OmniDex Privacy Policy

Naturalist's Field Guide · Local-first · Privacy-respecting
Effective: June 17, 2026 Version: 1.0 Last reviewed by maintainer

OmniDex ("we", "our", "the App") is a naturalist field-guide app. This policy explains what data the App collects, why, how it is stored, and the choices you have. The App is local-first: by default your captures, location, and analytics stay on your device. Cloud sync is opt-in.

1. Data We Collect

1.1 Account & Profile

1.2 Capture Media & Sensor Evidence

1.3 Collection, Achievements & Sharing

1.4 Purchases

1.5 Analytics

2. Why We Use It

3. Location Handling (Privacy-First)

Location is requested only when you capture or publish a record. Raw coordinates are used solely for on-device city-level reverse geocoding, then stripped before the capture record is stored. Stored location data is limited to a city/region label and coarse geohash. Shared payloads and public surfaces contain only a city-level or hidden label; the App does not expose a precise spot label.

4. AI Vision Processing

To identify a specimen we send the photo (and minimal context) to a configured vision provider. The default is a self-hosted MiMo endpoint; the fallback is Google Gemini. Photos are processed to return a recognition result and are not retained by us beyond the recognition call. Provider data handling is governed by the provider's own privacy policy (MiMo / Google).

5. Children

The App is rated 4+. It does not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact us and we will delete it.

6. Tracking & Advertising

OmniDex does not track you across other companies' apps or websites, and does not use a third-party advertising or attribution SDK. We do not show an App Tracking Transparency prompt. If we ever add such an SDK, we will update this policy and request consent first.

7. Third-Party Services

Each provider processes only the minimum data needed for the feature you use. See their privacy policies for retention and security details.

8. Data Retention

Local data remains on your device until you delete it via the App's "Delete Account" / "Delete Capture" controls. Cloud-synced data (Phase 2) is retained while your account is active; closing your account triggers a server-side deletion within 30 days, except where retention is required by law (e.g. tax records for paid subscriptions).

9. Your Controls

10. Security

Data in transit is encrypted via HTTPS/TLS. Local storage uses the platform's application sandbox. Cloud data (Phase 2) is protected by Supabase Row Level Security; only the row owner can read or write their own records.

11. International Transfers

Cloud providers (Supabase, RevenueCat) may process data in regions outside your home country. We rely on standard contractual clauses and provider certifications for any such transfer.

12. Changes to This Policy

We will post material changes in the App and bump the version number above. Continued use after the effective date constitutes acceptance.

13. Contact

Privacy questions, data requests, or complaints:
Email: privacy@omnidex.app
Entity: OmniDex (个体/工作室, to be filled by legal entity registration)
Response window: within 30 days.

14. Legal Bases (EEA / UK)

Where applicable, we rely on: