Shoal is built to work without an account and without a server. This policy describes exactly what happens to your information, in plain terms.
Everything you enter — tank details, water parameter readings, livestock, maintenance schedules, journal entries and any photos you attach — is written to a file inside Shoal's own storage on your device. Without an account it is not uploaded anywhere. Deleting the app deletes this data permanently, which is why Shoal offers a one-tap JSON and CSV export you can keep yourself.
Shoal uses Firebase Authentication and Cloud Firestore (Google Ireland Limited, data stored in the European Union) for the optional account. You can sign in with an email address and password, with Google, or — on iPhone and iPad — with Apple.
Signing out stops the sync and leaves the copy on your device intact.
If you buy Shoal Pro, the transaction is processed by Apple (App Store) or Google (Google Play). Shoal uses RevenueCat to verify and restore purchases. RevenueCat receives an anonymous app-user identifier generated on your device, your purchase and subscription status, and basic device and country information. It does not receive your name, email address or any of your aquarium data. RevenueCat's privacy policy: revenuecat.com/privacy. Apple's handling of payments is covered by Apple's own privacy policy.
Shoal's diagnosis library, symptom matcher, calculators and every analysis engine run entirely offline. The AI Tank Vet is part of the paid Shoal Pro tier and sends data off the device only when you tap the button to run a check. At that moment Shoal sends to OpenAI:
This is sent over an encrypted connection, processed to produce the answer, and returned to your device. Shoal does not store the request or the answer on any server; the result is only shown on your screen. OpenAI's handling of API data is described at openai.com/policies/privacy-policy. Do not include personal information in the description field — it is not needed to identify a fish disease.
Shoal asks for camera access so you can photograph a fish, an algae outbreak or your tank, and for photo library access so you can attach an existing picture. Access is requested only at the moment you use one of those features. Selected images are copied into Shoal's own storage and stay on your device unless you deliberately send one to the AI assistant.
Maintenance reminders are local notifications scheduled by your device. There is no push server and no notification token is sent anywhere.
Shoal is a general-audience aquarium tool and is not directed at children under 13. It does not knowingly collect information from children.
You have direct control of your data: export it at any time from Settings, delete individual records in the app, sign out to stop syncing, or use Settings → Account → Delete account to erase your account and everything stored with it. Deleting the app removes the local copy.
If you are in the EU, EEA, UK, or a US state with a comparable privacy law, you have the right to access, correct, export and erase your data, and to object to processing. The account screen covers all of it directly; for anything else, email the address below and it will be answered within 30 days. The legal basis for processing account and tank data is performance of the contract you enter into by using the sync feature.
| Service | When it is used | What it receives |
|---|---|---|
| Google Firebase | Only while you are signed in | Your email address, a user id, and the tank data and photos you choose to keep |
| Apple / Google | Only if you make a purchase | Payment, handled entirely by the platform |
| RevenueCat | Only if you make or restore a purchase | Anonymous app-user id, purchase status, device and country |
| OpenAI | Only when you run an AI diagnosis | Your photo, your description and the tank context for that request |
If this policy changes, the date at the top changes with it, and any change that affects what leaves your device will be described in the app's release notes.