WildList

Privacy policy

What WildList collects, and why

Last updated 25 August 2026

WildList is made by ENTITY_NAME_PENDING. This page describes what the app collects, who else receives it, how long it is kept, and what happens when you delete your account. It is written from an inventory of the app's actual code rather than from a template, so if something is not listed here, the app does not do it.

The short version

Account and profile

To create an account you give us an email address and a password, a display name, and a username. The email and password are held by our sign-in provider (Firebase Authentication) and are not written into the app's database. The display name and username are visible to every signed-in user and are indexed so people can find you by typing the first letters. There is no Google, Apple, or anonymous sign-in.

Optionally you can add a profile photo and customise your Nature Card (theme, featured stats, badges, favourite species, a "top four", and a trophy case). Your list of friends is stored on your profile and is visible to other signed-in users, as are your badges and your paid-tier flag.

Sightings

Each sighting stores the species and its scientific name, the category, your notes, the observation date, a rarity grade, whether it was captive, the photo, and the location (see below). When the AI identified the photo, we also keep a short description the AI wrote of what it saw, the list of candidate species it considered, and the place name and date that were sent with the request, so you can reopen that reasoning later. Likes and comments on sightings are stored with the account that made them, and comments carry your display name.

Sighting records are readable by any signed-in user of the app. Sighting photos themselves are private to your account.

Location

When you tag a sighting, the app reads your phone's position (foreground only, at "balanced" accuracy, roughly tens of metres) or the GPS coordinates embedded in the photo you chose. It then turns the coordinates into a place name on the device. That place name can be as specific as a street address or the name of a building.

The location is stored precisely. The exact coordinates and the full place name are saved on the sighting, unrounded, with no option to hide or blur them. The app does not request background location and never tracks you between sightings.

Who can read it today. Friends see a coarse label in the app — a neighbourhood or city, or a coordinate rounded to about a kilometre — but that rounding happens on the viewer's phone after the precise value has already been delivered to it. Under the app's current access rules, any signed-in WildList user, not only your friends, can read the precise coordinates and the full place name of any sighting. Treat a sighting's location as visible to other users of the app, not as approximate.

The place name (not the raw coordinates) is also included in the request sent to Anthropic when a photo is identified, and your exact current coordinates are sent to iNaturalist when you open the Discover tab. Both are described under "Who else receives your data".

Photos

Before a photo leaves your phone — whether to be stored or to be identified — it is resized and re-encoded. That re-encoding removes the camera metadata (GPS, timestamp, camera make and model), so uploaded photos do not carry it. The app does read the date and GPS position from a photo's metadata first, on the device, to pre-fill the sighting's date and location; those values are then stored on the sighting as described above.

When you ask the app to identify a photo, a reduced-size copy is sent to Google Cloud Vision to screen for unsafe imagery, and then to Anthropic's model to identify the species, together with the sighting's place name and date. Photos are stored privately in your account's cloud storage. The app never scans your photo library and never writes to it; sharing a card uses your phone's share sheet.

Photos imported from your iNaturalist account are copied from iNaturalist as-is, without re-encoding.

Who else receives your data

WildList runs on Google Firebase (sign-in, database, file storage, and the server functions that power AI, friends, reports, and deletion). Beyond that, these services receive data, each for a specific purpose:

None of these are advertising or analytics services. There is no purchase or payment provider: Pro subscriptions cannot be bought yet, and no payment data exists.

Identifiers and tracking

The app uses your account ID (assigned at sign-up) and, if you allow notifications, a push token. It does not read the advertising identifier (IDFA), does not ask for tracking permission, and includes no analytics, advertising, or attribution software. We do not sell data and do not share it with data brokers.

Usage records

To enforce daily limits and monitor cost, the server keeps a per-day count of your AI requests, with token counts and an estimated cost. If the AI safety screen blocks an image or detects misuse, a strike is recorded on your account; strikes are never removed. When the app meets a species name it does not have in its reference, it records the name (with no account attached) so we can add it. Feedback you send from Settings is stored with your account ID, app version, and platform.

What stays on your phone

Sightings saved while offline, including their precise location, wait in local storage until they upload. Photos being uploaded, camera-roll import copies, cached species text and thumbnails, and any collection export you create are also kept on the device. Signing out does not clear these; deleting the app does.

How long we keep things

Everything is kept until you delete it or delete your account. There are no automatic expiry jobs. Reports about content and moderation strikes are retained indefinitely.

Deleting your account

Settings → Delete account. Deletion runs on our servers and removes: your profile and username, your sightings (with their likes and comments), your species cards and badges, your photos, friend requests you sent or received, notifications addressed to you, reports you filed, your AI usage records, your push token, blocked-user list and settings, and your sign-in. Your account is also removed from your friends' friend lists.

What deletion leaves behind:

If you need any of these removed, contact us at the address below and we will do it by hand.

Children

WildList does not ask for your age and has no age gate. It is not designed for children, and we do not knowingly collect data from anyone under 13; if you believe a child has created an account, contact us and we will delete it.

Changes

When the app's behaviour changes, this page changes with it and the date at the top is updated. The Location section in particular is expected to change as access rules are tightened.

Contact

Questions, deletion requests, or anything else: support@wildlist.app.