Baitlab Privacy Policy
Baitlab is a recipe app for people who pour their own soft-plastic fishing baits.
This policy describes what the app collects, where it goes, and what you can do
about it. It was written against the app's source code rather than from a
template, so everything below is something the app actually does.
Controller: Mika Kuusisto, trading as Kuusisto Tech, Santintie 14,
38700 Kankaanpää, Finland. Contact: mika@kuusisto.tech — for anything about
your data, write there rather than to in-app support.
What we collect
Your account
Creating an account stores your email address and, if you sign in with Apple
or Google, the identifier those services return. You can hide your address using
Apple's Hide My Email — Baitlab never needs the real one.
Signing in with Google or Apple also keeps what that service shares with the
sign-in: from Google your name and a link to your Google profile picture, from
Apple your name if you choose to share it. Baitlab does not show or use them —
other people see only the nickname you choose. They go with the account when you
delete it.
Your profile
Nickname, and optionally a bio, a country, and an avatar image. All of it is
visible to other users. The country is one you choose from a list; the app does
not read your device location.
If you answer the short questions when you first open the app — how you heard of
Baitlab, how long you have been pouring, what you want to make — the answers are
stored with your account and are visible only to you.
What you create
Recipes (names, notes, ingredients and amounts, photos), posts and reels,
comments, likes, follows, blocks, and the pour and stock entries you log.
Anything you publish is visible to other users. Anything you don't publish is
visible only to you.
Push notifications
If you allow notifications, the app stores a Firebase Cloud Messaging token for
the device along with its platform, so we can tell you when someone likes your
recipe, comments on or replies to something of yours, when someone you follow
posts or publishes a recipe, and when something of yours is removed by review.
Turning notifications off in iOS or Android Settings stops this.
Subscriptions
Purchases are handled by Apple or Google. RevenueCat processes the receipt on our
behalf and tells our server which tier you are on. Your Baitlab account ID is
used as the RevenueCat customer ID. We never see your card details.
Crash reports
Firebase Crashlytics receives a report when the app crashes, including your
account ID so a repeated crash can be tied to one user. Collection is enabled in
release builds only.
Usage counters
The app increments daily counters for a fixed list of events — for example
app_open, recipe_created, search_used. What reaches the server is: the app
name, the event name, the day, the app version, and the platform.
No identifier, no timestamp, no session. The server stores one row per
(app, event, day, version, platform) and adds to it. A single person's visit
cannot be reconstructed from this data, by us or by anyone else. That is a
property of how it is stored, not a promise about how we behave.
You can turn the counters off in the app: Profile → Settings → Share anonymous
usage statistics.
Feedback
If you send feedback from the app, we receive your message and title, the app
version, the platform, your device model and OS version, your locale, your
account ID, and — only if you type it — your email address. The account ID is
there to enforce a limit of five messages per hour.
Unlike the usage counters, feedback is linked to you.
Automated content screening
New posts, recipes and comments are screened automatically before they spread.
The text you wrote and, where there is one, the image, are sent to
Anthropic's Claude API for a judgement on whether the content is acceptable.
Anthropic processes it on our behalf and does not use it to train models.
Content the screener is unsure about is held for human review rather than
removed. A screening decision can be reversed.
Who else processes your data
| Processor | What it receives | Why |
|---|---|---|
| Supabase (EU) | Everything in the sections above except crash reports and purchases | Database, authentication, file storage |
| Anthropic | Post, recipe and comment text and images | Automated content screening |
| Cloudflare | Photos and videos you post | Media hosting and delivery |
| Google Firebase | Crash reports with your account ID; push tokens | Crash reporting, notification delivery |
| RevenueCat | Purchase receipts, your account ID | Subscription status |
| Apple / Google | The purchase itself | Payment |
Feedback and usage counters go to a separate database from the rest of the
app, shared with the developer's other apps so that support messages arrive in
one place. That database can only be written to, never read, by the app.
We do not sell your data. We do not use it for advertising. There are no
third-party advertising or tracking SDKs in the app.
How long we keep it
- Deleted recipes sit in the trash for 30 days and are then permanently
deleted. You can delete one permanently yourself at any time, which also
removes its photo.
- Photos and videos nothing shows any more — an upload you cancelled, a photo you replaced — are deleted from our media host within a few days.
- Usage counters are kept indefinitely. They contain no identifier, so they are not personal data once written.
- Deleting your account deletes everything attached to it in our database, your photos and videos, your device's push registration and your customer record at RevenueCat, and revokes Sign in with Apple if you used it. The stores keep their own purchase records, and a subscription keeps renewing until you cancel it with Apple or Google. Feedback you sent stays in the separate feedback database until you ask us to delete it. The photo of a published recipe that someone copied stays with their copy.
- Everything else is kept until you delete it or delete your account.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, delete it,
restrict or object to processing, and take it elsewhere. Most of it you can do
yourself in the app: edit your profile, delete recipes and posts, empty the
trash.
You can delete your account yourself in the app: Profile → Settings → Delete account. Step-by-step instructions, and what goes and what stays, are on the account deletion page.
To request anything else — including a copy of your data — email mika@kuusisto.tech. We answer within 30 days.
You can complain to the Finnish Data Protection Ombudsman
(https://tietosuoja.fi) if you think we have handled your data wrongly.
Children
Baitlab is not directed at children under 13 and we do not knowingly collect
their data. If you believe a child has created an account, email
mika@kuusisto.tech and we will remove it.
Changes
If this policy changes in a way that affects you, the app will say so before the
change takes effect. The date at the top always reflects the current version.
Back to baitlab.app