1. Our core promise
StashMap is a local-first fishing record app. Core content is saved on your device first. After first use on a new installation, signing in or choosing to continue without signing in both establish a private archive; pending changes remain on-device while offline.
When connected, structured records and controlled photo/video copies join the server archive for recovery and multi-device continuity. The server can process private-archive content; temporary encrypted sharing and legacy recovery-code backup continue to upload only on-device encrypted ciphertext. Existing 1.x data joins only after one explicit confirmation.
2. What the app itself collects
Core spot records and underwater-structure drawing run on-device and work without sign-in. Outside mainland China, the app offers Sign in with Apple only and creates no email password. Accounts are used for device sessions, Cloud Archive recovery/sync and media quotas—not public profiles, social recommendations or advertising profiles.
Permissions and their purpose: Location (show your position and set the default coordinate of new spots); Photo library (attach images/videos); Camera (capture photos/videos); Network (load maps, query weather and marine conditions, open Fishing knowledge, and connect to account, Cloud Archive, encrypted sharing or recovery-code backup services when you use them); Haptics (tactile feedback).
We never use these permissions unless you actively trigger the corresponding feature. Location is used for map display and new-spot defaults. It is not sent to StashMap's servers except when you request weather, tide or marine data; Apple Maps and the weather services process only what is needed as described below.
Usage analytics: when enabled, version 2.3 and later attributes a small allow-listed set of real product actions to the current private account, including a guest account used only on this device. Each event contains only its type, time, product session, platform, version, and build; the server derives account and device relationships from the verified session. Events never contain spots, coordinates, species, gear models, notes, photos, videos, search terms, share destinations, or advertising identifiers, and are used only for aggregate product decisions. You can turn analytics off in the app; this stops collection and clears pending events without affecting local saves or cross-device sync. Deleting the account removes raw events that remain linkable to it. Anonymous installation-level signals produced by version 2.2 and earlier remain historical and are never stitched to account records.
Only when you open Fishing knowledge does the app connect to cattle-horse.cn to load articles, quizzes and scenario practice. Quiz and learning progress stays in that WebView's local site storage. It is not written to StashMap's app database or included in .stash files, manual backup, cloud backup or cross-device sync. The app does not send spots, coordinates, logs, reviews, photos, videos, membership state or anonymous analytics identifiers to the knowledge page. Clearing app/site data or uninstalling removes this local progress.
The Home screen may show one dismissible operational notice. Eligibility uses only platform, app version, interface language, service region and account kind. Per-account, device and app-session eligible, truly visible impression, click and dismiss events support frequency limits and CTR; spots, coordinates, records, media, underwater structures and gear are never targeting inputs. Survey answers, schema version and submission time are stored only after you voluntarily submit, linked to the current private account to prevent duplicate responses and rewards. The short-lived survey URL carries only a random opaque token—never an account, device, phone or Apple identifier. Notices, events and answers are not part of the fishing archive, .stash or backups. Account deletion removes events and answers; minimal membership facts may remain only under the separate recovery/refund boundary described below.
3. Third-party services
Apple Maps (MapKit) — Provider: Apple Inc. Purpose: base-map rendering, map interaction, place search and location. When you use map features, Apple processes the necessary location and request data under Apple's own privacy policy (https://www.apple.com/legal/privacy/). This data does not pass through StashMap's servers.
StashMap Weather Service — when you open the environment / tide / ocean panel for a spot, the app sends only that spot's coordinates to our weather service to retrieve forecasts. We use QWeather for weather, Open-Meteo Marine for marine conditions, and our self-hosted pyTMD + EOT20 service for tides. We send coordinates only — never your identity, photos, field records, or underwater-structure content — and retain them only for short-lived caching.
4. How data flows when you share
When you use encrypted spot sharing, the app packs one spot and the nearby underwater-structure excerpts you choose into an AES-256-GCM encrypted file using a fresh per-share key. You may send the .fspot file through a system share channel, or temporarily upload its ciphertext to our private object storage to create a QR code and link. The key is shared separately and is never sent to or stored by our servers.
The link contains only a random share identifier, not the key, spot name or coordinates. Stopping a share blocks new downloads immediately; an already issued temporary download URL may remain usable for up to 5 minutes, and copies already downloaded or imported cannot be recalled. Expired or stopped ciphertext enters asynchronous deletion with storage lifecycle cleanup as a backstop.
5. What we do not do
We do not bypass first-use disclosure or add existing 1.x data to the server archive without one explicit confirmation. The private archive creates no public profile, feed or searchable spots, and private content is not used for recommendations, profiling or model training. We do not hold sharing keys or recovery codes, sell personal information or serve targeted ads, and we do not require a sign-in identity.
6. Backup and deletion
The app offers manual encrypted export. Legacy recovery-code cloud backup encrypts on-device before uploading ciphertext; account Cloud Archive instead stores server-processable structured records and controlled media copies. You can separately pause Cloud Archive, sign out a device, delete the remote archive or delete the account; local records are preserved by default. Uninstalling removes local content but does not automatically delete an enabled Cloud Archive.
Deleting an account signs out every device and deletes account identity, nickname, device and Cloud Archive content. To restore any still-valid membership and process refunds, we retain minimal transaction records separately from account content: irreversible HMACs of payment or redemption records, original occurrence time, duration or lifetime status, revocations, and an irreversible HMAC of the verified sign-in identity. This does not include a plaintext phone number, Apple name or email, nickname, device name, coordinates, spots, field records, photos or videos.
7. Children
StashMap is not directed to children under 13 (or the minimum age required in your jurisdiction). The app does not collect age. It processes the device credential and private archive needed when you continue without a sign-in identity, and a verified account identifier only when you choose to sign in.
8. Your privacy rights (GDPR / CCPA)
Whether you sign in or continue without a sign-in identity, a new installation establishes a private archive. When connected, the server stores the necessary account or device credential, entitlements, structured records and controlled media copies. Continuing without sign-in requires no phone number or third-party identity, and that archive is accessible only through the current device credential. You can access, export or delete server-side data in the app or by contacting us.
If you are in the EU/EEA or UK (GDPR) or California (CCPA/CPRA), you still have the right to access, correct, delete and port your personal data, to object to or restrict processing, and to not be discriminated against for exercising these rights. We do not sell or share personal information. Data on your device is removed by uninstalling. For any request, contact us below.
9. Policy changes
If this policy or a data flow changes, we will update the effective date and provide necessary context at the relevant feature. The consent gate is shown only on first use; later launches do not repeatedly check or block on it, and the latest policy remains available in the app.
10. Contact
Email: zhuhao.henry@gmail.com. Project: https://github.com/Stash-Map. We aim to reply within 7 business days.