Privacy Policy
Contents
- Who we are
- Summary
- What we collect
- Your photos and AI identification
- Location
- What is public
- Analytics, attribution and advertising
- Purchases
- What we don't collect
- Legal bases
- Who we share with
- International transfers
- How long we keep it
- Your rights
- Deleting your account
- Children
- Security
- Changes
- Contact
1. Who we are
Xenolog ("Xenolog", "we", "us") is an iOS app that lets you photograph wild animals, have them identified by an automated instrument, and log them as specimen records.
The data controller for the purposes of the UK GDPR and EU GDPR is PUFF JOURNEY LTD, registered at Suite 14 Railway House, Chertsey Road, Woking, GU21 5AH. You can reach us at baggedsupport@gmail.com.
We are not required to appoint a Data Protection Officer and have not appointed one. Questions about this policy go to the address above.
2. Summary
In plain terms:
- You can use Xenolog without giving us your name or email, by signing in anonymously.
- We never receive your exact GPS position. Location is rounded on your phone to about 100 metres before it is sent, and only when you allow it.
- Photos you take in the app are uploaded so the animal can be identified, and are sent to a third-party AI provider for that purpose.
- Your username, your survey grade and your DATA total are public. Your cut-out specimen images are served from public URLs.
- We use one product-analytics tool and one marketing-attribution tool. Both collect usage and device information, and both run only if you consent, in a single question you can say no to. Apple's tracking prompt is shown only after that yes. There is no advertising in the app.
- We do not sell your personal information.
3. What we collect
3.1 Account information
Xenolog offers three ways to sign in, and they differ in what we receive:
| Method | What we receive |
|---|---|
| Anonymous | A randomly generated account identifier only. No name, no email address. |
| Sign in with Apple | An account identifier and the email address you choose to share. If you use Apple's Hide My Email, we only ever see the private relay address. |
| An account identifier, your email address, your display name and your Google profile picture URL. |
A username is generated for you automatically at sign-up (for example SneakyOtter42). You can change it at any time. Usernames are public.
3.2 Information created by playing
| Data | Why |
|---|---|
| Photos you take in the app | To identify the species and to make your specimen record. See section 4. |
| Approximate location (~100m) and country code | To place specimens on your sector map and rank you on your territory's ranking. See section 5. |
| Time of capture | To score the specimen, run streaks and reject stale submissions. |
| Your device timezone | So a streak day ends at midnight where you are rather than in UTC. |
| A cryptographic hash and a perceptual hash of each photo | Anti-cheat: to detect the same image being submitted twice. |
| Motion and screen-detection signals | Anti-cheat: to detect photographs of screens and printed images. |
| Your archive, DATA, streaks, Commendation Points and directive progress | To run the game. |
| Friend relationships and blocks | To run the social features. |
| Specimen nicknames you write | To display on your specimen records. |
3.3 Device and technical information
- Apple App Attest. Xenolog uses Apple's App Attest to confirm that scans come from a genuine, unmodified copy of the app. This produces a device-bound cryptographic key and attestation, which we store and verify. It is used only to prevent cheating.
- Push notification token. If you allow notifications, we store the token Apple issues for your device, along with the platform and environment, so we can send reminders and social alerts.
- Standard technical data. IP address, app version, device model and operating system version, received by our backend and our analytics providers in the ordinary course of serving requests.
4. Your photos and AI identification
This is the most sensitive processing Xenolog does, so it is set out in full.
When you scan an animal:
- The photo is taken inside the app. Xenolog does not read your photo library.
- The photo is uploaded to our storage, hosted by Supabase.
- Our server sends the image to a third-party AI vision provider, which returns a species identification and related signals. The provider is Google, through the Gemini API.
- A cut-out version of the animal is produced on your device and uploaded so your specimen record can show your own photo.
We do not use your photographs to train any model of our own, and we do not sell or share them. The image is sent to Google only to obtain an identification, and is processed under Google's Gemini API terms.
Where your photos live:
- The original photo is stored in a private bucket that is not publicly readable.
- The cut-out image and thumbnail are stored in public buckets. They are served from URLs that are hard to guess but are not access-controlled — anyone with the URL can view them. This is how specimen records are displayed to friends and on shared records.
Do not photograph anything you would not want to be visible from a public link: people, documents, house numbers, number plates or the inside of your home.
5. Location
Xenolog asks for "When In Use" location access only. You can refuse, and the app still works — you simply get no sector marker and no territory ranking placement for that specimen.
Your exact coordinates never leave your device. The app requests only around 100-metre accuracy from iOS, then rounds the result to three decimal places of latitude and longitude — roughly a 110-metre grid square — before anything is transmitted. We store that rounded square and a two-letter country code. We never receive, store or reconstruct your precise position, and we do not track your location in the background.
Your country is also used to set your home territory for ranking purposes, and to apply regional classification adjustments.
6. What is public
The following are visible to other people:
- Your username, survey grade, insignia and DATA, on the ranking.
- Your agent file and a selection of showcase specimen records, to anyone who views your profile.
- Your full archive, to accounts you have accepted as friends.
- Cut-out specimen images, to anyone holding the image URL.
Friends see your country only — never the approximate square a specimen was logged in. That is visible to you alone. You can also set your account to private, and you can block other accounts.
7. Analytics, attribution and advertising
Only with your consent, and off until you give it. Xenolog includes two tools: a product-analytics tool, described in 7.1, and a marketing-attribution tool, described in 7.2. Neither starts until you agree, both are covered by the same question, and switching it off in Settings stops them both. The app carries no advertising code.
7.1 PostHog — product analytics
With your consent, PostHog records how the app is used: features used and events such as a scan completing, along with a pseudonymous identifier, device model, iOS version, app version, country and IP address. We use it to find what is broken and what is working. We do not use it to build advertising profiles; screen-view capture is switched off, and so is session replay — we never record your screen. We never tell PostHog who you are, so it holds no profile tied to your account.
If you decline, or withdraw consent later, the tool is shut down and the identifier it was using is discarded — so opting back in later starts a fresh trail rather than rejoining the old one.
PostHog data is held in PostHog's EU Cloud.
7.2 AppsFlyer — marketing attribution
With your consent, AppsFlyer tells us which advert or link a new player arrived from, so we know where a small marketing budget is worth spending. It receives your device's vendor identifier (IDFV), the install, and each launch of the app, along with device model, iOS version, app version, country and IP address. It also receives your advertising identifier (IDFA), but only if you allow it through Apple's tracking prompt, which the app shows once, immediately after you agree to analytics. If you choose "Ask App Not to Track", attribution still works through Apple's own privacy-preserving SKAdNetwork and Apple Ads mechanisms, which report campaign results without identifying you.
AppsFlyer matches that data against records from the advertising networks we buy from, which is what Apple calls tracking, and why the prompt is required. We do not use it to personalise adverts to you, and the consent we pass to AppsFlyer says so. We never tell AppsFlyer who you are: it holds no name, email or account identifier.
If you decline, or withdraw consent later, the tool is stopped and sends nothing further. Unlike PostHog, AppsFlyer keeps its install identifier on your device, so opting back in later rejoins the same install rather than starting a new one. Deleting the app removes it.
7.3 Advertising
Xenolog does not show advertising, and we have no plans to. We do not sell your data to advertisers and there are no ad networks in the app.
7.4 Your consent
Neither tool starts until you agree to it. You are asked once, in plain words, during onboarding, separately from any prompt Apple shows, and you can say no and keep using every part of Xenolog. Apple's tracking prompt follows only if you said yes. You can change your mind at any time in Settings, and the switch there withdraws consent for both tools at once. In the UK and EU this is your consent under PECR; refusing costs you nothing.
8. Purchases
Xenolog is free to play, with an optional paid upgrade called Xeno+, sold as a weekly or yearly subscription or as a one-off lifetime purchase. Purchases are handled by Apple and managed for us by RevenueCat, which records which products you own and keeps that entitlement in step across your devices.
Neither RevenueCat nor we ever receive your card number or payment details. Those go to Apple alone, under Apple's own privacy policy. We see only that a purchase happened and what it unlocked.
If you have consented to attribution (section 7.2), RevenueCat also tells AppsFlyer when a subscription starts, converts from a trial, renews or ends, so we can see which campaign a purchase came from. That message carries the purchase, the price, and the AppsFlyer install identifier — never your name, email or card details.
9. What we don't collect
- Your precise GPS location, ever.
- Your photo library. The app can only add sticker images to it, never read from it.
- Your contacts, calendar, microphone, health or fitness data.
- Your payment card details.
We do not sell your personal information, and Xenolog shows no advertising. Attribution data of the kind described in section 7.2 may count as "sharing" under the CCPA; it is only ever collected for people who have agreed to it, and you can withdraw that at any time in Settings.
10. Legal bases (UK and EU users)
| Purpose | Legal basis |
|---|---|
| Creating and running your account, storing your archive, running rankings and directives | Performance of a contract |
| Identifying animals in your photos | Performance of a contract |
| Approximate location for sector maps and territory ranking | Consent (the iOS location permission), which you can withdraw in Settings |
| Push notifications | Consent, which you can withdraw in Settings |
| Anti-cheat, App Attest, hashing, abuse prevention | Legitimate interests — keeping the game fair and the service secure |
| Analytics and marketing attribution | Consent |
| Purchases and entitlements | Performance of a contract |
| Responding to reports and enforcing our Terms | Legitimate interests, and compliance with legal obligations |
11. Who we share with
We share personal data with the following categories of recipient, as processors acting on our instructions unless stated otherwise:
| Recipient | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All account and gameplay data, photos |
| Google (Gemini API) | Species identification | Specimen photos |
| Apple | Sign in with Apple, App Attest, push notifications | Account identifiers, device attestation, push tokens |
| PostHog | Product analytics, only with your consent | Usage events, device and technical data |
| AppsFlyer | Marketing attribution, only with your consent | Device identifiers (IDFV; IDFA only if you allow tracking), install, launch and device data; subscription events forwarded by RevenueCat |
| RevenueCat | Purchase and entitlement management | Purchase and receipt data — never card details |
| Google (Sign-In) | Authentication, if you choose it | Email address and name |
We may also disclose information where we are legally required to, to protect our rights or the safety of others, or in connection with a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.
12. International transfers
Our database and file storage are hosted in the European Union. Some of the providers listed above process data in the United States or elsewhere. Where personal data leaves the UK or EEA, we rely on the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies.
In practice: your account, specimen records and photographs are stored by Supabase in the EU (Paris) and do not leave it. The only transfer outside the UK and EEA is the photograph sent to Google for identification, which relies on the Standard Contractual Clauses and the UK Addendum under Google's API terms.
PostHog data stays in the EU, on PostHog's EU Cloud. RevenueCat is in the United States and relies on the Standard Contractual Clauses and the UK Addendum. AppsFlyer is an Israeli company with servers in the European Union and the United States; Israel is covered by UK and EU adequacy decisions, and any processing in the United States relies on the Standard Contractual Clauses and the UK Addendum under AppsFlyer's data processing agreement.
13. How long we keep it
| Data | Retention |
|---|---|
| Account, archive, DATA and specimen records | Until you delete your account |
| Specimen photos (original, cut-out, thumbnail) | Until you delete the specimen record or your account |
| Image hashes used for anti-cheat | Until you delete your account |
| Analytics events, where you have consented | Kept no longer than 14 months, then deleted |
| Attribution data, where you have consented | Held by AppsFlyer for up to 25 months; you can ask us to have it deleted sooner (section 14) |
| Records needed for tax, accounting or legal claims | As long as the law requires |
Note that releasing a specimen record is a soft delete: the serial number recording that a species was logged for the Nth time is kept, because that fact stays true whether or not you still hold the record. It retains no photo.
14. Your rights
If you are in the UK or EEA, you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time. Exercising these rights is free, and we will respond within one month.
You can complain to a supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk).
If you are a California resident, you have the right to know what personal information we collect and how we use it, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA, at all. Xenolog carries no advertising or attribution technology — see section 7.
To exercise any of these rights, contact us at baggedsupport@gmail.com.
15. Deleting your account
You can delete your Xenolog account, and everything in it, from within the app: Agent → Settings (the cog, top right) → Delete account. Deletion removes your agent file, archive, specimen records, photos, friendships and DATA. It cannot be undone.
You can also ask us to delete your account by emailing baggedsupport@gmail.com.
Deletion removes your photographs from our storage as well as your records. Serial numbers are the one exception: the fact that a species was logged for the Nth time stays true, so that number is retired rather than reissued. It carries no photo and is no longer linked to you.
16. Children
Xenolog is not intended for children under 13, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, contact us and we will delete it.
The minimum age of 13 is the same in our Terms of Service and in our App Store age rating. Xenolog carries no advertising, and the one analytics tool it does use runs only with consent and is never used to build advertising profiles — so there is no behavioural profiling of anyone, of any age.
17. Security
Access to your data is enforced at the database level with row-level security, so one account cannot read another's private records. Traffic is encrypted in transit. Original photographs are held in a private, access-controlled bucket. App Attest is used to reject requests that do not come from a genuine copy of the app.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulator where the law requires it.
18. Changes to this policy
We will update this policy when what we do changes. If a change is significant we will tell you in the app before it takes effect. The version and date at the top always tell you which text is current.
19. Contact
PUFF JOURNEY LTD
Suite 14 Railway House, Chertsey Road, Woking, GU21 5AH
baggedsupport@gmail.com