Agama Get the app

Legal

Privacy Policy

Effective date: 3 August 2026

Last updated: 30 August 2026

Agama is a field companion for reptiles and amphibians: browse species, log what you find, plan trips, and keep a life list. This policy explains what we collect, what we deliberately refuse to collect, and what you can do about it.

Agama is operated by Ramon Duran Romaña, Groot Begijnhof 40, 3000 Leuven, Belgium ("we", "us"). For anything in this policy, write to support@agamaapp.com.


1. The short version


2. What we collect

Information you give us

WhatWhyNotes
Email addressSign-in, password reset, essential service messagesHandled by our authentication provider. If you use Sign in with Apple or Google, we receive your email (and a name, if you share it) from them
PasswordSign-inStored only as a salted hash; we never see it
First name, last name, @handleHow you appear to others and how people find youPublic to other signed-in users
Bio, profile photoOptional profile detailPublic to other signed-in users
ObservationsThe core of the appSpecies, date (or approximate date), country, broad area name, counts, notes
TripsGrouping observationsTitle, dates, countries, notes, members you invite
Photos you uploadAttaching your own images to species and observationsSee §3 and §5
PreferencesMaking the app behave the way you wantNaming, units, theme, taxa filter, photo licence, privacy toggles

Information collected automatically


3. What we deliberately do not collect

This is the part that matters most for wildlife, so we are specific about it.


For users in the EU/EEA and the UK, our legal bases under the GDPR are:

PurposeLegal basis
Creating and running your accountPerformance of a contract
Storing and displaying your observations, trips and photosPerformance of a contract
Showing your profile and content to people you allowPerformance of a contract
Keeping the service secure and preventing abuseLegitimate interests
Reviewing photos proposed as reference imagesLegitimate interests, and your consent when you propose one
Essential service emails (password reset, account notices)Performance of a contract
Managing your Supporter subscription, if you buy onePerformance of a contract
Complying with legal obligationsLegal obligation

We do not rely on consent for the core service, except where stated (for example device permissions for camera, photo library and location, which you grant or refuse in your operating system and can change at any time).


5. Who can see what


6. Service providers and third parties

We keep this list short on purpose.

ProviderWhat they doWhat they receive
SupabaseHosts our database, authentication and file storageAll account data and content described above
Photon (komoot)Place-name search when you name a broad areaOnly the place text you type. Never any observation data, and never wildlife coordinates
GBIFProvides species occurrence evidence shown in ExploreOnly the species and country being browsed
Apple / GoogleApp distribution, in-app purchases if enabled, and — if you choose Sign in with Apple or Google — authenticationGoverned by their own privacy policies. On sign-in we receive your email, and a name if you share it. If you subscribe, they are the seller and process your payment; we never receive your card details
RevenueCatManages the Supporter subscription (receipts, renewal status) if you subscribeAn app-specific user ID and your purchase/subscription status from Apple or Google. No email, photos or observations

Maps are drawn on your device from country outlines shipped inside the app, so no map provider is contacted and nothing about where you have been is sent anywhere to render them.

Species names, taxonomy and checklists come from GBIF. Species reference images come from iNaturalist, credited to their photographers under their own licences. Native/introduced status is checked against The Reptile Database. These are sources we read from; they do not receive your data.

We do not use third-party analytics, crash-reporting or advertising SDKs. If that ever changes, this section will be updated before it happens.


7. International transfers

Our infrastructure providers may process data outside your country, including outside the EEA. Where that happens, transfers are covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.


8. How long we keep things


9. Your rights

You can export all your observations as a spreadsheet, and delete your account and everything in it, from Settings, without contacting us.

Depending on where you live, you also have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent where we rely on it. Write to support@agamaapp.com and we will respond within the time the law allows (one month under the GDPR). You may also complain to your local data protection authority; in Belgium that is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données).


10. Security

Photos are stored in a private bucket, access to database rows is enforced per user at the database level, and passwords are hashed by our authentication provider. No system is perfectly secure, but we do not keep the information that would do the most damage if it leaked — precise animal locations — because we never collect it.


11. Children

Agama is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has created an account, write to support@agamaapp.com and we will remove it.


12. Changes to this policy

If we make a material change we will notify you in the app before it takes effect. The "last updated" date at the top always reflects the current version.


Contact: support@agamaapp.com · Ramon Duran Romaña, Groot Begijnhof 40, 3000 Leuven, Belgium