Privacy notice

What is collected, why, and how location is handled.

Version 2026-09-25 · Published 25 September 2026

This is a notice, not a contract. You are not asked to agree to it — it tells you what happens to your data.

Who is responsible for your data

The controller is the person who decides what happens to your data and the one you can hold to it. For Magpeye that is Flinn Gilroy-Evans, trading as Magpeye, at support@magpeye.app.

The controller is an individual, not a company. There is no limited company behind Magpeye, so there is no company number to give you. It is not a number that is pending — it is one that does not apply to a person. Article 13(1)(a) asks who the controller is and how to reach them, and a named person with a mailbox somebody reads is the answer to both. We would rather do that than write “Magpeye is the controller”, which names nobody and binds nobody.

Why there is no postal address here. Magpeye is free: no payment, no in-app purchase, no advertising, no revenue of any kind. On that basis its developer is declared a non-trader on the app stores, and a non-trader publishes no name and no postal address on a store listing. The only address there would be to publish is a home one, and publishing a home address to get a game onto a phone is not a trade worth making. If you need to write to us on paper, ask by email and we will give you an address to send it to. If Magpeye ever becomes commercial — if premium goes on sale — the trader declaration changes with it, and a service address will be published here at the same time.

Contact us at support@magpeye.app. A person answers it.

This notice is written to satisfy Articles 13 and 14 of the UK GDPR. It is a notice rather than a contract: you are told what happens, you do not agree to it.

We are not required to appoint a Data Protection Officer, and we have not appointed one. Requests go to the address above and a person answers those too.

What we collect, why, and on what lawful basis

Your email address, so we can create your account, sign you in, send a sign-in link or a password reset, and contact you about the account. Lawful basis: contract.

Your password, so you can sign in. It is stored hashed by our authentication provider and we never see it. Lawful basis: contract.

Your display name and home region — your name in the app, and the region that decides your rarity tiers. Lawful basis: contract.

Your date of birth, so we know whether you are a child and which protections to apply to your account. Lawful basis: legal obligation.

Your handle, so somebody who knows it can add you as a friend. Lawful basis: contract.

Your bio and profile photograph, if you are 18 or over and choose to have them, so people who know you recognise you. Lawful basis: contract.

Your sightings: species, date and time, coordinates, region, and whether you marked the sighting hidden. This is the product — it is your record of what you saw and where. Lawful basis: contract.

Your bird walks: the track, the distance and the duration, so an outing holds together as one list and a complete list can say what was not there as well as what was. Lawful basis: contract.

Photographs of birds you upload, with the date and time the camera recorded taking them, if the file records one. They are private to you — no other account can see them, ever. Lawful basis: contract.

Your friends, blocks, groups, parties, battles, wishlists, clues, trades and notifications, so the social features work, if you switch them on. Lawful basis: contract.

Whether your account can be found by a handle search. Lawful basis: consent. It is off by default and you can turn it off again at any time.

Whether your sightings go into the conservation export, so records can be useful to the people who study birds. Lawful basis: consent. You can turn it off for the whole account or for a single sighting.

Reports you make and reports made about you, so we can look into abuse and keep a record of what we did about it. Lawful basis: legitimate interests — running a service where people can be dealt with when they behave badly — together with our duties under the Online Safety Act 2023.

Which version of which document you accepted, and when, so there is evidence of what you agreed to. Lawful basis: legitimate interests.

Technical logs kept by our hosting and database providers: IP address, request times and error traces, so the service keeps running and attacks can be dealt with. Lawful basis: legitimate interests — security and availability.

Where we rely on legitimate interests, the interest is running a small service safely. We have weighed it against your interests, and in each case the data involved is either something you gave us deliberately or a technical record with a short life. You can object — see your rights, below.

What we do not collect

No advertising identifiers. No third-party analytics. No tracking or advertising cookies. No contact list, no address book, and no social graph imported from anywhere else.

Sound identification and photo identification both run on your phone. The recording and the photograph are not uploaded, are not sent to us, and are not sent to anybody else. Nothing about them leaves the device. What your phone asks permission for, below, says exactly what happens to each of them instead.

Magpeye sets one cookie, the one that keeps you signed in. What else is kept on your device, and why none of it needs a consent banner, is set out in What Magpeye keeps on your device.

What your phone asks permission for

Four permissions, and one sensor most apps never mention. Each is asked for at the moment it is used, never at startup, and refusing any of them leaves the rest of the app working.

Location. Asked for when you log a bird with sharing switched on, when you start a bird walk, and when you set a meeting point for a party. During a walk the app watches your position continuously, because a walk is a track — and the walk bar stays on screen the whole time it is doing that, deliberately, because a GPS watch is the most expensive thing this app does to a battery and it must never run with nothing on screen to say so. There is no background location. Close the app and nothing is being followed. What happens to a position once it is stored is the whole of the next section.

Microphone. Only while you are holding the record button for sound identification. The clip is decoded on the device, resampled, scored against the model on the device, and discarded when you leave the screen. It is never uploaded, never sent to us, and never sent to anybody else. The recording you hear played back beside a result is not yours — it is a reference recording of the species, made by somebody else and shipped with the app.

Camera and photo library. Two different things, and the difference matters.

A photograph used for identification is decoded on the device, cropped to the 224-pixel square the model eats, scored on the device and discarded. It is not uploaded. Nothing about it reaches us.

A photograph you deliberately attach to a sighting, or set as your profile picture, is uploaded and stored — that is the point of it. Before it goes it is redrawn through a canvas at a smaller size, and a canvas holds pixels and nothing else, so the EXIF block goes with it: the camera serial and any location the camera wrote into the file never reach our storage.

One thing is read out of a photograph of a bird before it is redrawn, and kept: the date and time the camera recorded taking it, if the file records one. It is stored with the photograph as part of your own record of that bird. Like the photograph, no other account can see it. The app does not currently show it or use it for anything else; it is included when you use “Download my data”, and it is deleted when you delete the photograph or your account. It is the camera’s own clock, so it is only as right as the camera was. A profile picture keeps nothing but its pixels. A location written into the file is read on your device along with the date, is not used for anything, and is never uploaded.

Motion and orientation sensors. Magpeye reads your device’s orientation to tilt a card as you move the phone. That is the entire use. On iOS the browser asks your permission for it and your answer is remembered on the device; on other phones the tilt just works, and if it is unavailable or refused, dragging the card with a finger does the same job.

We name this one because motion sensors are a known fingerprinting technique and it is fair to be suspicious of an app that reads them. So, plainly: the numbers are read in the browser, used to set a CSS transform on the card in front of you, and never stored, never sent to a server, and never used to recognise a device. We hold no orientation data, because none of it ever arrives.

What Magpeye keeps on your device

The Privacy and Electronic Communications Regulations are about anything stored on or read from your device, not only cookies, so here is everything.

One cookie. The session cookie set by our authentication provider, which is what keeps you signed in. It is strictly necessary — there is no version of a personal collection that works without knowing whose collection it is — and it is the reason there is no cookie banner. It is not an advertising or analytics cookie, and there are none of those anywhere in the app.

A handful of small settings in local storage. Whether you have chosen to attach your location to a logged bird; whether you have already answered the tilt permission prompt; the bird walk currently in progress, so that closing the app mid-walk does not lose the track; whether you have said “not now” to the sound model download, so that it does not nag; and the date on which you last saw the once-a-day panel, so it does not open twice. All of it is your own choice, or your own walk, written down so the app can honour it. None of it identifies you, none of it is read by anybody else, and none of it leaves the phone.

Being honest about that last one: the once-a-day flag is a convenience rather than a strict necessity. It is a date and nothing else, and clearing the app’s storage removes it.

Cache storage. Two things. The app’s own static files — species artwork, the reference bird calls, the build’s code — cached so that the app opens and works with no signal. And, if you asked for it, the sound identification model, which is several hundred megabytes and lives in a cache of its own so that removing it frees every byte in one action. Nothing containing your data is ever cached: pages that show your collection go to the network every time, because a stale bundle is an annoyance and a stale collection is a lie about what you have seen.

The model is only ever downloaded after you press a button that has the size written on it, and the same screen deletes it again. Nothing about you goes out with that request beyond what any file download reveals — it fetches a file, it sends nothing.

Everything in this section is removed by clearing the app’s storage from your browser settings, or by uninstalling the app. Signing out clears the cookie.

Location — how it actually works

This is the part that matters most, so here is the mechanism rather than a summary of it.

Your own coordinates are stored precisely. When you log a bird, the position is stored as you recorded it, and your own map always shows you the exact spot you were standing. That never changes and is never blurred.

Any coordinate that leaves your account is moved first. Before another account can see one of your sightings, the position is replaced with a random point inside a circle drawn around the true one. This happens in the database, on the server, before anything is sent. The browser is never given the true point, so there is nothing in the response to undo. Blurring in the app would be worthless — the real value would already have crossed the network.

The circle is sized by how scarce the bird is where you saw it. A Common bird gets 500 metres. Uncommon, 1 kilometre. Rare, 5 kilometres. Ultra Rare, 10 kilometres. Legendary, 15 kilometres. A bird with no records at all for that region and month gets the widest circle of the lot, 15 kilometres — a bird well outside its usual range is the most sensitive record there is, not the least.

The offset never changes for a given sighting. Same sighting, same offset, for as long as the record exists. This is deliberate: if the position were re-randomised on every request, somebody could ask a hundred times and average the answers back to the true point.

The size of the circle does not change either. It is decided once for each sighting, from how scarce the bird was there, and then kept: when Magpeye’s rarity figures are updated later, the circle around a sighting you have already logged stays the size it was. Two circles of different sizes around one sighting would give its position away.

There is no way to ask for the offset. The value it is derived from lives in a part of the database no account can read, and there is no function anybody can call that returns it. A caller who could get the offset could subtract it.

Some birds are not shared at all. Species on Schedule 1 of the Wildlife and Countryside Act 1981, and species on the Rare Breeding Birds Panel list, are withheld entirely between March and August. Not blurred further — withheld. They do not appear on community maps, they are excluded from party feeds, they trigger no wishlist alerts, and no clue can be sent about them in that window. A 15 kilometre circle still tells somebody which valley to search, and a disturbed nest fails. Those sightings still count towards your own collection, badges, metals and XP.

A few birds are withheld all year round. Magpeye also keeps a short list of its own, separate from the two British lists above, of species rare enough that a position is sensitive in every month and in every country, not only in a British breeding season. A sighting of one of those never appears on a community map, is never in a party feed, triggers no wishlist alert, and no clue about it can be sent or traded, in any month. Those sightings still count towards your own collection, badges, metals and XP.

You can hide any sighting. A hidden sighting is off every community surface completely — no circle, no species, no date. It still counts for you.

The one deliberate exception is a clue. A clue is a message you choose to send, to one confirmed friend, about one bird, at a precision you choose. It is the only place in Magpeye where a position crosses accounts at better than the circle above. There is no exact clue for a protected species, whatever the month, or for a sighting you marked hidden, and an account under 18 cannot send an exact clue at all. The app does not offer the exact option in any of those cases, and the database will not send an exact position for one even if it is asked to: the most such a clue can carry is an approximate circle, blurred by the same mechanism as everything else.

The conservation export carries the observation, never the observer. If you leave the conservation share switched on, your sightings can be included in a dataset for conservation work: species, date, region, and coordinates rounded to about a kilometre. There is no account identifier in it and no way to join it back to you, and your uploaded photographs are never in it. We will not share that dataset with any organisation without naming them here first.

Who else sees your data

Five companies are involved in running Magpeye. Here is what each one gets and why.

Supabase hosts the database, the authentication and the file storage. That means Supabase holds everything you put into Magpeye: your email address and password hash, your sightings and their true coordinates, your walks, your uploaded photographs, and the whole social layer. They act on our instructions under a written contract and do not use any of it for their own purposes.

Vercel hosts the app itself and serves the two identification models as ordinary file downloads. Vercel therefore sees the requests your phone makes: IP address, time, and which page was asked for. It does not see your password, and it holds no copy of the database. Same contract position.

Google, if you choose to sign in with Google. Google confirms who you are and gives us your email address and your name, and Google necessarily learns that you have an account with Magpeye. That part is Google acting for its own purposes under its own privacy policy, not on our instructions. If you install Magpeye from Google Play, the same is true of the installation itself.

Apple, on the same basis, if you sign in with Apple. That is not switched on yet; when it is, this sentence stays true and Apple’s own relay address option means we may only ever see a forwarding address rather than your real one.

Resend delivers the transactional email — a sign-in link, a password reset, a confirmation. They receive your email address and the contents of that message. They receive no sightings, no location, and nothing about what you have collected.

Other people using Magpeye, but only as far as you have allowed. Nothing is shared by default: the social layer is off until you switch it on, your account is not findable until you make it findable, and an uploaded profile photograph is visible only to confirmed friends and people in your groups. There is no directory of accounts anywhere in Magpeye and no endpoint that lists them. Handle search resolves a handle somebody has already typed in full, and it gives the same answer for a handle that does not exist and one that has chosen not to be found.

Nobody else. We do not sell data, we do not share it with advertisers or data brokers, and there is no advertising in the app. If the law requires us to disclose something — a court order, or a report we are obliged to make about the safety of a child — we will.

Where your data is kept, and when it leaves the UK

The database, the sign-in records and the uploaded files are in Stockholm. The Supabase project runs in eu-north-1, which is AWS in Sweden, inside the EEA. The app’s own server code runs in the same city, in Vercel’s arn1 region. Your sightings and your photographs sit in the EEA and are served from the EEA.

A transfer from the UK to the EEA is covered by the UK’s adequacy regulations, so nothing extra is needed for the hosting itself.

The companies, though, are American. Supabase, Vercel and Resend are US-incorporated, and their staff can reach the systems they run for support and engineering. That is a transfer, and it needs a safeguard. Each of the three publishes a data processing agreement with the standard contractual clauses and a UK addendum in it, which is the mechanism we expect to be relying on — but we have not yet read the executed agreements line by line, so each of the three names its mechanism in its published data processing agreement, and we have read them. Supabase relies on the Standard Contractual Clauses together with the UK Addendum approved by the ICO. Vercel relies on the Standard Contractual Clauses together with the UK International Data Transfer Agreement. Resend relies on the Standard Contractual Clauses with the UK Addendum, and is additionally certified under the Data Privacy Framework. If any of them changes mechanism, this paragraph changes with it.

Google and Apple are not processors here. When you sign in with one of them, they handle that sign-in as a controller in their own right, under their own notices and their own transfer arrangements.

How long we keep it

Article 13(2)(a) wants a period, or the criteria that decide one. Here is a line for every category in the list above.

Your email address, password hash and sign-in record. For as long as the account exists, and then they go with it — see Deleting your account, which describes what that means today.

Your display name, home region and handle. For as long as the account exists. The handle, the bio and the profile photograph are cleared the second you ask for deletion, before anything else happens.

Your date of birth. For as long as the account exists, and it is worth saying why it cannot be shorter: it is the value every age protection reads, and an account with no date of birth falls into the most restricted band rather than the least. Deleting it would not free the account, it would freeze it. It goes when the account goes. Today it is one of the values that survives the immediate part of a deletion and is removed in the manual step below, which is longer than it ought to be; if you want it removed sooner than the rest, say so and we will do it by hand.

Your sightings, your collection, your badges, metals, XP and your walks. For as long as you have an account. They are the point of it, and nothing about a record of a bird you saw expires.

Photographs you uploaded. Until you delete them, or until the account is deleted.

Friends, groups, parties, battles and wishlists. Deleted the moment you ask for deletion.

Clues. A clue expires as advice after 30 days — the app marks it stale rather than pretending a bird is still where it was. The row itself stays until the sender deletes it, until either account asks for deletion, or until an account goes.

Trades and event cards. For as long as the account exists, as a record of what moved and when.

Notifications. For as long as the account exists. Nothing prunes them on a timer, for the reason at the end of this section, and you can clear them yourself.

Reports. Kept after they are resolved, because a record of one report is what makes a pattern visible. The criterion is that we keep a report while it is still capable of doing that job or of answering a complaint or a legal claim about how we handled it. If the account a report was about is deleted, the report survives with the account identifier removed. Article 17(3) of the UK GDPR allows this, for legal obligations and for the establishment of legal claims.

Records of which document you accepted, and when. Deleted with the account.

Technical logs. Kept by Supabase and Vercel under their own retention settings rather than ours, because they are the ones producing them. On the plans Magpeye is actually on, those windows are short: Supabase keeps API and database logs for one day, and Vercel keeps runtime logs for one hour. Both are the providers’ own defaults for those plans and both would lengthen if Magpeye moved to a paid plan, which is a change we would make here.

Be aware of one thing. There is no scheduled job anywhere in Magpeye that deletes data — nothing runs on a timer. Everything above goes when you delete it, or when the account is deleted, and where we describe a period it is a period we work to by hand rather than something automated.

Your rights

Under the UK GDPR you can ask us to give you a copy of the personal data we hold about you.

To correct anything that is wrong.

To delete your data.

To restrict what we do with it while a dispute is sorted out.

To give you your data in a portable form, or send it to somebody else.

To stop processing that we do on the basis of legitimate interests, where you object to it.

Where we rely on your consent — for handle search and for the conservation share — you can withdraw it at any time from the settings screens, and withdrawing it does not affect anything that happened before.

Email support@magpeye.app. We will respond within one calendar month. There is no charge.

If you are not happy with how we handle it, you can complain to the Information Commissioner’s Office: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, or at ico.org.uk. You do not have to speak to us first.

The ICO also keeps the register of controllers who pay the data protection fee, and we are on it. Our registration number is ZC232626, and you can look it up on the register at ico.org.uk rather than taking our word for it. That takes nothing away from the right to complain in the paragraph above — you can complain to the ICO about us whether or not we appear on their register.

If you are in the EU

Magpeye is a European app — the rarity engine covers the Western Palearctic and most of the species in it are not British — so this section is not a footnote.

If you are in the EU, the EU GDPR applies to your data, not the UK version of it. The two are close to identical in what they give you, and every right listed above is a right you have. Where this notice cites a UK article number, the EU article of the same number says the same thing.

You can complain to your own supervisory authority. You do not have to bring it to the ICO in Britain, and you do not have to complain to us first. The data protection authority of the country you live or work in, or where you think something went wrong, can take your complaint, in your own language. The ICO remains available to you as well, because we are established in the UK.

We have not yet appointed an Article 27 representative in the EU. Article 27 requires a controller outside the EU that offers services to people in the EU to name a representative there, unless the processing is occasional and low risk — and processing children’s location data is not that. This is therefore an appointment to be made and named here before the app is offered generally in the EU, or a written decision that the exemption applies. Saying nothing about it is not one of the options, which is why this paragraph is here rather than a silence.

Deleting your account, honestly described

Account settings has a delete option. Here is exactly what it does.

Immediately, when you press it: your account is marked for deletion; your handle, bio and profile photograph are cleared; being findable and the whole social layer are switched off; every friendship, group membership and party membership is deleted; your wishlist is deleted; every clue you have sent or received is deleted; and any open trade is cancelled. Within a second of pressing it, you have stopped existing as far as every other account is concerned.

Not immediately: your sign-in record and your sightings. Deleting those needs a key the app itself does not hold, deliberately — an app that can delete its own authentication records is an app that can be made to delete somebody else’s. A person completes that step by hand.

We will do it as quickly as we can and within one calendar month, which is the limit the UK GDPR sets. If you want to know when it is done, say so in the same message and we will tell you.

We would rather describe it this way than give you a button that looks final and is not.

Children

The product this comes from is a family on holiday — dad finds the gulls, the daughter finds owls, mum finds pigeons. Children are not an edge case in Magpeye, they are the point of half of it. We have designed against the ICO’s Age Appropriate Design Code, the Children’s code, on that basis.

Under 13: no account of their own, and no social layer at all on any account whose date of birth says under 13. The whole game still works.

Thirteen to seventeen: not findable by handle search, so an adult cannot go looking for them by typing names. No uploaded photograph as a profile picture — the app’s own bird icons instead. No bio. No exact clues, which means no account under 18 can send a message saying precisely where they were standing and when. They can still be added by somebody they give their handle to, deliberately, because that is how a family adds each other.

Everybody: the privacy-affecting settings all start at the private end. The social layer is off, being findable is off, and a position is blurred before you choose anything at all. Location sharing is never silent — the app tells you what circle a sighting will be shared at, in metres, and draws the circle on the map rather than a pin that implies an accuracy nobody has.

There is no advertising, no profiling and no recommendation engine anywhere in Magpeye, so there is nothing that could nudge a child towards weaker settings, and no behavioural data to build a profile out of.

Our age check is a date of birth you type in once. It is not a hard identity check, and we say so rather than implying otherwise. If you are a parent and you think a child has entered a false date of birth, email us and we will fix the account.

Automated decisions

There are none. Nothing in Magpeye makes a decision about you automatically, and nothing profiles you. The bird identification models run on your phone and make a guess about a bird, not about you.

Changes to this notice

If we change it, the version date at the top changes, and material changes will be flagged in the app. Because this is a notice rather than a contract, you are not asked to accept it — you are told.

Privacy notice · Magpeye