In short
Redfish is a social network built for sharing real moments with people you know. We only collect what the app needs to work, we don’t sell your data, and you can export or delete it at any time from the app.
This policy explains which personal data we process when you use the Redfish mobile app and the red-fish.app website, why, for how long, and your rights under the General Data Protection Regulation (GDPR) and French data protection law.
Data controller
The data controller is [publisher name or company — to be completed], [address — to be completed] (“Redfish”, “we”).
For any question about your data: contact@red-fish.app.
Data we process
| Category | Examples | Why | Legal basis |
|---|---|---|---|
| Account | Email address, @username, display name, password (stored hashed), Apple or Google sign-in identifier | Create and secure your account | Performance of contract (Terms) |
| Photos | Photos taken with your rolls, “One Take” profile photo, capture date | Provide the service: rolls, developing, shared memories | Performance of contract |
| Connections | Friends, requests, shared rolls, blocked users, privacy preferences | Share your memories with the right people | Performance of contract |
| Events | Name, dates, city, participants, event settings | Create, join and manage events | Performance of contract |
| Location | Precise location, only while the app is open and if you allow it | Show nearby events, check you are at an event, optional place on shared photos | Consent (phone permission) |
| Notifications | Device notification token, notification preferences | Notify you about friend requests, rolls ready and invites | Consent |
| Payments | Transaction reference, amount, status (card details are processed by Stripe, never by us) | Charge for paid events | Performance of contract, accounting obligations |
| Reports | Photo concerned, reason, date | Handle removal requests and moderate content | Legitimate interest, legal obligations |
| Technical data | IP address, date and time, device model, app version, security logs | Secure the service, prevent abuse, fix bugs | Legitimate interest |
We only ask for camera access to take photos, photo library access to pick a home background, and microphone access because the camera module requires it: no audio is ever recorded.
Who can see your photos
- Your photos are only visible once the roll has been developed.
- They are shared with your friends and, for a shared roll or an event, with the relevant participants.
- You choose who can add you (everyone, friends of friends, nobody) and whether your profile shows up in search.
- You can block a user at any time.
What we don’t do
- We don’t sell your personal data.
- We don’t track your location in the background.
- We don’t use your photos for advertising.
- The red-fish.app website uses no cookies, no analytics and no third-party resources.
Recipients and processors
Your data is only accessible to authorized Redfish staff and to service providers strictly needed to run the service:
- Hosting: INFRAWIRE NETWORKS SAS (France) — servers and database.
- Stripe — payment processing.
- Mapbox — event map display.
- Apple and Google — sign in with your Apple or Google account, and notification delivery.
We may also disclose data to authorities when required by law.
Transfers outside the EU
Some providers (Stripe, Mapbox, Apple, Google) may process data in the United States. These transfers are covered by the EU–US Data Privacy Framework and/or the European Commission’s standard contractual clauses.
Retention periods
- Account, photos, connections: as long as your account is active. When you delete your account, this data is permanently erased; backup copies are overwritten within 7 days.
- Payment records: 10 years, as required by accounting law.
- Technical and security logs: 12 months maximum.
- Support conversations: 3 years after last contact.
Your rights
You have the right to access, rectify, erase, restrict, object to and port your data, to withdraw your consent at any time, and to set instructions regarding your data after your death.
- Right in the app: Settings → Data & privacy → “Export my data” or “Delete my account”.
- By email: contact@red-fish.app. We reply within one month.
If you believe your rights are not respected, you can lodge a complaint with the CNIL, the French data protection authority (cnil.fr), or your local authority.
Minimum age
Redfish is for people aged at least 15, the age from which a minor can consent to data processing on their own in France. If we learn that an account belongs to someone younger, it is deleted.
Security
Traffic between the app and our servers is encrypted (TLS), passwords are stored hashed (Argon2), internal access is restricted and logged, and backups are made regularly.
The red-fish.app website
The website is static: it sets no cookies and loads no external resources. Our server keeps technical logs (IP address, requested page, date) for security purposes. Your theme preference (day / night) is only stored in your browser.
Changes
We may update this policy. For significant changes, we will let you know in the app. The last update date is shown at the top of this page.