Tightlog Privacy Policy
Last updated: 28 August 2026
Tightlog is a fishing logbook provided by Luke Howsam, who is the data controller for the purposes of UK and EU data protection law. This policy explains what information Tightlog uses and how it is handled, and this page is the only place it is published.
Information stored on your device
Your catches, photos, fishing spots, sessions, settings and app preferences are stored locally on your device, and the app works fully without an account and without a network connection.
The app reads your camera, photo library, microphone and location only when you grant the relevant permission, and each one is requested at the point you use the feature:
- Camera - photographing a catch, and the fish identification screen
- Photo library - attaching an existing photo, and saving AI artwork
- Microphone - only while recording video of a catch
- Location, while using the app - stamping a catch or a spot with coordinates, and fetching local weather, tide and river conditions
Weather and tide conditions come from Open-Meteo, and river levels in the UK come from the Environment Agency. Place search uses OpenStreetMap's Nominatim and Photon. These requests carry only the coordinates or the search text you typed - never your name, your logbook or any account identifier.
You can export your logbook or delete entries from the app at any time. A copy is kept on Tightlog's servers only if you turn cloud backup on, as described next.
Cloud backup
Copying your logbook to Tightlog's servers is optional and stays off until you turn it on. Onboarding asks which you want, and you can change it at any time in Settings > Data & backup > Cloud backup. While it is off, no catch, photo or coordinate is uploaded unless you share that catch yourself.
When you turn it on, your catches, spots, sessions, notes and the photos attached to them are copied to Tightlog's servers as you record them, over an encrypted connection. It needs no account or email address.
Each logbook is tied to a sync key generated on your device. Your recovery code is that key, and it is what restores the logbook onto a new phone. Keep it somewhere safe, and treat it like a password, because anyone holding it can reach your logbook. On iPhone the key is also stored in your iCloud Keychain, so it carries across your own devices without you doing anything.
If cloud backup is on and you lose the code, our support team can help as a last resort: we hold an encrypted copy of it for that case only, and only use it once we have verified it is really you. If cloud backup is off, we hold nothing and cannot restore a lost code.
Backed-up data is stored on servers we control and is protected by access controls. We do not sell it, mine it, or use it for advertising, and we access it only where needed to run the service or to answer a request from you.
Accounts
Optional account features use Clerk for authentication. Clerk may process your email address, user identifier and authentication information. An account is needed only for the social features - friends, groups, competitions, and publishing a catch to the public feed. Everything else in the app works signed out.
Notifications
Some notifications - the daily debrief, bite windows, the top-day outlook - are scheduled on your device and involve no server.
Push notifications are delivered through OneSignal when you allow them. OneSignal receives a push token, technical device information, a random identifier tied to your logbook, and a few tags used to time and target alerts, such as your plan, your catch count and when you last logged a session. Our own server keeps a registry of which alerts each device asked for; its entry is removed when you sign out or delete your account.
AI features
Tightlog generates a daily read of the day on your device using Apple Intelligence, on devices that support it, and skips it where Apple Intelligence is not available. Nothing is uploaded for that feature.
The chat coach, AI Studio artwork and fish identification send data to a service we operate, which forwards the request to Google Gemini. What is sent depends on the feature:
- Chat coach - your messages and a short profile of the kind of angling you do. Your logbook database is not uploaded. This runs on-device via Apple Intelligence where the device supports it, and only falls back to the server where it does not
- AI Studio - the catch photo you select, and your prompt
- Fish identification - the photo you are identifying
- Generated images are saved to your own logbook and are not published anywhere unless you share that catch yourself
Do not submit information you do not want processed by these services.
Analytics, crash reports and purchases
Tightlog uses Google Firebase Analytics for optional product analytics, which can be turned off in Settings > Privacy.
Firebase Remote Config is also used to switch features on and off remotely; it receives an installation identifier only.
Statsig is used to run product experiments: it receives a random identifier tied to your device
Sentry is used for crash and error reporting, with personal information scrubbed before it is sent. These services may receive an installation identifier, event information, diagnostics and technical device information.
Subscriptions and purchases are handled through Apple or Google and RevenueCat. Tightlog never receives your card details. RevenueCat receives a purchase identifier, your subscription status and an identifier for your logbook. The app uses these to know what you have paid for, and support uses them to find your account. When you are signed in, it also receives the name and email address on that account. It never receives your backup key, your catches or your photos. Refunds are handled entirely by the app store, as set out in the Terms of Use.
Sharing
Publishing a catch to the public feed is optional and always an explicit action. A logged catch stays private until you choose to share it.
A shared catch contains the photo, the species and measurements, an optional caption, and your chosen display name and handle. It is visible in the app to other people, including people who are not signed in.
A shared catch's text and photo are checked against the community rules by our moderation service. The providers that run these checks do not use your content for analysis or training.
Any shared catch can be reported. A report stores the catch, the reason you give and an identifier for you as the reporter, and is reviewed by us. You can also block another angler, which hides you from each other and ends any friendship.
Locations on a shared catch are rounded to a coarse grid on your device before anything is uploaded, so an exact spot never leaves your device unless you deliberately choose exact precision for that share. You can unshare any of your own posts at any time from Settings > Shared catches.
Retention and deletion
Data stored on your device stays until you delete it or remove the app. Deleting a catch removes it on the device immediately, with a Recently deleted window to undo, and the deletion is propagated to our servers and to your other devices where cloud backup is on.
Deleting your account, from Settings > Account > Delete account, removes the account and everything shared with it - published catches (and their photos), friendships, group posts + memberships, competition entries, and any competition that account created.
Your logbook is not shared: it stays on your phone and a cloud backup you opted into stays restorable from the recovery code, which belongs to the device rather than the account. To have that copy erased as well, turn cloud backup off or contact support@tightlog.com.
Your rights
If you are in the UK or EU, you can ask for a copy of your personal data, ask us to correct or delete it, object to or restrict how we use it, withdraw consent, and ask for it in a portable format. Email support@tightlog.com and we will respond within one month.
You do not need to ask us to export your logbook: Settings > Data & backup exports the whole thing to CSV or a photo archive at any time, subscribed or not.
Where your data is held
Our servers and the providers listed above operate in the UK, EU and United States, so your information may be transferred outside your country. Where it is, we rely on the transfer safeguards those providers offer, such as standard contractual clauses.
Children, security and changes
Tightlog is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe a child has provided us with personal information, contact us and we will remove it.
Tightlog does not track you across other companies' apps and websites. It does not use the advertising identifier, does not collect a device identifier for tracking, and does not share your data with advertisers or data brokers. There are no ads in the app.
We may update this policy when the app or its services change. The date above is updated when we do, and significant changes are announced in the app.
Contact
Questions about privacy or a request about your data can be sent to support@tightlog.com. Support email is delivered through Resend, which processes the messages you exchange with us.