Privacy Policy

Privacy Policy

Privacy Policy

Effective date: September 2, 2026 · Last updated: September 2, 2026

Bioregion Studios, Inc. (“Bioregion,” “we,” “us,” or “our”) provides the Bioregion mobile application and related services (together, the “App”). This Privacy Policy (the “Policy”) describes the personal information we collect in connection with the App, how we use and disclose it, how long we retain it, and the rights and choices available to you. “Personal information” means information that identifies, relates to, or could reasonably be linked with you or your device.

The App is offered only in the United States, and this Policy applies to users in the United States. This Policy takes effect the first time you open the App and constitutes our notice at or before the point of collection. It is separate from our Terms of Service, which govern your use of the App; where this Policy refers to the Terms of Service, it does not restate them.

Privacy at a glance.

  • Plant identification runs entirely on your device — your photos are not uploaded to our servers.

  • We use no third-party advertising or analytics networks, we do not sell your personal information or share it for cross-context behavioral advertising, and we do not track you across other apps or services (the App presents no App Tracking Transparency prompt because it performs no tracking).

  • Precise location is optional and opt-in. While the App is open, your location is used on your device to center the map and show nearby parks; a single location fix is transmitted to us only when you save a plant observation. The App performs no background location tracking.

  • The App is for adults. You must be 18 or older to create an account, and we do not knowingly collect personal information from anyone under 18 (Section 10).

This summary is provided for convenience only; the numbered sections of this Policy control.

Contents

  1. Who this Policy is for

  2. Information we collect

  3. How we use information

  4. How we disclose information

  5. Where your information is stored

  6. Data retention

  7. Security

  8. Your privacy rights

  9. State privacy disclosures

  10. Children and minors

  11. Changes to this Policy

  12. Contact us

1. Who this Policy is for

The App is intended for adults. You must be 18 years of age or older to create an account or otherwise use the App. We do not knowingly collect personal information from anyone under 18. See Section 10 (Children and minors).

2. Information we collect

This section describes the categories of personal information that the App transmits off your device. Except for the pre-account data described in Section 2.1, each category is linked to your account. We do not use any of this information to track you across other companies’ apps, websites, or services.

Account email — the email address you provide at registration. If you use Sign in with Apple, we receive the email address or the Apple private-relay address you choose to share. We do not request your name (Section 2.2); the name shown to other users is always the username you choose.

Why: to create, authenticate, and secure your account and to send service and account communications.

Username — the name you choose for use within the App. Your username is visible to other users on leaderboards and, unless you opt out, in friend search (Section 3.1).

Why: to identify you within the App’s social features.

Age Confirmation — Your confirmation at registration that you are 18 or older, and the time you gave it. We do not collect your date of birth.

Why: To enforce the App's minimum age (18) and keep a record that you confirmed it

Precise location — while the App is open, it reads your device’s location — only if you have granted the operating-system location permission — and uses it on your device to center the map and show parks near you. A single GPS fix is transmitted to us only when you save a plant observation. Collection is foreground-only, opt-in, and optional: the App performs no background location tracking, and an identification works without a location.

Why: to attribute your observation to the correct park or ecoregion (which powers leaderboards, quests, and challenge results), to maintain aggregate counts of species sightings by area, and to protect service integrity (Section 3).

Your collection and gameplay records — the plants you identify and when; the cards in your collection; your quest progress, archetypes, seals, level, experience, and streaks; and the friend challenges you send, receive, or complete.

Why: to operate the App’s core features — your field guide, quests, leaderboards, and challenges — and to restore your collection when you sign in on another device.

Usage data — in-app events such as screens viewed, time spent, and actions taken (for example, an identification started, a card collected, quest progress, purchase options viewed, or map interactions). Each event also carries basic device and app information — your device model, operating-system version, app version and build, platform, and language setting — so we can understand how the App performs across devices. These events contain no name, email address, or location coordinates.

Why: to perform first-party analytics that help us understand and improve the App.

Pseudonymized identifier — a one-way hash of your account identifier, attached to usage events. Your raw account identifier is never placed in the usage-data stream.

Why: to associate usage events with an account for aggregate analysis. We do not use this data to build profiles of, or make decisions about, individual users.

Installation identifier — a randomly generated identifier created on your device when you first open the App, and attached to usage events. It is not derived from your account, and it is not a hardware, advertising, or cross-app identifier. It persists while the App remains installed and resets if you reinstall the App. Once you create an account, this identifier appears alongside the pseudonymized identifier described above, and is therefore linked to your account.

Why: to connect a single installation’s usage events into a coherent sequence — including the events recorded before an account exists (Section 2.1) — so we can understand and improve the App.

Push notification token — if you enable notifications, a push token issued for your device.

Why: to deliver the notifications you have enabled (Section 3); you can turn notifications off at any time in your device settings.

Device and connection data — when your device connects to our infrastructure providers (Cloudflare and Supabase), those providers automatically receive standard connection data — including your IP address, request headers, and timestamps — as an inherent part of routing internet traffic. Your IP address is not part of your profile or your observation records; it appears in operational and security logs — including authentication logs — maintained by us and our infrastructure providers.

Why: to deliver, maintain, and secure the service — including routing, rate-limiting, and abuse prevention, and investigating suspected fraudulent or falsified activity.

Purchase / entitlement data — your subscription or consumable entitlement status. To associate purchases with your account, we provide RevenueCat (Section 4.1) an account identifier; we never receive your card number or payment-account details — Apple processes all payment.

Why: to deliver, maintain, and restore paid features.

Support correspondence — information you provide when you contact us or submit an in-app report or feedback form, along with basic app and device information (such as app version and device model), and records of the reports you submit and the users you block.

Why: to respond to, document, and resolve your request and to keep the App safe.

Friend connections — the friend links you create. Your friend list is private to you and is not browsable by other users.

Why: to operate the friends and challenge features.

Precise location is “sensitive personal information” (or “sensitive data”) under Connecticut, California, and other state privacy laws. We collect it only after you grant the operating-system location permission, and we use it only for the purposes stated in Section 3. You may revoke the permission at any time (Section 8).

IP addresses. Because an IP address can indicate approximate location, we treat it as personal information. We do not use it to build a location history, to infer where you live or travel, or to track you, and it is not part of the location data described above.

2.1 Before you create an account

Before you create an account, we record a limited set of usage events about the onboarding flow (for example, which onboarding step you reach), keyed to the installation identifier described in Section 2 — not to your name, email address, or any account. We use these events only to understand where people leave onboarding and to improve it. If you create an account, these onboarding events are associated with your account. If you do not create an account, we retain these pre-account events only as long as reasonably necessary to understand and improve onboarding, and then delete or de-identify them. (The installation identifier itself is not a time-limited value: it remains on your device until you reinstall the App, and it continues to accompany usage events after you create an account.)

2.2 What we do not collect

  • Photos and camera images. Plant identification runs on your device. Photos remain on your device (including any locally cached copies), and the App does not currently upload them to our servers. If you choose to save a photo, it is written to your own device library.

  • Your name. The App does not ask you for your name, and we do not request it from Apple. When you use Sign in with Apple, the App requests only your email address — not the name Apple is able to share — so no name is transmitted to us at any point. The only name associated with your account is the username you choose, and our Terms of Service recommend that you not use your real name.

  • Message content between users. The App contains no user-to-user messaging feature, so no such content exists to collect. (This is distinct from support correspondence you send to us, described in Section 2.)

  • Biometric identifiers. None. The on-device model analyzes images of plants, not people.

  • Crash, diagnostics, or performance telemetry. None at this time. The App contains no crash-reporting or performance-monitoring service. This is distinct from the device and app information described in Section 2, which accompanies usage events and ordinary server requests and which we do disclose.

  • Contacts, health information, financial-account information, or browsing / search history. None.

  • Advertising or cross-app tracking identifiers. None. We do not access the device advertising identifier, and the App presents no App Tracking Transparency prompt because it performs no tracking. The installation identifier described in Section 2 is generated by the App for its own use only; it is not shared with any other company and cannot be used to recognize you in another company’s app or website.

3. How we use information

We use the information described in Section 2 to:

  • Operate the App — create and authenticate your account and run identifications, cards, quests, leaderboards, challenges, and friends.

  • Enforce our minimum age — record your confirmation that you are 18 or older.

  • Use precise location, exclusively to: (a) attribute each observation to the correct park or ecoregion, which powers leaderboards, quests, and challenge results; (b) maintain aggregate counts of species sightings by park or ecoregion — these counts are not linked to you (Section 4.4); and (c) protect service integrity, including investigating suspected falsified location or activity using identification records and server logs.

  • Deliver purchases — provide, maintain, and restore subscriptions and consumable features.

  • Send notifications — deliver the service and gameplay push notifications you have enabled; you can turn them off at any time in your device settings.

  • Understand and improve the App — aggregate, first-party analytics.

  • Communicate with you — service and account messages and responses to your requests.

  • Protect the App and comply with law — maintain the security and integrity of the App, prevent and investigate abuse, enforce our Terms of Service, and meet our legal obligations.

We do not use your personal information for advertising, for cross-context behavioral advertising, or to build profiles about you for third parties.

3.1 What other users can see

Other users can see your username and your identification counts for a given area on leaderboards. Leaderboards are computed at the level of a park or ecoregion, and appearing on a leaderboard indicates that you have recently recorded identifications in that area (for example, during the current period). Other users cannot see your precise coordinates, the specific plants you identified, your observation history, or your friend list. Friend Challenges assign each player their own plant to find (there is no shared target); if you challenge a friend, they see the result of the challenge only — not your assigned plant, your progress, your score, or your location.

Friend discoverability. Other users can find your username in friend search by default, and you may turn this off in settings. Turning discoverability off does not remove you from leaderboards, which show username and identification counts only, as described above.

4. How we disclose information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as described in this Section 4.

4.1 Service providers

We use vendors that process personal information on our behalf under their written terms of service and data-processing terms. For personal information, each is bound by data-processing commitments — including, under US state privacy laws, service-provider terms — that limit processing to providing their services to us and prohibit selling personal information or sharing it for cross-context behavioral advertising. Like most infrastructure vendors, their standard terms also permit them to compile aggregated or de-identified statistics about the use of their services (for example, service-performance metrics and industry benchmarks); information in that form does not identify you. Our database provider is additionally prohibited from using our data to train, fine-tune, or improve any artificial-intelligence model without our prior written consent, which we have not given. None of these vendors is an advertising network or a data broker.

Supabase — authentication and application database. Processes: account email, username, age confirmation, identification records (including coordinates), friend connections, push tokens; connection data (IP address, request headers, timestamps) in operational and authentication logs.

Cloudflare (R2) — storage of first-party analytics and app assets. Processes: pseudonymized identifier, installation identifier, usage events and their device and app information; connection data (IP address, request headers, timestamps) in operational logs.

RevenueCat — subscription entitlement management. Processes: purchase / entitlement status, associated with the account identifier we provide.

Expo (650 Industries, Inc.) — push-notification delivery. Processes: push token and, in transit, the content of notifications sent to your device.

4.2 Platform services (Apple)

Certain features rely on Apple under Apple’s own terms and privacy policy, not as our service provider: Sign in with Apple (authentication) and in-app purchases (Apple processes all payment; we receive only entitlement status).

If you sign in with Apple and choose Apple’s Hide My Email option, we receive only an Apple-generated private relay address — not your personal email address. We use that relay address exactly as we would use any account email (Section 2), and we do not attempt to resolve it to your underlying address.

4.3 Legal process, enforcement, and safety

We may disclose personal information where we have a good-faith belief that disclosure is reasonably necessary to: (a) comply with applicable law, legal process, or an enforceable governmental request (such as a subpoena or court order); (b) enforce our Terms of Service or investigate potential violations of them; (c) protect the safety, rights, or property of any person; or (d) protect the security and integrity of the App. When we respond to a legal request, we disclose only the information we reasonably believe is necessary to respond.

4.4 Aggregated and de-identified information

We create and use aggregated or de-identified information that cannot reasonably be used to identify you. This includes aggregate counts of species sightings by park or ecoregion — with no link to any user — which we use to show which plants are discoverable in an area and to improve our plant catalog. We maintain and use aggregated and de-identified information only in that form and do not attempt to re-identify it, except as permitted by law to test whether our de-identification processes remain effective.

5. Where your information is stored

Our service providers store and process personal information in the United States. Your authentication session is stored securely on your device (in the iOS Keychain). Personal information in transit is protected using encryption (HTTPS/TLS).

6. Data retention

We retain personal information for as long as reasonably necessary for the purposes stated in this Policy, and then delete it. Where a fixed period is not stated below, we determine the retention period based on the life of your account and any period required by applicable law.

Account email, username, friend connections — for the life of your account; deleted when you delete your account.

Age Confirmation — for the life of your account; deleted when you delete your account.

Your collection and gameplay records — for the life of your account; deleted when you delete your account.

Precise location (identification records) — for the life of your account; deleted when you delete your account.

Usage data — for the life of your account; aggregated or de-identified analytics (which are no longer personal information) may be retained afterward as described in Section 4.4.

Pseudonymized identifier — for the life of your account; on deletion, deleted or de-linked from usage events.

Installation identifier — stored on your device until you reinstall the App. In our analytics records it follows the usage events it is attached to (above); on account deletion it is deleted or de-linked from those events in the same way as the pseudonymized identifier.

Push notification token — until you disable notifications, sign out, or delete your account.

Device and app information (attached to usage events) — retained with the usage events it accompanies (above).

Device and connection data (IP address, request headers, timestamps) — retained in operational and security logs — including authentication logs — maintained by us and our infrastructure providers, for the period reasonably necessary for security and operations, then deleted.

Purchase / entitlement data — for the life of your account, plus any period required to meet tax, accounting, and other legal record-keeping obligations.

Support correspondence — retained as needed to handle and document your request, then deleted on a routine schedule.

Pre-account onboarding events (Section 2.1) — if you do not create an account, retained only as long as reasonably necessary to understand and improve onboarding, then deleted or de-identified.

Safety / moderation records (for example, a user report) — retained as long as reasonably necessary for safety, security, and legal purposes.

Backups. When you delete personal information, we remove it promptly from our active systems; residual copies may persist in routine backups for a limited backup cycle before they are overwritten. Legal holds. Where we are subject to a legal obligation or an active safety matter, we may preserve relevant information for as long as required, notwithstanding the periods above.

7. Security

We maintain administrative, technical, and organizational measures designed to protect personal information, including encryption in transit and access controls that limit personal information to those who need it to operate the App. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify you and any regulators as required by applicable law.

8. Your privacy rights

We honor the following rights for all users, in every US state, regardless of residence:

  • Know / access — request confirmation that we process your personal information and the categories and specific pieces of personal information we hold about you.

  • Delete — request deletion of your personal information. The fastest way is in the App: Settings → Delete Account, which permanently deletes your account and associated data (this action is irreversible). You may also email us.

  • Correct — request correction of inaccurate personal information.

  • Data portability — request a copy of your personal information in a portable and, to the extent technically feasible, readily usable format.

  • Withdraw location consent — grant or revoke the App’s location permission at any time in your device’s settings. Declining or revoking the permission still lets you identify plants (without a location).

  • Limit use of sensitive information — we collect and use precise location only for the purposes stated in Section 3, each of which is necessary to provide App features you request or to maintain the security and integrity of the App; we do not use it to infer characteristics about you.

  • Non-discrimination — we will not discriminate against you for exercising any of these rights.

How to exercise. Use the in-app deletion control, or email privacy@bioregionstudios.com. We verify each request using information associated with your account, to a degree of certainty proportionate to the sensitivity of the information involved, before acting on it. For your security, we deliver copies of personal information only within your authenticated App session or to the email address associated with your account. We respond within the timeframes required by applicable law. You may use an authorized agent to submit a request, subject to verification.

Appeals. If we decline to act on your request, you may appeal by replying to our decision or emailing privacy@bioregionstudios.com with “Appeal” in the subject line. We will respond with our decision and the reasons for it within the time required by applicable law. If we deny your appeal, residents of states that provide this remedy (including Colorado and Connecticut) may contact their state Attorney General to submit a complaint.

9. State privacy disclosures

This Policy constitutes our notice at collection. We apply the protections in this Policy uniformly to residents of all US states.

Connecticut and other sensitive-data states. We process precise geolocation, which is sensitive data. As amended effective July 1, 2026, the Connecticut Data Privacy Act applies to the processing of sensitive data regardless of processing volume. We comply as follows: we collect precise location only with your opt-in consent (the operating-system location permission, presented with an in-app explanation of our purposes); we use it only for the purposes stated in Section 3; you may withdraw consent at any time; and we maintain a data protection assessment for this processing. We extend these same protections to residents of all states with comparable sensitive-data requirements (including Virginia, Colorado, Texas, and others).

Artificial-intelligence training disclosure. We do not collect, use, or sell personal data for the purpose of training large language models, whether directly or by instructing or authorizing any service provider to do so on our behalf. Our database provider is contractually prohibited from using our data to train, fine-tune, or improve any artificial-intelligence model without our prior written consent, which we have not given.

Minors. The App’s minimum age is 18, and we do not knowingly collect personal data from anyone under 18 (Section 10). We do not sell any user’s personal data, do not process any user’s personal data for targeted advertising, and do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects.

Categories of personal information (California framework, applied to all US users)

Identifiers (email, username, pseudonymized identifier, installation identifier, push token, IP address). Collected: yes. Purposes: account creation and security; minimum-age enforcement; service delivery; notifications; aggregate analytics. Not sold or shared.

Internet / electronic network activity (usage events; device and app information; connection data). Collected: yes. Purposes: first-party analytics; App improvement; security. Not sold or shared.

Geolocation data (precise location) — sensitive. Collected: yes, with opt-in consent. Purposes: observation attribution (leaderboards, quests, challenges); aggregate sighting counts; service integrity. Not sold or shared.

Commercial information (purchase / entitlement status). Collected: yes. Purposes: deliver, maintain, and restore purchases. Not sold or shared.

Customer-records information (support correspondence; reports and blocks; your collection and gameplay records — identifications, cards, quest progress, archetypes, seals, level, experience, and streaks; friend connections and friend challenges). Collected: yes. Purposes: respond to requests; safety; operate the App’s core features — field guide, quests, leaderboards, and challenges. Not sold or shared.

Biometric, health, financial-account, or protected-classification information. Not collected.

  • Sources: directly from you, from your use of the App, and — for your email or relay address — from Apple when you use Sign in with Apple.

  • Sensitive personal information: precise geolocation, collected only with your opt-in consent and used only as stated in Section 3; we do not use or disclose it to infer characteristics about you.

  • No sale; no sharing for cross-context behavioral advertising; no targeted advertising; no profiling in furtherance of decisions that produce legal or similarly significant effects.

  • Retention: as stated in Section 6. Rights and appeals: as stated in Section 8.

  • California “Shine the Light”: we do not disclose personal information to third parties for their own direct-marketing purposes.

10. Children and minors

The App is intended for adults. It is not directed to children, and it is not intended for anyone under 18. We do not knowingly collect personal information from anyone under 18, and we do not knowingly permit anyone under 18 to use the App. We enforce this by requiring you to confirm at registration that you are 18 or older, by the minimum-age term in our Terms of Service, and by acting on any credible information that an account holder is under 18. We do not collect your date of birth.

Before September 2, 2026, the App collected a date of birth at registration to verify age. We have deleted the dates of birth we collected from our systems and no longer collect them.

If we learn that we have collected personal information from a person under 18, we will delete it and terminate the account. If you believe a person under 18 has provided us personal information, contact privacy@bioregionstudios.com.

11. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will update the “Last updated” date above and provide notice through the App or by other reasonable means before the changes take effect. If we intend a materially new use of personal information we previously collected — including any new use of precise location, such as a future citizen-science program — we will provide notice and, where required by applicable law, obtain your consent and give you an opportunity to withdraw consent, before beginning that use. If a change adds or removes a category of personal information we collect, we will also update our App Store privacy disclosures to match.

12. Contact us

Questions, requests, or concerns about this Policy or your personal information:

Bioregion Studios, Inc.

privacy@bioregionstudios.com (privacy matters)

info@bioregionstudios.com (general inquiries)

legal@bioregionstudios.com (legal notices)