Privacy Policy
RealDex identifies wildlife on your device. Your photos stay on your phone unless you deliberately ask for Cloud AI. This page explains everything else.
In short
RealDex is a wildlife identification and collection app. It is built local-first, and the short version of this policy is:
- Identification runs on your device. The camera, the model and your collection work with no network connection at all. Photos are not uploaded for ordinary identification.
- Photos leave your phone only if you tap Cloud AI. That feature is optional, off unless you invoke it, and sends the single image you chose.
- Your collection, your photos and your saved locations stay on your device. We hold no copy of them and no account to attach them to. There is no login.
- Location is optional and can be switched off inside the app.
- Free users see ads. They are non-personalised by default on both platforms.
- We do not sell your personal information.
The rest of this page is the long version, because the short version is not enough to make an informed decision.
Who is responsible
RealDex is made and operated by Alp Yalay, a sole developer resident in the Republic of Türkiye, acting as data controller.
- Contact: alpyalay@gmail.com
- Privacy requests: use the subject line "Privacy Request — RealDex"
- Postal address: provided on request to any user or supervisory authority that asks for it
There is no company, no staff and no third party with administrative access to RealDex data. That is relevant to several sections below, so it is worth stating plainly up front.
On EU/UK representatives. RealDex is operated from outside the EU and UK. Having assessed Article 27 GDPR, the processing carried out is occasional, involves no large-scale processing of special-category data, and is unlikely to result in a high risk to individuals — so no representative has been appointed. If that assessment changes, a representative will be appointed and named here. This is a stated position, not an oversight.
What the app collects
Photographs
Photographs you capture, or select from your photo library, are used to identify a species.
For ordinary identification the photo is processed entirely on your device and is never transmitted. It is written to your device's own storage along with the resulting encounter. We receive no copy of it, we cannot browse it, and it is not backed up to any server we control.
If you choose Cloud AI, that specific image is transmitted — see Cloud AI below.
Encounter records
When you save a catch, the app records the identified species, a timestamp, the model's confidence score, and — if you have enabled location — the coordinates. This is stored in a SQLite database on your device.
Location — optional
If you grant location permission, the app records latitude and longitude at the moment of an encounter, so your collection can show where you found each animal and so the territory map works.
Specific commitments about this data:
- Coordinates are stored on your device, with the encounter.
- Exact coordinates are not used for advertising, and are not disclosed to any advertising partner.
- Exact coordinates are not included in Cloud AI requests.
- We hold no copy of your location history, because there is no account for one to be attached to.
You can turn location off at Settings → Privacy → Location inside the app, or revoke the permission in your device settings. Both work; neither deletes coordinates already saved to past encounters, which you can remove by deleting those encounters or by using Delete All Data.
Territory and regional-hint features send an approximate area — not your exact position — to fetch city boundary geometry and regional species lists.
A device identifier
The app generates a random identifier and stores it locally. It is not your device's hardware ID, advertising ID, or any identifier issued by Apple or Google, and it is not linked to your name or email.
It exists to enforce Cloud AI rate limits and to attach a subscription entitlement to the right installation. It is sent to our cloud services and is the value you need when making a data request — find it at Settings → About → Device ID.
Subscription data
If you subscribe, the transaction itself is carried out by the Apple App Store or Google Play. We never see your payment details. RevenueCat manages entitlements, and we receive your subscription status plus a RevenueCat user ID linked to the device identifier above.
Advertising data
Free users see ads served by Google AdMob, which collects data including an advertising identifier, IP address, and device information. How this is configured, and what consent applies, is set out in Advertising below.
Analytics and crash reports — optional
Firebase Analytics and Crashlytics record feature usage and crash diagnostics. You can turn this off at Settings → Privacy → Analytics.
Game Center — iOS
If you are signed in to Game Center, achievements are reported to Apple's Game Center service. This is handled by Apple under Apple's privacy policy, not by us. Signing out of Game Center stops it.
Notifications — optional
If you allow notifications, we deliver reminders and progress alerts. Notification content is composed on your device from data already on it.
Support messages
If you contact us through the support form, we receive the name, email address and message you type. The form is delivered by Web3Forms and arrives in a Gmail inbox.
Deletion requests
The data deletion form is a Google Form, and responses are stored in Google Drive. If you would rather not use a Google service, email us instead — the address is above, and it works exactly as well.
The website
realdex.alpyalay.org uses Google Analytics, subject to consent. See the Cookie Policy.
Why we process it, and on what legal basis
| Purpose | Data used | Legal basis (EEA/UK/Türkiye) | | --- | --- | --- | | On-device identification and your collection | Photos, encounters, settings | Performance of a contract | | Cloud AI, when you invoke it | Submitted image, device identifier | Performance of a contract, at your request | | Recording where you found an animal | Location | Consent — the permission prompt and in-app toggle | | Territory map and regional hints | Approximate area | Performance of a contract | | Subscriptions and entitlements | Subscription status, RevenueCat ID, device identifier | Performance of a contract | | Rate limiting and abuse prevention | Device identifier, usage counters | Legitimate interests — keeping a free service available | | Crash reporting and analytics | Diagnostics, usage events | Consent — the in-app Analytics toggle | | Advertising to free users | Advertising identifier, IP, device data | Legitimate interests for non-personalised ads; consent for personalised ads | | Answering support requests | Name, email, message | Legitimate interests, or performance of a contract | | Handling privacy requests | Device identifier, request contents | Legal obligation |
Cloud AI
Cloud AI is optional and off unless you ask for it. On-device identification is checked first, always, and the cloud is never consulted on its own initiative.
When you tap Cloud AI:
- The selected image is encoded and sent to a Firebase Cloud Function we operate, in the us-central1 region (United States).
- It is passed to Google Gemini for identification.
- The result comes back to your device.
We do not store submitted images in our own cloud storage after the request completes. Our providers may retain limited service logs under their own policies, which we do not control. We may change AI provider or model; if we do, this page will be updated.
Exact coordinates are not included in Cloud AI requests.
Advertising
Free users see ads. Because this is where most apps are vague, here is precisely how it is configured:
- Non-personalised ads are the default on both iOS and Android.
- On iOS, personalised ads are served only if you allow tracking at Apple's App Tracking Transparency prompt. Decline, or never answer, and ads stay non-personalised.
- On Android, ads are currently always non-personalised.
- Ad content is capped at the G rating.
- RealDex is not tagged as child-directed, on the basis that the service is for users aged 13 and over.
One thing we want to be straightforward about. RealDex does not currently present a separate consent dialogue for advertising to users in the EEA, UK or Switzerland. Ads to those users are non-personalised, which is the protective setting, but a consent management platform has not yet been implemented and we are not going to claim otherwise. Adding one is planned. Until then, if you would prefer to see no ads at all, a subscription removes them.
There is no in-app ads toggle today. Personalised advertising is controlled through the ATT prompt on iOS and through your device's advertising settings on both platforms — you can reset or delete your advertising ID there, and Google account holders can adjust ad personalisation in their Google account.
Who we share data with
We share only what is needed to run the app. Each entry below is a processor or independent controller with a role we can describe precisely.
| Provider | What it does | Data it receives | Region | | --- | --- | --- | --- | | Google Firebase | Cloud Functions, Firestore, Analytics, Crashlytics | Device identifier, usage counters, submitted images in transit, diagnostics | United States | | Google Gemini | Cloud identification | Submitted image | United States | | RevenueCat | Subscription entitlements | Device identifier, subscription status | United States | | Google AdMob | Advertising | Advertising identifier, IP, device data | Global | | Apple App Store / Google Play | Billing, distribution, Game Center | Purchase and account data held by them, not us | Global | | iNaturalist | Regional species hints | Approximate area | United States | | Web3Forms | Support form delivery | Name, email, message | European Union | | Google Forms / Drive | Deletion request intake | Device identifier, request contents | United States |
We do not sell personal information for money. Some laws define "sale" or "sharing" broadly enough to cover disclosing identifiers to advertising partners for cross-context behavioural advertising. Because ads are non-personalised by default, that disclosure is limited — and on iOS it only occurs at all if you allowed tracking at the ATT prompt, which you can withdraw at any time in your device settings.
Where data is stored, and for how long
Most RealDex data never leaves your phone. What does is listed here, with an honest distinction between periods that are actually enforced and periods that describe our practice.
| Data | Location | Retention | | --- | --- | --- | | Photos, encounters, collection, settings | Your device only | Until you delete them or uninstall. Not ours to expire. | | Device identifier, usage counters, subscription tier, reset timestamps | Firestore | 13 months from last activity, then deleted or anonymised — enforced | | RevenueCat entitlement records | RevenueCat | Active subscription plus 24 months, per RevenueCat's configured retention | | Crash reports | Crashlytics | Google's default retention for Crashlytics, currently 90 days | | Analytics events | Firebase Analytics | Our configured retention window in Firebase | | Submitted images for Cloud AI | Processed in transit | Not stored by us after the request completes. Provider logs are outside our control. | | Support messages | Web3Forms delivery, then Gmail | Kept while needed to resolve your request and any follow-up, then deleted. Reviewed periodically rather than automatically. | | Deletion request records | Google Drive | Kept as evidence that the request was honoured, then deleted. Reviewed periodically rather than automatically. |
Where the table says "reviewed periodically", it means exactly that — a mailbox we clear by hand, not an automated expiry. We would rather say so than publish a schedule that sounds enforced and is not.
International transfers
Our cloud processing happens in the United States (Cloud Functions and Gemini in us-central1). If you use RealDex from the EEA, UK, Türkiye or elsewhere, your data is transferred there.
For transfers out of the EEA and UK we rely on the Standard Contractual Clauses incorporated into our providers' data processing terms, together with those providers' own supplementary measures. For Turkish users, transfers rely on the mechanisms available under KVKK for transfers to third countries.
Your rights and how to use them
Wherever you live, you can ask us to:
- Access the data we hold that is linked to your device identifier
- Correct it if it is wrong
- Delete it
- Receive a copy in a portable format
- Withdraw consent for location or analytics — the in-app toggles do this immediately, no request required
- Object to or restrict processing based on legitimate interests
- Opt out of personalised advertising
Depending on where you live these may be statutory rights under the GDPR, UK GDPR, KVKK, or a US state privacy law; we offer them to everyone regardless.
How to make a request. Use the data deletion page, or email alpyalay@gmail.com with the subject "Privacy Request — RealDex". Include your Device ID from Settings → About.
Verification. The device identifier is how we locate your records — without it there is nothing to look up, since there is no account, name or email attached to app data. If you have lost it, a subscription receipt can help us identify the right entitlement record. We will not ask you for identity documents.
Timing. We aim to respond within 30 days. If a request is complex we will tell you, and say why.
Refusals and complaints. If we decline a request we will explain the reason and how to challenge it. You can also complain to a regulator: in the EEA or UK your national supervisory authority, and in Türkiye the Personal Data Protection Authority (KVKK).
What we cannot do. We cannot delete the data on your phone remotely — no server holds it and no mechanism exists to reach it. Settings → Data → Delete All Data does that, and so does uninstalling.
Security
The honest framing here is that RealDex holds very little in the cloud, and that is the main protection: there is no server-side store of photos, locations or collections to lose.
For what we do hold:
- All traffic between the app and our services uses TLS; the iOS build disallows arbitrary insecure loads.
- Firestore is protected by security rules restricting access to the records tied to a device identifier.
- No user media or location data is stored in our cloud at all.
- Administrative access is limited to a single operator with multi-factor authentication. There are no shared credentials and no staff accounts to deprovision.
- Cloud AI requests are rate limited to limit abuse.
- Our providers — Google, RevenueCat — maintain their own certified infrastructure security programmes.
What we do not claim: RealDex has no SOC 2 report, no third-party penetration test, and no bug bounty. Saying otherwise would be easy and false.
To report a vulnerability, see Security and vulnerability disclosure.
If a personal data breach occurs that requires notification, we will notify the relevant supervisory authority and affected users within the deadlines applicable law sets — 72 hours to the authority under the GDPR, UK GDPR and KVKK Board Decision 2019/10 — and tell you what happened and what you can do about it.
How identification works, and its limits
Identification is machine learning, and it is wrong sometimes.
An on-device detector locates the animal in frame, and an in-house classifier named FieldNet 1 names it. It can name 5,077 species; a further set is searchable for manual identification. Optional Cloud AI adds a second opinion from a general-purpose model.
- Results are probabilistic, and confidence scores are estimates, not guarantees.
- No automated decision producing legal or similarly significant effects is made about you. The app ranks candidate species. It does not evaluate, score or profile you.
- You can always override an identification manually.
RealDex is for recreational and educational use. Do not rely on it for anything that matters: not for deciding whether an animal is venomous, dangerous or safe to approach; not for veterinary, medical, conservation-enforcement, legal or regulatory decisions; and not in an emergency.
Children
RealDex is intended for users aged 13 and over. It is not directed at children under 13, and we do not knowingly collect their personal information.
Because the app is about animals and collecting, we recognise it may appeal to younger users. So, regardless of age:
- There is no account, no login, no username and no profile to make public.
- There is no social feature — no sharing, no messaging, no friends, no public map. Nothing a user posts can reach another user, because there is no route for it.
- Location is optional and stored only on the device.
- Ad content is capped at the G rating.
- Ads are non-personalised by default.
If you believe a child under 13 has provided personal information, contact us and we will delete it. In practice the most effective step is immediate and needs no request from us: Settings → Data → Delete All Data, which erases everything on the device.
RealDex's Google Play content rating is 13–15. Its App Store age rating is under review to bring it into line.
Changes
We will update this page as the app changes, revise the "last updated" date, and give notice in the app for changes that materially affect you.
Contact
Alp Yalay — alpyalay@gmail.com
Related pages: Terms of Service · Cookie Policy · Data deletion · Security · Subscriptions and refunds · Accessibility