Back to the front page

Legal

Privacy policy

Last updated 10 September 2026

MinFangst is a personal, private fishing logbook built for Nordic conditions. You log fishing sessions and catches, and the app automatically builds a species register of what you have caught. Privacy is a load-bearing part of the design, not something added afterwards: your data lives on your own device, we show no advertising, and we never sell information about you.

This policy explains which information MinFangst processes, why, and what rights you have. The processing follows the General Data Protection Regulation (GDPR).

1. Data controller

MinFangst (company number 837 813 522) is responsible for the processing of the personal data described here. If you have questions about privacy, or want to exercise your rights, you can contact us at kontakt@minfangst.no. We answer every privacy enquiry within a month, as the rules require, and usually far sooner than that.

2. What we process

2.1 Account details

To use MinFangst you need an account. When you register you provide:

  • Username: a unique name. It is also your public handle if your profile is open (see section 5).
  • Email address: used for signing in, email verification and password resets.
  • Password: never stored in clear text. We use the established argon2id algorithm to hash it before storage.

You can instead create an account and sign in with Apple or Google. If you do, we store which provider you used, the stable user ID the provider gives us for you, and the email address the provider supplies. If you use Apple's “Hide My Email”, we receive that relay address, not your private one. We never receive your password at Apple or Google. An account created this way has no password with us until you choose to set one, and you can have both a password and Apple or Google sign-in on the same account. If you already have an account on the same email address, the sign-in is linked to that account instead of creating a new one.

2.2 Logbook data you record

This is the content you enter into the app yourself. It may include:

  • Fishing sessions: date and time, place, species and counts, and notes.
  • Catches: species, date, weight, length, bait, notes and up to one photo per catch. If you fish in the sea, you can also record the depth the fish was holding at.
  • Sightings: fish you saw but did not catch, with species, time, place and a note.
  • Species register: which species you have caught, with the first date and place.
  • Your own saved spots: name, coordinates and notes you choose to save.
  • Places: a named water from the built-in database, one of your own saved spots, or a free-text place with optional coordinates.
  • Favourites: which waters, rivers, sea areas and gauging stations you have marked as favourites, and the name you may have given them. Favourites are stored on the server so they follow you to a new phone, and they are what the notifications in section 2.6 are built on.
  • The conditions where you fished: when you save a session or a catch, the app fetches the weather for that place and time and attaches it to the entry, together with water temperature, tide and discharge or water level from the nearest gauging station where such figures exist. If you enter a trip afterwards, the historical figures for the date you give are fetched instead. This is information about the place, not about you, and it is stored so that the statistics and analyses in the app have something to work with. Section 7 says where we get it from.
  • Exact position (GPS): you can save the precise point where you fished, on a catch or a sighting. The point is set either from your position at that moment, or by you pointing it out on the map.
  • Position during a running session: if you record fish while a session is running, the position is saved for each entry. That lets the species be shown where it was actually caught, rather than on a single point for the whole trip. While the session screen is open for a running session, the app keeps your position updated in the background so that recording does not have to wait for the GPS. This happens only while that screen is open: the app never uses your position in the background.

Position is optional. If you do not give the app access to your position, everything else works as normal, and entries are tied to the named water you choose yourself.

2.3 Photos

You can attach up to one photo per catch. Photos are handled carefully:

  • The photo is compressed on your device before it is stored.
  • EXIF data is stripped on import, including hidden GPS coordinates. The position where the photo was taken does not travel with it.
  • The photo file itself is stored in the app's file system; the database only stores a reference to it.

2.4 Subscription details

If you choose to buy MinFangst Premium, the payment itself is handled by the App Store (Apple) or Google Play (Google). We never receive your card or payment details. To activate and keep track of the subscription we process:

  • a subscription status: whether you have active Premium, and when it renews or expires,
  • which product you bought and events such as purchase, renewal, cancellation and expiry, and
  • a pseudonymous purchase ID linked to your user ID, so that the right account gets premium access.

We use RevenueCat as a processor to verify purchases with Apple and Google and pass the subscription status on to us. Apple and Google process your payment as independent controllers under their own terms.

2.5 Water temperature readings (optional)

On the map you can see an estimate of the water temperature for a chosen water, and you can voluntarily submit a real reading you have taken yourself to improve the estimate for everyone. If you submit a reading, we process:

  • the measured temperature itself, and which water the reading applies to (the coordinates of the place, not an exact fishing spot),
  • the time of the reading and weather context captured automatically for the location (for example air temperature and air pressure), and
  • a link to your user ID, which we use to limit submissions to one reading per water per hour and to assess data quality.

The readings are used to fine-tune the shared estimation model and are never shown to other users as yours. Submitting is entirely optional: if you submit no readings, we process no such data about you.

2.6 Push notifications (optional)

If you turn notifications on, we store a device key from Apple or Google, linked to your user account, together with the language the app is set to, so the notification reaches you in the language you use. The key is used for three things, and nothing else:

  • Friend requests: when someone sends you one, and when someone accepts yours.
  • Conditions at your favourite places: if you have premium and have turned it on, the app tells you when something changes where you usually fish, for example when the river drops sharply or the water passes twelve degrees in spring. This is worked out on the server from your favourites (section 2.2) and from public measurement data, not from your position, and we store which kinds of notification you have turned on and what we have already sent you, so the same message does not arrive again the next day. You choose which notifications you want, and you can turn all of them off.
  • Decisions about your content: when we hide or correct an entry (section 6), and when we have answered an appeal from you. The notification itself does not say which entry it concerns, since it can be read by others on a locked screen. The case is in the app, behind your login.

We never send notifications about activity in the feed, and never marketing.

The notifications we send you are also recorded in a notification log on your account, so that you can read them in the app afterwards. The reason is simple: a notification is gone the moment you swipe it away, and if your phone was off when it arrived, it was never seen at all. The log holds the title and the text as you received them, the time, and whether you have opened them. It is shown only to you, and it is deleted along with the rest of your data when you delete your account. The reminder about an ongoing fishing session is a local notification the phone schedules itself, so that it works without coverage. It never reaches the server, and stays on your device.

  • The device key says nothing about who you are, where you are or what you fish.
  • The notification itself travels through Apple Push Notification service (iOS) or Firebase Cloud Messaging (Android), which act as processors for us.
  • The key is deleted when you sign out, and when Apple or Google tell us the app has been uninstalled.
  • You can turn notifications off at any time in your phone's settings. We then stop sending.

2.7 Polls (optional)

From time to time we ask our users what we should build next. A poll appears as a banner in the app, and it is up to you whether to answer. If you submit an answer, we process:

  • which options you picked, and any text you wrote yourself in an “Other” field,
  • a link to your user ID, so that each user answers once and the banner disappears once you have answered, and
  • the time you submitted your answer.

The answers are read by us who build the app, and they can be read per user, not only as a total. So do not write anything in the free-text field that you would rather we did not see. The answers are only used to prioritise our work on the app, never for marketing, and they are not shared with other users. An answer you start but do not submit stays on your phone. Answers are deleted when you delete your account.

2.8 Anonymous usage statistics

To know how many people use MinFangst in Norway and how many use it in Sweden, we count once a day which language the app is set to and which time zone the device is set to, along with whether it is an iPhone or an Android phone. The time zone is a setting on the phone and not your position: it says that the device is in Norway or in Sweden, never where in the country you are, and the app does not ask for location permission to read it.

What we store are plain counters per day, for example “4 September: 174 in Norwegian in Europe/Oslo on iPhone”. The counters contain no user ID, no IP address and no device ID, so a line cannot be traced back to you. On your account we store only the date you were last counted, so that you are counted once per day rather than once per synchronisation. Which language or time zone you had is never stored on your account. The figures are used to plan further development, and they are not shared with anyone.

2.9 Reference data (not personal data)

The app ships with built-in, read-only databases of fish species and fishing waters in Norway and Sweden. These are the same for every user, contain no information about you, and are only updated through app updates.

3. Where the data is stored

MinFangst is built local-first. All logbook data is written first to a local database on your device, and the app works fully offline after the first sign-in.

So that you can use the same logbook on several of your own devices, your data is synchronised to our server. The synchronisation mirrors only your own data between your own devices. Your logbook itself (sessions, catches and spots) is never shared with other users through synchronisation. Anything you make visible to others is described in section 5. Photos are synchronised to secure object storage, and you can choose in the app to upload photos over Wi-Fi only.

The server is operated within the EU/EEA. MinFangst is developed and run in Norway, which is part of the EEA, so the processing takes place under the same rules as within the EU and is not a transfer to a third country. If processors outside the EEA are used, the transfer takes place on a lawful basis under the GDPR.

4. Why we process the data (legal basis)

  • Providing the service: account, sign-in and synchronisation of your logbook are necessary to perform the agreement between you and MinFangst (GDPR art. 6(1)(b)).
  • Subscription: processing purchases and subscription status for MinFangst Premium is necessary to deliver and administer the subscription you have entered into (GDPR art. 6(1)(b)).
  • Security: password hashing, rate limiting on sign-in and email verification rest on our legitimate interest in protecting your account (art. 6(1)(f)).
  • Shared species data: contributing anonymised species data is processed on the basis of your consent (art. 6(1)(a)). The mode is on by default, you are given the choice right after registration, and you can turn it off at any time. See section 8.
  • Moderation: handling content that is reported to us, and looking at entries we have a concrete reason to review, rests on our legitimate interest in keeping the service safe to use and in meeting the requirements the app stores place on user-generated content (art. 6(1)(f)). See section 6.
  • Water temperature: if you voluntarily submit a measured water temperature to improve the model, the submission is processed on the basis of your consent (art. 6(1)(a)), which you give by submitting it.
  • Usage statistics: the anonymous counting of language and time zone, and the date on your account that makes sure you are counted once a day, rest on our legitimate interest in knowing which countries the app is used in, so that we can prioritise further development (art. 6(1)(f)). See section 2.8.
  • Polls: if you answer a poll in the app, the answer is processed on the basis of your consent (art. 6(1)(a)), which you give by submitting it. If you choose not to answer, we process nothing. See section 2.7.
  • Notifications: if you turn notifications on, we send them on the basis of the consent you give when your phone asks for permission (art. 6(1)(a)). Notifications about conditions at your favourite places are in addition part of the subscription you have entered into (art. 6(1)(b)). You can turn notifications off at any time, in the app or in your phone's settings. See section 2.6.
  • Friends, feed and blocking: friend lists, hearts in the feed and blocks are necessary to provide the social side you have chosen to use (art. 6(1)(b)), and blocking rests in addition on our legitimate interest in letting users keep unwanted contact away (art. 6(1)(f)). See section 5.

5. Profile and friends

Your logbook is private. Sessions, catches, spots and notes are visible only to you, and your content is not shared with anyone unless you choose it on the individual entry (section 5.3).

The profile itself, however, is searchable by default: new users start with Private profile off. Other anglers can then find your username and see simple statistics, that is the number of species, sessions and catches, and which species you have caught. If you would rather not, you turn on Private profile. You are given the choice right after registration, and you can change it at any time in the app.

5.1 Open profile

With an open profile, which is the starting point for a new account, your username is searchable, and other anglers who find your profile see only:

  • simple statistics, for example the number of species, sessions and catches, and
  • which species you have caught.

Nothing else is available to anyone but your friends. Seeing your profile gives no access to your logbook, your catches or your spots.

5.2 Friends

You can also send and receive friend requests. A friendship only comes about when both parties accept, and can also be formed with users who have a private profile, but only if you type the exact username (private users do not appear in search). To provide the feature we store who you are friends with and any pending requests. You can decline a request or remove a friend at any time.

A friend sees the same as on an open profile (statistics and species list), and in addition:

  • a scoreboard comparing you on number of catches, number of species, longest fish and heaviest fish, for a week, a month, a year or the whole time you have been members, and
  • your catches, sightings and new species, as you have chosen to share them (section 5.3).

A friend sees this even when your profile is otherwise private. That is exactly the point of being friends. You share more with a friend than with others who find your profile.

What your friends share is collected in a feed under the Friends tab. There a friend can put a heart on an entry, and we then store who put it there and when. You can open the hearts on your own entries and see the names of the friends who liked your trip. It only works that way round: you see the hearts on your own, not who has liked what other people have posted. If the heart is taken back, or the entry is deleted, the row goes with it.

5.3 You choose visibility on every single entry

Your fishing sessions are never shared. A session tells where and for how long you fished, and it is not shown to anyone. The choice you make on the session applies to the catches and sightings you enter into it, which inherit it.

Every catch and sighting has its own visibility setting. You set it when you enter it, and you can change it afterwards:

  • Friends: friends see species, size, photo, date and which water. This is the default.
  • Without place: friends see everything except which water.
  • Private: not shared with anyone. Only you see it.

The shared species data follows the place. Only entries marked «friends» can be included in the anonymised species data (section 8). If you mark an entry «without place» or «private», it is kept out, and the water never reaches the species map. This covers catches, sightings and whole sessions.

5.4 The exact point

The exact GPS point is never shared. If you have saved the precise place where you stood, on a catch or a sighting, neither friends nor other users see it, whatever visibility you choose on the entry. The point is yours, and is used to show your own catches on the map.

What your friends can see is which water the entry belongs to, and only when you have chosen «friends» (section 5.3). If the catch was entered at a named waterfall or pool, the main river is what is shown, not the place within it.

If you contribute shared species data (section 8), a coarse position travels with the row: the point is rounded to a grid of about 50 metres on the server before anything is stored, and the row carries no link to you. Your exact position therefore exists nowhere but in your own logbook.

Entries you made before this feature existed give up no position at all, not even a coarse one. They were recorded under a different promise, and that promise stands.

5.5 This is what nobody else sees

  • your fishing sessions,
  • your notes,
  • bait, the time of day (only the date is shown), the weather saved with the session or the catch, and the exact point (section 5.4), and
  • entries you have marked «private». Entries marked «without place» never show which water.

What a friend is shown is all that is shared. Friends cannot open a session or a catch of yours and see the rest of what you entered.

You can make your profile private again and remove friends at any time under «Profile». You then become invisible in search again.

5.6 You can turn everything social off

If you do not want the social side at all, you turn it off under «Profile». MinFangst is then a purely private fishing log: no Friends tab, no sharing, no friend requests, and you do not appear in search. You can turn it back on at any time without losing anything.

5.7 Blocking

If you would rather have nothing to do with a particular user, you can block them. We then store who you have blocked and when, and that is all we store about it: we do not ask you for a reason. A block works both ways when it is read, so the two of you disappear from each other's feed and search, any friendship ends, and neither of you can send the other a friend request. The person you blocked is not told about it. You find your blocked users under «Privacy and sharing» in the app, and can lift a block there. Your blocks are deleted along with the rest of your data when you delete your account.

6. Moderation of content you share

When you share a catch or an observation with your friends, they can report the entry to us if they consider it inappropriate. Both Apple and Google require that user-generated content can be reported and is actually acted upon, and we have given ourselves a deadline of one day.

If you report an entry, we store who you are, which entry it concerns, who posted it, the reason you chose and anything you wrote in the comment field, together with the time and what we ended up doing. The person who posted the entry never learns who reported it. Your report is used only to handle the case, and you can report the same entry once.

If an entry is reported, we may open it to assess the case. We then see what the entry actually contains: species, weight, text and photo. We never see which water it concerns, and never the position. Location data is not sent to the moderation tool at all, because none of the reasons an entry is reported for are easier to judge by knowing where the fish was.

We may also open an entry without anyone reporting it, but only when we have a concrete reason, such as a new account posting the same entry many times over. The reason must then be written down before the entry is opened, and it is stored alongside the lookup. We never read our way through what is shared just to see what people are up to.

Every entry we open is logged: who at our end opened it, which entry it was, when it happened and on what basis. The log is deleted automatically after twelve months. If you want to know whether we have looked at anything of yours, ask us at kontakt@minfangst.no and we will answer from the log.

Entries you have marked «private» are outside this entirely. They are not shared with anyone, they cannot be reported, and they cannot be opened by us.

If we consider that an entry breaches the terms, we can hide it. It then disappears from your friends' view, but it remains in your own journal, and you lose nothing of what you have recorded.

We can also correct details that are plainly wrong, such as a trout recorded at 500 kg, or a catch filed under the wrong species. Figures like that make the leaderboard, the statistics and the shared species data misleading for everyone who uses them. We can change species, weight and length, and we can remove a note or a photo. We never write new text into your entry: a note can be removed, not reworded. We do not touch place or position.

Before we change anything, we store a copy of what was there before. It is used to restore the entry if you appeal and the appeal is upheld, and it is deleted along with the rest of your data when you delete your account.

You are always told. If we hide or correct something, we send a notification to your phone, and the case appears under «Decisions about your content» in the app together with our reasoning. That is where you can appeal. We review the case again and answer you in the same place. If your appeal is upheld, we reverse the decision immediately, and a corrected field is restored to what you wrote. You can also write to kontakt@minfangst.no.

The legal basis is our legitimate interest in keeping the service safe to use and in meeting the requirements the app stores place on user-generated content (GDPR art. 6(1)(f)).

7. Sharing with others: what we do not do

Beyond what you may share yourself through an open profile (section 5), we keep your data to ourselves. Therefore:

  • We show no advertising.
  • We never sell information about you.
  • We do not share your logbook with third parties for marketing.

We use certain subcontractors (processors) to run the service, among other things for server and storage, and RevenueCat to handle subscriptions. They process data only on our behalf and under data processing agreements. When you buy Premium, Apple and Google additionally process your payment as independent controllers under their own terms, and the same applies when you sign in with Apple or Google: the sign-in itself happens with them, and we only receive the confirmation and the details listed in section 2.1. Some of these parties may be established outside the EEA; the transfer then takes place on a lawful basis under the GDPR, for example the EU Standard Contractual Clauses (SCC). We may also disclose information where we are legally required to.

Maps, weather and measurement data are fetched from open sources while you use the app. The map tiles come from OpenFreeMap, which builds on OpenStreetMap, and the satellite imagery from Esri. The weather comes from the Norwegian Meteorological Institute and Open-Meteo, the tides from the Norwegian Mapping Authority, and discharge, water level and depth maps from NVE, and from SMHI for Swedish waters. Some of these requests go straight from your phone, others through our server. What is sent is which area you are looking at on the map, or which place and time we should fetch the conditions for, and the source additionally sees the IP address of whoever is asking. We never send them your username, your user ID or your logbook, and they are not told that the requests have anything to do with your particular account.

8. Shared species data: optional, and on by default

MinFangst has a mode in which you contribute anonymous species data to a shared database of where the fish species occur. The purpose is to create open and useful information that benefits other anglers, researchers and public bodies alike, and it is the sum of many anglers that makes the numbers useful. In older versions of the app the same mode is referred to as «citizen science».

The mode is on by default for new users. You are given the choice with its own switch right after registration, before you start using the app, and you can turn it off there or at any time later under Privacy in the app.

This is how your privacy is protected when the mode is on:

  • Data is shared anonymously and with no link to you, typically species, named water, time and size.
  • The position is always coarse. If the entry has an exact point, it is rounded to a grid of about 50 metres on the server, before the row is stored. Your exact position never exists in the shared database.
  • The rows carry no link to your user. It is not possible to see who recorded what, or to piece several rows together into a route somebody has fished.
  • In a river, the rounded point is pulled onto the river course itself, so the species is not shown on land beside the river. That is done on the already rounded point, so it does not reveal where in the grid square you stood.
  • You decide per entry. If you mark a catch, a session or a sighting «private» or «without place», it is kept out.
  • You can turn the contribution off again at any time.

Why we ask for this: a fish species is not evenly distributed in a body of water. Lake Mjøsa is 117 kilometres long, so «trout in Mjøsa» says almost nothing about where the trout actually are. With a coarse point, the species can be shown on the right part of the lake, the river or the fjord, instead of being smeared across the whole of it.

If you delete a catch, a species on a session or a sighting, the corresponding anonymous row is removed as well.

The legal basis is your consent (GDPR art. 6(1)(a)). You are told about the choice with its own switch right after registration, and you can withdraw your consent at any time by turning the mode off. New collection then stops.

9. How long we keep the data

We keep your logbook and your account for as long as you have an active account. When you delete your account, your data on the server is deleted as well. Local data on the device is removed when you sign out and/or uninstall the app. Subscription details are kept for as long as you have an active subscription or an account, and may be kept somewhat longer where necessary for accounting or to handle a dispute. Security logs and the like may be kept for a shorter period where necessary for operations and security. The log of entries we have opened for moderation (section 6) is deleted automatically after twelve months.

Your notification log (section 2.6) stays for as long as you have an account, so that you can look back at messages you have received, and is deleted with the account. The measurement data we fetch in order to work out the notifications, that is the hourly figures from the gauging stations, is cleared after a week. It describes the river, not you, and exists with NVE and SMHI regardless.

10. Your rights

Under data protection law you have the right to:

  • obtain access to the information we process about you,
  • have inaccurate information corrected,
  • have information erased (the right to be forgotten),
  • restrict or object to the processing,
  • receive your data (data portability), and
  • withdraw a consent you have given, without affecting the lawfulness of processing before the withdrawal.

Much of this you can do directly in the app. You can edit your profile, change your password and delete your account under «Profile → Settings». You can also contact us at kontakt@minfangst.no. If you believe we process your data contrary to the rules, you can lodge a complaint with the data protection authority where you live, for example the Norwegian Data Protection Authority (Datatilsynet) or the Swedish Authority for Privacy Protection (IMY).

11. Security

We use industry standard measures to protect your account and your data, among them:

  • All traffic between the app and the server is encrypted over HTTPS/TLS.
  • Passwords are never stored in clear text. They are hashed with argon2id, an established algorithm made for exactly this. If you sign in with Apple or Google, we hold no password for you at all.
  • Sign-in is protected with rate limiting to slow down guessing attempts.
  • Your email address is verified at registration, and passwords can be reset safely by email.
  • Long-lived mobile sessions are handled with refresh tokens, so you do not have to sign in again all the time.

The server is operated within the EU/EEA (see section 3). No security measure gives a hundred per cent guarantee, but we work to keep the level high and up to date over time.

12. Children

MinFangst is not directed at children. If you are under 15, you should have the consent of a parent or guardian before creating an account.

13. Changes to this policy

We may update this privacy policy, for example when new features launch. Significant changes are announced in the app or by email. The date at the top shows when the policy was last changed.