the precision of the position.
(b) Country determination. Exclusively from the GPS location, to decide whether a legality check is displayed. For this purpose the coordinate is processed by the operating system’s geocoding service (Google) in order to be converted into a country code. Legal basis: Article 6(1)(b)/(f) GDPR. The account country, mobile-network country and IP address are not used. The country is confirmed once per fishing trip and retained for its duration.
(c) Wind data. To display wind speed, gusts and direction; legal basis: Article 6(1)(a) GDPR (consent). The data is obtained from the OpenWeather service via our server; the App never communicates directly with the provider. Before transmission, our server rounds the position so that the provider receives a wider area rather than your exact location (currently approximately eleven kilometres). Because the transmission is made by our server, the provider does not receive your device’s IP address either.
3.6 Crash reports (Firebase Crashlytics)
Purpose: diagnosing and fixing errors. Legal basis: Article 6(1)(f) (legitimate interest). Google (Firebase Crashlytics) acts as processor. The report contains technical data (error location, device model, versions) and a technical installation identifier generated by the Crashlytics service. It does not include a photograph, location, journal or user content. It may involve a transfer outside the EEA.
3.7 Technical recognition errors
Purpose: improving recognition reliability. Legal basis: Article 6(1)(f). Only the error code/message, the provider and model, and a timestamp are sent to our server. The last one hundred (100) records are retained and older ones are automatically deleted. No photograph, location or device identifier is sent. At the network/infrastructure level the IP address may be processed for security/operational purposes.
3.8 Map background (MapTiler)
Purpose: displaying the map of your spots. Legal basis: Article 6(1)(b)/(f) GDPR. When you open the map, the map-tile requests to the MapTiler service reveal the displayed area — which derives from your stored catch locations — together with the IP address. Raw catch coordinates are not transmitted. It may involve a transfer outside the EEA (see section 6).
4. What we do not do
The App does not integrate any analytics system — verified in the code. It does not display advertising, does not build profiles, and does not sell data.
5. Recipients and processors
- Google: Google Play Billing (subscriptions/payments), Firebase Crashlytics (crash reports), speech-recognition service (audio), geocoding service (country determination), and processing of the photograph for recognition via Gemini.
- MapTiler: map-background provider for the spots screen.
- OpenWeather: wind data provider; receives a rounded position via our server and not your device’s IP address.
- TideCheck: tide data provider; receives the coordinate without rounding, as set out and for the reasons given in section 3.5(a).
- Infrastructure provider (Cloudflare): hosting of our server.
6. International transfers
Some recipients may process data outside the EEA (in particular in the USA). Such transfers are carried out with the appropriate safeguards of Chapter V GDPR (standard contractual clauses and/or an adequacy framework).
7. Retention
Each data category is kept only for as long as necessary for its purpose, as described above. In summary:
- Hashed device identifier: for as long as necessary for abuse prevention; the request-frequency control records, sixty (60) seconds.
- Purchase-receipt-to-device link record: one hundred and eighty (180) days from your last use of the App.
- Remaining subscription records: at the latest thirty-seven (37) days after the end of the billing period; if the App communicates with our servers thereafter, the verification records are deleted at the latest seven (7) days after that communication.
- Technical recognition errors: up to the last one hundred (100) records.
8. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, as well as to withdraw consent where it is the basis, without retroactive effect.
Erasure procedure: send a request to TsNickGr@gmail.com with the subject “Data erasure request”, stating the identifier shown in the App’s Settings. Erasure covers the hashed identifier and the subscription records traceable through it. The request is satisfied without undue delay and within one month (extendable by two months for complex requests). Manifestly unfounded or excessive requests, in particular repetitive ones, may be refused or charged, on a case-by-case and reasoned basis (Article 12(5) GDPR).
Limit of targeted erasure: the subscription records are located through the record linking the purchase receipt to the device. If more than one hundred and eighty (180) days have elapsed since your last use of the App, that link has already been deleted and the records can no longer be located from the identifier shown in Settings; in that case targeted erasure on request is not possible. Those records are in any event deleted automatically, as set out in section 7.
You have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).
9. Security
Reasonable technical and organisational measures are taken (Article 32 GDPR), including pseudonymisation by irreversible hashing, encrypted data transmission, and limitation of the data held to what is strictly necessary.
10. Minors
The App is intended for adults (18+) and is not intended for minors.
11. Amendments
This policy may be updated. The version in force is published, with a date, at the address stated on Google Play.
12. Contact
For any matter regarding this policy: TsNickGr@gmail.com.