Legal
Privacy Policy
Effective date: 3 August 2026
Last updated: 30 August 2026
Agama is a field companion for reptiles and amphibians: browse species, log what you find, plan trips, and keep a life list. This policy explains what we collect, what we deliberately refuse to collect, and what you can do about it.
Agama is operated by Ramon Duran Romaña, Groot Begijnhof 40, 3000 Leuven, Belgium ("we", "us"). For anything in this policy, write to support@agamaapp.com.
1. The short version
- We never store the exact location of a wild animal. Not once, not anywhere.
- Photo location metadata is removed on your phone, before anything is uploaded.
- Your photos are stored privately by default and shown through short-lived links, not public URLs.
- You can export everything you have added, and you can delete your account and its contents from inside the app.
2. What we collect
Information you give us
| What | Why | Notes |
|---|---|---|
| Email address | Sign-in, password reset, essential service messages | Handled by our authentication provider. If you use Sign in with Apple or Google, we receive your email (and a name, if you share it) from them |
| Password | Sign-in | Stored only as a salted hash; we never see it |
| First name, last name, @handle | How you appear to others and how people find you | Public to other signed-in users |
| Bio, profile photo | Optional profile detail | Public to other signed-in users |
| Observations | The core of the app | Species, date (or approximate date), country, broad area name, counts, notes |
| Trips | Grouping observations | Title, dates, countries, notes, members you invite |
| Photos you upload | Attaching your own images to species and observations | See §3 and §5 |
| Preferences | Making the app behave the way you want | Naming, units, theme, taxa filter, photo licence, privacy toggles |
Information collected automatically
- Approximate location, only when you ask for it. Tapping "Use current location" reads your device location once, to work out which country you are in, or to suggest a nearby broad area. See §3 for what is kept.
- Basic technical data needed to run the service: app version, platform, and the network requests your app makes to our backend. We do not use advertising identifiers, and Agama contains no third-party analytics or advertising SDKs.
3. What we deliberately do not collect
This is the part that matters most for wildlife, so we are specific about it.
- No exact wildlife coordinates, ever. An observation is stored with a country and a broad area (a national park, a mountain range, an island, an administrative region). The only coordinate kept is a centroid of that broad area, rounded to a grid of roughly 2 km, used solely to place a dot on your personal travel map. It describes a region, not a find.
- No photo EXIF or GPS metadata. Every image is re-encoded on your device before upload, which discards all embedded metadata, including GPS coordinates, camera serial numbers and timestamps. The original file never leaves your phone.
- No continuous or background location tracking. Location is read only in the moment you tap a button that asks for it.
- One thing we cannot strip: what you type. Notes and day journals are free text, stored as written. If you record a precise locality there, it is saved — privately to your account, but saved. Everything above describes what Agama collects; it cannot police what you choose to write.
- No sale of personal data. We do not sell, rent, or share your personal information for advertising or profiling, and we do not build advertising profiles.
4. Why we process your data, and on what legal basis
For users in the EU/EEA and the UK, our legal bases under the GDPR are:
| Purpose | Legal basis |
|---|---|
| Creating and running your account | Performance of a contract |
| Storing and displaying your observations, trips and photos | Performance of a contract |
| Showing your profile and content to people you allow | Performance of a contract |
| Keeping the service secure and preventing abuse | Legitimate interests |
| Reviewing photos proposed as reference images | Legitimate interests, and your consent when you propose one |
| Essential service emails (password reset, account notices) | Performance of a contract |
| Managing your Supporter subscription, if you buy one | Performance of a contract |
| Complying with legal obligations | Legal obligation |
We do not rely on consent for the core service, except where stated (for example device permissions for camera, photo library and location, which you grant or refuse in your operating system and can change at any time).
5. Who can see what
- Your observations and life list are yours. Other people see them only according to your privacy settings.
- Followers. Agama uses one-way follows. You can require approval before someone follows you, and you can block accounts. You can also report an observation or a person; reports go to us for review.
- Your photo gallery is off by default and can be shown to followers with a single toggle in Settings.
- Photos are stored in a private location and served through short-lived signed links, so a link cannot be shared or indexed to give lasting access.
- Reference images are public. If you propose one of your photos as a species' reference image and we accept it, that image becomes visible to everyone using Agama, credited to you, under the licence you chose. This is the one case where a photo you uploaded becomes public, and it only ever happens because you proposed it. See the Terms of Service for the details.
- Trip members you invite can see the observations and photos within that shared trip.
6. Service providers and third parties
We keep this list short on purpose.
| Provider | What they do | What they receive |
|---|---|---|
| Supabase | Hosts our database, authentication and file storage | All account data and content described above |
| Photon (komoot) | Place-name search when you name a broad area | Only the place text you type. Never any observation data, and never wildlife coordinates |
| GBIF | Provides species occurrence evidence shown in Explore | Only the species and country being browsed |
| Apple / Google | App distribution, in-app purchases if enabled, and — if you choose Sign in with Apple or Google — authentication | Governed by their own privacy policies. On sign-in we receive your email, and a name if you share it. If you subscribe, they are the seller and process your payment; we never receive your card details |
| RevenueCat | Manages the Supporter subscription (receipts, renewal status) if you subscribe | An app-specific user ID and your purchase/subscription status from Apple or Google. No email, photos or observations |
Maps are drawn on your device from country outlines shipped inside the app, so no map provider is contacted and nothing about where you have been is sent anywhere to render them.
Species names, taxonomy and checklists come from GBIF. Species reference images come from iNaturalist, credited to their photographers under their own licences. Native/introduced status is checked against The Reptile Database. These are sources we read from; they do not receive your data.
We do not use third-party analytics, crash-reporting or advertising SDKs. If that ever changes, this section will be updated before it happens.
7. International transfers
Our infrastructure providers may process data outside your country, including outside the EEA. Where that happens, transfers are covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
8. How long we keep things
- Account data and content: for as long as your account exists.
- After you delete your account: your profile, observations, trips and photos are deleted from our live systems immediately, and from routine backups within 30 days.
- One exception: a photo of yours that we accepted as a species reference image stays in the app with your credit, because it has become part of the shared reference data other people rely on. You can ask us to remove it and we will act on that request — see the Terms of Service.
9. Your rights
You can export all your observations as a spreadsheet, and delete your account and everything in it, from Settings, without contacting us.
Depending on where you live, you also have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent where we rely on it. Write to support@agamaapp.com and we will respond within the time the law allows (one month under the GDPR). You may also complain to your local data protection authority; in Belgium that is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données).
10. Security
Photos are stored in a private bucket, access to database rows is enforced per user at the database level, and passwords are hashed by our authentication provider. No system is perfectly secure, but we do not keep the information that would do the most damage if it leaked — precise animal locations — because we never collect it.
11. Children
Agama is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has created an account, write to support@agamaapp.com and we will remove it.
12. Changes to this policy
If we make a material change we will notify you in the app before it takes effect. The "last updated" date at the top always reflects the current version.
Contact: support@agamaapp.com · Ramon Duran Romaña, Groot Begijnhof 40, 3000 Leuven, Belgium