Your finds stay yours.
NatureLog is a personal field journal. This policy explains what the app and its service store, why, and what you control. This draft describes the accountless development version. Public service hosting, operator details and retention periods must be confirmed before release.
1. What we collect
What you add
Chat messages, photos, short sound recordings, notes, saved observations and an optional place for each find. You decide what to attach and what to save.
Device journal
Your chosen display name and an anonymous device session identify your journal. The development version has no email registration, password or account sign-in.
Technical data
A session secret stored in the iOS Keychain, its hash on the server, and the sync state of your journal. No advertising identifiers. Production logging and retention are not yet finalised.
NatureLog requires no registration. Your journal is linked to an anonymous key on this device. There is no cross-device sign-in or recovery if that key is lost; reinstalling the app is not a recovery method.
2. Why we use it
- To answer you. With AI sharing enabled and a configured service available, your current message, attachments and recent conversation text are sent for an AI reply. You can save manual observations without AI.
- To keep your journal in sync. Changes are saved locally first and queued for the configured NatureLog server. Syncing requires a connection and an active app. Server storage does not provide account recovery or cross-device sign-in.
- To separate journals. The server uses the device session to authorise access to its journal.
- To run the service. Request limits and inference reservations help manage errors, abuse and repeated requests. Production logging periods are still to be defined.
We do not use your content for advertising, do not build advertising profiles and do not sell personal data.
3. Device permissions
Camera, microphone and location permissions are requested when needed. Notification permission may be requested during the introduction. You can change permissions in iOS Settings.
- Camera and Photo Library — to attach photos to a chat or observation. Imported images are re-rendered on your device before upload; original photo-library EXIF is not copied.
- Microphone — to record sounds (up to 60 seconds) for a chat or observation.
- Location — to suggest a place for a find when permission is already granted, or after you explicitly request it. You can remove the suggestion, type a name or save without a place.
- Notifications — permission is optional; remote push delivery and reminders are not currently implemented.
- Local network — only for development builds that talk to a server on your own network.
4. Storage and security
Your journal lives in two places: locally on your device (an on-device database and attachment cache) and on the NatureLog server. Public builds require HTTPS; local development builds may use a local HTTP server. Each device journal is isolated on the server. Session tokens are kept in the iOS Keychain; clearing the attachment cache in the app removes downloaded files but keeps your history.
5. Sharing with third parties
We share data only with providers that are needed to operate the service:
- Hosting and infrastructure providers that store and transmit data on our behalf.
- Recognition services. The development backend integrates OpenRouter and a configured model provider. AI requests require your AI-sharing choice and a configured backend. Current text, selected photos/audio and bounded recent chat text may be sent; saved place and collection metadata are not included, although any location you type into a chat is part of that message. Live identification has not yet been validated. The website demo sends nothing to an AI provider.
- Apple provides iOS device services and any future App Store distribution under its own terms. NatureLog is not yet publicly available in the App Store.
We may disclose data when required by law or to protect the rights and safety of users and the service.
6. Retention and deletion
- The development journal keeps chats and saved finds until they are removed through supported controls or you delete the device journal.
- Deleting a saved observation queues its removal on the server. Individual chat deletion is not currently offered.
- Delete journal data in Profile removes the device journal on the server and revokes its session. The current device clears its local journal after confirmation. A lost network response can be retried.
- Backup retention, production log periods and the final service operator are not yet defined. The development deletion endpoint does not erase external backups.
7. Children
NatureLog is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect personal data from children. If you believe a child has created a profile, contact us and we will delete it.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. The app currently offers observation deletion, journal deletion and an AI-sharing control. Self-service export is not implemented. The support channel is being prepared; see the contact page.
9. Changes to this policy
We will update this page when the app changes — for example, when a live recognition service is connected. The date at the top shows the current version. Review this page again before using a public release.
10. Contact
Questions about privacy
NatureLog is an independent product in development. The support channel is being prepared. See the contact page for its current status.