CREEL Privacy Policy
Effective date: August 25, 2026 Applies to: the CREEL mobile app and the CREEL backend service.
CREEL ("CREEL", "we", "us") is a mobile app for anglers in North Carolina. You log catches with photos, environmental conditions, and GPS location; the app provides fishing forecasts and lets you choose how your catches are shared, and it contributes catch data to angler-built North Carolina fishery stock assessments. This policy explains what we collect, why, who we share it with, and the choices and rights you have.
1. Who is responsible for your data
CREEL is operated by CREEL APP LLC, a North Carolina limited liability company, in North Carolina, United States. For any privacy question or request, contact us at steve@creel-app.com.
2. What we collect
Account information - Email address (used to sign in, for password reset, for two-factor sign-in codes, and for essential service messages). - Username / display name and, optionally, a short bio and avatar image. - Your birth year, collected to confirm you are at least 13 — at sign-up if you register with an email and password, or on your first sign-in if you sign in through Google. We store a derived age-confirmation record, not a full date of birth. - A "fishing guide" flag if you choose to set one.
Sign-in with Google (only if you use it) - If you choose "Continue with Google," we receive from Google your name, your email address, and your Google account identifier, and we use them solely to create your CREEL account, link it to your Google account, and sign you in. - We never receive or store your Google password, and CREEL never posts to your Google account or acts on your behalf there. - Google sign-in is optional — email-and-password registration is always available. We may support additional third-party sign-in providers in the future; this section applies the same way to any provider we add.
Catch and trip data - Catch photos you capture or import. - The species you select, and the length/weight and other details you enter. - Precise GPS coordinates of where you fished (when you allow location access), stored at full precision. - Trip details (start/end times, platform, bait), and environmental conditions (tide, weather, moon) sourced for your location and time. - Trip route: while a trip is in progress, the app records your GPS position about once every 15 minutes (a new point is skipped if you haven't moved more than a few meters). Recording continues while the app is in the background during the trip — Android shows a persistent "trip in progress" notification and iOS shows the location indicator — and stops when you end the trip. You can move or delete any route point afterward, and route points are private to you like all your location data.
Social and messaging data - Comments, likes, follows, group memberships, and the content of direct messages you send. - Reports you submit about other content or users, and moderation actions taken on content.
Tournament verification documents (only if you enter a tournament) - An image of a government photo ID (to confirm identity and age) and an image of a fishing license, captain's license, or pier pass. These images are used only for one-time human review by tournament reviewers and are hard-deleted after the review decision. We retain the reviewer's yes/no result and an audit record of the decision, not the images.
Device and technical data - A push-notification token (if you enable notifications) and basic technical logs needed to operate and secure the service. - A trusted-device token, only if you choose "Remember this device" when entering a two-factor sign-in code: a random token kept in your device's secure storage, with a one-way hash of it on our servers, used solely to recognize that this device has already completed the two-factor check. By design it stays on the device after you sign out (so a device you trust is not re-challenged at every sign-in); it is removed when you remove the app or its data, and we keep a per-device record so that remote "sign out of all devices" revocation can be offered.
3. How we use your data
- Run the app: create your account, store your logbook, show feeds you choose, deliver messages and notifications.
- Protect your account (two-factor authentication): when you sign in from a device we don't recognize, we email a one-time 6-digit code to your account email address; if you ask us to remember the device, we store the hashed trusted-device token described in Section 2.
- Verify catches: with your consent, your catch photo, selected species, and reported measurements may be shown to CREEL verifiers so other anglers can trust achievements. Verifiers are not shown your location, name, or personal details.
- Build stock assessments: catches you log contribute to aggregated North Carolina fishery stock assessments. This is a core purpose of CREEL. Assessments never include your precise location — the only location fact used is that a catch occurred somewhere in North Carolina.
- Improve automatic catch recognition (ML): with your consent, catch photos (with the species and length label) may be used to develop a CREEL model that recognizes species and length from a photo. CREEL runs this itself; we do not send your photos to any third-party AI/vision service.
- Safety and moderation: review reports, enforce our Terms, and remove content that violates them.
- Security and legal: prevent abuse, and comply with law.
We may aggregate or de-identify data so that it no longer identifies you — stock assessments are an example — and use it to run, improve, and study CREEL. Once data is de-identified, we keep it in de-identified form and never attempt to re-identify it.
Limited Use of Google user data. CREEL's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The name, email address, and account identifier we receive from Google are used only to provide the Google sign-in feature described in Section 2. We do not sell this data, do not use it for advertising, and do not transfer it to anyone except as necessary to provide sign-in, to comply with applicable law, or as part of a merger or acquisition of which you will be notified.
4. Your choices about sharing
- Location is always a separate choice. Confirming catch-review consent never shares where you fish. Verifiers and the photo/ML project never see your spots.
- Public feed shows your photo, angler name, species, and size — never your location.
- Public leaderboards: if a catch you share publicly becomes verified, it can appear on public leaderboards, which show its species, length, and photo (still never your location).
- Groups: a group's creator sets one sharing level that applies equally to every member; you decide what to share at the end of each trip, and you can always keep any individual catch out.
- Consent toggle: catch-review/photo consent is optional and can be switched off anytime in your profile. Turning it off stops future use of your photos for review and ML. See Section 7 for what cannot be recalled.
5. Who we share data with (processors)
We do not sell your data, we do not use it for advertising, and we do not share it for targeted or behavioral advertising. We use a small number of service providers that process data on our behalf:
- Railway — cloud hosting and the database where your account, catches, and messages are stored.
- Resend — email delivery: password-reset codes, two-factor sign-in codes, and other essential account emails are sent through Resend.
- Cloudflare R2 (object storage) — catch photos and tournament verification documents are stored in private R2 buckets.
- Expo push notification service — to deliver push notifications (if enabled).
- Public conditions data sources (e.g. NOAA, Open-Meteo) — we request weather/tide data for your location through our backend; these providers are data sources, not recipients of your account data.
- Google (sign-in provider, only if you use Google sign-in) — Google is your identity provider, not a processor for CREEL. What CREEL receives from Google is described in Sections 2 and 3; what Google itself collects when you sign in is governed by Google's own privacy policy.
We may disclose data if required by law or to protect the rights, safety, or property of CREEL, our users, or the public.
Business transfers. If CREEL is ever part of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you (in-app or by email) before your data becomes subject to a different privacy policy.
6. Children
CREEL is for anglers 13 and older; the app does not knowingly collect data from children under 13.
- Registering with an email and password requires your birth year, and our servers refuse to create an account for anyone under 13 — the check happens before the account exists.
- Signing in with Google for the first time creates the account before we know your age (Google does not tell us), so we ask for your birth year on your first sign-in. If the answer indicates you are under 13, the account and all data associated with it are immediately deleted.
- If you believe a child under 13 has created an account, contact us and we will delete it and its data.
7. Retention, deletion, and two important limits
- Delete your account anytime from your profile (password-confirmed). Deletion permanently removes your catches, catch photos, GPS rows, trips, messages, and group memberships; groups you own are transferred or deleted.
- Two residual data limits you should know about: 1. ML-exported photos are not recalled. If a catch photo was already included in an ML training export before you withdrew consent or deleted your account, that already-exported copy cannot be pulled back out of the export. 2. Moderation and edit audit records persist. For safety and integrity, records of moderation actions and verifier/edit history are retained after an account is deleted, with the acting user reference cleared (set to null) so they no longer identify you.
- Data requests / access. We do not yet offer a self-serve data export. You can request access to, or correction of, your data by emailing steve@creel-app.com; we fulfill these manually. Email is not currently changeable or verifiable in-app; contact support to correct an email.
8. Security
Traffic uses HTTPS. Passwords are hashed; auth tokens are stored in the device secure store (Keychain/Keystore). Sign-ins from unrecognized devices can require a one-time code emailed to your account address (two-factor authentication); two-factor codes and trusted-device tokens are stored only in hashed form on our servers. Tournament ID/license images are encrypted at rest and deleted after review. No system is perfectly secure, but we take reasonable measures to protect your data.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your data, and to withdraw consent. To exercise any right, email steve@creel-app.com — you may also have an authorized agent contact us on your behalf. Because we fulfill these requests manually, we may first ask you to verify your identity (for example, by writing from your account email address) so we never disclose or delete data at an impostor's request. If we decline a request, we will explain why, and you may appeal by replying to the same address; appeals receive a fresh review. We will not discriminate against you for exercising a right.
We do not make decisions that produce legal or similarly significant effects about you solely by automated means — tournament verification and content moderation decisions are made by humans.
10. Governing law
CREEL operates from North Carolina, United States, and this policy is governed by the laws of the State of North Carolina and applicable U.S. federal law.
11. Changes
We may update this policy; we will change the effective date and, for material changes, notify you in-app. Continued use after an update means you accept the revised policy.
12. Contact
steve@creel-app.com