App privacy
The Grzybiarz app is designed so that your data stays with you. Here are the key principles.
Works offline: detection, recognition, and maps run without a network.
On-device models: the photo is scored on your phone, without being uploaded. A photograph leaves the device only when you share it yourself: with a public find plus the photo consent, with the training contribution, or in the tester programme.
Finds and photos stay in your device’s storage. Trips including the route go to your account so the history survives a change of phone: only you can see them, you can turn the upload off in settings, and you can delete the history from the server at any time.
GPX export: you can export your own copy of the data at any time.
No tracking: we use no tracking pixels and no advertising profiling. Visit statistics cover the website only, and only if you agree to them.
Contributing to model training (optional)
If you turn this on in settings, your photos of confirmed finds can be used to train the recognition model. This is a separate, optional consent, independent of whether a find is private or public. Photos have their location stripped (EXIF/GPS), and you can withdraw consent anytime. After you withdraw it, we delete your contributed photos from the training data. This option is off by default.
Friends, duels and the leaderboard
The friend code, the friends list and duels are yours to switch on: until you add somebody, none of it does anything. Whoever accepts your invite sees your profile name and photo, and that is the point of a friends list. Whoever you send an invite to sees neither, until they accept. On the leaderboard you are a four-character tag; your name and photo appear there only if you turn that on in your profile. Routes, coordinates and catch times never reach friends through any of these features.
App privacy policy
This part covers the processing of data in the Grzybiarz mobile app and in your account. The app is built to work without a network, and most data never leaves the phone. Below we set out exactly what does leave it, why, and on what legal basis.
Data controller
The controller of your data is ArchXS Dariusz Tyszka, email: kontakt@grzybiarz.app. Write to that address on data protection matters; we answer requests within one month.
Why we process data and on what basis
Your account: an identifier, a hashed recovery code and an optional email address. Without an account there is no way to recover your history after changing phones. Basis: performance of a contract, Art. 6(1)(b) GDPR.
Trip history in your account: statistics and the GPS track, visible only to you. The upload is on by default, you can turn it off in Settings, and you can delete uploaded tracks from the account at any time. Basis: performance of a contract, Art. 6(1)(b) GDPR.
Public finds, the heatmap and the live feed: species, time and location. A find becomes public only when you mark it so yourself. Basis: consent, Art. 6(1)(a) GDPR.
A photo attached to a public find: a separate consent, independent of publishing the point itself. Without it we publish the point without the photograph. Basis: consent, Art. 6(1)(a) GDPR.
Training contribution: photos of confirmed finds with the species label, stripped of location. Off by default. Basis: consent, Art. 6(1)(a) GDPR.
Leaderboard, friends and duels: name, profile picture, points and quiz results. Each of these features is enabled separately. Basis: consent, Art. 6(1)(a) GDPR.
Notifications: a device identifier, a push token and, if you enable nearby alerts, an approximate location and radius. Basis: consent, Art. 6(1)(a) GDPR.
Tester programme: dataset frames and field reports, described by a grid cell of roughly 5 km², never by coordinates. Basis: consent, Art. 6(1)(a) GDPR.
Diagnostics: aggregates of battery use and GPS signal quality, with no photos and no coordinates, deleted after 90 days. Basis: consent, Art. 6(1)(a) GDPR.
Service security: abuse reports, rate limits, detection of inflated scores and hashed IP addresses. Basis: our legitimate interest in protecting users and the service, Art. 6(1)(f) GDPR.
Strava: if you connect an account, we send the trips you choose there. You can revoke access in Strava or in the app Settings. Basis: consent, Art. 6(1)(a) GDPR.
Location: what stays and what leaves
This is the most sensitive category of data in the app, so it gets its own section. Species recognition, fruiting-body detection and offline maps run on the phone and need no location on the server. Private finds and the track recorded during a trip stay in the device storage. Three things reach the server: the GPS track of trips, until you turn the history upload off; the exact coordinates of a find you mark as public yourself; and an approximate area for alerts about new finds. Before storage, a public find is shifted by 200 metres in a random direction and aggregated into a grid cell of roughly 5 km²; the heatmap and the feed show only the shifted point, and we never disclose the exact coordinates to anyone. In the field game the server never sees your position more precisely than such a cell.
Who we entrust data to
We do not sell data and we do not pass it on for marketing. We use processors bound by data processing agreements:
Hetzner Online GmbH, Germany: application server and database.
Cloudflare, Inc.: photo storage in the European region, content delivery and attack protection.
Resend, Inc.: sending email, when you add an address to your account.
Google, that is Firebase Cloud Messaging, and Apple, that is APNs: delivering notifications, only once you enable them.
Strava, Inc.: only after you connect an account, and only to the extent you choose.
Vercel Inc.: hosting for grzybiarz.app. Website statistics are covered by the cookie section and concern the site itself, not the app.
Transfers outside the European Economic Area
Some of the services listed above may process data outside the EEA, in particular in the United States. This takes place under the European Commission adequacy decision, that is the EU-U.S. Data Privacy Framework, or under standard contractual clauses. We will provide a copy of the safeguards applied on request.
How long we keep data
Your account and its contents: until you delete the account. An account with no activity is deleted after 12 months.
Public finds and uploaded trip history: until you withdraw the publication, delete the track or delete the account.
Diagnostics: 90 days from recording, then deleted automatically.
Database backups: daily for 30 days, weekly for 12 weeks, monthly for 5 years.
Server and attack-protection logs: 30 days.
Your rights
You have the right of access, rectification, erasure, restriction of processing, portability, and objection to processing based on legitimate interest. Consents, on which most features rest, can be withdrawn at any time without giving a reason; withdrawal is as easy as giving consent and does not affect the lawfulness of processing before it.
You can exercise most of these rights yourself in the app: Settings and Account let you export your data, withdraw every consent with its own switch, delete uploaded trip history from the account, and delete the whole account together with its server-side data.
Complaint to the supervisory authority
If you believe we process data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.
User age
The app is not intended for children under 16 and we do not knowingly collect their data. If you are under 16, the consent-based features, that is publishing finds, the leaderboard, friends and duels, require a guardian's consent.
Automated decisions
We do not take decisions about you based solely on automated processing that would produce legal effects. Species recognition scores a photograph of a mushroom, not a person, and its output is a hint, not a ruling. An account's community trust level is computed from the number of confirmed finds and from other people's reports, and its consequence can be the loss of the right to publish, not a judgement of you as a person.
Website visit statistics (cookies)
This part covers the grzybiarz.app website only, not the app on your phone. If you agree to statistics, we use Google Analytics 4 to see which texts you read and where you get lost. Consent is optional: without it the site works exactly the same.
We keep your decision in the browser (localStorage, key "grzybiarz-consent"). It is not a cookie, it never leaves your device, and it exists only so we do not ask you twice.
After consent, Google Analytics sets its own cookies (_ga and _ga_*) that recognise repeat visits from the same browser.
We collect the address of the page you opened, an approximate location derived from your IP address (country and city, without storing the full IP), your device and browser type, and where you came from.
We never use this data for advertising or remarketing, and we do not link it to any account in the app.
Legal basis and withdrawing consent
Statistics run on your consent alone (Art. 6(1)(a) GDPR). Until you give it, we load no Google script and send nothing to it. You can withdraw at any time: "Cookie preferences" in the site footer or Settings in the web version. Withdrawal stops the sending immediately, with no page reload.
Recipient and transfers outside the EEA
Statistics are run by Google Ireland Limited, and data may also be processed by Google LLC in the USA under the European Commission adequacy decision (EU-U.S. Data Privacy Framework) and standard contractual clauses. How long events are kept follows the data-retention setting in Google Analytics (2 to 14 months).
Privacy policy: beta test
This policy describes how we process the data you provide in the Grzybiarz beta-test signup form. It covers only the testers list, not your use of the app itself (which runs offline, on your device).
Data controller
The data controller is ArchXS Dariusz Tyszka, email: kontakt@grzybiarz.app.
What we collect
Email address, to send the confirmation link and the test invitation.
Platform (Android / iOS), to assign you to the right test track.
Name (optional), only if you provide it, to personalize messages.
Date and version of the consent given, for accountability (GDPR).
Technical data: a hash of your IP address and your browser header, solely for abuse prevention. We do not store the raw IP address.
Purpose and legal basis
We process the data based on your consent (Art. 6(1)(a) GDPR) in order to invite you to the beta test and communicate about it. You may withdraw consent at any time.
Recipients
We use Resend (Resend, Inc.) as a processor to deliver emails. Data is stored on our own server (EU).
Retention period
We keep the data until the beta-test program ends or until you withdraw consent, whichever comes first. After that it is deleted.
Your rights
You have the right to access, rectify, erase, restrict processing of your data, and to withdraw consent. To exercise these rights, email kontakt@grzybiarz.app.
Contact
For data matters: kontakt@grzybiarz.app