Privacy Policy
Effective date: March 1, 2026
Overview
AquariumAssist (operated by Lindahl Produktion, Finland) processes personal data as a data controller under the EU General Data Protection Regulation (GDPR). This policy explains what data we collect, how we use it, and your rights.
1. Data we collect
Account data
Email address, name, hashed password, preferred language. Required to create and maintain your account.
Subscription data
Plan tier, subscription status, trial dates. Stripe processes payment card details â we do not store them.
Aquarium data
Aquarium descriptions, fish inventories, water readings, diary entries, reminders. This data is personal content you create.
AI usage
When you use the AI advisor, your message and relevant aquarium context are sent to Anthropic's Claude API to generate a response. We log question counts and token usage for billing purposes but do not retain the content of AI conversations beyond your session.
Usage and security logs
Login events, IP addresses, session tokens (stored as secure cookies). Retained for up to 90 days for security purposes.
Push notification tokens
If you enable push notifications, we store your browser's push subscription endpoint. You can revoke this at any time in Settings.
2. Legal basis for processing
- Contract â providing the service you signed up for
- Legitimate interest â security monitoring, abuse prevention
- Legal obligation â tax records, invoicing
- Consent â push notifications (you can withdraw at any time)
3. Third-party processors
- Stripeâ Payment processing (US/EU)
- Anthropicâ AI advisor responses (US)
- Sweegoâ Transactional email delivery (EU)
- Hetznerâ Server hosting (Finland/Germany) (EU)
We do not sell your data to any third parties.
4. Data retention
Account data is retained for as long as your account is active. After account deletion, data is permanently removed within 30 days, except where retention is required by law (e.g., invoicing records are kept for 7 years under Finnish accounting law).
5. Your rights (GDPR)
Under GDPR, you have the right to:
- Access â request a copy of your personal data
- Rectification â correct inaccurate data
- Erasure â request deletion of your account and data
- Portability â export your data in a machine-readable format
- Restriction â limit how we process your data
- Objection â object to processing based on legitimate interest
You can exercise many of these rights directly in the app under Settings. For other requests, email privacy@aquariumassist.com. We will respond within 30 days.
6. Cookies
We use strictly necessary cookies only: session authentication (aqua_session) and language preference (NEXT_LOCALE). No third-party tracking or advertising cookies are used.
7. Contact and complaints
Data protection contact: privacy@aquariumassist.com
You have the right to lodge a complaint with the Finnish supervisory authority: Office of the Data Protection Ombudsman (tietosuoja.fi)