Privacy Policy
Effective date: September 14, 2026
Chum ("the app") is built by a small company run by anglers. This policy says plainly what the app collects, why, and what we don't do with it.
The short version
- Your catch log — photos, locations, and conditions — is stored under your account so it backs up and syncs to your devices. It is private to you: no other user can ever see your catch records, locations, or spots unless you share them yourself through a sharing feature you choose to use (Send Catch today, described below). The one other exception, for photos only: a catch photo may be selected to illustrate the species guide — shown without your name, location, or catch details, with a Settings switch to opt out.
- Your fishing licenses never touch our servers at all — they live on your device and in your own iCloud.
- We don't sell your personal data, and we don't track you across other apps or sites. Chum has no ad networks. If we ever show sponsored gear or affiliate links, they'll be labeled as such.
What the app collects, and why
Your account. You sign in with Apple. We receive a unique account identifier and, if you choose to share them, your name and email address. This is how your catch log follows you to a new phone. Your name is kept with your account and is not shown in the app or on anything you share. If you type a signature for your share cards in Settings, that line is stored with your account so it follows you too.
Your catches. When you photograph a fish, the app records the photo, the species identification, the date and time, your location, and conditions from your phone's sensors (barometric pressure, boat speed and heading) — plus anything you add yourself: corrections, lengths, weights, whether the fish was kept or released, how you caught it (method, bait, lure, rig, depth, boat speed, tag number), your notes on the catch, more photos of the same fish, and the name and notes you give a day of fishing. This is your catch log; capturing it completely at the moment of the catch is the entire point of the app, because most of it can never be reconstructed later.
Photos from your library. When you pick a photo from your library instead of using the camera, the app reads the date and location that Photos keeps for that picture, so the catch is filed on the day and at the place it was taken. The app asks for photo access the first time you do this; only the photos you pick are read. If you decline, the catch is filed with whatever date the photo file itself carries, and you can set the date by hand.
Where it goes. Your catch log is stored on our servers (database and photo storage hosted in the United States) so it can back up automatically and sync across your devices. Records are stored with their exact locations — that precision is what makes your log useful to you — and access is locked to your account at the database level.
Sending a catch. Send Catch is the one way a catch leaves your account, and only you can trigger it, one catch at a time. When you use it, the app uploads a copy of that catch — its photos and its record, including its exact location and conditions — to our servers and gives you a private link to hand to whoever you choose. Your notes on the catch, and your day notes, never travel with it. Anyone who has the link can see the photo and species on a web page, and anyone who opens it in the app receives the full catch, location included, as a catch in their own log; from then on it is theirs, under their account, and deleting your original does not remove their copy. The link is not listed or searchable anywhere, but it is a link: if it is forwarded, the copy goes with it. Shared copies expire and are deleted from our servers 90 days after you send them. For a photo without the location, use Share Card or Share Photo instead: the card names only the waters you were in (“NC waters”), never a spot, and the photo carries no location at all.
Your licenses. Documents you add to the license wallet are stored on your device and synced through your own iCloud account. They are never uploaded to our servers, and we cannot see them.
Species identification runs entirely on your phone. Photos are not sent anywhere for identification.
Notifications. Reminders (license expiration, regulation changes) are scheduled on your device. If you allow notifications, the app may register a push address for your device with our servers so we can send alerts such as emergency season closures and, if you keep that type switched on, occasional news about the app. Each type of notification can be switched off in Settings.
Feedback. If you send feedback from inside the app, we receive your message, which page or catch you were looking at (the species, never the photo or the location), and basic app details (app version, iOS version, device model) so we can reproduce what you saw.
How we use your data
- To run the product: backup, sync, restore, and the features you see.
- To see how the app is doing: the app records small usage events — which species pages you open, which state's rules you browse, whether an identification found a fish, how onboarding went, when you combine or split catches or add photos, whether you allowed photo access, which updates you open, and errors it hit — tied to your account, never including your position, your photos, or your notes, and never your search terms. It also keeps one small record per install (device model, iOS version, app version, how often the app is opened). We use these to decide what to fix and build next.
- To improve the app: your species corrections and catch records help us make fish identification and fishing insights better. When we analyze data in aggregate — for example, understanding regional catch trends — results are only ever used or presented in forms that do not reveal any individual's identity or fishing spots. Aggregate and de-identified data of this kind may be shared with partners such as researchers and fisheries agencies; it never includes anything that identifies you or your spots.
- To train the models: your catch photos, gear photos, species corrections, and catch records train the models behind the app's identification and fishing insights — that's how they get better for everyone. Identification itself still runs entirely on your phone; training happens on our systems, using the data your account already backs up.
- To reach you: messages about your account and the service, and, if you don't opt out, occasional news about Chum by email or notification. Every marketing message carries an unsubscribe.
- To illustrate the species guide: catch photos may be selected to appear on the guide's species pages, so the reference is built from real fish caught by real anglers. A selected photo is shown without your name (unless you ask for a credit line), your location, or any other detail of your catch. The “My photos in the species guide” switch in Settings keeps your photos out of consideration entirely. Because the guide is a lasting reference, a photo already published there may remain even if the catch or account it came from is later deleted; contact us about a published photo and we will take a reasonable removal request seriously.
What we don't do
- Never show your catch records, locations, or spots to another user except through a sharing feature you choose to use — Send Catch today, which only you can use, one catch at a time, and which tells you it includes the location before you send. Any sharing feature we add later will be your choice the same way. Species-guide photos, described above, are the one other exception — and they carry none of those details.
- We don't sell your personal data.
- We don't track you across other apps or sites, and Chum runs no ad networks or ad tracking. Sponsored gear or affiliate links, if we ever show them, are labeled.
If Chum changes hands
If Chum is ever acquired, merged, or its assets sold, your data may transfer to the new owner. It stays under this policy, and we'll tell you before it happens.
Who touches the data
We use infrastructure providers to run the service: Apple (sign-in, iCloud, notifications), Supabase (database and authentication), and Cloudflare (photo storage, content delivery, and the shared-catch links). They store and transmit data on our behalf and are not permitted to use it for their own purposes.
Your controls
- Delete a catch and it is deleted everywhere — our servers and photo storage included, not just your phone. (A photo already published in the species guide is the one exception, described above.)
- My photos in the species guide can be switched off in Settings to keep your photos out of consideration.
- A sent catch cannot be recalled once someone has opened it — it is their catch now, like a photo you texted. The shared copy on our servers expires on its own after 90 days.
- Sign out anytime; your data stays on your phone and your account keeps your backup.
- Delete your account from Settings, which permanently removes your account and all catch data and photos from our servers.
- Notification types can be switched off individually in Settings.
Retention
Your catch log is kept as long as your account exists — that's what a log is for. Deleted catches and deleted accounts are removed from our systems permanently. A copy made by Send Catch is kept for 90 days from sending, then deleted. Photos published in the species guide are retained as part of the guide, as described above. Aggregate and de-identified data, and models already trained on your content, may be retained; they never identify you or your spots.
Children
The app is not directed at children under 13, and we do not knowingly collect data from them.
Regulations disclaimer
The app's fishing regulations are gathered from official state and federal sources, dated, and monitored for changes — but they are a convenience, not legal advice. Always confirm with the official source; the official regulations govern.
Changes
If this policy changes materially, the app will tell you before the change applies to you.