← Forage

Privacy Policy

Last updated: 19 September 2026

This privacy policy applies to the Forage app (“Application”) for mobile devices and to the website foragewildfood.app, created by Kevin Baur (the “Service Provider”) as a commercial service. The service is provided “AS IS”. The controller for the personal data described here is Kevin Baur, BSc, Hochstraß 542, 3033 Klausen-Leopoldsdorf, Austria, reachable at [email protected]; further details are in the imprint.

Your account

Using the Application requires an account. To create one you provide an email address, a password and a display name. The password is stored only as a salted hash by our authentication provider (Supabase); we never see it in plain text. If you do not choose a display name, the part of your email address before the “@” is used as a starting name. You can change it in your profile at any time, and because the display name is public (see below), we recommend doing so.

Before you sign up, for example on the subscription screen, the Application may create a temporary anonymous account without email or password so that a purchase can be assigned. Anonymous accounts without a purchase are deleted automatically after 7 days.

What is public

Forage has a community. The following is visible to other users and, where noted, to anyone:

  • Your public profile: display name, profile picture, level and experience points, whether you have a Pro subscription, the date you joined, your leaderboard ranks, and activity figures such as the number of spots, harvests, posts, answers, followers, quiz and weekly wins, collected species, people you invited, and the amount harvested per species this year. Other users can find you by searching for your display name.
  • Leaderboards, including regional leaderboards for the area of about 300 km in which you are active, and quiz leaderboards.
  • Spots you share: a spot becomes visible to others only once a species has been identified and you chose to share it. A shared spot is shown on the map and on your profile with its exact location and photo.
  • Community posts, answers, comments and likes, with your display name and profile picture. When you share a find, a post is created with the location rounded to about 1 km. Photos from community posts can appear as questions in the daily quiz, linked to the original post.
  • Shared links: if a community post is shared, anyone with the link can open it on foragewildfood.app, including its photos, text, date and the author's display name. These pages are excluded from search engines.

What the Application stores about you

Your data is kept in our own backend (hosted on Supabase in the EU, Ireland) and tied to your account, so it survives a reinstall or a change of device. It includes your watchlist, saved spots and finds with their coordinates, harvest log entries, notes, uploaded photos, your species collection (“Foragedex”), quiz and challenge progress, the people you follow, saved posts, the users you blocked, reports you submit, and referral invitations.

When you log a harvest and location permission is already granted, the last known position of your device is stored with the entry. It is only visible to you and is used for counts such as your own finds near a species. If you cancel a subscription and answer the short cancellation survey, your answer, an optional comment and your platform are stored. Technical information such as server and access logs, device platform and app version is processed to operate and secure the service.

Posts, answers and display names can be reported by other users and are reviewed to keep the community safe.

Photos and species identification

When you identify a plant or mushroom, the photo is sent to Kindwise (plant.id and mushroom.id, operated by Kindwise s.r.o., Czech Republic), which returns the candidate species. Where a location is available, the coordinates are sent along with the photo to improve the result. See Kindwise's privacy policy at kindwise.com.

To place a find on the map, the Application needs to know where the photo was taken: a photo taken in the Application uses the current device location, a photo picked from your gallery uses the location stored in the photo's own EXIF data. Photos without any location information cannot be saved as a find. Before upload, photos are re-encoded, which removes their embedded metadata.

Photos you attach to a find, a profile picture and photos in the community feed are stored in our backend. Community photos and profile pictures are shown publicly. Photos on a private spot are not shown to other users, but the photo files themselves sit behind a long, unguessable link rather than a login, so anyone you hand that link to can open it.

Location

With your permission, the Application uses the precise location of your device. You can grant or revoke this permission at any time in your device settings; without it, the Application falls back to a coarser, region-based calendar. The Application only uses your location while it is open.

  • Our backend receives your exact coordinates to compute what is in season around you, to place your finds and to send in-season notifications. If you enable community notifications, a home location is stored with your profile to decide which nearby posts to notify you about.
  • Weather: before your location leaves our backend for a weather lookup at Open-Meteo, it is rounded to a grid cell of 0.25° (roughly 28 km).
  • Species occurrences: to show which species have been recorded near you, your coordinates are sent to GBIF (Global Biodiversity Information Facility, Denmark) and iNaturalist (United States). These requests are made partly directly from your device and partly by our backend, and they currently use your precise coordinates, not a rounded area.
  • Maps: the map is provided by Apple Maps on iOS and by Google Maps on Android, which load map tiles for the area you are viewing. “Directions” opens Google Maps with the coordinates of the chosen spot.

Your location is not sold and is not used to target advertising.

Notifications

If you allow notifications, your device is issued a push token that is stored with your account and used to send in-season alerts, watchlist reminders and community notifications: new posts near your home location within the distance you set, questions that still need an answer, mentions of your name and new followers. Delivery runs through the Expo push service, which hands the message to Apple (APNs) or Google (FCM). You can revoke notification permission at any time in your device settings.

In-App Purchases and Subscriptions

Optional purchases may include subscriptions and one-time purchases. The Apple App Store or Google Play Store processes all transactions. The Service Provider neither collects nor retains payment information: the respective platforms handle billing under their own policies.

Subscriptions auto-renew unless cancelled at least 24 hours before the end of the current billing period. You can manage or cancel subscriptions in your App Store or Google Play settings. A free trial may be offered; no charges apply during the trial, and a subscription activates automatically afterwards unless cancelled.

RevenueCat, a third-party service, manages in-app purchases and subscriptions. It receives your account identifier, purchase history and subscription status, as well as device identifiers used for attribution: on iOS the identifier for vendors, the IP address and, only if you allowed tracking, the advertising identifier (IDFA); on Android the advertising ID, the Android ID and the IP address. It also receives the anonymous identifier of the Meta SDK. Your name, email address and payment details are not passed to RevenueCat. See RevenueCat's Privacy Policy at revenuecat.com/privacy.

App analytics

The Application uses PostHog (PostHog Inc., data hosted in the EU) to understand how the Application is used and where it needs improving. PostHog receives events such as app opens, screens viewed, onboarding steps, identifications, spots, harvests, quiz activity and the steps of a purchase, together with your account identifier (or an anonymous identifier before sign-up), device type, operating system, app version, language and the IP address of the request. Your profile's level, experience points, number of scans, sign-up date and subscription status are attached as properties. Your coordinates are not included in these events.

PostHog can also make session recordings: screenshots of the Application's screen at short intervals and technical log messages, so that problems can be reproduced. All text input fields and all images are masked in these recordings.

Our backend additionally reports subscription events (such as trial start, renewal or cancellation, with product, price, currency, country and cancellation reason) to PostHog under the same identifier. Analytics runs on the basis of our legitimate interest in improving the Application (Art. 6(1)(f) GDPR). You can object to it at any time by writing to [email protected].

Advertising and attribution

The Application includes the Meta (Facebook) SDK so that app-install campaigns can be measured. It reports events such as installs, app launches, completed sign-ups, trial starts and purchases to Meta, together with a randomly generated anonymous device identifier and technical data such as IP address, device model and operating system; on Android this includes the advertising ID. Purchase and trial events are additionally forwarded to Meta by RevenueCat using that same anonymous identifier.

On iOS you are asked for permission through Apple's App Tracking Transparency dialog. If you decline, no advertising identifier (IDFA) is used and attribution runs only in Apple's aggregated form. You can change this at any time under Settings → Privacy & Security → Tracking; on Android you can reset or delete the advertising ID under Settings → Privacy → Ads. Your foraging content, your photos, your notes and your precise location are never sent to Meta, though the IP address of a request lets any recipient infer a rough area. Meta's data policy is at facebook.com/privacy/policy.

The website foragewildfood.app

The website is hosted by Cloudflare, which processes the IP address and technical request data to deliver the pages. Fonts are loaded from Bunny Fonts (BunnyWay d.o.o., Slovenia) and some images from Google Cloud Storage; in both cases your browser sends its IP address to that provider.

For visitor statistics the website uses DataFast, a cookieless analytics tool. It does not set cookies and does not track you across websites. In addition, visits by automated AI crawlers are reported to DataFast with the crawler's user agent and IP address; this concerns bots, not human visitors.

Season Finder: if you search for a place, the search term is sent directly from your browser to the Open-Meteo geocoding service. If you use “my location”, your browser asks for permission and the coordinates, rounded to about 100 m, are sent to our server. Where no data exists yet for that area, our server passes the coordinates and your IP address to our backend (Supabase) to build the list. The IP address is used only to limit the number of new areas per day and is stored for that purpose as a hashed value, not in plain text.

Shared community posts can be opened on the website as described under “What is public”.

Service providers

We use the following services, each only for the purpose named:

  • Supabase (EU, Ireland): database, file storage, authentication and backend functions.
  • Kindwise (Czech Republic): species identification from the photo you submit, plus coordinates where available.
  • GBIF (Denmark) and iNaturalist (United States): species occurrences near your location.
  • Open-Meteo: weather, elevation and climate normals for the rounded grid cell (about 28 km) around you, and place search in the website's Season Finder.
  • Apple Maps (iOS) and Google Maps (Android): map display and directions.
  • Expo (push service), Apple (APNs) and Google (FCM): delivery of notifications to your device.
  • RevenueCat: subscription validation, purchase status and attribution.
  • PostHog: app analytics and session recordings, as described above.
  • Meta: measurement of advertising campaigns, as described above.
  • Apple and Google: app distribution and billing.
  • Resend: sending the message when you contact us through the in-app feedback form (your message and the email address on your account).
  • Cloudflare, Bunny Fonts, Google Cloud Storage and DataFast: operation and statistics of the website.

The species content in the Application (profiles, lookalikes, seasons, images) is compiled by our backend from public sources such as GBIF, iNaturalist, Wikipedia and OpenStreetMap, with the help of Anthropic's Claude API. Only species information is sent there: no accounts, photos, notes or user locations.

No other third parties have access to data generated through the Application. Your data is not sold.

Where your data is stored

The database, the stored files and the backend functions run in the European Union (Ireland). Some of the services listed above are based outside the EU, in particular in the United States (Apple, Google, Meta, RevenueCat, PostHog, Expo, Cloudflare, iNaturalist, Anthropic, Resend). Where data reaches them, the transfer is covered by those providers' standard contractual clauses or by their certification under the EU-U.S. Data Privacy Framework.

Legal bases and how long data is kept

Your account, your foraging data and the community features are processed to provide the service you signed up for (Art. 6(1)(b) GDPR). Location access, notifications and, on iOS, app tracking rest on the permission you grant and can be withdrawn at any time (Art. 6(1)(a) GDPR). Operating and securing the service, preventing abuse, moderating the community, app analytics and measuring campaigns rest on a legitimate interest (Art. 6(1)(f) GDPR).

Account and foraging data is kept until you delete your account, see Delete your account. Anonymous accounts without a purchase are deleted after 7 days. Technical logs are kept for a short period only. Deleting your account does not automatically delete data already held by PostHog, RevenueCat or Meta; write to [email protected] and we will have it removed there as well. Purchase and billing records are held by Apple or Google under their own retention policies.

Your rights

You have the right to access the data held about you, to have it corrected or erased, to have processing restricted, to receive your data in a portable form, and to object to processing based on legitimate interest. Where processing rests on your permission, you can withdraw it at any time; this does not affect processing that already took place. To exercise any of these rights, contact [email protected].

You also have the right to lodge a complaint with a supervisory authority, for example the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at).

What are my opt-out rights?

You can revoke location, notification and tracking permissions at any time in your device settings, object to app analytics by email, cancel an active subscription through the App Store or Google Play, and delete your account and its data as described under Delete your account. Uninstalling the Application stops all collection on the device, but does not by itself delete the data held under your account.

Children

The Application is not directed at children and is not marketed to them. Users must be at least 16 years old to create an account and to consent to the processing of their personal data; in some jurisdictions a parent or guardian may consent on their behalf. We do not knowingly collect personal data from children below that age. If you believe a child has provided personal information, please contact [email protected] and it will be deleted.

Security

The Service Provider is concerned about safeguarding the confidentiality of your information. Traffic between the Application and our backend is encrypted in transit, passwords are stored only as hashes, and database access is restricted per user by row-level security, so other users cannot read your private data. No method of transmission or storage is completely secure, so absolute security cannot be guaranteed.

Changes

This privacy policy may be updated from time to time. The Service Provider will notify you of any changes by updating this page. Continued use of the Application or website is regarded as acceptance of those changes.

Your Consent

Where processing rests on your consent, you give it through the permission dialogs in the Application: location, notifications and, on iOS, app tracking. You can withdraw any of them at any time in your device settings, and the corresponding feature simply stops. Everything else described here is processed on the legal bases set out above, not on consent.

Contact Us

If you have any questions about privacy, please contact [email protected].