Privacy Policy
Last updated: 5 October 2026
- Bird identification runs on your phone. Photos are uploaded only when you save a sighting.
- We never sell your data and we don't show ads.
- Usage analytics are on only if you agree to them in the app.
- The waitlist on this website stores your email address only to tell you once when Birdie launches.
- You can delete your account and data in the app at any time.
1. Who we are
Birdie – Bird Identifier (the "App") and this website are run by Michał Ciechanowicz, an independent developer based in Poland ("we", "us"). We are the controller of your personal data. Contact: birdieapp.team@gmail.com.
2. The waitlist on this website
If you join the waitlist, we collect your email address and the date you signed up. Our email provider, Kit (Kit Inc., USA), also records technical details of the sign-up, such as your IP address, as proof of consent.
- Why: to send you one email when Birdie is available in the App Store (and, later, Google Play).
- Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with the unsubscribe link in the email or by writing to us.
- How long: until you unsubscribe, and no longer than 3 months after the launch email is sent. Then we delete the list.
- We don't add you to any other mailing list, and we don't share your email with anyone except Kit, which processes it on our behalf.
The website itself uses no cookies, no analytics and no advertising trackers. Our hosting provider keeps short-lived technical server logs (such as IP address and browser type) to deliver the site and protect it from abuse. Fonts are served from this website, not from Google.
3. Data the App collects
| Data | What and why |
|---|---|
| Account | Your email address and, if you give one, a display name and avatar. If you sign in with Apple or Google, we receive the email address and name they share with us (Apple lets you hide your email). If you use the App as a guest, we create an anonymous account with no email. Needed to keep your collection across devices. |
| Photos | Identification happens on your device; the photo is not sent anywhere for that. When you save a sighting, its photo is uploaded to our cloud storage so it appears in your history and collection. |
| Sightings | The species, the identification confidence, date and time, and any note you add. Used to build your history, collection, statistics and Wrapped. |
| Country | The country you choose (or that the App suggests from your device region or approximate location) to show the birds that live near you. If you allow location access, the App uses it on your device to work out the country. We don't store your coordinates. |
| Daily usage counter | How many identifications you saved today, to apply the free plan's daily limit. |
| Purchases | Whether you have Premium, your plan and its renewal status. Payments are handled by Apple or Google; we never see your card details. |
| Notifications | If you allow notifications, a device token so we can send them, and a reminder scheduled on your device before a free trial ends. |
| Crash reports | Device model, OS version, App version and technical error details when something breaks, so we can fix it. |
| Usage analytics | Only if you agree when the App asks. Events such as "app opened" or "bird identified", linked to a random ID. You can withdraw your consent at any time by writing to us. |
| Feedback | If you email us, your address and message, to reply to you. |
Legal bases (GDPR): providing the App you asked for (Art. 6(1)(b)) for account, photos, sightings, country, limits, purchases and notifications; our legitimate interest in a working, secure App (Art. 6(1)(f)) for crash reports; your consent (Art. 6(1)(a)) for usage analytics and the waitlist.
4. Who processes data for us
- Supabase: database, sign-in and photo storage.
- RevenueCat: manages subscriptions together with Apple and Google.
- Sentry: crash reports.
- PostHog: usage analytics, only with your consent.
- Apple and Google: sign-in, payments, push notifications and app distribution, under their own privacy policies.
- Kit: the website waitlist.
- Our website host: serves this website.
To show bird facts and photos, the App also requests public content from Wikipedia, Wikidata and Wikimedia Commons (and uses openly licensed data from GBIF and AVONET). Those requests contain a species name, not your personal data, but like any internet request they reveal your IP address to those services.
Some of these providers are based in the USA. Where data leaves the European Economic Area, transfers rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
5. What we don't do
- We don't sell or rent personal data, and we don't use it for advertising.
- We don't track you across other companies' apps or websites.
- We don't publish your photos. They leave the App only when you share a card or story yourself.
6. How long we keep data
App data stays while your account exists. When you delete your account in the App (Profile, Account and data, Delete account), we delete your account, sightings and saved photos. Backups roll over and are gone within 30 days. A guest account that signs out loses its data straight away. Crash reports and analytics events are deleted automatically by those services within their standard retention periods (at most 12 months). Waitlist data: see section 2.
7. Your rights
Wherever you live, you can ask us to access, correct, export or delete your data, and you can withdraw consent at any time. If you are in the EEA or the UK, you also have the right to restrict or object to processing and to complain to a data protection authority (in Poland: the President of the Personal Data Protection Office, UODO). Residents of California and other US states have similar rights to know, delete and correct, and we don't sell or share personal data as those laws define it.
Most of this you can do yourself in the App: export your sightings, edit your profile, or delete your account. For anything else, email birdieapp.team@gmail.com. We reply within 30 days.
8. Children
Birdie is not directed at children under 13 (under 16 in the EEA), and we don't knowingly collect their data. If you think a child has given us personal data, write to us and we will delete it.
9. Security
Data travels encrypted (TLS), database access is limited per user by row-level security, and only the developer has access to production systems. No system is perfectly secure, so we also keep the amount of data we hold small.
10. Changes
If this policy changes, we update the date at the top. For important changes we will also tell you in the App.