GILLI is a native iOS and Android fishing app. This notice explains how PelagicLabs and the providers used by GILLI handle personal data.
This legally operative notice is currently provided in English. You may contact us to request an explanation in another European language.
1. Controller and contact
- Controller: PelagicLabs
- Country: Belgium
- VAT / enterprise number: BE1032.515.015
- Privacy contact: lukasmeerschaut@pelagiclabs.io
PelagicLabs determines the purposes and essential means of the processing described here. Service providers process data under their applicable terms and roles.
PelagicLabs has not appointed a data-protection officer because the present scale and nature of the processing do not require one. Privacy requests are handled through the contact above.
2. Personal data GILLI handles
2.1 Accounts and authentication
GILLI uses Firebase Authentication. Depending on how you sign in, this can include your Firebase user ID, authentication-provider identifiers, email address, phone number, display name, profile image, identity tokens, session state, and account-security metadata.
2.2 Profile, preferences, and social data
Profile and community features can include your username, display name, avatar, biography, country or region, fishing preferences, app settings, privacy choices, friendships, blocks, activity state, clubs, challenges, and other social records. Visibility settings control supported public and friend-facing information.
2.3 Fishing records and personal tools
GILLI can store catches and blank-day records, photos, notes, sizes and weights, fishing methods, coordinates, environmental context, spots, trips, tackle, licences, imports, offline caches, and synchronization state when you use those features.
2.4 Location, maps, and sensors
With the relevant device permission, GILLI can use current, selected, last-known, or recorded location for maps, local conditions, catches, spots, trips, regional features, and live sessions. Some features can also use device sensors such as barometric pressure.
2.5 Camera, photos, and documents
With permission, GILLI can access the camera or photo library for catch photos, profile images, sharing, licences, fish identification, and measurement tools. Files associated with cloud features can be stored in Firebase Storage.
2.6 Fish identification
When you request fish identification, the submitted image is sent through the GILLI backend to a private inference service. The active identification request path processes image bytes in memory and does not persist the submitted image. A photo separately saved to a catch follows the normal catch-photo storage rules. Limited operational telemetry can remain for security and quality analysis.
2.7 Notifications
If you enable notifications, GILLI and its providers can process a push token, platform and app information, notification preferences, subscriptions, and delivery or interaction state needed for that feature.
2.8 Subscriptions and purchases
GILLI uses RevenueCat and the Apple App Store or Google Play for subscriptions and purchases. They can process account or app-user identifiers, products, entitlements, transactions, receipts or purchase tokens, and related device or store information. PelagicLabs does not receive your complete payment-card details.
2.9 Optional product analytics and crash diagnostics
Product analytics and crash diagnostics are disabled by default in GILLI and are sent to Google Firebase only if you enable the corresponding choice in Privacy settings. You can enable or disable Product Analytics and Crash Diagnostics independently at any time.
- Product Analytics: helps us understand app and feature use and performance. Event properties are designed to exclude names, email addresses, raw coordinates, and photos.
- Crash Diagnostics: can send crash and non-fatal error information, technical context, and diagnostic attributes needed to investigate app problems.
Disabling either choice stops future optional collection by GILLI. Disabling Product Analytics resets the local analytics identifier. Disabling Crash Diagnostics clears the Crashlytics user association and deletes unsent reports where the installed app version supports those actions. Data sent to Firebase while a choice is enabled is handled under Google's applicable Firebase terms and privacy information. See Firebase Privacy and Security.
If your installed app version does not yet expose these controls, the default-off behavior described here applies once you update to a release that includes them. Contact us if you need help with an older build.
3. Sources of data
GILLI receives data directly from you, from your device when you use a permission or feature, from service providers used for authentication, purchases and delivery, from other users when they interact with you, and from environmental and geospatial data providers used by the GILLI backend.
4. Purposes and legal bases
| Purpose | Examples | GDPR basis |
|---|---|---|
| Provide the app and account | Authentication, cloud sync, fishing records, maps, forecasts, exports, and account controls | Article 6(1)(b): performance of the service contract |
| Features you choose | Location, camera, sensors, notifications, and social features | Article 6(1)(b), with device permission or consent where required |
| Subscriptions and purchases | Purchases, restores, entitlements, refunds, and fraud controls | Article 6(1)(b); Article 6(1)(c) for financial obligations; Article 6(1)(f) for fraud prevention |
| Security, reliability, and support | Security controls, logs, support, moderation, and disputes | Article 6(1)(f): legitimate interests in a secure and dependable service |
| Optional product analytics | Product and performance measurement | Article 6(1)(a): your in-app choice, withdrawable at any time |
| Optional crash diagnostics | Crash and non-fatal error diagnostics | Article 6(1)(a): your in-app choice, withdrawable at any time |
| Legal compliance and claims | Tax, accounting, legal duties, and disputes | Article 6(1)(c) and Article 6(1)(f) |
5. Required and optional data
Data needed to operate an account, purchase, security control, or requested cloud feature is necessary for that feature. Location, camera, photos, sensors, notifications, public sharing, analytics, and crash diagnostics are optional and can be refused where the dependent feature permits it.
6. Automated scores and recommendations
GILLI combines environmental data, species biology, forecast models, selected regions or species, tackle information, and—when you use personal intelligence features—your fishing records to produce fishing scores and recommendations. These outputs are advisory and do not produce legal or similarly significant effects within GDPR Article 22.
7. Recipients and providers
- Google Firebase: authentication, Firestore, Storage, Cloud Functions, push messaging, and optional Analytics and Crashlytics when enabled by you;
- Apple and Google: identity services, permissions, maps, app distribution, push delivery, and store payments;
- RevenueCat: purchases, entitlements, and subscription lifecycle;
- GILLI backend and hosting providers: environmental data, forecasts, maps, security, caching, and authenticated APIs;
- Fish-identification and environmental-data providers: information needed to perform the feature you request;
- Other GILLI users: information you choose to share with them;
- Support, advisers, and authorities: where needed for support, legal obligations, safety, or claims.
GILLI does not sell personal data or use an advertising SDK to build a cross-app behavioural advertising profile.
8. International transfers
Some provider systems and subprocessors operate outside the European Economic Area. Several Firebase Cloud Functions used by GILLI are deployed in a European region, but that does not mean every Firebase, app-store, analytics, support, or payment operation remains exclusively in the EU. Where GDPR transfer restrictions apply, transfers rely on an applicable adequacy decision, Standard Contractual Clauses with required supplementary safeguards, or another lawful transfer mechanism. Contact us for information about safeguards relevant to your data.
9. Retention and deletion
- Account and cloud records: retained while the account or relevant feature is active, subject to applicable retention requirements.
- Account deletion: the in-app deletion flow deletes the Firebase Authentication user and triggers cleanup of covered user-linked GILLI records, including user documents, catches, skunk logs, favorite spots, tackle data, prediction feedback, public-profile and social records, leaderboard references, clubs, challenges, and other linked data handled by the deployed deletion functions.
- Local data: remains until you delete it, clear app data, use an applicable deletion flow, or uninstall the app; device backups follow Apple or Google settings.
- Exports: current generated export links and files expire after approximately 7 days.
- Photos and licences: remain with the associated record until deletion, subject to backup and provider deletion cycles.
- Photo-ID requests: submitted image bytes are not retained by the active identification request path; limited operational telemetry can remain for security and quality analysis.
- Optional analytics and diagnostics: GILLI stops future collection when you disable the relevant choice. Information already sent while enabled is handled under the applicable Firebase settings and terms.
- Purchase, security, and legal records: can be retained where needed for subscriptions, accounting, tax, fraud prevention, security, or legal obligations.
Deleting your GILLI account does not cancel an Apple App Store or Google Play subscription. Manage subscription cancellation through the relevant store. Some provider, transaction, anti-fraud, backup, or legally required records may remain after account deletion under the provider's lawful retention rules.
10. Your controls and GDPR rights
GILLI provides device-permission controls, social and visibility settings, separate Product Analytics and Crash Diagnostics choices, editing and deletion controls for supported records, account deletion, and data export where available.
Subject to applicable conditions, you may request access, rectification, erasure, restriction, portability, object to legitimate-interest processing, and withdraw consent at any time.
Send requests to lukasmeerschaut@pelagiclabs.io. We may request proportionate identity verification and normally respond within one month, subject to applicable GDPR extension rules.
You may complain to the Belgian Data Protection Authority at Rue de la Presse 35, 1000 Brussels, Belgium, telephone +32 (0)2 274 48 00, email contact@apd-gba.be, or through its citizen portal. You may also contact the supervisory authority where you live or work in the EU or EEA.
11. Security
Safeguards include encrypted transport, Firebase security rules, authenticated operations, scoped storage paths, validation, rate limiting, restricted provider credentials, account reauthentication for sensitive actions, image-size and decode controls, and deletion functions. No system is completely secure. Keep your device protected and avoid publishing sensitive fishing locations.
12. Children
GILLI is a general fishing utility and community service. It is not directed at children below the minimum age at which they may independently consent to an online service under the law of their country. Where parental authorisation is required, the account must be used with that authorisation. A parent or guardian may contact us to request review or deletion of a child's data.
13. Changes
We update this policy when GILLI, its cloud services, providers, consent controls, social functions, or legal requirements materially change. We will update the date above and provide additional in-app notice or request a new choice where required.