Bird Book is a place to keep and share your birding. This policy explains what data we collect, why we collect it, who receives it, how long we keep it, and the choices you have.
We collect the information Bird Book needs to run, keep the community safe, understand how the Service is used, and fix problems. We don't run ads, sell your personal data, or track you across other companies' apps and websites for advertising.
01What we collect
- Account. When you sign in with Apple or Google, we receive the email address and name your provider shares, along with the provider's account identifier, and create your Bird Book username and profile. If you use Sign in with Apple, we also keep an Apple refresh token so we can revoke Bird Book's access when you delete your account. Your profile and cover photos are stored if you add them.
- Photos and their details. Photos you add to your gallery or posts are uploaded to our servers, along with the metadata the app reads from them: capture date, camera and lens model, focal length, ISO, and — if your photo has it — the GPS coordinates and place name where it was taken. We keep the photo's full technical metadata (EXIF) on our record of it, and strip it out of the image file we publish, so your camera's data — including any location it recorded — never travels with the picture.
- Posts and activity. Your posts, titles, captions, comments, likes, bird species tags, collections, and birding stats.
- Trip routes. If you record a trip, the app tracks your GPS route, distance, and duration and stores them with the resulting post.
- Purchases. For Bird Book Pro, Apple processes the payment; we store your subscription status and identifiers needed to verify it. For photo books, payment is processed by Stripe — your card details never touch our servers — and we store your order, its price, and the shipping address you provide. We also record which pages of the book preview you looked at before paying to document the custom book you approved before it was printed and to help us resolve support requests.
- Device and app use. If you enable notifications, we store your push token and notification preferences. Firebase also assigns an app-installation identifier and automatically records basic product interactions such as first opens, sessions, screen views, and notification interactions. It may also receive your device model, language, time zone, operating-system version, app version, and IP-derived general location.
- Reports and blocks. If you report content or block someone, we keep a record so moderation works.
- Diagnostics. When the app or our servers hit an error, Sentry receives crash, error, performance, profiling, and structured-log data. Firebase Crashlytics also receives app crash reports. These reports can include your IP address, device model, iOS and app versions, and a technical trace of what was happening. A sample of app sessions sends performance and profiling data. We use this to find faults, understand stability, and improve performance.
- How you use the app. Your sign-in dates, how many times you've opened the app and roughly when you last did, which first-run setup steps you got through, any referral code you entered, and whether you opened a survey we linked to. This is informational — we look at it to see whether the app is being used and where people get stuck. Nothing about your account depends on it.
- Other birding apps on your device. The app checks whether a short list of well-known birding apps (for example eBird or Merlin) is installed, and records which of them are. It cannot see anything else on your device, or anything inside those apps. We use it to understand what our birders already carry into the field.
- Website and network data. When you use birdbook.io or the Bird Book API, our infrastructure receives the information needed to serve and protect the request, including your IP address, request time, requested URL, browser or app information, and security signals. Cloudflare may set a short-lived
__cf_bmcookie to distinguish automated traffic. The public website also loads its typefaces from Google Fonts.
02How and why we use it
We use your data to run Bird Book: authenticating your account; showing your posts to the audience you chose; syncing your gallery; computing stats and milestones; fulfilling subscriptions and photo-book orders; sending notifications you've enabled; fetching weather; providing support; detecting fraud and abuse; moderating the community; understanding use; and finding and fixing faults.
Where data-protection law requires a legal basis, we rely on:
- Our contract with you. To provide the account, social, subscription, and ordering features you request.
- Your consent. For permissions and optional features that ask for it, such as location, notifications, and any processing for which local law requires consent. You may withdraw a permission in iOS Settings; you may change sharing choices in Bird Book or contact us.
- Our legitimate interests. To secure and operate the Service, moderate content, prevent abuse, measure how the Service is used, understand our audience, and diagnose and improve performance — where those interests are not outweighed by your rights.
- Legal obligations. Such as tax, accounting, consumer-protection, and lawful-request requirements.
03What we don't do
Bird Book contains no advertising SDK and does not use the advertising identifier (IDFA). It does use Firebase Analytics for product-usage measurement and Firebase Crashlytics and Sentry for diagnostics, as described above. We do not join that data with data from other companies to advertise to you.
04Location, specifically
Location is central to birding, so we're explicit about it:
- Photo locations come from your photos' own metadata and are shown where you share those photos.
- Trip routes are recorded only while you record a trip. You choose each post's audience (Everyone, Followers, or Only Me), and you can hide a post's map at any time after posting — the route then stops being shown or shared.
- Your U.S. state may appear on leaderboards. You choose whether it does when you first set up your account; to change that afterwards, email us and we'll do it for you.
- Weather lookups are made by our servers, not your phone, and send only coordinates to our weather provider (Open-Meteo) — never your name, your account details, or your device's address.
05When we share data
- With other users: what you post, to the audience you chose.
- Apple: sign-in, subscriptions, and final delivery of push notifications to your device.
- Google: Google sign-in; Firebase Cloud Messaging, which holds the device and installation tokens used for push; Firebase Analytics; Firebase Crashlytics; and Google Fonts on the public website.
- Cloudflare and DigitalOcean: Cloudflare provides network delivery, caching, and security for birdbook.io and its API. DigitalOcean hosts the application, database, cache, and stored media.
- Stripe and Prodigi: Stripe processes photo-book payments. Prodigi receives the name, shipping address, and book files needed to print and deliver an order.
- Open-Meteo: coordinates used for a weather lookup, without your Bird Book account details.
- Sentry: the app and server diagnostic data described above.
- Email and survey providers: moderation reports may be delivered to our moderators through Google-hosted email and can include the reporter's username, reason, reported target, and optional details. If you choose to open a survey, its provider (for example, SurveyMonkey) receives the information your browser sends and anything you submit under that provider's privacy notice; Bird Book records only that you engaged with the survey.
- When required by law, or to protect the safety and rights of our users and Service.
We limit disclosures to what each service needs. Providers acting for us are expected to protect personal data consistently with their contractual commitments and applicable law; some providers, such as Apple, Google, and a survey provider, also process data under their own terms when you use their service.
06Retention and deletion
- Account and content. Your account information, posts, photos, comments, routes, preferences, usage history, installed-app report, and other account records stay until you delete the relevant content or delete your account. Routine caches and backups may retain a deleted copy until they are overwritten under their normal schedules; those copies are not used except for recovery, security, or legal needs.
- Photo-book orders. Unpaid drafts are deleted with the account. After an order is paid, we retain the print files, finished book, order and shipping record, and preview-approval evidence for as long as reasonably needed to provide reprints and support, answer payment disputes or legal claims, and meet accounting and tax obligations. These records survive account deletion detached from the Bird Book account, and are deleted or anonymised when those purposes no longer require them.
- Diagnostics and analytics. Sentry, Firebase Analytics, Firebase Crashlytics, Cloudflare, and our hosting provider retain diagnostic, usage, security, and network records under the retention settings and schedules for those services. We keep them only while useful for measuring use, investigating faults or abuse, securing the Service, or meeting legal obligations.
- Tokens. Bird Book access tokens are short-lived; Bird Book session refresh tokens rotate and are stored only as hashes. An Apple refresh token cannot be stored only as a hash because we must present it back to Apple to revoke access. It is kept in the protected server database, excluded from the admin interface, and deleted after the revocation attempt when you delete your account.
07Security
Traffic between the app, website, providers, and our servers is encrypted with HTTPS. Bird Book access tokens are short-lived, our session refresh tokens rotate and are hashed, administrative access is restricted, and payment credentials are handled by Apple and Stripe. No system is perfectly secure; if we learn of a breach, we will respond and notify affected people and authorities when the law requires it.
08Children
Bird Book is not directed at children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
09Your rights
Depending on where you live and whether a law applies to Bird Book, you may have rights to know about and access personal data; correct it; receive a portable copy; delete it; restrict or object to processing; and withdraw consent. You may delete content and your account in the app, change iOS permissions in iOS Settings, change post and map audiences in Bird Book, or email us for anything else. We may need to verify your identity, and legal exceptions may require us to keep certain records.
If you are in the EU/EEA or UK, you may also complain to the data-protection authority where you live or work. If the California Consumer Privacy Act applies, California residents may request to know, correct, or delete covered information and will not receive discriminatory treatment for exercising a right. Bird Book does not sell personal information or share it for cross-context behavioural advertising. California residents may also contact the California Privacy Protection Agency.
Personal data may be processed in the United States and other countries where our providers operate. Where a restricted international transfer requires safeguards, we rely on the provider's contractual safeguards or another transfer mechanism permitted by law.
10Changes
If we change this policy in a material way, we'll give you notice in the app or by email before the change takes effect.
11Contact
Bird Book is operated by Arthur De Araujo in Washington, United States. Arthur De Araujo is the controller responsible for the personal data described in this policy.
Questions or privacy requests can be sent to [email protected], or through the Support page. Our Terms & Conditions cover everything else.