1. Who We Are
This Privacy Policy explains how Aljoša K. ("we", "us", "My Wild Patch") handles personal data in the My Wild Patch mobile application ("the App").
For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the limited processing described in Sections 5 and 6.
Contact for privacy questions: naturescoutapp@gmail.com. We have not appointed a Data Protection Officer, as our processing does not require one under Article 37 GDPR. We are established in the EU, so no Article 27 representative is required.
This Privacy Policy forms part of our Terms & Conditions. Where the two overlap regarding personal data, this Privacy Policy prevails.
2. The Short Version
- Your foraging data stays on your device. Locations, paths, harvest records, notes, and photos are stored only in the App's own storage. We have no server and no copy of them.
- We have no user accounts. We do not ask for your name, email address, or any other identifier.
- Usage analytics and crash reporting are off until you turn them on. The App asks once, after the introduction screens, and collects nothing unless you agree. Both work from random identifiers, never your identity, and never receive your saved locations, paths, harvests, or photos (Sections 6.4–6.5).
- We run no advertising SDK, and we do not sell or share personal data for advertising.
- Some features send data to third parties to work at all — maps, weather, and purchases. Those third parties process data under their own privacy policies (Section 6).
3. Data Stored On Your Device
The following is created by you and stored locally on your device, in the App's private database and file storage:
| Data | Where it is stored |
|---|---|
| Marked locations (name, description, coordinates, type, species label, date) | App database |
| Recorded paths (sequences of coordinates and timestamps) | App database |
| Harvest records (name, description, weight, date and time) | App database |
| Photos you take or attach | App-specific file storage |
| App settings and preferences (units, language, theme, map type) | App preferences |
We cannot see this data, and it is not transmitted to us. It is removed when you delete the relevant entries or uninstall the App — with one exception, see Section 4 on device backups.
4. Device Backups
The App allows Android's standard backup and device-transfer features to include its data. Depending on your device settings, your on-device My Wild Patch data (including locations, paths, harvest records, and photos in the App's storage) may be copied to Google's backup service under your Google account, and restored when you set up a new device.
This backup is performed by Android and Google, not by us, and is governed by Google's Privacy Policy. You can turn it off in your device's Android settings (Settings → Google → Backup, or equivalent for your device).
5. Data Processed by Device Permissions
5.1 Location (precise and approximate)
What: your device's GPS/network position. Why: to show your position on the map, to mark locations, to record paths, and to fetch weather for where you are. Where it goes: your position is used on the device and stored on the device when you save a location or record a path. Coordinates are additionally sent to third-party services as described in Section 6.
While a path recording is running: the App runs an Android foreground service, so a recording you started keeps going when the App is not on screen. A permanent notification is shown for as long as it runs, and recording stops when you stop it.
The App does not request Android's background location permission. It receives your position only while the App is open or while a recording you started is running — never when the App is idle or closed.
5.2 Camera
What: photos you take through the App. Why: to attach photos to your locations and harvest records. Where it goes: photos are saved to the App's own storage on your device. They are not uploaded to us and are not sent to any third-party service by the App.
5.3 Notifications
What: permission to post notifications. Why: to display the ongoing notification required by Android while a path recording is running. We do not send marketing or push notifications.
5.4 Motion and position sensors
What: accelerometer and magnetometer readings. Why: to display the compass. Sensor readings are used only in memory, in real time, and are neither stored nor transmitted.
You can grant or withdraw these permissions at any time in your device settings. Withdrawing a permission disables the features that depend on it; the rest of the App keeps working.
6. Third-Party Services
The App relies on the third-party services listed below. When a feature uses one of these services, data is transmitted to that third party and processed under its own privacy policy, over which we have no control.
6.1 Google Maps and Google Play services
Used for map display and for determining your device's location. Google receives data including your location, IP address, and device and usage information in accordance with Google's Privacy Policy and the Google Maps/Google Earth Additional Terms of Service.
6.2 WeatherAPI.com (weather data)
When you view weather, the App sends the coordinates of the relevant point (your position, or a place you selected) to WeatherAPI.com in order to receive the forecast, together with your IP address as part of the request. Coordinates are truncated to four decimal places. No other data from the App is sent. See WeatherAPI.com's privacy policy.
6.3 RevenueCat and Google Play Billing (purchases and subscriptions)
If you buy a subscription or paid feature, the purchase is handled by Google Play, and subscription status is managed through RevenueCat.
- The App creates no user account. RevenueCat generates a random, anonymous identifier stored on your device to keep track of your purchases; we do not link it to your name or email.
- RevenueCat receives purchase and device information such as the anonymous identifier, purchase receipts, country, device type, and IP address. See RevenueCat's privacy policy.
- We never receive your payment details. Card and billing data are handled entirely by Google Play under Google's Privacy Policy.
6.4 Google Firebase Analytics
The App uses Google Firebase Analytics to understand how the App is used in aggregate — for example which screens are opened and how often features are used — so that we can fix problems and decide what to improve.
What Firebase Analytics collects, automatically and without us configuring it:
- an app instance ID — a random identifier generated on your device that identifies your installation of the App (it is not your name, email, or Google account, and it is reset if you reinstall the App or clear its data);
- device and app information — device model, operating-system version, App version, language, and screen resolution;
- approximate location derived from your IP address, typically at country/region level. The App does not send your GPS coordinates to Firebase Analytics;
- usage events — app opens, screen views, session length, and similar interaction events.
We see this data only as aggregated statistics. We do not use it to identify you, and we do not combine it with the foraging data on your device — that data stays local (Section 3) and is never sent to Firebase.
Firebase is a Google service; the data is processed under Google's Privacy Policy and the Firebase data-processing terms. Retention is configurable, and in our property it is set to 2 months for event-level data and 14 months for user-level data. After those periods the individual records are deleted. Aggregated reports — totals and trends that identify no one — are not covered by these settings and may be kept by Google indefinitely.
Analytics is off unless you turn it on. No analytics data is collected when you first install the App. After the introduction screens, the App asks you once whether you want to enable it, explaining what it is for. Nothing is collected unless you choose "Turn on" — if you choose "Not now", or simply never answer, collection stays disabled. Your choice is stored on your device and applied every time the App starts.
You can change your mind at any time. The App has a Settings → Privacy → "Usage data and crash reports" switch that turns collection on and off. Switching it off takes effect immediately and applies to both analytics and crash reporting.
You can also limit ad personalisation in your device settings (Settings → Google → Ads).
6.5 Google Firebase Crashlytics
The App uses Firebase Crashlytics to report crashes, so that we can find and fix the faults that cause them.
When the App crashes, Crashlytics collects a report containing:
- the stack trace of the error and the App version it happened in;
- device state — device model, operating-system version, orientation, available memory and storage, and whether the device is rooted;
- a Crashlytics installation identifier — a random identifier for your installation, separate from the analytics one and reset on reinstall.
Crash reports do not contain your saved locations, paths, harvest records, or photos, and we do not add your identity to them.
This is covered by the same consent as analytics (Section 6.4): crash reporting is off until you choose "Turn on", and choosing "Not now" leaves it off. The prompt names both.
Crashlytics is a Google service, processed under Google's Privacy Policy and the Firebase data-processing terms. Google retains crash reports for a limited period (currently 90 days for individual reports).
6.6 What we do not use
The App contains no advertising SDK and no social-media tracking, and we do not sell personal data or share it for cross-context behavioural advertising. If this changes in a future version, we will update this policy and, where the law requires it, ask for your consent before such processing begins.
7. Legal Bases for Processing (EU/EEA and UK users)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — processing needed to provide the features you asked for: maps, path recording, weather, and the handling of purchases and subscriptions.
- Consent (Art. 6(1)(a)) — the device permissions you grant for location, camera, and notifications, and the analytics and crash reporting you enable in response to the prompt described in Sections 6.4–6.5. Permissions can be withdrawn at any time in your device settings, and analytics and crash reporting under Settings → Privacy in the App. Withdrawal does not affect processing already carried out.
- Legal obligation (Art. 6(1)(c)) — retention of transaction records where tax or consumer law requires it.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
8. Retention
- On-device data is kept until you delete it or uninstall the App. We set no retention period because we do not hold this data.
- Purchase records held by Google Play and RevenueCat are retained under those providers' own policies and applicable tax law.
- Analytics data is retained by Firebase for the periods configured in our property — 2 months for event-level data and 14 months for user-level data — after which those records are deleted. Aggregated reports, which identify no one, may be kept indefinitely.
- Crash reports are retained by Firebase Crashlytics for the period Google applies to them (currently 90 days for individual reports); this is not a setting we control.
- Requests you send us by email are kept only as long as needed to answer them and to comply with any legal obligation.
9. International Transfers
The third-party providers in Section 6 may process data outside the European Economic Area, including in the United States. Those transfers are made under the safeguards those providers put in place — typically the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework. Details are set out in each provider's privacy policy.
10. Security
Data created in the App is stored in the App's private storage area on your device, protected by the operating system's app sandbox and by your device's own lock screen and encryption. Network requests use HTTPS.
Please note that no method of storage or transmission is completely secure. Your device's own security matters: if your device is unlocked, lost, rooted, or compromised, the App's data may be accessible to others. We recommend using a screen lock and keeping your device software up to date.
11. Your Rights
Under the GDPR (and comparable laws elsewhere) you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing.
Because your foraging data never leaves your device, you exercise most of these rights directly in the App: you can view, edit, and delete your locations, paths, harvest records, and photos at any time, and uninstalling the App removes them from your device.
For data held by the third parties in Section 6, please contact those providers directly — they are the ones holding it. We will help where we can if you contact us at naturescoutapp@gmail.com.
You also have the right to lodge a complaint with a supervisory authority. In Slovenia this is the Information Commissioner (Informacijski pooblaščenec, https://www.ip-rs.si). If you live elsewhere in the EU/EEA, you may complain to your local authority.
12. Children
The App is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided personal data to us, please contact us and we will delete it. Younger users should use the App only with the involvement of a parent or legal guardian.
13. Changes to This Policy
We may update this Privacy Policy as the App changes. The current version will be available in the App and at https://mywildpatch.com/privacy.html, with the "Last updated" date above. Material changes will be announced in the App where reasonably possible. If a change requires your consent under applicable law, we will ask for it before the new processing begins.
14. Contact
Questions, requests, or complaints about this Privacy Policy: naturescoutapp@gmail.com.
Aljoša K.