BaitLab Privacy Policy
Last updated: 13 August 2026
BaitLab is a recipe app for people who pour their own soft-plastic fishing baits.
This policy describes what the app collects, where it goes, and what you can do
about it. It was written against the app's source code rather than from a
template, so everything below is something the app actually does.
Controller: Mika Kuusisto (Finland). Contact: zanttux@gmail.com
What we collect
Your account
Creating an account stores your email address and, if you sign in with Apple
or Google, the identifier those services return. You can hide your address using
Apple's Hide My Email — BaitLab never needs the real one.
Your profile
Nickname, and optionally a bio, a country, and an avatar image. All of it is
visible to other users. The country is one you choose from a list; the app does
not read your device location.
What you create
Recipes (names, notes, ingredients and amounts, photos), posts and reels,
comments, likes, follows, blocks, and the pour and stock entries you log.
Anything you publish is visible to other users. Anything you don't publish is
visible only to you.
Push notifications
If you allow notifications, the app stores a Firebase Cloud Messaging token for
the device along with its platform, so we can tell you when someone likes your
recipe. Turning notifications off in iOS or Android Settings stops this.
Subscriptions
Purchases are handled by Apple or Google. RevenueCat processes the receipt on our
behalf and tells our server which tier you are on. Your BaitLab account ID is
used as the RevenueCat customer ID. We never see your card details.
Crash reports
Firebase Crashlytics receives a report when the app crashes, including your
account ID so a repeated crash can be tied to one user. Collection is enabled in
release builds only.
Usage counters
The app increments daily counters for a fixed list of events — for example
app_open, recipe_created, search_used. What reaches the server is: the app
name, the event name, the day, the app version, and the platform.
No identifier, no timestamp, no session. The server stores one row per
(app, event, day, version, platform) and adds to it. A single person's visit
cannot be reconstructed from this data, by us or by anyone else. That is a
property of how it is stored, not a promise about how we behave.
Feedback
If you send feedback from the app, we receive your message and title, the app
version, the platform, your device model and OS version, your locale, your
account ID, and — only if you type it — your email address. The account ID is
there to enforce a limit of five messages per hour.
Unlike the usage counters, feedback is linked to you.
Automated content screening
New posts, recipes and comments are screened automatically before they spread.
The text you wrote and, where there is one, the image, are sent to
Anthropic's Claude API for a judgement on whether the content is acceptable.
Anthropic processes it on our behalf and does not use it to train models.
Content the screener is unsure about is held for human review rather than
removed. A screening decision can be reversed.
Who else processes your data
| Processor | What it receives | Why |
|---|---|---|
| Supabase (EU) | Everything in the sections above except crash reports and purchases | Database, authentication, file storage |
| Anthropic | Post, recipe and comment text and images | Automated content screening |
| Cloudflare | Photos and videos you post | Media hosting and delivery |
| Google Firebase | Crash reports with your account ID; push tokens | Crash reporting, notification delivery |
| RevenueCat | Purchase receipts, your account ID | Subscription status |
| Apple / Google | The purchase itself | Payment |
Feedback and usage counters go to a separate database from the rest of the
app, shared with the developer's other apps so that support messages arrive in
one place. That database can only be written to, never read, by the app.
We do not sell your data. We do not use it for advertising. There are no
third-party advertising or tracking SDKs in the app.
How long we keep it
- Deleted recipes sit in the trash for 30 days and are then permanently
deleted. You can delete one permanently yourself at any time, which also
removes its photo.
- Usage counters are kept indefinitely. They contain no identifier, so they
are not personal data once written.
- Everything else is kept until you delete it or delete your account.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, delete it,
restrict or object to processing, and take it elsewhere. Most of it you can do
yourself in the app: edit your profile, delete recipes and posts, empty the
trash.
To request the rest — including deleting your account and everything attached to
it — email zanttux@gmail.com. We answer within 30 days.
You can complain to the Finnish Data Protection Ombudsman
(https://tietosuoja.fi) if you think we have handled your data wrongly.
Children
BaitLab is not directed at children under 13 and we do not knowingly collect
their data. If you believe a child has created an account, email us and we will
remove it.
Changes
If this policy changes in a way that affects you, the app will say so before the
change takes effect. The date at the top always reflects the current version.