← Xenolog

1. Who we are

Xenolog ("Xenolog", "we", "us") is an iOS app that lets you photograph wild animals, have them identified by an automated instrument, and log them as specimen records.

The data controller for the purposes of the UK GDPR and EU GDPR is PUFF JOURNEY LTD, registered at Suite 14 Railway House, Chertsey Road, Woking, GU21 5AH. You can reach us at baggedsupport@gmail.com.

We are not required to appoint a Data Protection Officer and have not appointed one. Questions about this policy go to the address above.

2. Summary

In plain terms:

3. What we collect

3.1 Account information

Xenolog offers three ways to sign in, and they differ in what we receive:

MethodWhat we receive
AnonymousA randomly generated account identifier only. No name, no email address.
Sign in with AppleAn account identifier and the email address you choose to share. If you use Apple's Hide My Email, we only ever see the private relay address.
GoogleAn account identifier, your email address, your display name and your Google profile picture URL.

A username is generated for you automatically at sign-up (for example SneakyOtter42). You can change it at any time. Usernames are public.

3.2 Information created by playing

DataWhy
Photos you take in the appTo identify the species and to make your specimen record. See section 4.
Approximate location (~100m) and country codeTo place specimens on your sector map and rank you on your territory's ranking. See section 5.
Time of captureTo score the specimen, run streaks and reject stale submissions.
Your device timezoneSo a streak day ends at midnight where you are rather than in UTC.
A cryptographic hash and a perceptual hash of each photoAnti-cheat: to detect the same image being submitted twice.
Motion and screen-detection signalsAnti-cheat: to detect photographs of screens and printed images.
Your archive, DATA, streaks, Commendation Points and directive progressTo run the game.
Friend relationships and blocksTo run the social features.
Specimen nicknames you writeTo display on your specimen records.

3.3 Device and technical information

4. Your photos and AI identification

This is the most sensitive processing Xenolog does, so it is set out in full.

When you scan an animal:

  1. The photo is taken inside the app. Xenolog does not read your photo library.
  2. The photo is uploaded to our storage, hosted by Supabase.
  3. Our server sends the image to a third-party AI vision provider, which returns a species identification and related signals. The provider is Google, through the Gemini API.
  4. A cut-out version of the animal is produced on your device and uploaded so your specimen record can show your own photo.

We do not use your photographs to train any model of our own, and we do not sell or share them. The image is sent to Google only to obtain an identification, and is processed under Google's Gemini API terms.

Where your photos live:

Do not photograph anything you would not want to be visible from a public link: people, documents, house numbers, number plates or the inside of your home.

5. Location

Xenolog asks for "When In Use" location access only. You can refuse, and the app still works — you simply get no sector marker and no territory ranking placement for that specimen.

Your exact coordinates never leave your device. The app requests only around 100-metre accuracy from iOS, then rounds the result to three decimal places of latitude and longitude — roughly a 110-metre grid square — before anything is transmitted. We store that rounded square and a two-letter country code. We never receive, store or reconstruct your precise position, and we do not track your location in the background.

Your country is also used to set your home territory for ranking purposes, and to apply regional classification adjustments.

6. What is public

The following are visible to other people:

Friends see your country only — never the approximate square a specimen was logged in. That is visible to you alone. You can also set your account to private, and you can block other accounts.

7. Analytics, attribution and advertising

Only with your consent, and off until you give it. Xenolog includes two tools: a product-analytics tool, described in 7.1, and a marketing-attribution tool, described in 7.2. Neither starts until you agree, both are covered by the same question, and switching it off in Settings stops them both. The app carries no advertising code.

7.1 PostHog — product analytics

With your consent, PostHog records how the app is used: features used and events such as a scan completing, along with a pseudonymous identifier, device model, iOS version, app version, country and IP address. We use it to find what is broken and what is working. We do not use it to build advertising profiles; screen-view capture is switched off, and so is session replay — we never record your screen. We never tell PostHog who you are, so it holds no profile tied to your account.

If you decline, or withdraw consent later, the tool is shut down and the identifier it was using is discarded — so opting back in later starts a fresh trail rather than rejoining the old one.

PostHog data is held in PostHog's EU Cloud.

7.2 AppsFlyer — marketing attribution

With your consent, AppsFlyer tells us which advert or link a new player arrived from, so we know where a small marketing budget is worth spending. It receives your device's vendor identifier (IDFV), the install, and each launch of the app, along with device model, iOS version, app version, country and IP address. It also receives your advertising identifier (IDFA), but only if you allow it through Apple's tracking prompt, which the app shows once, immediately after you agree to analytics. If you choose "Ask App Not to Track", attribution still works through Apple's own privacy-preserving SKAdNetwork and Apple Ads mechanisms, which report campaign results without identifying you.

AppsFlyer matches that data against records from the advertising networks we buy from, which is what Apple calls tracking, and why the prompt is required. We do not use it to personalise adverts to you, and the consent we pass to AppsFlyer says so. We never tell AppsFlyer who you are: it holds no name, email or account identifier.

If you decline, or withdraw consent later, the tool is stopped and sends nothing further. Unlike PostHog, AppsFlyer keeps its install identifier on your device, so opting back in later rejoins the same install rather than starting a new one. Deleting the app removes it.

7.3 Advertising

Xenolog does not show advertising, and we have no plans to. We do not sell your data to advertisers and there are no ad networks in the app.

7.4 Your consent

Neither tool starts until you agree to it. You are asked once, in plain words, during onboarding, separately from any prompt Apple shows, and you can say no and keep using every part of Xenolog. Apple's tracking prompt follows only if you said yes. You can change your mind at any time in Settings, and the switch there withdraws consent for both tools at once. In the UK and EU this is your consent under PECR; refusing costs you nothing.

8. Purchases

Xenolog is free to play, with an optional paid upgrade called Xeno+, sold as a weekly or yearly subscription or as a one-off lifetime purchase. Purchases are handled by Apple and managed for us by RevenueCat, which records which products you own and keeps that entitlement in step across your devices.

Neither RevenueCat nor we ever receive your card number or payment details. Those go to Apple alone, under Apple's own privacy policy. We see only that a purchase happened and what it unlocked.

If you have consented to attribution (section 7.2), RevenueCat also tells AppsFlyer when a subscription starts, converts from a trial, renews or ends, so we can see which campaign a purchase came from. That message carries the purchase, the price, and the AppsFlyer install identifier — never your name, email or card details.

9. What we don't collect

We do not sell your personal information, and Xenolog shows no advertising. Attribution data of the kind described in section 7.2 may count as "sharing" under the CCPA; it is only ever collected for people who have agreed to it, and you can withdraw that at any time in Settings.

10. Legal bases (UK and EU users)

PurposeLegal basis
Creating and running your account, storing your archive, running rankings and directivesPerformance of a contract
Identifying animals in your photosPerformance of a contract
Approximate location for sector maps and territory rankingConsent (the iOS location permission), which you can withdraw in Settings
Push notificationsConsent, which you can withdraw in Settings
Anti-cheat, App Attest, hashing, abuse preventionLegitimate interests — keeping the game fair and the service secure
Analytics and marketing attributionConsent
Purchases and entitlementsPerformance of a contract
Responding to reports and enforcing our TermsLegitimate interests, and compliance with legal obligations

11. Who we share with

We share personal data with the following categories of recipient, as processors acting on our instructions unless stated otherwise:

RecipientPurposeData
SupabaseDatabase, authentication, file storage, server functionsAll account and gameplay data, photos
Google (Gemini API)Species identificationSpecimen photos
AppleSign in with Apple, App Attest, push notificationsAccount identifiers, device attestation, push tokens
PostHogProduct analytics, only with your consentUsage events, device and technical data
AppsFlyerMarketing attribution, only with your consentDevice identifiers (IDFV; IDFA only if you allow tracking), install, launch and device data; subscription events forwarded by RevenueCat
RevenueCatPurchase and entitlement managementPurchase and receipt data — never card details
Google (Sign-In)Authentication, if you choose itEmail address and name

We may also disclose information where we are legally required to, to protect our rights or the safety of others, or in connection with a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.

12. International transfers

Our database and file storage are hosted in the European Union. Some of the providers listed above process data in the United States or elsewhere. Where personal data leaves the UK or EEA, we rely on the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies.

In practice: your account, specimen records and photographs are stored by Supabase in the EU (Paris) and do not leave it. The only transfer outside the UK and EEA is the photograph sent to Google for identification, which relies on the Standard Contractual Clauses and the UK Addendum under Google's API terms.

PostHog data stays in the EU, on PostHog's EU Cloud. RevenueCat is in the United States and relies on the Standard Contractual Clauses and the UK Addendum. AppsFlyer is an Israeli company with servers in the European Union and the United States; Israel is covered by UK and EU adequacy decisions, and any processing in the United States relies on the Standard Contractual Clauses and the UK Addendum under AppsFlyer's data processing agreement.

13. How long we keep it

DataRetention
Account, archive, DATA and specimen recordsUntil you delete your account
Specimen photos (original, cut-out, thumbnail)Until you delete the specimen record or your account
Image hashes used for anti-cheatUntil you delete your account
Analytics events, where you have consentedKept no longer than 14 months, then deleted
Attribution data, where you have consentedHeld by AppsFlyer for up to 25 months; you can ask us to have it deleted sooner (section 14)
Records needed for tax, accounting or legal claimsAs long as the law requires

Note that releasing a specimen record is a soft delete: the serial number recording that a species was logged for the Nth time is kept, because that fact stays true whether or not you still hold the record. It retains no photo.

14. Your rights

If you are in the UK or EEA, you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time. Exercising these rights is free, and we will respond within one month.

You can complain to a supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk).

If you are a California resident, you have the right to know what personal information we collect and how we use it, to delete it, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA, at all. Xenolog carries no advertising or attribution technology — see section 7.

To exercise any of these rights, contact us at baggedsupport@gmail.com.

15. Deleting your account

You can delete your Xenolog account, and everything in it, from within the app: Agent → Settings (the cog, top right) → Delete account. Deletion removes your agent file, archive, specimen records, photos, friendships and DATA. It cannot be undone.

You can also ask us to delete your account by emailing baggedsupport@gmail.com.

Deletion removes your photographs from our storage as well as your records. Serial numbers are the one exception: the fact that a species was logged for the Nth time stays true, so that number is retired rather than reissued. It carries no photo and is no longer linked to you.

16. Children

Xenolog is not intended for children under 13, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, contact us and we will delete it.

The minimum age of 13 is the same in our Terms of Service and in our App Store age rating. Xenolog carries no advertising, and the one analytics tool it does use runs only with consent and is never used to build advertising profiles — so there is no behavioural profiling of anyone, of any age.

17. Security

Access to your data is enforced at the database level with row-level security, so one account cannot read another's private records. Traffic is encrypted in transit. Original photographs are held in a private, access-controlled bucket. App Attest is used to reject requests that do not come from a genuine copy of the app.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulator where the law requires it.

18. Changes to this policy

We will update this policy when what we do changes. If a change is significant we will tell you in the app before it takes effect. The version and date at the top always tell you which text is current.

19. Contact

PUFF JOURNEY LTD
Suite 14 Railway House, Chertsey Road, Woking, GU21 5AH
baggedsupport@gmail.com