← Forage

Privacy Policy

Last updated: 20 August 2026

This privacy policy applies to the Forage app (“Application”) for mobile devices and to the website foragewildfood.app, created by Kevin Baur (the “Service Provider”) as a commercial service. The service is provided “AS IS”. The controller for the personal data described here is Kevin Baur, BSc, Hochstraß 542, 3033 Klausen-Leopoldsdorf, Austria, reachable at [email protected]; further details are in the imprint.

Your account

Using the Application requires an account. To create one you provide an email address, a password and a display name. The password is stored only as a salted hash by our authentication provider (Supabase); we never see it in plain text.

Your account carries a profile: display name, level and experience points, counters such as finds and identification scans, your settings, and optionally a profile picture you upload. Your display name, level and profile picture are public inside the Application: they appear on leaderboards, in the community feed and to people who follow you. Everything else on your profile stays private to you.

What the Application stores about your foraging

Your foraging data is kept in our own backend (hosted on Supabase in the EU, Ireland) and tied to your account, so it survives a reinstall or a change of device. It includes your watchlist, saved spots and finds with their coordinates, harvest log entries, notes, uploaded photos, your species collection (“Foragedex”), quiz and challenge progress, the people you follow, and any posts, comments and likes you contribute to the community feed.

Spots you save stay private until a species has been identified. Only when a find has a confirmed species, and you chose to share it, does it become visible to other users. Technical information such as server and access logs, device platform and app version is processed to operate and secure the service.

Photos and species identification

When you identify a plant or mushroom, the photo is sent to Kindwise (plant.id and mushroom.id, operated by Kindwise s.r.o., Czech Republic), which returns the candidate species. Where a location is available, the coordinates are sent along with the photo to improve the result. See Kindwise's privacy policy at kindwise.com.

To place a find on the map, the Application needs to know where the photo was taken: a photo taken in the Application uses the current device location, a photo picked from your gallery uses the location stored in the photo's own EXIF data. Photos without any location information cannot be saved as a find.

Photos you attach to a find, a profile picture and photos in the community feed are stored in our backend. Community photos and profile pictures are shown publicly. Photos on a private spot are not shown to other users, but the photo files themselves sit behind a long, unguessable link rather than a login, so anyone you hand that link to can open it.

Does the Application collect precise location information?

Yes, with your permission. Your exact coordinates are sent to our own backend to compute what is in season around you, to place your finds, and to trigger in-season notifications. You can grant or revoke this permission at any time in your device settings; without it, the Application falls back to a coarser, region-based calendar.

Before your location leaves our backend for a weather lookup, it is rounded to a grid cell of 0.25° (roughly 28 km), so the weather provider only ever receives a coarse area, never your exact position. Your location is not sold and is not used to target advertising.

Notifications

If you allow notifications, your device is issued a push token that is stored with your account and used to send in-season alerts, watchlist reminders and community notifications. Delivery runs through the Expo push service, which hands the message to Apple (APNs) or Google (FCM). You can revoke notification permission at any time in your device settings.

In-App Purchases and Subscriptions

Optional purchases may include subscriptions and one-time purchases. The Apple App Store or Google Play Store processes all transactions. The Service Provider neither collects nor retains payment information: the respective platforms handle billing under their own policies.

Subscriptions auto-renew unless cancelled at least 24 hours before the end of the current billing period. You can manage or cancel subscriptions in your App Store or Google Play settings. A free trial may be offered; no charges apply during the trial, and a subscription activates automatically afterwards unless cancelled.

RevenueCat, a third-party service, manages in-app purchases and subscriptions and processes “a randomly generated anonymous user identifier, purchase history, and subscription status.” So that a purchase can be matched to the right account, your account identifier is passed to RevenueCat; your name, email address and payment details are not. See RevenueCat's Privacy Policy at revenuecat.com/privacy for more details.

Advertising and attribution

The Application includes the Meta (Facebook) SDK so that app-install campaigns can be measured. It reports events such as installs, app launches, completed sign-ups, trial starts and purchases to Meta, together with a randomly generated anonymous device identifier and technical data such as IP address, device model and operating system. Purchase and trial events are additionally forwarded to Meta by RevenueCat using that same anonymous identifier.

On iOS you are asked for permission through Apple's App Tracking Transparency dialog. If you decline, no advertising identifier (IDFA) is used and attribution runs only in Apple's aggregated form. You can change this at any time under Settings → Privacy & Security → Tracking; on Android you can opt out under Settings → Privacy → Ads. Your foraging content, your photos, your notes and your precise location are never sent to Meta, though the IP address of a request lets any recipient infer a rough area. Meta's data policy is at facebook.com/privacy/policy.

Do third parties see or have access to information obtained by the Application?

We use the following services, each only for the purpose named:

  • Supabase (EU, Ireland): database, file storage, authentication and backend functions.
  • Kindwise (Czech Republic): species identification from the photo you submit, plus coordinates where available.
  • Open-Meteo: weather, elevation and climate normals for the rounded grid cell (about 28 km) around you. Elevation is returned within the same weather response; there is no separate elevation or geocoding provider.
  • Expo (push service), Apple (APNs) and Google (FCM): delivery of notifications to your device.
  • RevenueCat: subscription validation and purchase status.
  • Meta: measurement of advertising campaigns, as described above.
  • Apple and Google: app distribution and billing.
  • Resend: sending the message when you contact us through the in-app feedback form (your message and the email address on your account).
  • Cloudflare: hosting of the website foragewildfood.app.

The species content in the Application (profiles, lookalikes, seasons, images) is compiled by our backend from public sources such as GBIF, iNaturalist, Wikipedia and OpenStreetMap, with the help of Anthropic's Claude API. Only public species information is sent there: no accounts, photos, notes or user locations.

No other third parties have access to data generated through the Application. Your data is not sold.

Where your data is stored

The database, the stored files and the backend functions run in the European Union (Ireland). Some of the services listed above are based outside the EU, in particular in the United States (Apple, Google, Meta, RevenueCat, Expo, Cloudflare, Anthropic, Resend). Where data reaches them, the transfer is covered by those providers' standard contractual clauses or by their certification under the EU-U.S. Data Privacy Framework.

Website analytics

The website foragewildfood.app uses DataFast, a privacy-friendly, cookieless analytics tool. It does not use cookies, does not track you across websites, and does not collect personally identifiable information. No cookie-consent banner is required.

Legal bases and how long data is kept

Your account and foraging data is processed to provide the service you signed up for (Art. 6(1)(b) GDPR). Location access, notifications and, on iOS, app tracking rest on the permission you grant and can be withdrawn at any time (Art. 6(1)(a) GDPR). Operating and securing the service, preventing abuse and measuring campaigns rest on a legitimate interest (Art. 6(1)(f) GDPR).

Account and foraging data is kept until you delete your account, see Delete your account. Technical logs are kept for a short period only. Purchase and billing records are held by Apple or Google under their own retention policies.

Your rights

You have the right to access the data held about you, to have it corrected or erased, to have processing restricted, to receive your data in a portable form, and to object to processing based on legitimate interest. Where processing rests on your permission, you can withdraw it at any time; this does not affect processing that already took place. To exercise any of these rights, contact [email protected].

You also have the right to lodge a complaint with a supervisory authority, for example the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at).

What are my opt-out rights?

You can revoke location, notification and tracking permissions at any time in your device settings, cancel an active subscription through the App Store or Google Play, and delete your account and its data as described under Delete your account. Uninstalling the Application stops all collection on the device, but does not by itself delete the data held under your account.

Children

The Application is not directed at children and is not marketed to them. Users must be at least 16 years old to create an account and to consent to the processing of their personal data; in some jurisdictions a parent or guardian may consent on their behalf. We do not knowingly collect personal data from children below that age. If you believe a child has provided personal information, please contact [email protected] and it will be deleted.

Security

The Service Provider is concerned about safeguarding the confidentiality of your information. Traffic between the Application and our backend is encrypted in transit, passwords are stored only as hashes, and database access is restricted per user by row-level security, so other users cannot read your private data. No method of transmission or storage is completely secure, so absolute security cannot be guaranteed.

Changes

This privacy policy may be updated from time to time. The Service Provider will notify you of any changes by updating this page. Continued use of the Application or website is regarded as acceptance of those changes.

Your Consent

Where processing rests on your consent, you give it through the permission dialogs in the Application: location, notifications and, on iOS, app tracking. You can withdraw any of them at any time in your device settings, and the corresponding feature simply stops. Everything else described here is processed on the legal bases set out above, not on consent.

Contact Us

If you have any questions about privacy, please contact [email protected].