Privacy Policy
The short version
- Fish is a communication tool for schools. Your school decides who has an account.
- We collect what the app needs to work: your email address, the messages and photos you choose to send, and a push token so notifications reach your device.
- There is no analytics, advertising or tracking software in Fish. We do not sell or rent your information, and we never have.
- We do not collect your location, your contacts, or the contents of your calendar.
- Your school administers Fish. You should assume anything you put into Fish can be seen by your school.
- Your school owns your account, so removing it is their decision. We will always help, and we delete the information we control on request.
Who we are, and what this covers
Fish is built by Attack Penguin LLC (“Attack Penguin”, “we”, “us”). This policy covers the Fish apps for iPhone, iPad, Mac and Android, the Fish web application your school uses, and this marketing website at fish.attackpenguin.com. Together we call these “Fish” or “the service”.
Fish is provided to schools, and your school administers its own community. Your school decides who is invited, what classes and rosters exist, and who may post. Where this policy describes information your school supplies or controls, requests about that information are usually best directed to your school first. We will always help.
Information we collect
Information you give us
- Your email address, when you sign in. Fish has no passwords: you sign in with a link sent to your email, so your address is the one piece of account information the app itself originates.
- Messages and reactions you send in chats, and reports you submit about content you believe breaks the rules.
- Photos and videos you choose to attach or share. This is optional. Fish only ever receives the specific items you pick, and has no access to the rest of your photo library.
- Your name and organization, if you fill in the “Get started” form on this marketing website. We use that only to reply to you about Fish.
Information your school provides
Schools maintain their own rosters in Fish, which include staff, families and students. A school may enter that information directly, or connect Fish to the student information system (SIS) it already uses, such as FACTS, so that rosters, classes and family relationships stay in step automatically.
Where a school connects its SIS, we receive roster data through OneRoster, the industry standard for exchanging roster information between schools and the software they use. We receive that data from your school; we do not go to the SIS vendor for it, and the school controls what is shared and can disconnect it. Either way the information originates with your school, and your school decides what we hold.
Teachers and staff also post classroom content. This means information about students, including their names and photographs, can be present in the service even though students do not have accounts and do not sign in. That information belongs to your school and is shared within your school community as your school directs.
Information collected automatically
- A notification token and an installation identifier, so push notifications can reach your device. See “Notifications” below.
- Basic activity needed to run the app, such as which messages you have read, so unread counts are correct across your devices.
- Ordinary server logs, including IP address and request details. These are used to keep the service running securely and to diagnose faults.
What we do not collect
These are worth stating plainly, because the capability is absent from the apps rather than merely unused:
- No location data. The apps request no location permission.
- No contacts. The apps request no access to your address book.
- No reading of your calendar. When you add a Fish event to your own calendar, your calendar app performs the write. Fish never reads what is already there.
- No microphone or camera access.
- No card numbers or bank details. Payment details go straight to your school's payment processor. See “Payments” below.
- No arbitrary file access. Sharing into Fish accepts text, images and video only.
- No analytics, advertising or tracking software of any kind in the Fish mobile apps, and no tracking scripts on this website.
How we use information
We use the information above to:
- operate Fish, which means signing you in, delivering messages, and showing your classes and calendar;
- send notifications you have asked for;
- keep the service secure, investigate abuse, and act on reports;
- process payments where your school runs them;
- diagnose faults and improve reliability;
- reply to you if you contact us.
We do not use your messages or your photographs to build advertising profiles, and we do not sell or rent personal information.
Who we share information with
Within Fish, your information is shared with your school community as the service is designed to do. The people in a chat see your messages, and a classroom's families see what a teacher posts.
Outside of that, we use a small number of service providers who process information on our behalf and are not permitted to use it for their own purposes:
- Apple delivers push notifications to Apple devices.
- Google delivers push notifications to Android devices, and connects your school's own Google Calendar where your school has chosen to use that. This is a calendar the school owns and connects; it is not your personal calendar.
- Amazon Web Services stores photos, videos and file attachments.
- Your school's payment processor, such as Stripe or Square, processes payments your school takes through Fish. Which one receives that information depends on which your school has connected. See “Payments” below.
- Sentry collects error reports so we can find and fix faults.
We may also disclose information if we are legally required to, or where it is necessary to protect someone's safety or our rights. If Fish is ever sold or transferred, we will tell you before your information becomes subject to a different policy.
What your school can see
Fish is administered by your school, and that is the most important thing to understand about privacy in Fish. Administrators at your school can:
- manage accounts and rosters, including who is a member and which classes they belong to;
- see classroom posts, calendars, fundraiser records and family relationships;
- create chats, change who is in them, and delete them, which means an administrator can add themselves to a conversation;
- review reported messages and remove content that breaks the rules.
You should assume that anything you put into Fish can be seen by your school. Fish is a tool your school runs for its community, not a private messaging service, and administrative access to school communications is expected to broaden over time as schools ask for it.
How your school uses that access is your school's decision, governed by its own policies rather than by this one. If you have a concern about it, raise it with the school first.
Notifications
Push notifications are delivered through Google's Firebase Cloud Messaging on Android, and Apple's Push Notification service on Apple devices. To reach your device, the notification, including the text shown on your lock screen, passes through whichever of those services your device uses. We keep notification text brief for that reason. You can turn notifications off at any time in your device settings.
Payments
Fish handles payments where your school uses it for them: fundraiser donations, lunch orders, school store purchases and sponsorships. Your school chooses its own payment processor and connects its own account, so the school is the merchant and the money goes to the school. Fish supports a number of payment processors, such as Stripe and Square.
Whichever processor your school uses, you enter your payment details on that processor's own secure checkout page, not in Fish. Card numbers, security codes and bank account numbers are submitted straight to the processor. We never receive them, and there is nowhere in Fish that they are stored.
What we do receive is confirmation that a payment succeeded, its amount, and what it was for, which is enough to credit the right fundraiser, order or account. Your payment processor handles your payment details under its own privacy policy.
How we protect information
- All traffic between the apps and our servers is encrypted with HTTPS.
- Your sign-in token is kept in the operating system's protected credential store rather than in ordinary app storage.
- Access to production systems is limited to those who need it.
No service can promise perfect security, but we take this seriously and design for it deliberately.
How long we keep information
We keep information for as long as your school's account is active and you are a member of it, and afterwards only as long as we need it to meet legal or accounting obligations. Messages and classroom content are retained for your school's community as your school directs. See “Deleting your information” below for who can remove what.
Deleting your information
Who can delete what depends on who controls it, so this section is in two parts.
Your Fish account, which your school controls
You do not create a Fish account. Your school creates it from its own roster, and you sign in with a link sent to an address the school already holds. Removing that account is therefore your school's decision rather than ours. We hold the information on your school's behalf and act on its instruction, and deleting someone unilaterally would remove them from their school's community without the school knowing.
To have your Fish account removed, ask your school. If you would rather not, or you are not sure who to ask, email privacy@attackpenguin.com and we will pass your request to the school and follow up with you. When a school instructs us to remove an account, we delete the account, its email address, sign-in details and notification tokens.
Content you posted into a shared space, such as chat messages and classroom comments, may remain visible to your school community, because it forms part of a conversation that belongs to the school. Whether that content is removed is also the school's decision.
Information we control, which we delete on request
Some information is ours rather than your school's: the name, organization and email address you gave us on this website's “Get started” form, anything you sent us by email, and marketing messages you signed up for. Email privacy@attackpenguin.com and we will delete it. We will acknowledge your request and complete it within 30 days.
Records we are required to keep for legal or accounting reasons, such as donation receipts, are retained for as long as the law requires.
Your choices
- Access and correction. Ask your school for a copy of your information or to correct it. Ask us and we will help.
- Deletion. See the section above, which explains what your school controls and what we do.
- Notifications. Turn them off in your device settings at any time.
- Photos. Attaching a photo is always your choice; Fish never reaches into your library on its own.
- Marketing email. If you signed up on this website, every message we send includes a way to stop them.
Depending on where you live you may have additional rights over your personal information. Write to us and we will honour them.
Children
Fish accounts are for adults: parents, guardians, teachers and school staff. Students do not sign in and cannot create accounts. As described above, information about students may still be present because schools maintain rosters and teachers share classroom content; that information is controlled by the school, and questions about it are best raised with them.
Changes to this policy
If we change this policy we will update the date at the top of this page. If a change materially affects how we handle your information, we will tell you in the app or by email before it takes effect.
Contact us
Questions about privacy, or about anything on this page, can go to privacy@attackpenguin.com. We read every one.
Fish
Fish