Legal

Privacy Policy

How TankForge handles account, aquarium, and operational security data. Clear boundaries around what we store and why.

Effective dateJuly 24, 2026
TankForge handles aquarium data, account data, and operational security data so the app can sync reliably and protect accounts. This page explains that boundary clearly.

This Privacy Policy explains how TankForge collects, uses, and protects your information when you use the TankForge mobile app, website, and related services (collectively, the “Service”). By using the Service you agree to the practices described here.

1. Definitions

“TankForge,” “we,” “us,” and “our” refer to the operator of the TankForge Service. “You” and “your” refer to the individual using the Service. “Service” means the TankForge iOS app, Android app, Web (Beta) app, website, and any related APIs.

2. Information we collect

Account data. When you create an account we collect your email address, username, and authentication metadata. If you sign in with Apple or Google, we receive a provider-specific user identifier and, if you authorize it, your email address. We do not receive or store your Apple or Google password.

Subscription and billing data. If you subscribe to TankForge Pro, your payment is processed by Apple (App Store In-App Purchase), Google (Google Play), or Stripe (Web (Beta), where checkout is available). We store a transaction identifier, subscription status, plan type, and expiration date. We do not receive or store full credit card numbers, bank account numbers, or billing addresses. Stripe may store a customer identifier on our behalf; Apple and Google process payments entirely within their own systems.

App data. Tanks, species preferences, water parameters, livestock records, maintenance logs, journal entries, equipment, treatment plans, settings, and shared tank snapshots you create within the Service.

Expanded tank and care records. Depending on the features you use, app data may also include tank photos and photo references, custom livestock or product records, plants, corals, macroalgae and invertebrates, care routines, build plans, cycling, acclimation, quarantine, treatment, breeding, vacation and Shared Care workflows, wishlist and product scanner records, inventory, expenses, reports, exports, losses, smart alert context, custom parameters, ICP, PAR, lighting and equipment details.

Business and customer records. If you use TankForge Business features, we may process business profile information, service zones, route plans, clients, service addresses, managed tanks, visits, estimates, invoices, service reports, customer-visible notes, products used, incident records, share tokens, claim status and related audit metadata.

Club and award records. If you join an aquarium club in TankForge, we process your club membership, the role the club assigns you, the display name you choose for that club, whether you opted in to public standings, and the award submissions you send to the club. A submission includes the species, date, counts, survival period, method notes, photo counts and any witness name you enter. Water parameters are only included in a submission when the program requests them and you turn that option on for that submission. When you submit, the club receives a copy of that submission that the club keeps as its own award record, so it remains part of the club’s award history even if you later delete your own copy or leave the club. If you delete your TankForge account, we delete your club memberships and your own copies of your submissions, and we permanently remove your identity from the club’s copies so the club keeps only de-identified award records that are no longer linked to you.

Device and security data. App version, device model, operating system version, push notification tokens, device registration identifiers, and basic request metadata (IP address, user agent, request path, and timestamp). On iOS we use Apple DeviceCheck and device attestation to verify that requests come from a genuine device. This process transmits a device-generated public key and a signed challenge to our server; it does not fingerprint or track you across apps.

Platform integrity and device proof. To protect accounts, sync, subscriptions and abuse-sensitive features, we may process security signals from Apple DeviceCheck or App Attest, Google Play Integrity, app tokens, device identifiers, app version, operating system version, request hashes, verdicts, failure reasons and related security logs.

Operational and product-improvement telemetry. We log API request metadata such as method, path, status code, response time, user agent, device or account identifiers when available, and the full request IP for security monitoring, abuse prevention, and reliability. API audit events can also include IP-derived country, region, city, latitude, and longitude resolved through ipwho.is. API audit retention is configurable and defaults to 30 days. For authenticated product analytics, we record meaningful actions such as opening the app or a top-level screen, creating or updating a tank, logging parameters or maintenance, changing reminders, creating journal entries or shares, generating exports, onboarding progress, notification state, and purchase outcomes. A bounded session summary can include up to four hours of active seconds, screen and meaningful-action counts, entry and last screen, entry source, error state, and end reason. Product events include the account identifier assigned by our server, event category, platform, app version, outcome, and limited non-content context; they do not include aquarium readings, tank identifiers, journal text, free text, email addresses, payment data, or full IP addresses. Product events expire after 90 days and are deleted with the account.

Website attribution and product improvement. When you visit TankForge public website pages, we may collect first-party attribution and interaction data such as tagged campaign parameters, referrer host, landing page, public-site click paths, checkout-start metadata, user agent, and inferred browser, operating system, and device class. Our backend derives the request IP from the trusted proxy chain and may send the full IP address to ipwho.is to infer country, region, city, latitude, and longitude; these are IP-derived estimates, not device GPS coordinates. We cache the raw IP and returned geography for up to 24 hours. Attribution and operational events can retain a masked IP and that source geography for up to 90 days. We use this data to understand visits, sign-ups, Pro checkout creation, and App Store, Google Play, or Web (Beta) handoffs. We do not use third-party advertising pixels or cross-site tracking scripts.

Public-page performance monitoring. On public marketing pages only, Cloudflare Real User Monitoring collects in-memory browser performance measurements such as Core Web Vitals and the page path. The beacon uses no cookies or browser storage. Cloudflare receives the source IP as part of normal HTTPS delivery, discards it at the nearest data center, and does not store it in RUM databases or logs. TankForge excludes visitors in the European Union and does not enable this beacon on the authenticated web app, care portals, shared records, or other user-specific routes.

Notification records. When you enable notifications, we may store device push tokens or browser push subscription endpoints and keys, endpoint hashes, permission status, user agent, notification preferences, quiet hours, delivery status and troubleshooting metadata. Browser notification permission prompts are also tracked locally in your browser so we do not repeatedly ask.

3. Device-local features and optional feedback

Certain optional features access device capabilities locally. TankAI answers are generated on your device using bundled TankForge aquarium logic, curated care content, local catalog retrieval, and supported on-device model features.

  • Location (Weather Alerts). If you enable Weather Alerts, TankForge requests your approximate location to query Apple WeatherKit on iOS or Open-Meteo on Android for local weather conditions that could affect your aquariums and outdoor ponds. If you opt in on an outdoor pond, the same weather feed may refresh that pond’s ambient outdoor temperature; logged water tests remain the source of truth for pond water temperature. Your coordinates are sent only from your device to the weather provider and are never sent to TankForge servers. Location data is not stored, logged, or tracked. You can revoke location access at any time in your device settings.
  • TankAI. TankAI questions and responses are not sent to TankForge servers for answer generation. On supported Apple devices, optional Apple Intelligence layers may process long-tail explanation requests on-device or, when eligible and needed for complex requests, through Apple Private Cloud Compute under Apple’s terms; TankForge still does not receive those prompts for generation. On supported Android devices, optional on-device Gemini Nano via Google AICore may process long-tail explanation requests locally under Google’s terms; TankForge still does not receive those prompts for generation. If you tap thumbs up or thumbs down on a TankAI response, TankForge may receive your feedback value, the text of your question, the full text of the response you rated, platform and app version, response type/source metadata, matched article identifiers, and optional correction text so we can improve answer quality. Long questions and responses are shortened before upload.
  • Camera (Test Strip Scanner). If you use the Test Strip Scanner, TankForge accesses your device camera or photo library to capture an image of your test strip and optionally your bottle color chart. All color analysis happens entirely on your device. Camera images are processed in memory only and are not stored by the app after the scan completes. Images are never transmitted to TankForge servers or any third party. Photos selected from your library are accessed in-memory only and are not re-saved or modified.
  • Line-item photo attachments. Storage depends on the platform and feature. A photo or reference may remain in device storage, browser storage, or configured cloud storage; a photo you explicitly include in a shared report, tank link, or Business customer view may be uploaded or visible to people with access to that surface. Do not assume every platform uses iCloud Drive or that every attachment remains device-only.

Journal photos, tank photos, line-item photos and scanner captures may follow different storage paths depending on platform and feature. Test strip and guided test-kit images are intended for local analysis unless you explicitly save or attach related results. Private photo attachments and references may remain on your device, browser storage or your configured cloud storage; photos or notes you include in shared reports, tank links or Business customer views can be visible to people with access to those links.

These features are optional, device-dependent, or require you to actively initiate them. Location access requires your explicit opt-in. Test Strip Scanner and line-item photo attachments require you to deliberately select or capture an image. Disabling a feature stops future related data access.

4. How we use information

  • Provide, operate, and sync core app functionality across your devices.
  • Authenticate your identity and protect account and platform security.
  • Process and manage subscriptions and communicate with payment processors.
  • Send transactional communications such as email verification and optional push notifications you enable.
  • Detect and prevent abuse, fraud, and unauthorized access.
  • Diagnose bugs, monitor performance, and improve the Service.
  • Measure the performance of first-party marketing campaigns, landing pages, and public-site conversion paths.

5. Product guidance and no professional advice

TankForge provides informational guidance only. We strive for accuracy, but we do not guarantee that recommendations, alerts, compatibility outputs, medication guidance, care plans, TankAI responses, or other content are complete, current, or 100% accurate. TankForge does not provide veterinary, medical, emergency, or life-safety services. Always verify care, treatment, and dosing information against reliable sources and manufacturer labels before acting.

6. Legal bases for processing

Depending on your location, we process personal data based on: (a) performance of the contract between you and TankForge (providing the Service); (b) legitimate interests such as security, fraud prevention, and reliability; (c) your consent where required by law; and (d) compliance with legal obligations.

7. Cookies and local storage

TankForge Web (Beta) uses a small number of strictly functional cookies to maintain your authenticated session and protect against cross-site request forgery (CSRF). These are:

  • tf_web_access — short-lived access token cookie (HttpOnly, Secure, SameSite=Lax).
  • tf_web_refresh — longer-lived refresh token cookie (HttpOnly, Secure, SameSite=Lax, 30-day expiry).
  • tf_web_csrf — CSRF protection token (HttpOnly, Secure, SameSite=Lax).

We also use limited first-party browser storage on public website pages to avoid double-logging the same tagged visit and to associate follow-on clicks with the same short-lived browsing session. This storage is used only within TankForge-owned pages and is not shared across unrelated websites.

We do not use advertising cookies, third-party analytics cookies, third-party pixels, or cross-site tracking cookies. We do not participate in ad networks or cross-context behavioral advertising.

8. Data sharing

We do not sell, rent, or trade your personal data. We do not share personal data for advertising purposes.

We use or share data with the following categories of service providers to operate the Service:

  • Infrastructure and analytics providers — hosting, database, content delivery, and operational analytics services. For API audit telemetry and public website attribution, ipwho.is may receive the full request IP to return IP-derived country, region, city, latitude, and longitude under its own terms and privacy policy.
  • Payment processors — Apple, Google, and Stripe process subscription payments. Each processor receives only the data required to complete the transaction and is subject to its own privacy policy.
  • Communication providers — Apple Push Notification service (APNs), Google/Android notification services, browser push services, and email delivery providers used for notifications and transactional email.
  • Notification delivery and platform services. We use platform notification services such as Apple Push Notification service, Google/Android notification services and browser push services to deliver reminders and alerts you enable.
  • Weather and location services. When you opt in to weather alerts, approximate location may be used with providers such as Apple WeatherKit or Open-Meteo as described above.
  • Aquarium clubs. Club officers can see the submissions you send to their club, the club's list of active members, the display name each member chose for that club, and whether each member opted in to public standings. They cannot see your email address, your tanks, your location or any other record. Because a display name can appear on a club's public standings page, officers can clear a display name, remove a member from public standings, or remove a member from the club, and we keep a record of that action for the club. Officers can never set a display name for you or opt you in to public standings. If a member's display name is offensive, misleading or impersonates someone, you can report it to that club's officers. A report records the reported member, the reported display name, the reason you chose and any note you add; officers reviewing it are never shown who filed it. A report about a club officer or administrator goes to TankForge instead, and that club cannot dismiss it. Reports you file, and reports about you, are deleted when your account is deleted. Club standings are private to the club unless the club turns on public standings and you separately opt in; both are off by default, and either one alone is not enough to publish your name. Clubs listed in our directory that have not claimed their listing were compiled from publicly available information and are not partners of TankForge.

We may also disclose data when required by law, regulation, legal process, or enforceable government request, or to protect the rights, property, or safety of TankForge, our users, or the public.

9. Shared links and public visibility

If you create a share link, anyone with that link may view the shared tank snapshot until the link expires or is deleted. Share links should be treated as public URLs. You control when to create and revoke them.

Shared Care invitations, public tank snapshots, Business customer tank links, service reports, estimates, invoices and claim links may expose the records you choose to include to anyone with the link, or to the invited account after a claim is completed. Do not include personal, customer or household information in shared records unless you have permission and are comfortable with that visibility.

10. Data retention

We retain account and app data for as long as your account is active. The raw-IP geolocation lookup cache expires after up to 24 hours. API audit events can include the full request IP and source country, region, city, latitude, and longitude when resolved; their retention is controlled by the API audit setting, which defaults to 30 days. First-party website attribution and operational events use a masked IP and can retain the same source geography for up to 90 days. Endpoint performance metrics are retained for 14 days. Limited billing, subscription, or payment-related records may be retained where needed to support disputes, compliance obligations, or processor requirements.

When you request account deletion, we delete or anonymize your personal data within 30 days, except where retention is required by law, necessary to resolve disputes, or needed for fraud prevention. For step-by-step deletion instructions, seeDelete Your TankForge Account.

11. Security

We use technical and organizational safeguards to protect your information, including encrypted connections (TLS), hashed credentials, HTTP security headers, rate limiting, CSRF protection, and access controls. No system can guarantee absolute security.

12. Your choices and rights

Depending on your jurisdiction you may have rights to access, correct, delete, port, or restrict processing of your personal data. To exercise any right, email[email protected] from your account email address. We will respond within 30 days (or the shorter period required by your local law).

  • Access and correction. View and update account information in the app, or request a copy of your data by contacting support.
  • Deletion. Request account deletion through the app when available or by contacting support. We will delete or anonymize your data within 30 days, subject to legal retention requirements. See Delete Your TankForge Account for the current deletion steps.
  • Data portability. You may export tank data from within the app.
  • Push notifications. Disable push notifications at any time in the relevant iOS, Android, browser, or device settings.
  • Do not sell or share. We do not sell or share personal data for cross-context behavioral advertising. No opt-out action is required because no such sharing occurs.

You can also manage push notifications through iOS, Android, browser and device settings, and you can revoke or regenerate sharing links from the relevant sharing or Business screens where supported.

13. Children

The Service is not directed to children under 13 (or a higher age where required by local law, such as 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will delete it promptly.

14. International transfers

Your data may be processed in countries other than your own, including the United States. We apply safeguards as required by applicable law, including standard contractual clauses where applicable.

15. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the revised policy with a new effective date and, where required by law, notify you by email or in-app notice before the changes take effect. Your continued use of the Service after the updated policy becomes effective constitutes acceptance.

16. Contact

Privacy questions or data requests:[email protected]