Privacy Policy
Effective date: [effective date] · Last updated: [effective date]
Applies to the Flying Bug Identifier mobile app, listed on the App Store as “Is It Dangerous? Bug ID” (“Flying Bug Identifier”, the “App”), and the website at flyingbugidentifier.bulpara.com.
DRAFT — review by qualified counsel before publishing. The bracketed blanks ([legal entity], [jurisdiction], [effective date]) must be completed and every disclosure below confirmed by counsel before this policy is published.
Flying Bug Identifier is published by [legal entity] (“Bulpara”, “we”, “us”, “our”). This policy explains what personal information the App collects, why, who processes it on our behalf, how long we keep it, and the choices and rights you have. It is governed by the laws of [jurisdiction] and is written to be consistent with Apple’s App Store requirements, the EU/UK GDPR, and the California Consumer Privacy Act as amended (CCPA/CPRA).
Flying Bug Identifier is an educational insect-identification aid. It is not a medical device, a diagnostic tool, a pest-control service, or an emergency service, and it never gives an all-clear or tells you that a bug poses no danger. Nothing in this Privacy Policy changes the safety terms in our Terms of Use. If you have been stung or bitten and develop trouble breathing, swelling of the face, tongue, or throat, dizziness, or widespread hives, contact your local emergency services (911 in the United States) immediately — do not rely on the App.
1. The short version
- No account, no login, no sign-in. You use the App anonymously. We do not ask for your name, email, or phone number to use it.
- One thing leaves your device when you run a scan: the bug photo you choose. That is the only user content sent to our servers.
- No location, no region, no GPS — ever. Unlike some identifier apps, Flying Bug Identifier does not collect, derive, or transmit any location or region. Bugs have no regional safety-dependency, so the App has no reason to know where you are, and it never asks.
- Your scan history stays on your device (stored locally). We do not keep a copy of your history on our servers.
- Uploaded photos auto-delete from our storage after 30 days, and you can delete them on demand at any time from within the App.
- We do not sell your personal information, and the AI provider does not train its models on your content.
- No ads and no tracking. The App shows no advertisements, uses no advertising identifier, contains no ad or analytics SDK that resells your data, and does not track you across other companies’ apps or websites — so there is no App Tracking Transparency prompt.
2. Information we collect and why
2.1 The bug photo
What: The photograph you capture or select to identify an insect. This is the only user content that leaves your device.
Why: It is sent to our backend and to our AI inference provider so the model can return a danger verdict (sting / bite / disease-vector / structural-pest risk), the identification, look-alikes, and related educational information.
Important — location metadata is stripped: Before your photo is uploaded, the App re-encodes the image and strips EXIF metadata, including any embedded GPS coordinates. The precise location of the photo is not transmitted.
Legal basis (GDPR): performance of our contract with you / provision of the service you request (Art. 6(1)(b)).
2.2 No location or region (a deliberate difference)
What we collect: nothing. Flying Bug Identifier does not collect a location, a region, a country, a city, or an address — in any form, coarse or precise.
Why we call this out: Some identification apps derive a coarse region (for example, from your device’s locale) because their subject matter is regional. Flying Bug Identifier does not: an insect’s ability to sting, bite, spread disease, or damage a home does not depend on where you are, so there is no reason to know your location. The App does not request the iOS location permission, does not read Core Location, and does not use Wi-Fi or IP-based geolocation to place you. The only geographic value the App ever shows is a generic reference (e.g. that “911” is the emergency number in the United States), which is fixed text, not a reading of where you are.
2.3 Scan history (stored locally on your device)
What: Your past scans and their result cards (risk class, identification, sting/bite and hazard details, look-alikes, follow-up chat, and the associated result data).
Where: Stored locally on your device using on-device storage (SwiftData). We do not keep a server-side copy of your history. Result JSON is cached only transiently, in-process on our backend, to return your result — it is not re-hosted or stored (the identification output is text/JSON, not media).
Optional iCloud sync: If you have enabled it, your history may sync through your own iCloud key-value store, which is controlled by your Apple ID and your iCloud settings — not by us. We cannot read your iCloud data.
Legal basis (GDPR): performance of the service (Art. 6(1)(b)); processing occurs on your device.
2.4 Purchases and subscriptions
What: Whether you hold an active Premium subscription, and purchase/restore events.
How: Purchases are handled by Apple through StoreKit and the App Store. We never receive or store your payment card, billing address, or Apple ID. Apple provides us only with the transaction/subscription status needed to unlock Premium and to validate entitlements. Apple’s handling of your payment information is governed by Apple’s Privacy Policy.
Legal basis (GDPR): performance of the contract (Art. 6(1)(b)); our legitimate interest in preventing fraud and abuse (Art. 6(1)(f)).
2.5 Technical and log data
What: When your device contacts our backend, our servers transiently process standard technical data such as IP address, request timestamps, and a device-generated API key/rate-limit token.
Why: To route requests, apply rate limits, prevent abuse, secure the service, and debug errors. This data is used for operational security and is not used to build a profile of you.
Legal basis (GDPR): our legitimate interest in operating and securing the service (Art. 6(1)(f)).
We do not collect your name, email address, contacts, health records, phone number, or any location.
3. How your photo is processed (the pipeline)
- You choose or capture a bug photo in the App.
- The App strips EXIF/GPS metadata and re-encodes the image, then uploads it to our backend over an encrypted (HTTPS/TLS) connection. No location or region is attached.
- The backend stores the photo in Cloudflare R2 and submits it to Replicate, which runs the openai/gpt-5-mini vision model (provided by OpenAI, executing on Replicate’s infrastructure) to produce the identification and danger verdict.
- The result is returned to your device and saved to your local history. The result JSON is cached only transiently, in-process, to deliver it — it is not re-hosted. Uploaded photos are automatically deleted from R2 after 30 days (see §5).
4. Third parties who process data for us
We share the limited data below with the following processors only to provide the App. Each is contractually bound to process data on our instructions. We do not sell your personal information and we do not share it for cross-context behavioral advertising. Because the App collects no location, no processor ever receives a location or region from us.
| Processor | What it receives | Purpose | Notes |
|---|---|---|---|
| Replicate (Replicate, Inc.) | The bug photo only | Runs the openai/gpt-5-mini vision model for inference and returns the result | Does not train on your content — inference only. |
| OpenAI (OpenAI, L.L.C.) | Provides the openai/gpt-5-mini model that Replicate runs; the model executes on Replicate’s infrastructure, so your photo is processed there for the inference | AI model provider for the identification and risk assessment | Inference only — your content is not used to train the model. |
| Cloudflare R2 (Cloudflare, Inc.) | The uploaded bug photo only | Temporary object storage of the photo (auto-deleted after 30 days) | S3-compatible storage. |
| Apple (Apple Inc.) | Purchase/subscription transactions | Processes payments and manages your subscription | We never receive your card details. |
We may also disclose information if required by law, to respond to lawful requests, or to protect the rights, safety, and property of our users, the public, or Bulpara.
5. Retention and deletion
- Uploaded photos (Cloudflare R2): automatically deleted by a storage lifecycle rule 30 days after upload. We do not use them after your scan completes.
- Inference (Replicate / OpenAI model): the photo is sent for a single inference and is not retained by us for training; the providers’ own transient handling is governed by their policies.
- Result JSON: cached only transiently, in-process, to return your result; it is not re-hosted or persisted server-side.
- Scan history (local): stored on your device until you delete it (or delete the App). We hold no server-side copy.
- On-demand deletion — “Delete All Data”: In Settings → Delete All Data, you can (a) purge your local scan history from the device and (b) request server-side deletion of your uploaded photos ahead of the automatic 30-day schedule.
- Technical/log data: retained only as long as needed for security, rate-limiting, and debugging, then deleted or aggregated.
6. No sale of data; no model training on your content; no ad or analytics resale
- We do not sell your personal information for money, and we do not “sell” or “share” it as those terms are defined under the CCPA/CPRA. The App shows no ads and uses no advertising identifier or cross-app tracking.
- Our AI provider does not train its models on your photos or results. Your content is used only to produce your identification.
- No ad SDK, no analytics resale. The App contains no third-party advertising SDK and no analytics component that sells, shares, or monetizes your data.
7. Your choices and controls
- Delete your data: Use Settings → Delete All Data in the App at any time.
- Photos: You choose which photo to submit for each scan; nothing is uploaded until you start a scan.
- Subscriptions: Manage or cancel your subscription in App Store → your account → Subscriptions (managed by Apple).
Because the App collects no location, there is no location setting to manage — the App simply never reads one.
8. Your legal rights
8.1 GDPR / UK GDPR (EEA, UK, and similar jurisdictions)
Where the GDPR applies, you have the right to: access the personal data we hold about you; request rectification of inaccurate data; request erasure (“right to be forgotten”); restrict or object to processing; data portability; and, where processing is based on consent, withdraw consent at any time without affecting prior processing. Because we operate the App without accounts, most of your data is either on your device (which you control directly) or is short-lived server-side photo storage that you can delete via §5. To exercise a right against data we control, contact us at privacy@flyingbugidentifier.bulpara.com. You also have the right to lodge a complaint with your local data protection authority.
International transfers: our processors may process data in the United States and other countries; where required, such transfers are covered by appropriate safeguards (for example, Standard Contractual Clauses).
8.2 CCPA / CPRA (California)
California residents have the right to know/access the categories and specific pieces of personal information collected, the right to delete, the right to correct, the right to opt out of the “sale” or “sharing” of personal information, and the right not to be discriminated against for exercising these rights. As described in §6, we do not sell or share your personal information; the App shows no ads and uses no advertising identifier or cross-app tracking. To make a California rights request, contact privacy@flyingbugidentifier.bulpara.com.
Categories of personal information (CCPA): identifiers (a device-generated API/rate-limit token, IP address); commercial information (subscription status); and visual information (the bug photo you submit). We do not collect geolocation data of any kind. We disclose the categories above to the processors listed in §4 for the business purposes stated there.
9. Children
Flying Bug Identifier is not directed to children and is not designed for children. Given its safety-critical subject matter (stings, bites, disease vectors, and emergency guidance), it is age-rated 12+ and is not a “kid-safe” or 4+ app; nothing in it should be read as a guarantee of a child’s safety around insects. We do not knowingly collect personal information from children under 13 (or under 16 where a higher age applies). If you believe a child has provided us information, contact privacy@flyingbugidentifier.bulpara.com and we will delete it.
10. How your Apple App Privacy label maps to this policy
- Data used to track you: none. The App shows no ads, uses no advertising identifier, and does not track you across other companies’ apps or websites; it presents no App Tracking Transparency prompt.
- Data linked to you: none. The App has no account and does not tie data to your identity.
- Data not linked to you: Photos (the bug photo) — collected for App Functionality; Purchases (subscription status) — for App Functionality; Identifiers/Diagnostics (device API token, IP, operational logs) — for App Functionality.
- Location: none. The App collects no location data of any kind — not precise and not coarse. There is no Location entry on the label.
If there is any conflict between the on-store label and this policy, this policy governs; we will keep them aligned.
11. Security
We use industry-standard measures to protect your data, including encryption in transit (HTTPS/TLS), authenticated API access, rate limiting, and short storage retention. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect your information and to limit what we collect in the first place.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide notice in the App or on flyingbugidentifier.bulpara.com. Your continued use of the App after an update takes effect constitutes acceptance of the revised policy.
13. Contact us
- Privacy questions / rights requests: privacy@flyingbugidentifier.bulpara.com
- Product support: support@flyingbugidentifier.bulpara.com
- Publisher: [legal entity], [jurisdiction]
If you have been stung or bitten and are having a severe reaction — trouble breathing, swelling of the face, tongue, or throat, dizziness, or widespread hives — do not use the App to decide what to do; call your local emergency services (911 in the United States) immediately.