1. The short version
- FreshFish does not upload the live camera stream, full market scene, imported video or audio.
- Detection, OCR, repeated-frame filtering and session lot identity run on the phone.
- When cloud identification is eligible, the app may send one representative image crop for a locally identified fish lot.
- Tray-label evidence and detector corrections use separate contribution controls and are not training data unless you explicitly choose to contribute them.
- FreshFish does not sell personal information, run advertising trackers or use third-party analytics in this website.
2. Data kept on the phone
The app processes camera frames and user-selected photos or videos to find candidate market lots. Its local database can contain session identifiers, lot identifiers, representative crops, image hashes, screen positions, device-relative world positions, bounded OCR text, review decisions and processing state.
Live frames, a selected source video and its audio are not sent to the backend. Imported video is processed without reading audio; the temporary local copy is deleted when replay closes. FreshFish does not intentionally collect precise geographic location. Device-relative positions describe the camera scene, not a map location.
3. Data sent to the cloud
Identification requests
The backend may receive a guest or signed-in account identifier, scan and local-lot identifiers, one representative JPEG, PNG or HEIC crop, its cryptographic hash and limited OCR text from a nearby market label. The backend stores normalized classification candidates and later human review decisions.
Accounts
A guest account uses an internal identifier. If you choose Apple, Google or Microsoft sign-in, the identity provider may supply a provider subject identifier and, depending on your provider choices, a name and email address. The production preview currently advertises Apple only.
Optional research evidence
With a separate, explicit contribution choice, the app may upload a tray-label crop and OCR text, or a representative crop you marked as not fish. These items begin as unverified research candidates and must be reviewed before any future training export. Excluding an item from identification does not contribute it.
4. Why data is used
Cloud data is used to operate account sessions, make identification screening requests idempotent, return candidate species, preserve human review history, retrieve source-attributed reference data, prevent duplicate uploads, diagnose failures, delete account data and—only when separately contributed—evaluate or improve the lot detector.
FreshFish does not use an image to measure freshness, mercury, calories, omega-3, food safety or health. Reference values are attached only after a person confirms a catalogue species and remain population or dataset observations, not measurements of the fish photographed.
6. Retention
The production backend is currently in report-only retention mode. It identifies records that would qualify for deletion but does not yet delete them automatically. Until an enforcement policy is approved, cloud data remains until you delete the account or an administrator performs a controlled deletion.
The proposed—not yet enforced—operational periods are a seven-day grace period after the latest guest credential expires, 180 days for unverified contributed evidence, and 30 days for rejected contributed evidence. These periods may change before release. Accepted research evidence needs a separate approved retention decision.
7. Your controls
- Training contribution: leave contribution off, or choose separately whether to contribute eligible label evidence or detector corrections.
- Sign out: revoke the current cloud session without deleting its account data.
- Delete cloud account: use the in-app account deletion control and confirm the permanent action. The backend deletes the account’s recorded database rows and exact stored image objects.
- Erase local cache: use the separate local reset control or remove the app. Cloud deletion and local erasure are separate because they act on different stores.
- Access, correction or complaint: contact the project through the support page. Do not include private photos, authentication tokens or sensitive information in a public issue.
8. Security and limits
FreshFish hashes bearer credentials before database storage, verifies uploaded image hashes, limits upload types and sizes, and records exact object keys for deletion. No internet service can guarantee absolute security. This preview has not completed an independent security or legal audit.
Do not rely on FreshFish to decide whether seafood is fresh, safe to eat or suitable for a medical condition. Follow local food-safety advice and use qualified professionals when needed.
9. Children
FreshFish is not directed to children and does not knowingly seek children’s personal information. The preview should be used by an adult responsible for the device and any contributed data.
10. Contact and changes
For access, correction, deletion or privacy questions, visit FreshFish Support. The current public contact channel is the project’s GitHub issue tracker; do not post private information there.
Material changes to this notice will be published at this URL with a new effective date. A qualified privacy and legal review is required before commercial public release.