Privacy Policy
Updated September 26, 2026
This policy covers feralmap.com and the FeralMap iOS app, operated by the FeralMap team at Nene.org. Contact contact@nene.org with privacy questions or requests.
Information you provide
Reports can include species, counts and uncertainty, observation time, a chosen map location, photos and notes. Additional context can include feeding activity, descriptions of people or vehicles, or known roadkill identification and microchip details. Provide relevant observations, not unrelated personal information.
Guest reporting does not require an account. A report identifier and private receipt credential support receipt recovery; the server stores the credential as a hash. Guest reporting does not make submitted information anonymous: a location, image or description can identify a person or place.
You can create a reporting account with a handle without providing an email or real name. Reports submitted while using that account are linked to its user identifier. An optional verified email lets you recover the same account; adding it does not consent to contact about a report. The iOS app stores its sign-in securely in the device Keychain and remembers your handle. Web account sessions are stored in the browser. Appearance settings stay on your device.
Where enabled, Sign in with Apple can connect to the same account and handle. Apple can share a relay email address instead of your personal email. This keeps your personal email private from FeralMap; it does not make account activity unlinked. We retain an encrypted Apple authorization credential on the server so that we can revoke the connection when you delete your account.
Private participation, where enabled, lets you save an optional preferred name and email or phone follow-up preferences, allow contact for a particular report, and exchange in-app messages with authorized staff. The email address comes from your confirmed account; a phone number is not verified. Saving a preference does not grant permission for every report. Changing or confirming an email does not automatically grant follow-up permission.
If you turn on email updates, we email your confirmed account address when a reviewer looks at one of your reports, when a reviewer writes you a note, and, only if you choose it, once a month with a summary for your island. These messages are delivered by Resend, our email provider, which receives your address and the message text. Every message carries an unsubscribe link that works without signing in, and withdrawing email permission stops messages that are still queued. Until a message is sent, the queue holds the text it will contain (species, island, day, and any note a reviewer wrote to you); that text is deleted as soon as the message is sent, cancelled or given up on. We keep the remaining record (account and report identifiers, kind, status and timestamps) for 90 days. The queue never holds your location, photos or email address, and the emails themselves never include coordinates or a reviewer's notes to staff.
Authorized Operations access requires a staff account. The in-app staff workspace has a separate browser session from the native reporting account. You can clear that staff session inside Operations; signing out of the native account also clears it on the device. A reporting handle does not grant staff permissions.
Location and photo choices
Starting a new report can request device location permission and use a fresh, accurate current location as its starting pin. You can change the pin or place it manually without location access. Saved and manually chosen places are preserved. The observation pin is separate from the device location: a submitted report may also include device coordinates, accuracy and capture time as context. A location difference does not prove that a report is false.
When you select a photo in a version with background photo preparation, the app can upload a private temporary copy before report submission. The photo controls explain this. The report itself is sent only when you choose Submit. Without a connection, selected photos remain locally available for later transfer.
The native app resizes photos and removes embedded metadata before upload. Image pixels may still identify faces, homes or license plates. Camera permission is requested when you choose to take a photo; the system photo picker lets you choose existing images.
Public and restricted information
Public map views use limited observation fields, such as species, reported counts, time and location. Locations may be approximate. A map point does not mean an observation has been verified.
Original photos, free-text notes, structured feeding-person or vehicle details, microchip information and account/contact details are excluded from the ordinary public observation projection. Authorized operational reviewers can inspect restricted evidence. Attached photos are published as resized, metadata-stripped copies by default; anyone can report a published copy, and reviewers can withdraw it. Prepared copies can still show faces, homes, license plates or other identifying image content. Resizing and removing metadata do not redact those details. Publishing a prepared copy never publishes the original. The published fields and copies are licensed under CC BY 4.0 as described in the Terms of Use.
Report conversations and contact permissions are private to the reporter and authorized staff. Participation history and contribution points are private in the current pilot. Points recognize reviewed usefulness; they are not a probability that a report is true. Sharing a name, confirming an email or providing a phone number does not earn additional points.
Uses and service providers
We use information to receive and review observations, provide maps and receipts, support conservation analysis, operate the service and prevent abuse. Account activity and access to identifying evidence may be logged for security and accountability.
Requests can include IP addresses, user-agent/device information, timings and errors. Infrastructure and authentication services may retain security or diagnostic logs. We do not promise that this information is never stored or anonymized on a fixed schedule.
Hosting, database, storage and authentication providers support the service, including Supabase; outbound email, when you turn it on, is delivered by Resend. Where configured, a Cloudflare Turnstile security check protects sign-in and reports sent without an account; Cloudflare processes browser and network signals to run it. The app uses Apple map services, which also have Apple's applicable privacy terms. We do not sell personal information or use third-party advertising trackers. We measure how the site is used with first-party, cookieless events sent to our own server: page views by page type, the referring site's host name, a device size class (phone, tablet or desktop), reporting steps (a card tapped, a form loaded, location granted, a report received, a share, a follow-up opt-in) and page performance timings. These never include coordinates, form contents, photos, IP addresses, email addresses, handles, report identifiers or account identifiers; they are kept for at most 400 days, and nothing is sent when your browser signals Global Privacy Control or Do Not Track.
Storage and deletion
Native drafts and photos are saved on your device. Deleting a notebook entry removes its local record and photos, not an already submitted server observation. Device backups may include local app data depending on your settings.
Unattached temporary photo uploads are scheduled for cleanup. Removing a selected photo or abandoning a draft can also request removal of its temporary upload. Offline requests need a connection to reach the service; cleanup is not necessarily immediate. Photos attached to submitted reports are retained as evidence rather than treated as abandoned uploads.
Submitted records are retained for conservation and research. Guest receipt access currently expires after 90 days; access expiry does not delete the report. Account, operational and security information may be retained for service, security and legal purposes.
Account controls in the app and on the account recovery page let you initiate account deletion. Deletion removes sign-in credentials, your public handle, profile information and structured contact details linked to your account, and removes the account link from submitted observations. Ecological observations, submitted evidence and pseudonymous moderation audit history remain. Free text or photos may still contain information you volunteered; contact us about a specific record or other privacy request. Deleting a local notebook entry only removes its copy from that device.
Deleting an account also removes its private report conversations and follow-up permissions and disconnects its contribution history from the account. Contribution and review audit records can remain to explain decisions; staff review notes may contain volunteered information. Apple authorization is revoked before deletion is confirmed. A temporary provider or network failure can require retrying deletion.
Request access, correction or deletion at contact@nene.org. Include a report identifier if available, but never email your password or private receipt credential. We may need to verify your authority over the information. When handling a request, we will explain information that must be retained and why.
Your controls
You can omit optional details, choose a manual pin and manage camera/location permission in iOS Settings. Remove local drafts or contact us about server data and withdrawing consent to future use. Revoking a device permission does not erase previously submitted information.
Participation controls let you withdraw contact permission for one report or remove all saved and report-specific follow-up permissions. Withdrawal removes those structured contact details; it does not erase earlier messages or undo a contact that already happened. In-app conversations work without sharing a name, email or phone number. Unsent message drafts may stay in browser session storage or on your device until sent or cleared; account controls isolate them from other accounts.
Optional note assistance uses Apple's on-device Foundation Models on supported devices. You choose whether to accept a suggestion. Notes you later submit still leave your device as report content.
FeralMap is not directed to children under 13. A parent or guardian should submit reports for a child under 13. Contact us if a child has provided personal information that should be removed.
Security and contact
We use HTTPS and restrict operational access to identifying evidence. No service guarantees absolute security. Keep receipt credentials and passwords private.
We update this policy when the service changes. The date above identifies this version. Privacy requests, support questions and concerns about submitted content can be sent to contact@nene.org.