CREEL Privacy Policy

Effective date: August 25, 2026 Applies to: the CREEL mobile app and the CREEL backend service.

CREEL ("CREEL", "we", "us") is a mobile app for anglers in North Carolina. You log catches with photos, environmental conditions, and GPS location; the app provides fishing forecasts and lets you choose how your catches are shared, and it contributes catch data to angler-built North Carolina fishery stock assessments. This policy explains what we collect, why, who we share it with, and the choices and rights you have.


1. Who is responsible for your data

CREEL is operated by CREEL APP LLC, a North Carolina limited liability company, in North Carolina, United States. For any privacy question or request, contact us at steve@creel-app.com.

2. What we collect

Account information - Email address (used to sign in, for password reset, for two-factor sign-in codes, and for essential service messages). - Username / display name and, optionally, a short bio and avatar image. - Your birth year, collected to confirm you are at least 13 — at sign-up if you register with an email and password, or on your first sign-in if you sign in through Google. We store a derived age-confirmation record, not a full date of birth. - A "fishing guide" flag if you choose to set one.

Sign-in with Google (only if you use it) - If you choose "Continue with Google," we receive from Google your name, your email address, and your Google account identifier, and we use them solely to create your CREEL account, link it to your Google account, and sign you in. - We never receive or store your Google password, and CREEL never posts to your Google account or acts on your behalf there. - Google sign-in is optional — email-and-password registration is always available. We may support additional third-party sign-in providers in the future; this section applies the same way to any provider we add.

Catch and trip data - Catch photos you capture or import. - The species you select, and the length/weight and other details you enter. - Precise GPS coordinates of where you fished (when you allow location access), stored at full precision. - Trip details (start/end times, platform, bait), and environmental conditions (tide, weather, moon) sourced for your location and time. - Trip route: while a trip is in progress, the app records your GPS position about once every 15 minutes (a new point is skipped if you haven't moved more than a few meters). Recording continues while the app is in the background during the trip — Android shows a persistent "trip in progress" notification and iOS shows the location indicator — and stops when you end the trip. You can move or delete any route point afterward, and route points are private to you like all your location data.

Social and messaging data - Comments, likes, follows, group memberships, and the content of direct messages you send. - Reports you submit about other content or users, and moderation actions taken on content.

Tournament verification documents (only if you enter a tournament) - An image of a government photo ID (to confirm identity and age) and an image of a fishing license, captain's license, or pier pass. These images are used only for one-time human review by tournament reviewers and are hard-deleted after the review decision. We retain the reviewer's yes/no result and an audit record of the decision, not the images.

Device and technical data - A push-notification token (if you enable notifications) and basic technical logs needed to operate and secure the service. - A trusted-device token, only if you choose "Remember this device" when entering a two-factor sign-in code: a random token kept in your device's secure storage, with a one-way hash of it on our servers, used solely to recognize that this device has already completed the two-factor check. By design it stays on the device after you sign out (so a device you trust is not re-challenged at every sign-in); it is removed when you remove the app or its data, and we keep a per-device record so that remote "sign out of all devices" revocation can be offered.

3. How we use your data

We may aggregate or de-identify data so that it no longer identifies you — stock assessments are an example — and use it to run, improve, and study CREEL. Once data is de-identified, we keep it in de-identified form and never attempt to re-identify it.

Limited Use of Google user data. CREEL's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The name, email address, and account identifier we receive from Google are used only to provide the Google sign-in feature described in Section 2. We do not sell this data, do not use it for advertising, and do not transfer it to anyone except as necessary to provide sign-in, to comply with applicable law, or as part of a merger or acquisition of which you will be notified.

4. Your choices about sharing

5. Who we share data with (processors)

We do not sell your data, we do not use it for advertising, and we do not share it for targeted or behavioral advertising. We use a small number of service providers that process data on our behalf:

We may disclose data if required by law or to protect the rights, safety, or property of CREEL, our users, or the public.

Business transfers. If CREEL is ever part of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you (in-app or by email) before your data becomes subject to a different privacy policy.

6. Children

CREEL is for anglers 13 and older; the app does not knowingly collect data from children under 13.

7. Retention, deletion, and two important limits

8. Security

Traffic uses HTTPS. Passwords are hashed; auth tokens are stored in the device secure store (Keychain/Keystore). Sign-ins from unrecognized devices can require a one-time code emailed to your account address (two-factor authentication); two-factor codes and trusted-device tokens are stored only in hashed form on our servers. Tournament ID/license images are encrypted at rest and deleted after review. No system is perfectly secure, but we take reasonable measures to protect your data.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your data, and to withdraw consent. To exercise any right, email steve@creel-app.com — you may also have an authorized agent contact us on your behalf. Because we fulfill these requests manually, we may first ask you to verify your identity (for example, by writing from your account email address) so we never disclose or delete data at an impostor's request. If we decline a request, we will explain why, and you may appeal by replying to the same address; appeals receive a fresh review. We will not discriminate against you for exercising a right.

We do not make decisions that produce legal or similarly significant effects about you solely by automated means — tournament verification and content moderation decisions are made by humans.

10. Governing law

CREEL operates from North Carolina, United States, and this policy is governed by the laws of the State of North Carolina and applicable U.S. federal law.

11. Changes

We may update this policy; we will change the effective date and, for material changes, notify you in-app. Continued use after an update means you accept the revised policy.

12. Contact

steve@creel-app.com