Share This
Privacy Policy
troutchallenge.com and the Trout Challenge app
troutchallenge.com and the Trout Challenge app
troutchallenge.com and the Trout Challenge app
Effective date: September 7, 2026
The rest of this page is the detail behind those lines.
Trout Challenge is built and run by Iverson Creative LLC, a New Mexico company.
Not affiliated with, endorsed by, or sponsored by the New Mexico Department of Wildlife or any other agency. The rules are theirs, and we link to them.
Questions about this policy, or a request about your own information: [email protected].
Two halves of one thing.
This policy covers both.
Arrive at troutchallenge.com and nothing is set. No cookies, first party or third party, until you make a choice.
A banner asks whether you want to accept analytics. If you accept, Google Analytics loads and sets two cookies (_ga and _ga_PE7SHJDNYE) that last about thirteen months. Google then receives the page you are on, the page you came from, your screen and window size, your browser language, your browser and device type, and your IP address, from which it works out an approximate location.
If you decline, or if you never touch the banner, none of that runs and none of those cookies are set.
Cloudflare, which sits in front of this site, may set a short lived security cookie (cf_clearance, thirty minutes) if its automated checks want to confirm a request is coming from a real browser. That one is about blocking abuse, not about measuring you.
There is a second, lighter measurement running on this site, and we would rather explain it than leave it out.
Cloudflare adds a small analytics script to the page at its network edge, after the page leaves our server and before it reaches you. The website software never sees it, which means the consent banner above cannot control it. It sets no cookies and it does not follow you to other sites. It records page views, the page you came from, your country, your browser and device type, and how fast the page loaded. It receives your IP address because every request does.
If you want to stop it, a tracker blocking extension will do it. We are telling you because you cannot decline it here, and a policy that quietly folded it in with the consent banner would be wrong.
The site loads two typefaces from Google Fonts on every page. That sends your IP address, your browser string, and the page you are viewing to Google, whether or not you accepted analytics.
There is one form on the site. It asks for your name and your email address, and it does two things with them: it emails them to us, and it saves them in the website’s database.
Right now that form is a placeholder while we work out whether to run a mailing list at all. We have no schedule for deleting what it stores, so treat it as kept until you ask us to remove it. Ask, and we will. If we move it onto a mailing list service, this page changes before that happens.
There is no comment form anywhere on the site.
The web server records every request: your IP address (your real one, not an anonymized or edge address), the time, the page, anything you typed into the site’s search box, the response, the page you came from, and your browser string. Those logs stay on our own server. They are not sent anywhere, and they are not exported to any third party.
We do not currently delete them on a schedule, so assume they are kept indefinitely. If we set a retention period, this page will say what it is.
Your email address, and nothing else. There is no password on this service, so there is no password of yours for us to hold or lose. You enter your email, we send you a link and a six digit code, and either one signs you in. Those emails go out through Resend, our mail provider.
We also keep a short record of sign in attempts, which is an email address or an account ID and a timestamp. No IP addresses, and never the code that was typed.
When you get ready to send a challenge submission, the app asks for the four things the program’s own form asks for:
All four are encrypted before they are written to our database.
About the CIN. New Mexico’s CIN is formatted MMDDYYYY-XXX, and the first eight digits are a date of birth. That makes it more sensitive than it looks, so we handle it accordingly: it is never written to a log file, never included in an error report, and never sent to any analytics service, ours or anyone else’s.
For each photo we keep the file, the file name, its size and dimensions, a fingerprint of the file, a timestamp, and where it is stored. Everything below covers what we do not keep.
About that point. The named water is the location the app asks for, because it is the only one the programs ask for. You can also attach an exact point to a catch if it helps you remember where you were. That one is yours and stays yours: it is never published, it is never on any public map, and it is left out of the file your catches export into. You can switch it off in your settings, and then no exact point is stored on any new catch at all.
The app is built to work on the water, where there is usually no signal. When you log a catch it is written to storage in your own browser on your own device, immediately, whether or not you have a connection. It syncs to us later, when you are back in range.
That is worth knowing plainly: for a while, sometimes for days, your catches exist only on your phone.
Every line here is enforced in the code, not just promised on this page.
We do not keep the coordinates in your photos. When a photo reaches our server we read its metadata once, use any coordinates in it to suggest which named water you were probably on, and then strip the metadata off before the file is stored anywhere it can be served. The coordinates are not written to the database. What survives that step is a list of candidate water names with no coordinates in it.
We do not publish where you caught a fish, at any precision. Not exact, not rounded off, not blurred, not as an option you could turn on. That covers the private point above: it stays in your own record and never travels. The programs themselves ask only for a named water, and we are not going to publish finer than the people responsible for the fish do.
Nothing that leaves the system carries photo metadata. We strip on the way in, and every copy that goes back out (a submission, an export, a share) is stripped again.
The public map only shows waters an agency has published. It is never built from anglers’ catch data, not even added up.
We do not sell your information. Not to anyone, not for any purpose, and there is no clause here reserving the right to do it later if the project changes hands.
We do not run advertising, and we do not track you across other websites.
We never charge for anything a challenge program provides for free. There are no payments on this service, so we hold no card numbers and no billing information of any kind.
Sign in emails go through Resend. They contain your link and code, nothing else.
Your submission. By default you send it yourself. The app assembles the message and hands it to you, and you press send from your own email program, which means the agency’s acceptance lands in your own mailbox. Your submission does not pass through us on that path.
New Mexico Trout Challenge submissions go to [email protected], a mailbox at the Department. The message carries your name, email address, mailing address, license number, CIN and your photos, because those are the fields the program asks for.
We are building an optional second path where the app sends it for you. It will be off unless you turn it on. If you do turn it on, the message goes out with From reading "<Your Name> via Trout Challenge" at our own address, and Reply-To set to you, so the agency replies to you and not to us. We will never put your address in the From line and send as you. On that path the submission passes through Resend, which keeps a copy under its own terms.
This page will be updated before that path opens.
We do not run a newsletter, and you will not be added to one because you made an account.
| Service | What it does | What it sees |
|---|---|---|
| Vercel | Runs the app | Requests to the app |
| Neon | The app’s database | Everything the app stores, including the encrypted profile fields |
| Cloudflare | DNS, network in front of both halves, photo storage, and the edge analytics described above | Every request, and your photos |
| Resend | Sends our email | Your email address, and the contents of anything we send |
| Fonts on the reading site, and Analytics if you accept it | Your IP address on every page, and the analytics data above if you accepted | |
| Our own server | Hosts the reading site | What the server logs section describes |
They handle this information to provide those services and for nothing else. We do not share your information with anyone for advertising, and we do not sell it.
We do not track you across other websites, so a browser’s Do Not Track signal has nothing here to change. Every visitor is treated the same way.
Others on the page are a different question, and here is the honest answer:
We answer these ourselves, by email. There is no ticket system and there does not need to be.
Accounts are for people 13 and older. When you create one, we ask your date of birth, and if you are under 13 we do not open the account and we do not keep what you entered.
We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has an account here, email [email protected] and we will delete it and everything in it.
The four profile fields (name, mailing address, license number, CIN) are encrypted before they are stored, and each one is tied to your account so it cannot be moved to someone else’s record and still read. Sign in is by emailed link or code, so there is no password to steal. Session cookies are locked to this host and cannot be read from anywhere else. The CIN is kept out of logs, error reports and analytics as a rule enforced in the code.
We take reasonable measures to protect what we hold. We are not going to tell you it cannot be broken into, because nobody can honestly say that.
Trout Challenge is built for anglers in the United States, around state challenge programs that are run in the United States. We do not offer it to people in the European Union or the United Kingdom, and it is not designed against those countries’ privacy rules.
If we change this page we will update the date at the bottom and post the new version here. If a change is material, we will say what changed at the top of the page for thirty days, and if you have an account we will email you about it.
Iverson Creative LLC, New Mexico.
Last updated: September 7, 2026