Privacy Policy
Effective 16 August 2026 · Applies to the Critterdex iOS app and critterdex.madpine.com
The short version
- Play as a guest or connect Apple. Critterdex uses a random account ID behind the scenes. Sign in with Apple is optional, and we do not ask for your name, email, or a password.
- Photos and precise locations stay on your phone. A connected account syncs only the animal, catch date, and random capture ID needed to rebuild your book on another device.
- Photos are sent only for identification: after you agree, compressed capture views go to our AI providers, the answer comes back, and Critterdex stores no server-side copy.
- Location is optional and stays local. It only tags your own cards.
- No ads or cross-app tracking. Optional anonymous usage statistics can be turned off in Settings.
What the app collects, and why
Photos you capture
Critterdex works by pointing your camera at an animal. Photos are stored on your device as part of your collection. When you choose to identify one, two compressed views of the capture are transmitted securely through the Critterdex API to OpenRouter and the selected AI model provider. The request carries the random account and installation identifiers needed for authentication, retry protection, and abuse limits, but never your name, email, or location. Critterdex does not store the image on its servers.
Account and collection backup
Critterdex creates a random account identifier so the identification service can authenticate requests and limit abuse. You may optionally connect Sign in with Apple to protect your collection. We do not ask Apple for your name or email and Critterdex has no password. For a connected account, Supabase stores only catalog-catch metadata needed to restore those pages on another device: capture ID, species ID, catch date, and whether it came from this device or an import. Personal pet and discovery cards, photos, filenames, precise location, confidence, saved shots, XP, quests, and energy are not synced.
Location (optional)
If you grant the “while using the app” location permission, Critterdex tags each capture with where you caught it, so your own cards can show the place. This data is stored only on your device and is never transmitted to us or anyone else. The app works fully without it — decline the permission and nothing breaks.
Identification corrections
If you mark an identification as wrong or request a re-check, Critterdex sends the request ID and that action to our server. This lets us compare model accuracy. The photo is not uploaded again as feedback, and the event contains no species name, location, email, or account profile.
Anonymous usage statistics (optional)
When anonymous usage statistics are enabled (the default), Critterdex sends a small set of action and result categories to PostHog, together with a separate random analytics identifier and basic app and iOS versions. It does not send photos, animal names, account IDs, email, location, device model or name, language, or network details. There are no person profiles, screen recordings, screen-name tracking, or tap tracking. You can turn this off at any time in Settings → Privacy.
The waitlist (this website)
If you enter your email address in the waitlist form on this site, we store that address so we can tell you once, when the app launches. Alongside it we keep the date you signed up and the two-letter country code Cloudflare provides with the request — that's it. We do not store your IP address, browser, or where you came from. The address is never used for anything other than that launch email, is never shared or sold, and there is no newsletter. Email critterdex@madpine.com and we'll delete it immediately, no questions. Signups are held in Cloudflare KV storage (see “Third parties”). The site itself sets no cookies and runs no analytics.
What we don't collect
- No Critterdex password or contacts, and Critterdex does not request your name or email from Apple. Apple may include account fields from an earlier authorization in its authentication response, which Supabase may retain as part of the account record.
- No advertising identifiers, cross-app tracking, analytics person profiles, or session recordings.
- No contacts, no photo-library scanning — Critterdex only sees the photos you capture inside the app.
Third parties
Critterdex uses service providers for these specific jobs:
- OpenRouter and the selected AI model provider receive the capture views and return the species identification for this single purpose. Requests require an eligible zero-data-retention route. Transmission is encrypted, and the providers may not use the captures for advertising or user profiles. OpenRouter's handling is governed by its privacy policy.
- Supabase (supabase.com, Supabase, Inc.) provides account authentication and the database for consent records and connected-account collection metadata. It receives the random Critterdex account identifier and, if you connect Apple, the Apple provider identifier. It does not receive collection photos, filenames, precise location, confidence, XP, quests, or energy. Supabase's handling is governed by its privacy policy.
- Hetzner (hetzner.com, Hetzner Online GmbH) hosts the Critterdex API that authenticates identification requests, applies abuse limits, forwards capture images, and records the privacy-minimal operational data described above. It does not store capture images. Hetzner's handling is governed by its privacy policy.
- PostHog (posthog.com, PostHog, Inc.) receives the optional anonymous usage statistics described above so we can see what works and where people get stuck. IP-based geographic enrichment, person profiles, screen recording, screen tracking, and tap tracking are disabled. PostHog never receives your Critterdex account ID, photos, animal names, or location. Its handling is governed by its privacy policy.
- RevenueCat (revenuecat.com, RevenueCat, Inc.) helps operate Critterdex+ subscriptions. It receives the App Store receipt or purchase history and the random Critterdex account identifier so subscription status can follow the same account across devices. It never receives your name, email, photos, cards, or location. RevenueCat’s handling is governed by its privacy policy.
- Cloudflare (cloudflare.com, Cloudflare, Inc.) hosts this website, stores waitlist email addresses, and protects and routes traffic to the Critterdex API. Capture images pass through without being stored. Cloudflare's handling is governed by its privacy policy.
We do not share data with advertising networks or data brokers. PostHog receives only the optional anonymous statistics described above. We do not sell data.
Retention and deletion
You control local collection data in the app and connected-account data through account deletion:
- Delete one card: its photos are removed from this device and its synced metadata is marked for deletion from the connected account.
- Reset your collection: removes every local capture and photo and queues deletion of synced capture metadata for a connected account.
- Delete the app: removes local photos and app data. Metadata already synced to a connected account remains available until that account is deleted.
- Leave the waitlist: email critterdex@madpine.com and your address is deleted. Every address is deleted once the launch email has gone out — the list has no purpose after that.
Photos sent for identification are processed transiently to produce the answer; Critterdex keeps no server-side copy. The API keeps privacy-minimal request, provider, quota, consent, and feedback records, including the returned catalogue species ID, for reliability, abuse prevention, cost control, and model-quality measurement, without raw photos, prompts, model responses, names, email, or precise location. Account-owned records are removed or detached when the account is deleted; raw operational events are kept for at most 90 days, while fully anonymous daily totals may be kept longer. OpenRouter requests zero data retention from eligible model providers.
Your choices and consent
- Camera and location permissions can be revoked at any time in iOS Settings → Critterdex. The camera is required to capture animals; location is entirely optional.
- Identification consent: before the first AI identification, the app explains where the photo goes and records the disclosure version and acceptance time. Choosing Not now sends no photo.
- Data deletion: you can remove captures or reset the local collection in Settings. A connected account can also be deleted in Settings; this does not cancel an App Store subscription.
Children
Critterdex is made for everyone, including families. It has no ads, social features, chat, or cross-app tracking, and collects no personal information beyond what is described above — the same minimal handling for every user, of any age.
The website
critterdex.madpine.com is a static page hosted on Cloudflare Pages. Cloudflare may process standard technical request data (such as IP addresses) to serve and secure the site. The site loads fonts from Google Fonts, which receives a standard web request from your browser. The website sets no cookies and runs no analytics.
Changes
If Critterdex changes how it handles data — for example, if optional social features are added — this policy will be updated first, the “effective” date above will change, and anything new will be explained in plain language inside the app.
Contact
Questions or requests about privacy: critterdex@madpine.com.