Privacy Policy — Fishies
Last updated: 11 May 2026
Fishies (“the app”) is operated by Wakeflow LTD (“we”, “us”) on behalf of Aquarius, a fish distributor based in the UK. The app is a B2B ordering tool for restaurant clients of Aquarius. This page explains what data the app collects, how it’s used, and how to contact us about it.
Who can use the app
Fishies is for staff of restaurants that have a customer account with Aquarius. Accounts are provisioned by Aquarius — users cannot self-register. The app is not directed at children under 13.
What we collect
- Email address — the email you use to sign in via Firebase Authentication.
- Display name — if provided.
- Linked customer code — links your sign-in to your restaurant’s Aquarius account.
Order content
- Cart contents, order history, and order notes — sent to Aquarius’s ordering system so your distributor can fulfil the order.
- Microphone audio — captured only while you actively tap and hold the voice button.
- Audio is streamed to Google Speech-to-Text for transcription and to OpenAI to generate the AI assistant’s reply.
- We do not store the audio after the request completes.
- Authentication tokens issued by Firebase, stored locally on your device.
- Crash and error logs generated by the app, used only for debugging.
We do not collect: location, contacts, photos, financial information, advertising identifiers, or analytics tracking data.
How we use the data
- Authenticate you to your restaurant’s Aquarius account.
- Show you the catalog and your order history.
- Place and track orders with Aquarius.
- Transcribe your voice for the in-app AI ordering assistant.
- Diagnose bugs and crashes.
We do not sell or share your personal data with third parties for marketing.
Third-party processors
The app uses the following services to deliver core functionality:
| Processor |
Purpose |
Data sent |
| Firebase Authentication (Google) |
Sign-in |
Email, password hash, session token |
| Aquarius API (the distributor) |
Place and fetch orders |
Customer code, cart contents, order notes |
| Google Cloud Speech-to-Text |
Transcribe voice input |
Microphone audio (only when voice button held) |
| OpenAI |
AI ordering assistant |
Voice/text messages during a chat session |
| Twilio |
Phone-call ordering (separate channel) |
Phone number and call audio when calling Aquarius |
All transfers are over HTTPS / TLS.
How long we keep it
- Order data: retained by Aquarius according to their business records policy (typically 7 years for UK VAT-relevant invoices).
- Audio for STT / AI: not retained by us after the request completes. Processors (Google, OpenAI) may briefly retain it per their own retention policies (typically <30 days, used for abuse detection only).
- Authentication records: kept until you delete your account.
Your rights
You can:
- Access your data — request a copy by emailing support@wakeflow.io.
- Delete your account — in the app, go to Settings → “Delete account”. This permanently removes your Firebase authentication record. Past orders remain on file at Aquarius for legal record-keeping.
- Correct your information — email support@wakeflow.io or contact your Aquarius account manager.
- Object or restrict processing — email support@wakeflow.io.
You can lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.
Security
- All network traffic uses HTTPS / TLS.
- Authentication tokens are stored in the device’s secure storage (iOS Keychain / Android Keystore).
- Server-side secrets (API tokens, third-party credentials) are stored in Google Cloud Secret Manager and never shipped to the device.
Changes to this policy
We’ll update this page when material changes happen. The “Last updated” date at the top reflects the most recent change.
- Email: support@wakeflow.io
- Operator: Wakeflow LTD
- App contact at the distributor: your Aquarius account manager