Birdpass

Privacy Policy

In effect from 23.9.2026.

1. Data controller

The data controller is Matkala Studios (Business ID 3628345-2), Finland. The service appears under the name Lintupassi, Fågelpass or Birdpass; this policy applies to all of them. Privacy questions: legal@birdpass.app

2. What data we process and why

  • Google account data: name, email address and Google's identifier. We use these to create your account and sign you in. Basis: contract (providing the Service).
  • Apple account data (Sign in with Apple): name (if you give it), email address or Apple's private relay email, and Apple's identifier. We also store the sign-in token (refresh token) Apple gives us, so we can revoke it when you delete your account; Apple requires this. Basis: contract and Apple's terms.
  • Profile: nickname, region (country) and language. We use these for settings and for tailoring species lists. Your nickname is visible to others only if you turn on your public page (it is part of the page's address). Basis: contract.
  • Sightings: species, date, note and, optionally, a location point together with a place name derived from it (e.g. bird hide, district and municipality). The place name is looked up on our own server from OpenStreetMap data; the location is not sent to any third party. We store these for your own bird passport, statistics and achievements. Basis: contract.
  • Public page (optional): if you turn on "Show on website" from the Account page, your sightings (species, date, note) become publicly visible via a link to anyone, without signing in; you can additionally allow sighting locations (place name and location point) to be shown. While your public page is on, your latest sightings may also appear anonymously in the website's "Latest sightings" section on the front page: species and date and, if you allow locations to be shown, municipality and country, without your nickname. Both settings are off by default and you can turn them off at any time from the Account page. Basis: consent.
  • Device location: the app reads the device's location only when you ask for it (for example, adding a sighting at your current location or finding yourself on the map). Location is not stored on the server unless you save a sighting with a location point. Basis: consent, which you can withdraw from your device settings.
  • Sound identification: when you start sound identification, the app records a short clip with the device's microphone and sends it to our own server for identification. The clip may contain other sounds too, such as speech. It is processed in memory only, never stored and never sent to a third party. For the free version's monthly quota we store only the time of each identification. The microphone is used only when you start an identification yourself, and you can withdraw its permission from your device settings. Basis: contract.
  • Sessions: to keep you signed in, we store a hash of your session token, its creation and last-used time, and the device identifier your app sends (User-Agent). Basis: contract and legitimate interest (security).
  • Subscription: the status and expiry of your Birdpass Plus subscription, the store and product identifier. We never receive your card details. Basis: contract.
  • Server logs: the server logs errors (time, error code and request identifier). We do not permanently store requests' IP addresses. Basis: legitimate interest (security and troubleshooting).
  • Crash reports (Android): when the app crashes, Firebase Crashlytics (Google) receives technical details of the error: the error message and stack trace, device model, Android version, app version and an install-specific identifier. We never attach your name, email address or sightings to these reports. Reporting is off by default; you can turn it on from the app's Account page. Basis: consent.
  • Website: the website (birdpass.app) uses no cookies, analytics or advertising, and visits to it are not logged. Fonts and pages come from our own server, species photos from Cloudflare (see Species photos). Your language choice on the website is stored only in your browser.
  • Map: map tiles are fetched from our own server, not a third party. Map requests are not logged.
  • Species photos: photos are stored in, and fetched directly from, Cloudflare R2; your device's IP address is passed to Cloudflare. Some species do not yet have a photo at all.

Providing your data is voluntary, but an account (name or email and sign-in identifier) is required to use the Service; location and notes are always optional. We do not carry out automated decision-making or profiling. We do not use analytics or advertising. We do not sell your data.

3. Who we share data with

  • Google: sign-in and crash reports (Firebase Crashlytics).
  • Apple and Google Play: subscription purchase and billing.
  • RevenueCat: managing and verifying subscription status. RevenueCat receives your user identifier and subscription data.
  • Cloudflare: species photo storage (see Species photos) and database backup storage. Backups are kept in the EU.
  • Server hosting: the database and server are located on a server in the EU.
  • Authorities: only where the law requires it.

4. Transfers outside the EU

Google, Apple and RevenueCat may process data outside the EU, for example in the United States. The same applies to Cloudflare for species photos; database backups, however, are kept in the EU. Where transfers concern Google, Apple, RevenueCat and Cloudflare, they rely on the European Commission's adequacy decisions or the EU's standard contractual clauses.

5. Retention periods

  • Account and sighting data: until you delete your account.
  • Sound identification: clips are never stored; the times of identifications are kept until you delete your account.
  • Account deletion: immediately removes your profile, sign-in data, sessions, sightings and subscription status from our server. Copies are removed from backups as they roll over, within 30 days at the latest.
  • Sessions: expire automatically; expired and revoked sessions are removed from the server within 30 days, and at the latest when the account is deleted.
  • Crash reports: Crashlytics keeps these for 90 days.
  • Server logs: rotate automatically; we do not intentionally keep them longer than needed to investigate errors and security incidents.
  • Store and RevenueCat data: purchase data is kept according to their own policies and accounting law. Deleting your account with us does not delete it.

6. Your rights

You have the right to access your data, correct it, delete it, restrict its processing, object to processing based on legitimate interest, and transfer your data to another service. You can also withdraw consent you have given (for example, location access, from your device settings) at any time, which does not affect the lawfulness of processing carried out before the withdrawal. You can delete your account and data yourself from the app's Account page, and export your data from the same page. For other requests, contact legal@birdpass.app; we respond within a month. You also have the right to lodge a complaint with a supervisory authority: the Office of the Data Protection Ombudsman, tietosuoja.fi.

7. Age limit

The Service is intended for those aged 13 and over. We do not knowingly collect data from children under 13. If we discover such data, we delete it.

8. Security

We protect data using technical and organisational measures. Session identifiers are never stored in plain text, and access to the server is restricted.

9. Changes

We update this policy as needed. We will notify you in the app of material changes. This policy is drafted in Finnish. If a translation and the Finnish version differ, the Finnish version governs.

10. Contact

legal@birdpass.app