Hosted-community privacy notice
Effective 17 July 2026. This notice applies only when you choose to create a hosted account or publish through the hosted community service.
Controller and contact
JMS Dev Lab operates the service and decides why and how hosted community data is used. John Moore is the privacy contact. Email [email protected] for access, correction, deletion, objection, restriction, portability or complaint requests.
The local-first boundary
The local logbook, saved places, private notes, private marks and fishing preferences stay in your browser unless you deliberately export them. Creating an account does not upload that local data. The hosted API rejects raw local catch objects, exact coordinates, access routes, private notes, device identifiers and original photo metadata.
Data used by the hosted service
- Identity: Clerk manages sign-in details. Cork Fishing receives only an opaque identity subject and session security claims; it does not store your password or copy your email/profile into its community database.
- Account: an internal user ID, state, policy versions, privacy-safe preferences and timestamps.
- Content you choose to host: reduced catch details, coarse named water/area, delayed time, public note, selected attribution/audience and processed photos.
- Community operations: group membership, hashed invite records, concerns, moderation decisions, appeals and deletion/export job status.
- Security and reliability: opaque IDs, event codes, correlation IDs, durations, rate-limit outcomes and coarse counters. Request bodies, bearer tokens, report slugs, email addresses and precise locations are excluded from logs.
Why we use it and our lawful bases
- Contract: create the account, deliver the audience you select, process media, provide exports and carry out deletion.
- Legitimate interests: secure the service, prevent abuse, keep content age-appropriate for the adult-only beta, operate proportionate moderation and diagnose reliability. These interests are limited by data minimisation, human review, access controls and your rights.
- Legal obligation and legal claims: respond to valid legal duties, rights requests and necessary evidence preservation.
- Vital interests: exceptionally, act on a credible immediate risk to a person.
The beta does not use hosted community data for targeted advertising, sell it or send marketing communications. A future optional notification or analytics purpose will require a separate review and, where required, consent.
Who receives it
Your selected audience receives only the hosted report projection. Authorised moderators can access the minimum material needed for a case, and privileged reads are audited. Service providers process data under their terms and data-processing agreements:
- Cloudflare: Pages, Workers, D1, R2, Queues, Images, Turnstile, delivery, security and limited operational logs.
- Clerk: authentication, session security, passkeys/recovery and identity deletion.
- GitHub: source and deployment automation; production user content is not intentionally placed in the repository or CI logs.
The approved processor assessment is recorded in the project's processor register.
International transfers
Cloudflare and Clerk are US-headquartered providers and may process data outside the EEA. Their published DPAs use recognised transfer mechanisms including the EU–US Data Privacy Framework where available and EU Standard Contractual Clauses where required. Cloudflare community storage is configured for EU jurisdiction where the product supports it, but network, identity, security and support processing may still be global.
How long data is kept
- failed or abandoned original uploads: no more than 24 hours;
- operational logs and content-free metrics: up to 30 days;
- expired invites: expiry plus 30 days;
- removed publication history and closed concerns: up to 180 days;
- security audit events and deletion/export completion evidence: up to 12 months;
- moderation decisions and appeals: up to 24 months; and
- active account, report, group and processed-photo data: while needed for the active service, then removed through the deletion flow.
Cloudflare D1 recovery can retain an older state for its configured recovery window. If data is restored, deletions and revocations after the recovery point must be replayed. A documented legal hold can extend a record only when necessary, access-limited and reviewed.
Your choices and rights
You choose attribution and audience, can edit or revoke a report, export hosted data and request account deletion. Depending on the circumstances, GDPR rights include access, correction, erasure, restriction, objection and portability. Requests are normally answered within one month. We may need to verify that a requester controls the relevant account.
You may complain to Ireland's Data Protection Commission or another competent supervisory authority. Please contact us first if you would like us to resolve the issue directly.
Automated processing and children
Automated signals can rate-limit, detect duplicates or temporarily hold content for human review. They do not make permanent bans or legal decisions. The hosted beta is limited to adults aged 18 or over and does not provide child profiles or direct messaging.
Cookies and local storage
Authentication may use essential cookies or browser storage to maintain and protect a session. The local guide uses on-device storage for private features. The hosted beta does not enable advertising cookies or non-essential behavioural profiling.
Changes
Material changes receive a new immutable privacy version and are shown before the account acknowledges them. This notice is version privacy-2026-07.