Privacy Policy
The short version
- Birdbrainz contains no advertising, no analytics SDKs, no crash-reporting SDKs, and no tracking identifiers. We don’t track you across apps or sell data.
- Your photos are sent to Google’s Gemini API to suggest bird species — as a reduced-size copy with camera metadata removed.
- When you use the map or location search, your device talks directly to our map providers (Mapbox) and geocoding provider (Geoapify).
- Adding a location to a post is optional. When you add one, you pick a named place; exact coordinates are public only when you place them yourself with the picker — never from your photos’ embedded GPS.
- You can delete your account and its data at any time, in the app or via our deletion page.
What we collect
Account. Your email address, sign-in provider (Google or Apple), and the account records needed to keep you signed in. We never see your provider password.
Profile. Display name, handle, bio, and profile photo. Your profile photo is re-encoded before storage; the uploaded original is not kept.
Content you post. Photos, captions, species tags, the date a photo was taken, and comments.
Photo metadata. When you add a photo, we extract and privately retain a snapshot of its embedded metadata: capture time, camera and lens details, exposure settings, authorship and copyright fields, content-authenticity (C2PA) identifiers, and — if present — the photo’s GPS coordinates. Publicly served copies of your photos are stripped of all embedded metadata except your authorship and copyright fields, which are preserved on your behalf.
Location. Three distinct kinds:
- Public post location — optional; you can post without one. When you add a location you pick a named place, and the post shows that place or a broader area label assigned by our display rules. Exact coordinates are public only when you explicitly place them with the location picker; coordinates from photo metadata are never made public.
- Private photo coordinates — GPS embedded in your photos is retained privately (see above) and never shown to other users.
- Device location — used only by the composer’s location picker, with your permission, to center the map.
Push notifications. If you enable them, your device’s push token and a random per-install identifier, used to tell you when your post is ready.
What we don’t collect: usage analytics, advertising identifiers, diagnostics profiles, contacts, or anything from your photo library beyond the photos you choose to post.
How we use information
To run Birdbrainz: showing your profile and posts, suggesting species identifications, placing sightings at the locations you added to posts, sending the notifications you asked for, moderating content, responding to support requests, and keeping accounts secure. That’s the whole list — we have no advertising or data-monetization uses.
What is public
Approved posts are public by design: the photo (metadata-stripped except authorship), caption, species tags, taken-on date, the post’s location label if you added one, and your profile name, handle, bio, and photo. Your email address is never public.
Who we share data with
We share data only with the service providers below, only as needed to run Birdbrainz:
- Google Gemini API (species identification): a reduced-size, metadata-free copy of your photo, the capture date, and — when a location is available — a place label and coordinates rounded to roughly 110 m (from your picked location, or otherwise from the photo’s embedded GPS). Your name, email, and caption are not sent.
- Geoapify (location search): when you use the location picker, your device sends the map-pin coordinates and any place names you type directly to Geoapify.
- Mapbox (maps): while you browse a map, your device requests tiles for the area you’re viewing, which reveals the viewed coordinates to Mapbox.
- Firebase Cloud Messaging (notifications): your push token and generic notification payloads (“Your post is ready”).
- Google Cloud Platform hosts our infrastructure; Google and Apple handle sign-in under their own privacy policies.
We do not sell data, and we do not share it with advertisers or data brokers.
Moderation and staff access
To operate moderation and support, authorized Birdbrainz staff can view account details (including email), full profiles, and post details including the privately retained photo metadata described above. Staff can also open a time-limited, read-only view of the app as your account to investigate problems; every such access is logged. Administrative actions are recorded in an audit log that is minimized to avoid storing personal details.
Data stored on your device
Your session is kept in your device’s secure storage (or browser storage on the web) and cleared when you sign out. While you compose a post, a crash-recovery draft — including photo copies and their metadata — is kept on your device until you publish or discard the post; discard drafts you don’t want kept. A random installation identifier and your theme preference also remain on the device.
Retention and deletion
You can delete your account at any time in the app (Profile → Settings → Delete account) or by following our deletion page. Deletion is immediate and permanent: your profile, posts, photos, comments, species-identification records, notification registrations, sessions, and sign-in identity are all hard-deleted, and your personal details are scrubbed from the administrative audit log.
A few things can outlive deletion, and we want to be explicit about them:
- Ban records. If an account was banned for abuse, we keep a minimal record — a one-way hash of the sign-in identity, a timestamp, and a reason code; no name, email, or content — so the ban remains effective. Deleting an account in good standing writes no such record.
- Server logs. Routine infrastructure logs referencing internal identifiers are retained for a limited period under our cloud provider’s default retention, then deleted.
- In-flight processing. A species-identification job already queued at deletion time may finish shortly afterward; its output is orphaned and not linked to any account.
- Your device. Anything stored on your own device (see above) is under your control and is not removed by server-side deletion.
Security
All traffic is encrypted in transit. Refresh credentials are stored only as one-way hashes, direct database access from apps is disabled, and access to production data is limited to authorized operators.
Children
Birdbrainz is not directed to children under 13 (or the applicable minimum age of digital consent in your region), and we do not knowingly collect data from them. If you believe a child is using Birdbrainz, contact us and we will delete the account.
Changes to this policy
We’ll update this policy when our practices change, and each version is identified by its date. Material changes will be announced in the app or by other reasonable means.
Contact
Privacy questions or requests: support@birdbrainz.co, or see Support.