Birdex Privacy Policy

Privacy Policy for BirdexLast Updated: August 23, 2026Effective Date: August 23, 20261. IntroductionBirdex ("we," "our," "us," or "the App") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Birdex mobile application on iOS and Android.1.1 Who We Are (Data Controller)The data controller responsible for your personal data is LAPWING LABS LTD, a company registered in England and Wales (company number: 17011251), registered office: Cornsclose, Aish Lane, South Brent, Devon, TQ10 9JF. We trade as "Birdex".For any data-protection question, or to exercise your rights, you can contact us at [email protected] or by post at the registered office above. We have not appointed a statutory Data Protection Officer because we are not required to do so under UK/EU GDPR.This Policy describes how we process your personal data. Please read it alongside our Terms of Service. If you do not agree with this Privacy Policy, please do not use the App.1.2 What's Changed in This VersionThis version reflects features added to Birdex in 2026, in particular: community sharing (the Discover, Nearby, and friends feeds, and what other users can see), Sound ID (microphone-based bird identification, processed on your device), AI Photo Identification (which sends your submitted photo to an AI provider), analytics on both platforms, advertising attribution (Meta SDK), leaderboards and leagues, and optional Discord account linking. Each is described in full below.This update (August 2026) also expands Section 2.8 (Advertising Attribution): if, and only if, you allow ad measurement, we now additionally use your device's advertising identifier on Android (the Google Advertising ID), your IP address, and your account email address (in hashed form) to match our ad campaigns to installs, trials, and subscriptions. Nothing changes for users who decline.2. Information We Collect2.1 Account InformationBirdex offers several ways to sign in:- Apple Sign-In (iOS): When you create an account using Apple Sign-In, we collect your Apple ID identifier, email address (if you choose to share it), and display name. We do not store your Apple ID password. Authentication is handled securely by Apple.
- Google Sign-In (Android): When you create an account using Google Sign-In, we collect your Google account identifier, email address, and display name. We do not store your Google account password. Authentication is handled securely by Google.
- Email and password (both platforms): You can instead create an account with your email address and a password. Your email address is stored to identify your account, and your password is securely handled and stored in hashed form by Supabase Auth; we never store or see your password in plain text. If you forget your password, we can send a reset link to your email.
All sign-in methods flow through Supabase Auth, our unified backend authentication service.We also store your timezone (the standard timezone identifier reported by your device, for example "Europe/London") so that daily features such as quests, streaks, and daily resets happen at the right local time for you.2.2 Bird Records (Sightings)When you log bird records, we collect and store:- Bird species information (which bird you identified)
- Count (number of birds observed)
- Date and time of the record
- Location data (GPS coordinates, only when you actively log a record and grant permission)
- Location name (human-readable place name, if provided)
- Observation notes (optional text you add)
- Photos (optional images you upload)
- Your privacy choices for the record (its visibility setting and location-detail setting; see Section 2.6)
2.3 Location DataBirdex collects precise location data only when you actively create a bird record, use AI Photo Identification with location attached, or save a location, and only if you have granted location permission.- Location is NOT tracked in the background
- Location data is stored with your records to show where you spotted birds
- On Android, location coordinates are obtained on demand via Google Play Services (Fused Location Provider)
- On Android, the app also holds the ACCESS_MEDIA_LOCATION permission so it can read the location stored inside a photo you choose from your gallery (EXIF data) and offer it as the record's location
- You can control location permissions in your device settings:
- iOS: Settings > Birdex > Location
- Android: Settings > Apps > Birdex > Permissions > Location
Location data is used to:- Record where you saw birds
- Display your records on a map within the app
- Power map-based features (such as the records map, nature-reserve markers, and species/county heatmaps available with Birdex Pro)
- Store your saved locations for quick selection when logging future records
- Show your records in community feeds in blurred form only, if and to the extent you share them (see Section 2.6)
- Show you the Nearby feed (records from other birders near your current position)
- Provide location context to the AI Photo Identification feature, if you attach a location to an identification request (see Section 2.15)
How location appears to other users (if you share): other Birdex users are never shown your exact coordinates. At most, they see an approximate area snapped to a grid of roughly 3 kilometres, plus a county name. For rare and sensitive species, the location is withheld entirely to protect both the birds and your whereabouts. See Section 2.6 for the controls.We do NOT:- Track your location continuously or in the background
- Send your location to analytics or advertising services
- Sell your location data to anyone
2.4 Saved LocationsYou may choose to save frequently used birding locations for convenience. Saved locations include:- A user-defined name
- GPS coordinates (latitude/longitude)
- An optional description or address
Saved locations are stored on our servers and are only accessible to you.2.5 Photos and MediaWhen you upload photos of bird records:- Photos are compressed and resized before upload to reduce file size (maximum 1 MB)
- Photos are stored securely in cloud storage (Supabase Storage)
- Photos are associated with your records
- Your record photos are not shown to other Birdex users. They do not appear in the Discover, Nearby, or friends feeds, on friend profiles, or on leaderboards
- If you set a custom photo as a bird-card image (a Birdex Pro feature), that photo is likewise shown only to you
- On Android, EXIF orientation data is used to correctly display your photos; on iOS, original photo metadata may be preserved
The exceptions, both under your control:- If you use AI Photo Identification, the photo you submit for that request is sent to an AI provider to identify the bird (see Section 2.15)
- If you share a photo yourself outside the app (for example via your device's share sheet), that is your own action
We do NOT:- Access photos outside of the app's record-logging and identification features
- Use your photos for marketing or advertising
- Use your photos to train AI models
2.6 Community and Social FeaturesBirdex includes community features, and this section explains exactly what other people can see and how to control it. Please read this section: some sharing is on by default.What can be visible to other users (depending on your settings):- Display name, avatar, avatar border, and level
- Species count, lifer count, and badges
- Your recent records as "cards" in the community feeds: the species seen, counts, rarity, card levels, and when they were logged
- An approximate location for a shared record: blurred to a roughly 3 km grid area plus a county name, and withheld entirely for rare or sensitive species (never your exact coordinates; see Section 2.3)
- Chirps: other users can send a "chirp" (a like-style reaction) on a shared card, and the names and avatars of users who chirped a card are visible on it
- Leaderboards and leagues: your display name, avatar, level, and score appear to other participants in the weekly Ranks leagues, the global streak leaderboard, and the daily Bird Blitz leaderboard
- Friend profile: users you are friends with can additionally see your full bird collection (species and card levels, not photos or notes), streak, league tier, badges, and how long you have been friends
What is NEVER visible to other users, regardless of settings:- Your photos
- Your notes
- Your exact location or saved locations
- Your email address
- Your Golden Egg balance or purchase history
Feeds and audiences:- Friends feed: your shared records, visible to confirmed friends
- Discover: a public feed of trending records, visible to any signed-in Birdex user
- Nearby: a public feed of records logged near a user's current position, visible to any signed-in Birdex user (records appear only with blurred location, as above)
- Birdex operates UK and Europe communities; shared records can appear to users in either community
Defaults and controls:- New accounts are set to share records publicly by default, with location shown at the blurred (approximately 3 km) level. This is what makes the community feeds work, but you are in control:
- Profile-level controls in Settings let you choose who can see your records (private, friends, or everyone) and how much location detail is shown, at any time
- Per-record controls when logging (or editing) a record let you override your profile setting for that record, in either direction
- A record's location detail can never exceed its overall visibility, and rare/sensitive species locations are suppressed automatically
- Friend connections are always opt-in: you must share your friend code or accept a request
- Setting your account to private removes your records from the community feeds
Moderation data: to keep the community safe, we also process:- Blocks: if you block a user, we store that relationship and hide you from each other across all social surfaces
- Reports: if you report a card or a user, we store the report (what was reported, the reason, and the fact that you reported it) so we can review it. Cards reported by several users are hidden from public feeds pending review
- Accounts that break our rules can be hidden from public surfaces
2.7 Usage and Diagnostic DataWe automatically collect certain technical information for diagnostic and improvement purposes:Crash reporting and diagnostics (Sentry, both platforms):- Crash reports and error logs to help us identify and fix bugs
- Device information (OS version and device model)
- App performance metrics (loading times; about 20% of sessions are sampled for performance)
- Screenshots on errors: when an error occurs, a screenshot of the app at that moment may be attached to the error report to help us fix the bug. This screenshot can incidentally include whatever was on the Birdex screen (for example a bird card or map view)
- User identifiers: on iOS, crash and diagnostic reports are not linked to your Birdex account identifier. On Android, where a user identifier is attached to diagnostic context it is in hashed (SHA-256) form. We strip authentication tokens before any report is sent
- On Android, navigation and tap breadcrumbs (which screens were visited before an error) may be included in error reports
Product analytics (Mixpanel, both platforms):- A small, fixed set of events: onboarding steps, account creation, region selection, first record logged, and paywall views/taps/dismissals
- Each event carries: a pseudonymous identifier (your account UUID), your app version, platform, region (UK/Europe), subscription status (free/trial/active), whether you are a new user, and days since install
- We do not send Mixpanel your name, email, location, bird data, or photos
- Mixpanel data is stored on EU servers (EU data residency)
- We do not use Mixpanel for advertising or for tracking you across other apps, and we do not use session replay
Because we rely on legitimate interests for analytics and crash diagnostics, you may object to this processing; see Section 7.5.

2.8 Advertising Attribution (Meta SDK) — Only With Your PermissionWe advertise Birdex on Meta platforms (Facebook/Instagram). To measure whether those ad campaigns work, the app includes the Meta (Facebook) SDK on both platforms — but it stays switched off until you give permission:- On iOS, we ask with Apple's standard App Tracking Transparency prompt ("Allow Birdex to track…"). If you tap Ask App Not to Track, no user-level data is ever sent to Meta. You can change your choice at any time in iOS Settings > Privacy & Security > Tracking.
- On Android, we ask with a one-time consent dialog. If you tap Don't allow, the Meta SDK never starts and no data is ever sent to Meta. To change your choice later, contact us at the email in Section 11.
If (and only if) you allow measurement:- The SDK reports app events (that the app was installed and opened) together with an app-scoped anonymous identifier generated by the SDK
- Your device's advertising identifier is used, as covered by the permission you granted: the IDFA on iOS, and the Google Advertising ID on Android
- Our subscription processor RevenueCat forwards subscription events (for example trial started, subscription purchased) to Meta so we can measure campaign performance. To let Meta match those events to the ad that led to them, RevenueCat sends them with matching information: the advertising identifier above, the app-scoped anonymous identifier, your IP address, and your account email address in hashed form (Meta's "Advanced Matching"). RevenueCat converts the email to a hash (a one-way code) before Meta receives it, so Meta is not sent your readable email address; hashed data can still relate to you, so we treat it as personal data and only use it with your permission
- We do not send Meta your name, location, bird records, or photos
Separately, on iOS, Apple's privacy-preserving SKAdNetwork framework provides aggregate, non-identifying campaign attribution for all users; it involves no personal data and no tracking.This data is used solely to measure and improve our advertising campaigns. Birdex does not show ads inside the app. For US users, we enable Meta's Limited Data Use mode, which applies restricted data handling in US states with privacy laws. Meta's privacy policy: https://www.facebook.com/privacy/policy/2.9 Game Progress DataWe store your game progress and achievements:- Player level and experience points (XP)
- Card collection progress (which birds you've seen and card levels)
- Achievement badges (lifetime and yearly badges)
- In-app currency (Golden Eggs balance)
- Login streaks (current and best streaks)
- Daily quest progress and completion
- Daily quiz and Bird Blitz attempts, scores, and completion
- Avatar customization (selected avatar and unlock status)
- Card cosmetics and effects (customizations applied to bird cards)
- Cosmetic inventory (items purchased or unlocked with in-game currency)
- League and weekly Ranks history
- Advanced statistics data (per-bird and profile-wide stats, available with Birdex Pro)
- Favorite birds (stored locally on your device)
- Global rank and percentile among all players
2.10 Push Notification DataTo deliver daily quests, badge progress, and social notifications (for example friend requests and chirps on your cards), we collect a device push token:- iOS: via the Apple Push Notification service (APNs)
- Android: via Firebase Cloud Messaging (Google). A device push token is generated and stored on our servers and sent to Google to route notifications.
The token is associated with your account and is deleted when you sign out. You can disable notifications at any time in your device settings.2.11 Giveaway and Promotional DataIf you view in-app giveaways or promotions, we record:- Whether you have seen a particular giveaway (to avoid repeat display)
- No entry forms, payment details, or additional personal data are collected through giveaways
If you win a giveaway, your display name may be shown in the app as the winner. If you would prefer it not to be, contact us.2.12 Offline DataIf you log a record while offline:- Record data (including any photo) is temporarily stored on your device in a local queue
- Data is automatically synced to our servers when your internet connection is restored
- The local queue is cleared after successful sync
2.13 Subscription and Purchase Data (Birdex Pro)If you subscribe to Birdex Pro, we and our subscription processor RevenueCat collect and store subscription-related data so that we can provide, verify, and manage your Pro access:- Subscription status (e.g. active, in free trial, in grace period, cancelled, or expired)
- The product you purchased (Birdex Pro Monthly or Birdex Pro Annual) and any promotional offer applied (for example a win-back discount)
- The store you bought it from (Apple App Store on iOS, Google Play on Android)
- Store/original transaction identifiers
- Purchase, renewal, and expiration dates
- Free-trial status
- Whether the subscription is shared via Apple Family Sharing (on iOS)
- Your Birdex user identifier (a UUID, used as the subscription account ID)
- Cancellation feedback: if you cancel and choose to tell us why, we store the reason you select, together with your plan and platform, to improve Birdex Pro
We use this data to grant and enforce your Pro entitlement on our servers (Pro features are gated server-side), to manage your subscription lifecycle, and to keep the accounting records the law requires. As described in Section 2.8, subscription events (not your identity) are also forwarded to Meta for ad-campaign measurement.We do NOT receive or store your payment card number or any raw payment details. All payment processing is handled entirely by Apple (App Store) or Google (Google Play). This subscription data corresponds to the "Purchases" data type on the Apple App Store and the "Financial info > Purchase history" data type in the Google Play Data Safety section.2.14 Contributing Records to NBN Atlas (Biodiversity Records)Birdex is a data partner of the NBN Atlas (the National Biodiversity Network Atlas, nbnatlas.org), the UK's open repository of wildlife records, used by researchers, conservation organisations, and public bodies to understand and protect biodiversity.This is entirely optional and is off unless you choose it. If, and only if, you opt in (either from the one-time prompt we show you, or under Settings → Contribute to Science), we contribute your bird records to the NBN Atlas, where they become publicly available open data under the Creative Commons Attribution (CC BY) licence.If you opt in, we contribute the following for each eligible record:- The species (common and scientific name)
- The date of the record
- The number of birds seen
- An approximate location, blurred to roughly a 1 km grid square (never your exact coordinates)
- A pseudonymous contributor reference; your contributed records are anonymous
We NEVER contribute:- Your precise location or exact coordinates
- Your photos or notes
- Your name, email, display name, or friend code
- Any account identifier
Additional protections:- Records for rare or sensitive species (for example Schedule 1 breeding birds and species vulnerable to persecution) are blurred to a coarser area or withheld entirely, to avoid revealing sensitive sites.
- Opting in applies to your existing eligible records as well as new ones you log afterwards.
- Contribution currently applies to UK records only.
You can opt out at any time under Settings → Contribute to Science. Opting out, or deleting your account, removes your records from the next update we publish to the NBN Atlas. Because contributed records are open data, copies already downloaded by others before you opt out cannot be recalled.The lawful basis for this contribution is your consent (see Section 4.1), which you may withdraw at any time.2.15 AI Photo IdentificationBirdex includes an AI-powered photo identification feature that suggests which bird is in a photo. When you use it:- The photo you submit, together with any description, behaviour notes, and location you attach (including precise coordinates, if you attach your location), is sent to our server and then to a third-party AI provider to generate the identification. We currently use Google (Gemini) as our primary AI provider, and may alternatively use OpenAI.
- We store a log of each identification request on our servers (your account ID, the details you provided, whether a photo was included, the AI provider used, and the response) so we can operate the feature, allocate identification credits, prevent abuse, and investigate wrong results you report.
- Identification requests use a credit allowance that refreshes periodically; your credit usage is stored with your account.
- We have API agreements with these providers under which the data is used to provide the identification service. We do not permit your photos to be used to train our or anyone else's AI models.
AI identifications are suggestions and can be wrong. They are provided for recreational use; see our Terms of Service for details.If you do not want your photo or location processed this way, simply do not use the AI Photo Identification feature (or do not attach a location to a request). Logging records normally does not involve any AI provider.2.16 Sound ID (Microphone)Birdex includes Sound ID, an AI-powered feature that identifies birds from their songs and calls. It is designed to be private by default:- Sound ID uses your microphone (with your permission) to listen for bird sounds.
- All audio analysis happens on your device. The audio is processed in memory by an on-device machine-learning model, is continuously overwritten, and is never recorded to a file, saved, or sent to our servers or anyone else as part of identification. Sound ID works with no internet connection.
- Sounds identified as human speech are filtered out on-device and are not processed further.
- If you report a wrong identification, only the bird species involved is sent to us; no audio and no location.
Sound ID sends us nothing at all: no audio, no recordings, and no derived audio data. The microphone can be disabled at any time in your device settings (see Section 7.4). Sound ID identifications, like all AI features, can be wrong; see our Terms of Service.(An earlier, optional "donate a fingerprint to improve the model" feature has been removed from the app. Any previously donated data is deleted automatically under its retention limit of at most 90 days, and none has been collected since the feature was removed.)2.17 Discord Account Linking (Optional)Birdex operates an official Discord community server with an optional Birdex bot. If (and only if) you choose to link your Birdex account to your Discord account, using a one-time code generated in the app:- We store the link between your Birdex account and your Discord user ID
- The bot can show, to members of the Discord server, your Birdex stats (for example level, species count, league, streak, badges, and similar gameplay numbers) and your display name and friend code when you use the bot's commands
- Linked members may be included in a daily community digest posted to the server (aggregate stats and a top-10 list)
- If you have Birdex Pro, the bot may assign you a Pro role on the server
The bot never shares your email, location, photos, notes, or purchase details. Discord itself is a separate service with its own privacy policy (https://discord.com/privacy); your use of Discord is governed by Discord's own terms. You can unlink at any time, and accounts set to hidden are excluded from bot outputs and digests.If you never link your account, no data is shared with Discord.2.18 Home-Screen WidgetsIf you add a Birdex widget to your home screen, the app writes a small snapshot of your own data (display name, avatar, level, streak, daily quest status, and similar) to shared storage on your device so the widget can display it. This snapshot stays on your device and is not transmitted anywhere.2.19 Data We Do NOT CollectBirdex does NOT collect:- Contacts or address book
- Calendar data
- Health or fitness data
- Raw payment card numbers or bank details (card processing is handled entirely by Apple or Google; we never see your card number)
- Precise location in the background
- Audio recordings or any audio-derived data (Sound ID runs entirely on your device, see Section 2.16)
- Data from other apps
- Device advertising identifiers, unless you allow ad measurement: the Google Advertising ID on Android is collected only if you allow the ad-measurement dialog, and the IDFA on iOS only if you allow the tracking prompt, in both cases solely for ad-campaign measurement (Section 2.8)
- Plain-text passwords (if you sign in with email, your password is stored only in hashed form by Supabase Auth and is never visible to us; Apple and Google Sign-In involve no password at all)
3. How We Use Your Information3.1 Provide Core App Functionality- Authenticate your account via Apple Sign-In (iOS), Google Sign-In (Android), or email and password
- Store and display your bird records
- Calculate rewards, XP, and player progression
- Track your card collection and achievements
- Display your records on maps
- Manage your profile and settings
- Operate community features (feeds, friends, chirps, leaderboards, leagues) according to your sharing settings
- Provide AI Photo Identification and Sound ID
- Deliver push notifications you have enabled
3.2 Improve the App- Fix bugs and crashes
- Analyze app performance and usage patterns
- Develop new features based on user behaviour
3.3 Ensure Safety, Security, and Integrity- Prevent fraud and abuse
- Verify user authenticity via server-side validation
- Protect against unauthorized access
- Maintain data integrity and prevent manipulation
- Review reported content and enforce our community rules (see Section 2.6)
3.4 Measure Advertising- Measure the performance of our app-install ad campaigns using the attribution data described in Section 2.8 (Birdex shows no ads in the app)3.5 Legal Compliance- Comply with applicable laws and regulations
- Respond to legal requests and prevent harm
- Enforce our Terms of Service
- Maintain billing and accounting records we are legally required to keep
3.6 Provide and Manage Birdex Pro- Process and validate your subscription purchases, renewals, cancellations, and free trial
- Verify your Pro entitlement on our servers before unlocking Pro features
- Manage Apple Family Sharing eligibility (iOS)
- Maintain the subscription, billing, and accounting records we are legally required to keep
4. Lawful Basis for Processing & Data Retention (UK/EU GDPR)

4.1 Lawful Basis for ProcessingWhere UK or EU data-protection law applies, we process your personal data on the following lawful bases:Purpose — Lawful basis
Creating and authenticating your account; storing and displaying your records; gameplay and progression; community features you use, according to your sharing settings; AI Photo Identification and Sound ID when you use them; providing and delivering the Birdex Pro subscription — Contract (Art. 6(1)(b)), necessary to perform our agreement with you
Retaining subscription, billing, and transaction records for statutory periods — Legal obligation (Art. 6(1)(c)), UK tax and accounting law
Security, fraud and abuse prevention, content moderation, server-side validation, crash and error diagnostics (Sentry), product/usage analytics (Mixpanel), and aggregate campaign attribution (SKAdNetwork, which involves no personal data) — Legitimate interests (Art. 6(1)(f)), to keep Birdex safe, secure, stable, improving, and sustainably marketed. You can object; see Section 7.5
Advertising attribution/measurement via the Meta SDK and RevenueCat's Meta integration, including the advertising identifier, IP address, and hashed-email matching described in Section 2.8 (only if you allow it via the iOS tracking prompt or the Android consent dialog) — Consent (Art. 6(1)(a))
Contributing your bird records to the NBN Atlas as open biodiversity data (only if you opt in; see Section 2.14) — Consent (Art. 6(1)(a))
Optional Discord account linking (see Section 2.17) — Consent (Art. 6(1)(a))
Any other optional processing that requires prior consent in your jurisdiction, and any future marketing — Consent (Art. 6(1)(a))
Where we rely on legitimate interests, we have carried out a balancing test to ensure our interests do not override your rights and freedoms; you may object to this processing (see Section 7.5). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.Using the App is not, by itself, treated as your consent to processing that is actually necessary to perform our contract with you or that relies on our legitimate interests.4.2 Data RetentionWe keep your account and gameplay data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we must keep certain records longer:- Subscription and billing/transaction records (including data held by RevenueCat and the relevant app store) are retained for up to 6 years to meet UK tax and accounting obligations
- Crash and diagnostic logs are retained for up to 90 days
- Moderation records (reports and enforcement actions) are retained while needed to keep the community safe and to evidence our decisions
- Records needed to resolve disputes or enforce our Terms are retained until the matter is concluded
After these periods, data is securely deleted or irreversibly anonymised.NBN Atlas contributions: If you opted in to contribute records to the NBN Atlas (Section 2.14), those records are published as open data. If you opt out or delete your account, we remove your records from the next dataset update we publish to the NBN Atlas; however, copies already downloaded by third parties under the open licence cannot be recalled.5. Third-Party ServicesBirdex integrates with the following third-party services:5.1 Supabase (Database and Storage)- Purpose: Backend database, authentication, and file storage
- Data shared: All user data, records, photos, and game progress
- Privacy Policy: https://supabase.com/privacy
5.2 Sentry (Crash Reporting)- Purpose: Error tracking, crash reporting, and performance monitoring on both platforms
- Data shared: Crash logs, error messages, device information, performance samples (about 20% of sessions), screenshots attached to error reports (which can incidentally show your in-app screen content), and, where attached, a user identifier used to correlate errors to your session. On Android, where a user identifier is attached it is in hashed (SHA-256) form; on iOS, reports are not linked to your Birdex account identifier. We strip authentication tokens before any report is sent.
- Data NOT shared: Network connectivity errors, HTTP 404 errors, and rate limit errors are filtered out before sending
- Privacy Policy: https://sentry.io/privacy/
5.3 Apple Sign-In (iOS Authentication)- Purpose: User authentication on iOS
- Data shared: Apple ID token, email (if you choose to share)
- Privacy Policy: https://www.apple.com/legal/privacy/
5.4 Google Sign-In (Android Authentication)- Purpose: User authentication on Android
- Data shared: Google account token, email, display name
- Privacy Policy: https://policies.google.com/privacy
5.5 Google Play Services (Android)- Purpose: Location services (Fused Location Provider), in-app review prompts, and app version management
- Data shared: Location coordinates (only when logging records), app review interactions
- Privacy Policy: https://policies.google.com/privacy
5.6 Google Gemini and OpenAI (AI Photo Identification)- Purpose: Generate bird identifications from photos you submit (see Section 2.15)
- Data shared: The photo you submit for identification and the context you attach (description, behaviour, and location including coordinates if provided). We use Google (Gemini) as our primary provider and may use OpenAI as an alternative
- Data NOT shared: Your name, email, account identifier, or your other records and photos. Submitted photos are not used to train AI models
- Privacy Policies: https://policies.google.com/privacy, https://openai.com/privacy
5.7 Mixpanel (Product Analytics, both platforms)- Purpose: Usage analytics to understand feature engagement and improve the app
- Data shared: A pseudonymous user identifier (account UUID only) and a small fixed set of events (onboarding, account creation, first record, paywall interactions) with app version, platform, region, subscription status, and days-since-install context. No name, email, location, bird data, or photos are sent to Mixpanel. Real-money purchase transactions are handled by RevenueCat and the app stores, not Mixpanel.
- Data residency: EU servers (api-eu.mixpanel.com)
- Privacy Policy: https://mixpanel.com/legal/privacy-policy/
5.8 Meta (Facebook) SDK (Advertising Attribution, both platforms — permission required)- Purpose: Measure the performance of our app-install advertising campaigns (see Section 2.8). Birdex shows no ads in the app
- Data shared: Nothing unless you allow measurement (via the iOS tracking prompt or the Android consent dialog). If you allow: app events (install, app launch) with an app-scoped anonymous identifier; your device's advertising identifier (IDFA on iOS, Google Advertising ID on Android); and subscription events forwarded via RevenueCat for campaign measurement, together with matching information (the advertising identifier, the anonymous identifier, your IP address, and your account email in hashed form; see Section 2.8). We never send your name, location, records, or photos, and your readable email address is never sent (only a hash)
- Privacy Policy: https://www.facebook.com/privacy/policy/
5.9 Firebase Cloud Messaging (Android Push Notifications)- Purpose: Deliver push notifications on Android
- Data shared: Device push token (used by Google to route notifications to your device)
- Privacy Policy: https://firebase.google.com/support/privacy
5.10 RevenueCat (Subscription Management, Birdex Pro)- Purpose: Manage the Birdex Pro subscription, validate App Store / Google Play purchases and receipts, track your subscription entitlement and trial status, and forward subscription events to Meta for ad-campaign measurement (Section 2.8)
- Data shared: Your Birdex user identifier (a UUID, used as the subscription account ID), subscription status (active/trial/grace/cancelled/expired), free-trial status, product identifier, any promotional offer applied, store transaction identifiers, the store used (Apple App Store or Google Play), purchase/renewal/expiration dates, and basic device/store context. Only if you allow ad measurement (Section 2.8), RevenueCat additionally holds, for your account, your device's advertising identifier, your IP address, the Meta anonymous identifier, and your account email address, which it uses to send Meta the hashed matching information described in Section 2.8. RevenueCat does NOT receive your name, bird data, or payment card details, and it receives your email only if you allow ad measurement
- Data residency: RevenueCat processes this data on servers located in the United States. RevenueCat acts as our data processor. See Section 9 (International Data Transfers) for the safeguards we apply.
- Privacy Policy: https://www.revenuecat.com/privacy/
5.11 Mapbox (Map Rendering, both platforms)- Purpose: Render interactive maps (records map, nature reserves, species/county heatmaps)
- Data shared: Approximate map-view location, record coordinates being displayed, and map-tile requests
- Privacy Policy: https://www.mapbox.com/legal/privacy
5.12 NBN Atlas (Biodiversity Records, Opt-In Only)- Purpose: If you opt in, publishing your bird records as open biodiversity data for research and conservation (see Section 2.14)
- Data shared: Species (common + scientific name), record date, count, and an approximate location blurred to roughly 1 km, under a pseudonymous contributor reference. No precise location, photos, notes, name, email, or account identifier.
- Role: The NBN Atlas is operated by the NBN Trust, a UK-based charity, which acts as a separate, independent data controller and open-data publisher of the contributed records, not as our data processor. Contributed records are UK-hosted open data, so no international transfer arises.
- Privacy Policy: https://nbnatlas.org/privacy-policy/
5.13 Discord (Optional Community Linking)- Purpose: If you choose to link your accounts, the Birdex bot displays your gameplay stats on our Discord server (see Section 2.17)
- Data shared: Your Discord user ID (stored by us), and gameplay stats, display name, and friend code shown on the server via bot commands and digests
- Privacy Policy: https://discord.com/privacy
5.14 What We Do NOT Use- In-app advertising networks (Birdex shows no ads)
- Session-replay tools
- Third-party cookies
- Data brokers, and we never sell or rent your data
6. Data Sharing and Disclosure6.1 We Do NOT Sell Your DataWe do not sell, rent, or trade your personal information to third parties.Contributing your records to the NBN Atlas (if you opt in; see Section 2.14) is not a sale: those records are published as free, open scientific data for research and conservation, and we receive no payment for them. Attribution events sent to Meta (Section 2.8) flow only with your permission, are used only to measure our own ad campaigns, we receive no payment for them, and they never include your location or bird data.6.2 Limited SharingWe may share your information only in the following circumstances:- Service Providers: With Supabase, Sentry, Mixpanel, RevenueCat, Apple, Google (including Firebase Cloud Messaging, Google Play Services, and Gemini for AI Photo ID), OpenAI, Meta (attribution only), Mapbox, and Discord (only if you link), to provide app functionality as described in Section 5
- Other Birdex users: According to your sharing settings, as described in Section 2.6
- Biodiversity data partner (opt-in only): If you opt in, your bird records (species, date, count, and a location blurred to roughly 1 km, under a pseudonymous reference) are contributed to the NBN Atlas as public open data (see Sections 2.14 and 5.12)
- Legal Requirements: If required by law, court order, or governmental request
- Safety and Security: To protect the rights, property, or safety of Birdex, our users, or the public
- Business Transfers: In connection with a merger, acquisition, or sale of assets (users will be notified)
7. Your Rights and ChoicesIf you are in the UK or EEA, you have rights under UK/EU GDPR, summarised in Section 10.2. The following choices are available to all users:7.1 Access Your DataYou can view your data within the app: profile information, records and photos, card collection and progress, badges, friends, and leaderboards. You can also request a full copy of your data (see Section 7.3).7.2 Correct Your DataYou can update your profile information (display name, avatar) in the app, and edit or delete individual records.7.3 Delete Your DataYou can permanently delete your account and all associated data (records, photos, profile, game progress, and friend relationships) in one of two ways:- In-app: open your Profile (or the in-app Settings) and tap Delete Account
- By email: contact us at [email protected] from your account email (see Section 11)
We will action deletion within 30 days. Please note: deleting your Birdex account does NOT cancel an active Birdex Pro subscription; you must cancel that separately in your Apple ID or Google Play account (see our Terms of Service). Some records may be retained where required by law (for example, billing/transaction and audit records; see Section 4.2) or kept in anonymised form. You can also request a copy of your data ("data portability") using the same channels.7.4 Control Your Sharing and PermissionsSharing controls (in-app): Settings lets you set who can see your records (private, friends, or everyone) and how much location detail is shown; each record also has its own privacy controls when you log or edit it. You can block users from any profile or card, and manage blocked users in Settings.Device permissions:iOS:- Location: Settings > Birdex > Location
- Camera: Settings > Birdex > Camera
- Photos: Settings > Birdex > Photos
- Microphone: Settings > Birdex > Microphone
- Notifications: Settings > Birdex > Notifications
Android:- Location: Settings > Apps > Birdex > Permissions > Location
- Camera: Settings > Apps > Birdex > Permissions > Camera
- Microphone: Settings > Apps > Birdex > Permissions > Microphone
- Notifications: Settings > Apps > Birdex > Notifications
Revoking permissions may limit certain app features (e.g., you cannot use Sound ID without microphone access, or log located records without location permission).7.5 Right to Object / Opt Out of Analytics, Diagnostics, and AttributionBecause we rely on legitimate interests for product analytics (Mixpanel) and crash diagnostics (Sentry), you can object to this processing. To opt out, contact us at [email protected] and we will disable analytics/diagnostics linkage for your account where technically possible. Opting out will not affect your ability to use core features.Advertising attribution (Meta SDK and the RevenueCat matching described in Section 2.8) runs only with your permission. To withdraw it: on iOS, turn Birdex off under Settings > Privacy & Security > Tracking; on Android, contact us at [email protected] and we will disable it for your device. On withdrawal we also stop using the advertising identifiers and email matching for measurement, and we will ask our processors to remove the related identifiers from your customer record where technically possible.7.6 Withdraw ConsentWhere we rely on your consent (NBN Atlas contribution, Discord linking, Meta ad measurement), you may withdraw it at any time, in the app where a control exists, or by contacting us. You may also stop using the app at any time and request account deletion to end processing, subject to the legal-retention exceptions in Section 4.2.7.7 ComplaintsIf you are unhappy with how we handle your personal data, please contact us at [email protected] with "Privacy complaint" in the subject line. We take complaints seriously and will acknowledge and respond within 30 days.You also have the right to lodge a complaint with a data protection supervisory authority. In the UK, this is the Information Commissioner's Office (ICO): www.ico.org.uk, helpline 0303 123 1113. If you are in the EEA, you may complain to your local Data Protection Authority. We would appreciate the chance to address your concerns first.

8. Children's PrivacyBirdex is not intended for children under the age of 13.- In the UK, the minimum age to consent to our services (information society services) is 13.
- In some EU/EEA countries the minimum age is higher (up to 16). If you live in such a country, you must be at least that age, or have parental/guardian consent, to use Birdex.
We do not knowingly collect personal information from anyone below the applicable age. If we learn that we have, we will delete it.We design Birdex with younger users in mind: location shown to other users is always blurred or withheld (Section 2.6), sharing can be set to private at any time, there is no in-app messaging or chat between users, there are no third-party ads, and community features include blocking and reporting.Parents/Guardians: If you believe your child has provided personal information to us, please contact us immediately.9. International Data TransfersSome of our processors are located outside the UK and EEA. In particular, RevenueCat, Sentry, OpenAI, and Meta are based in the United States, and Google processes AI-identification requests in various locations.Where we transfer your personal data outside the UK/EEA, we rely on appropriate safeguards, namely the UK International Data Transfer Agreement / Addendum (IDTA) and the EU Standard Contractual Clauses (SCCs), and/or a valid adequacy or Data Privacy Framework certification, together with supplementary measures where appropriate. You can request a copy of the relevant safeguards by contacting us at [email protected].Mixpanel analytics data is stored on EU servers (EU data residency).We do not rely on "consent by using the app" as the basis for these transfers.10. Region-Specific Privacy Rights10.1 California and Other US StatesIf you are a resident of California or another US state with a comprehensive privacy law, you may have the following rights:- Right to Know/Access: Request disclosure of personal information we collect, use, and share
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt Out of Sale or Sharing: We do not sell personal information. If our use of advertising-attribution events (Section 2.8) is treated as "sharing" for cross-context behavioural advertising under your state's law, you may opt out by contacting us at the email in Section 11, and we will disable attribution for your account where technically possible
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
To exercise these rights, contact us at the email in Section 11.10.2 United Kingdom and European Economic Area (UK/EU GDPR)If you are located in the United Kingdom or the European Economic Area (EEA), you have the following rights:- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests, including analytics, diagnostics, and advertising attribution (see Section 7.5)
- Right to Withdraw Consent: Withdraw consent where processing is based on consent
- Right to Complain: Complain to us (Section 7.7) and/or to a supervisory authority: the UK Information Commissioner's Office (ICO) (www.ico.org.uk), or your local Data Protection Authority in the EEA
The lawful bases on which we rely are set out in Section 4. To exercise your rights, contact us at the email in Section 11.10.3 Other JurisdictionsIf you reside in a jurisdiction with specific privacy laws (e.g., Brazil's LGPD, Australia's Privacy Act), you may have additional rights. Contact us for more information.11. Contact UsIf you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:Data controller: LAPWING LABS LTD (company number: 17011251), registered office: Cornsclose, Aish Lane, South Brent, Devon, TQ10 9JF, trading as "Birdex"Email: [email protected]We will respond to your inquiry within 30 days (or as required by applicable law).12. Changes to This Privacy PolicyWe may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or app features.If we make a material change (for example, collecting a new category of data or sharing data with a new category of recipient), we will give you advance notice in the app before the change takes effect, and where the change relies on your consent we will ask for it. For minor changes, we will update the "Last Updated" date at the top of this policy.We encourage you to review this Privacy Policy periodically.13. App Architecture and Data IntegrityBirdex uses a server-authoritative architecture:- All business logic is executed on the server (Supabase RPC functions)
- Client apps are presentation layers only (no local calculations or data manipulation)
- Data integrity is enforced server-side to prevent cheating or tampering, including server-side enforcement of Birdex Pro entitlements and of your sharing settings
This architecture ensures:- Fair gameplay
- Consistent progression calculations
- Secure data storage
- Prevention of client-side manipulation
- Your privacy settings are applied on the server, not just hidden in the app
Internet connection is required for most app functionality as operations are server-dependent. Limited offline support is available for queuing records (see Section 2.12), and Sound ID works fully offline.14. Data Storage, Security, and Transmission14.1 Where Your Data is StoredYour data is securely stored using Supabase, a third-party cloud database and authentication service built on PostgreSQL and hosted on secure servers.- Database: PostgreSQL with PostGIS (for geographic location data)
- Storage: Supabase Cloud Storage (for photos and media assets)
- Authentication: Supabase Auth (Apple Sign-In on iOS, Google Sign-In on Android, or email and password on both; email passwords stored hashed by Supabase Auth)
14.2 Local Storage on Your DeviceBirdex stores limited data locally on your device:- iOS: UserDefaults for preferences and session state; Keychain for authentication tokens; offline record queue as a local JSON file; widget snapshot in the App Group; image cache
- Android: SharedPreferences for preferences, favourite birds, and onboarding status; offline record queue; widget snapshot; image cache managed by the Coil library
Local data is not encrypted beyond the protections provided by your device's operating system.14.3 Security MeasuresWe implement industry-standard security measures:- Encryption in transit: All data transmission uses HTTPS/TLS encryption
- Encryption at rest: Data stored on our servers is encrypted
- Secure authentication: Apple, Google, and email sign-in with cryptographic token validation, managed by Supabase Auth
- Server-side validation: All game logic, sharing settings, and Birdex Pro entitlement checks are executed server-side to prevent tampering
- Access controls: Strict database row-level security (RLS) policies
- Location blurring: Locations shown to other users are snapped to a coarse grid on the server; exact coordinates are never sent to other users' devices, and sensitive-species locations are withheld
- On-device audio: Sound ID audio never leaves your device (Section 2.16)
- Minimised diagnostics: Crash and error reports are stripped of authentication tokens before sending; on iOS they are not linked to your account identifier, and on Android any attached user identifier is hashed (SHA-256)
- Certificate pinning: iOS implements SSL/TLS certificate pinning for additional transport security
- Photo upload validation: File paths are validated to prevent path-traversal attacks
- Regular security updates: Dependencies and infrastructure are kept up to date
14.4 Encryption and TransmissionAll data transmission between the Birdex app and our servers uses:- HTTPS/TLS encryption (industry-standard secure protocol)
- Cryptographic token validation for authentication
- Secure API endpoints with authentication headers
- Certificate pinning (iOS) for additional transport security
Birdex does NOT use proprietary or custom encryption algorithms beyond standard HTTPS.15. Your ConsentWhere processing relies on consent (NBN Atlas contribution, Discord linking, Meta ad measurement, and any other processing we ask you about), we ask for that consent separately and specifically; using Birdex is not itself treated as consent. For processing that relies on contract, legal obligation, or our legitimate interests, the lawful bases in Section 4 apply rather than your consent.You may withdraw consent (where applicable), object to legitimate-interests processing, or request account deletion at any time; see Section 7.16. DisclaimerWhile we implement robust security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your data.We are not responsible for:- Unauthorized access due to device loss or compromise
- Third-party service breaches (e.g., Supabase, Sentry, RevenueCat, Google, Apple)
- Data loss due to unforeseen circumstances
Nothing in this section limits our own obligations under data-protection law or any liability that cannot be excluded by law.17. Governing LawThis Privacy Policy is governed by the laws of England and Wales. If you are a consumer living in the EEA, you also benefit from any mandatory protections of the law of your country of residence, and nothing in this Policy takes those away.18. Summary of Key Points- Controller: LAPWING LABS LTD (England and Wales), trading as "Birdex"
- Platforms: Available on iOS and Android
- Authentication: Apple Sign-In (iOS), Google Sign-In (Android), or email + password (both); we never store passwords in plain text
- Location: Only collected when you log a record, use AI Photo ID with location, or save a location (never tracked in background). Other users only ever see a blurred (~3 km) area at most, and nothing for sensitive species
- Community sharing: New accounts share records publicly by default in the Discover and Nearby feeds; you can change this at any time, per profile and per record. Photos, notes, and exact locations are never shown to other users
- Leaderboards: Display name, avatar, and level are visible to other participants in leagues and leaderboards
- AI features: Sound ID audio is analysed on your device and nothing is ever uploaded. AI Photo ID sends your submitted photo (and attached details/location) to Google Gemini or OpenAI. AI results can be wrong
- Subscriptions: Optional Birdex Pro paid subscription; purchases processed by Apple/Google; subscription state managed via RevenueCat (US); no card details collected
- No ads in the app: Birdex shows no advertising. We measure our own ad campaigns only if you allow it (the iOS tracking prompt or the Android consent dialog); if you do, we use the Meta SDK plus your device's advertising identifier, IP address, and hashed email for conversion matching (Section 2.8), plus Apple's aggregate SKAdNetwork on iOS
- No selling data: We never sell your personal information
- NBN Atlas (opt-in): You can choose to contribute anonymised bird records (species, date, and a ~1 km-blurred location) to the NBN Atlas as open conservation data; off by default and revocable anytime
- Discord (opt-in): You can link your account to show your stats on our Discord server; off unless you link
- Analytics: Pseudonymous usage analytics via Mixpanel on both platforms (EU servers, no name/email/location); crash reporting via Sentry on both platforms (error screenshots may be attached)
- Moderation: Reporting and blocking are available; reports are stored so we can act on them
- Your rights: Access, correct, delete (including in-app), export, object, withdraw consent, complain to us and to the ICO/your DPA
- Children: Not intended for users under 13 (up to 16 in some EU/EEA countries)
Thank you for using Birdex!If you have any questions about this Privacy Policy, please contact us at [email protected].End of Privacy Policy