1. Our core promise
StashMap is a local-first fishing spot manager. By default, your spots, photos, videos, hand-drawn layers and logs stay on your device.
Only when you actively use temporary encrypted sharing or zero-knowledge cloud backup does the app encrypt data on your device and upload ciphertext. The developer cannot decrypt it.
2. What the app itself collects
Core spot records and layer drawing run on-device. We do not operate accounts, do not require sign-in, and do not build user profiles.
Permissions and their purpose: Location (show your position and set the default coordinate of new spots); Photo library (attach images/videos); Camera (capture photos/videos); Network (load maps, query weather and marine conditions, open the fishing knowledge library, transfer ciphertext when you opt into sharing or cloud backup, and send the anonymous feature counts described below); Haptics (tactile feedback).
We never use these permissions unless you actively trigger the corresponding feature. Location is used for map display and new-spot defaults. It is not sent to StashMap's servers except when you request weather, tide or marine data; Apple Maps and the weather services process only what is needed as described below.
Anonymous feature counts: the app sends a small allow-listed set of lifecycle and feature-count events, such as first launch, first spot creation, purchase-page display, share export, or layer use. Each event contains only an anonymous installation identifier, event type, time, and necessary platform and version information. It does not contain spot coordinates or names, photos, logs, layer content, or advertising identifiers. We use these counts only to understand whether features are useful, not to reconstruct individual activity or build profiles.
Only when you open Fishing knowledge does the app connect to cattle-horse.cn to load articles, quizzes and scenario practice. Quiz and learning progress stays in that WebView's local site storage. It is not written to StashMap's app database or included in .stash files, manual backup, cloud backup or cross-device sync. The app does not send spots, coordinates, logs, reviews, photos, videos, membership state or anonymous analytics identifiers to the knowledge page. Clearing app/site data or uninstalling removes this local progress.
3. Third-party services
Apple Maps (MapKit) — Provider: Apple Inc. Purpose: base-map rendering, map interaction, place search and location. When you use map features, Apple processes the necessary location and request data under Apple's own privacy policy (https://www.apple.com/legal/privacy/). This data does not pass through StashMap's servers.
StashMap Weather Service — when you open the environment / tide / ocean panel for a spot, the app sends only that spot's coordinates to our weather service to retrieve forecasts. We use QWeather for weather, Open-Meteo Marine for marine conditions, and our self-hosted pyTMD + EOT20 service for tides. We send coordinates only — never your identity, photos, logs or layer content — and retain them only for short-lived caching.
4. How data flows when you share
When you use encrypted spot sharing, the app packs one spot and its nearby layers into an AES-256-GCM encrypted file using a fresh per-share key. You may send the .fspot file through a system share channel, or temporarily upload its ciphertext to our private object storage to create a QR code and link. The key is shared separately and is never sent to or stored by our servers.
The link contains only a random share identifier, not the key, spot name or coordinates. Stopping a share blocks new downloads immediately; an already issued temporary download URL may remain usable for up to 5 minutes, and copies already downloaded or imported cannot be recalled. Expired or stopped ciphertext enters asynchronous deletion with storage lifecycle cleanup as a backstop.
5. What we do not do
We do not upload unencrypted spot content without your action; we do not hold sharing keys or cloud-backup recovery codes; we do not build user profiles, perform cross-app behavioural tracking, sell personal information or serve targeted ads; we do not require an account.
6. Backup and deletion
The app offers manual encrypted export, where you keep the file yourself. If you actively enable zero-knowledge cloud backup, the app encrypts data on your device before uploading ciphertext. The recovery code remains with you; our servers do not store it and cannot decrypt the backup. A lost recovery code cannot be recovered. Core local data is removed when you uninstall the app; temporary shares and cloud backups can be deleted in the app, but copies already downloaded by recipients cannot be removed remotely.
7. Children
StashMap is not directed to children under 13 (or the minimum age required in your jurisdiction) and does not knowingly collect any user's age or identity.
8. Your privacy rights (GDPR / CCPA)
Because StashMap is local-first and does not collect your personal data on our servers, there is generally no server-side personal data to access, export, correct or delete.
If you are in the EU/EEA or UK (GDPR) or California (CCPA/CPRA), you still have the right to access, correct, delete and port your personal data, to object to or restrict processing, and to not be discriminated against for exercising these rights. We do not sell or share personal information. Data on your device is removed by uninstalling. For any request, contact us below.
9. Policy changes
If we update this policy (for example, a new feature introducing a new data flow), we will show a notice on next launch and update the effective date above. Material changes will require you to re-confirm.
10. Contact
Email: zhuhao.henry@gmail.com. Project: https://github.com/Stash-Map. We aim to reply within 7 business days.