Last updated: August 25, 2026
Fishlimpia ("we", "us", or "our") operates the Fishlimpia mobile application and website at fishlimpia.com. This Privacy Policy explains how we collect, use, and protect your personal information.
Techbyte OÜ, a company registered in Estonia under registry number 16817909, with its registered address at Ruunaoja tn 3, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia, is the controller for personal data processed by Fishlimpia (fishlimpia.com). Contact: info@fishlimpia.com.
We process personal data under the following legal bases of the GDPR:
We use the following third-party services to operate Fishlimpia:
| Service | Purpose | Data Shared |
|---|---|---|
| Google Identity Services (Google OAuth) | Account sign-in with Google | Authentication credentials |
| Stripe | Payment processing for subscriptions | Billing country, postal code where required, email; card details go directly to Stripe and never reach our servers |
| Cloudflare Turnstile | Bot protection at registration | Browser and device signals evaluated by Cloudflare to tell humans from bots |
| YouTube | Embedded exercise demonstration videos | Standard request data (IP address, browser info) when you view or play an embedded video; we use YouTube's privacy-enhanced mode (youtube-nocookie.com) |
| OpenAI | Content translation | Exercise and training text (no personal data) |
| Firebase Cloud Messaging | Push notifications | Device tokens, notification content |
| Resend | Email delivery | Email address, name |
| DigitalOcean | Hosting and media storage | All service data (servers and file storage) |
| Sentry | Error tracking | Error logs, browser info |
We do not sell your personal data to any third party.
Some of the providers above (OpenAI, Sentry, Resend, Google/Firebase, Stripe) may process data in the United States or other countries outside the European Economic Area. Where that happens, the transfer is protected by recognized safeguards: the European Commission's Standard Contractual Clauses and, for providers certified under it, the EU-US Data Privacy Framework. You can contact us for more information about the safeguards applied to a specific provider.
We retain your data for as long as your account is active. Training logs and performance data are kept indefinitely to preserve your training history.
Email verification tokens expire after 24 hours.
When your account is deleted, all associated data is permanently removed, including:
To request account deletion, contact us at info@fishlimpia.com.
You have the right to:
To exercise any of these rights, write to info@fishlimpia.com. You can also lodge a complaint with your supervisory authority (for example the AEPD in Spain or the AKI in Estonia).
We do not use third-party analytics services (no Google Analytics): we measure website visits with our own Umami instance, hosted on our own servers, which sets no cookies and stores no personal data. On our public marketing pages, and only if you accept it on the consent banner, that same tool also records the session (scrolling, clicks and the content of the page, with form fields always masked) for a few days; never inside the app or the mobile apps. The web app itself sets no cookies: authentication uses a token kept in your browser's local storage, alongside your language preference and interface settings. On our public marketing pages, and only if you accept it on the consent banner shown there, we use the Meta pixel to measure our advertising; it is never present inside the application or the mobile apps, and rejecting it changes nothing about the service. If you arrived through an ad and consented, we may also share the ad click identifier and a hashed (unreadable) form of your email with Meta to attribute your registration or purchase to the ad that produced it; the legal basis is your consent, which you can withdraw by clearing this site's data. Third-party cookies can be set by the providers behind specific features when you use them: Stripe (payments), Google (sign-in), Cloudflare Turnstile (registration), and YouTube (embedded videos). See our Cookie Policy for the full details.
Paid subscriptions are purchased on our website and processed by Stripe, our payment processor. Your card details are entered directly into Stripe's payment form and never reach or get stored on our servers. To comply with tax rules we collect your billing country (and postal code where required) and share it with Stripe, which also issues your invoices. We keep subscription records (plan, status, renewal dates, invoice references) linked to your account for as long as required for accounting and tax purposes.
Fishlimpia is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or by email. The "Last updated" date at the top reflects the most recent revision.
If you have questions about this Privacy Policy or your data, contact us at: