AquariumAssist

Privacy Policy

Effective date: March 1, 2026

Overview

AquariumAssist (operated by Lindahl Produktion, Finland) processes personal data as a data controller under the EU General Data Protection Regulation (GDPR). This policy explains what data we collect, how we use it, and your rights.

1. Data we collect

Account data

Email address, name, hashed password, preferred language. Required to create and maintain your account.

Subscription data

Plan tier, subscription status, trial dates. Stripe processes payment card details — we do not store them.

Aquarium data

Aquarium descriptions, fish inventories, water readings, diary entries, reminders. This data is personal content you create.

AI usage

When you use the AI advisor, your message and relevant aquarium context are sent to Anthropic's Claude API to generate a response. We log question counts and token usage for billing purposes but do not retain the content of AI conversations beyond your session.

Usage and security logs

Login events, IP addresses, session tokens (stored as secure cookies). Retained for up to 90 days for security purposes.

Push notification tokens

If you enable push notifications, we store your browser's push subscription endpoint. You can revoke this at any time in Settings.

2. Legal basis for processing

  • Contract — providing the service you signed up for
  • Legitimate interest — security monitoring, abuse prevention
  • Legal obligation — tax records, invoicing
  • Consent — push notifications (you can withdraw at any time)

3. Third-party processors

  • Stripe— Payment processing (US/EU)
  • Anthropic— AI advisor responses (US)
  • Sweego— Transactional email delivery (EU)
  • Hetzner— Server hosting (Finland/Germany) (EU)

We do not sell your data to any third parties.

4. Data retention

Account data is retained for as long as your account is active. After account deletion, data is permanently removed within 30 days, except where retention is required by law (e.g., invoicing records are kept for 7 years under Finnish accounting law).

5. Your rights (GDPR)

Under GDPR, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your account and data
  • Portability — export your data in a machine-readable format
  • Restriction — limit how we process your data
  • Objection — object to processing based on legitimate interest

You can exercise many of these rights directly in the app under Settings. For other requests, email privacy@aquariumassist.com. We will respond within 30 days.

6. Cookies

We use strictly necessary cookies only: session authentication (aqua_session) and language preference (NEXT_LOCALE). No third-party tracking or advertising cookies are used.

7. Contact and complaints

Data protection contact: privacy@aquariumassist.com

You have the right to lodge a complaint with the Finnish supervisory authority: Office of the Data Protection Ombudsman (tietosuoja.fi)