This policy explains what data Conchquest collects, why, and how it's used, when you use our mobile app or website.
| Data | Why we collect it |
|---|---|
| Account info (email, display name) | To create and secure your account, via our authentication provider. If we add social login (Google/Apple) later, it will share only what those providers permit. |
| Precise location (GPS) | To fetch tide, weather, and wave conditions for your current beach, and to let you log a find with coordinates. |
| Photos | To attach images to shell finds you choose to log, stored with our cloud storage provider. |
| Find data (species, condition, notes, timestamp) | To build your personal shelling history and, if you choose to share it, contribute to the community find map. |
| Device and usage data | To keep the app secure, diagnose crashes, and understand feature usage. |
| Subscription status (once premium features launch) | Will be handled by Apple, Google, and RevenueCat to manage premium entitlements. We will not receive or store your payment card details. |
Each find you log is either:
| Category | Purpose |
|---|---|
| Authentication provider | Creates and secures your account |
| Cloud hosting & storage provider | Runs our backend, database, and stores your uploaded photos |
| Environmental data providers | Tide, weather, and wave forecast data (we send them a location, not your identity) |
| AI text-generation provider | Generates the "Shelling Strategy" natural-language summary from your forecast conditions |
| Push notification provider | Delivers the notifications you've enabled |
| RevenueCat, Apple App Store, Google Play | Subscription billing (once premium features launch — not yet active) |
We name Apple, Google, and RevenueCat specifically above since you'll interact with them directly for billing; other categories are handled through providers we may change from time to time.
We do not sell your personal data.
We keep your account and find data until your account is closed. Deleting your account starts a 14-day window during which it can be restored; after that it's purged automatically. A deleted find disappears from the app and the community map immediately.
Copies can survive a little longer in our backups, which exist so a mistake or an outage can't destroy everyone's shelling history. Database backups roll off within 30 days. Photo backups are deliberately kept longer and are never pruned automatically — that's what makes them useful when something is deleted by accident. If you need a specific photo removed from our backups as well as the app, email privacy@conchquest.app and we'll purge it.
Conchquest is not intended for children under 13, and we do not knowingly collect data from them.
Traffic between the app and our servers is encrypted in transit (HTTPS). Passwords are handled entirely by our authentication provider — we never see or store them. Photos are stored privately and served through short-lived links rather than public URLs. Backups are encrypted and access to them is limited. Access to production data is restricted to the people who operate Conchquest.
No service can promise perfect security. If a breach ever affects your personal data, we'll tell you and the relevant authorities as required by law.
Depending on where you live — California, Colorado, Connecticut, Virginia and a growing list of others — you may have the right to know what personal data we hold about you, get a copy of it, correct it, delete it, and not be discriminated against for exercising any of those rights.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We run no advertising and no third-party tracking in the app or on this site.
To exercise any of these rights, email privacy@conchquest.app. We'll verify your request against your account email and respond within 45 days.
If we make material changes to how we handle your data, we'll notify you in-app before the changes take effect.
Questions, or want to exercise a data right? Email privacy@conchquest.app.