OmniDex Privacy Policy
OmniDex ("we", "our", "the App") is a naturalist field-guide app. This policy explains what data the App collects, why, how it is stored, and the choices you have. The App is local-first: by default your captures, location, and analytics stay on your device. Cloud sync is opt-in.
1. Data We Collect
1.1 Account & Profile
- Display handle, profile title, and home region (stored locally in MVP).
- If you later sign in to a cloud account: email and authentication token.
1.2 Capture Media & Sensor Evidence
- Photos you submit for AI identification (stored locally on your device).
- Capture timestamp, approximate location, camera metadata, motion/depth confidence, and anti-fraud signals (computed on-device).
1.3 Collection, Achievements & Sharing
- Catalog progress, species templates, rarity tier, valuation estimate, achievements, and leaderboard score (stored locally).
- Share events: poster creation, QR payloads, and deep-link routing metadata. Payloads contain only what you choose to publish.
1.4 Purchases
- Subscription status and entitlement are validated with Apple's StoreKit and, if configured, RevenueCat. We receive a transaction receipt; we do not collect your full payment-card details — those are handled by Apple.
1.5 Analytics
- On-device KPI events: session starts, D1 retention, capture_created, catalog_lit, share_created, paywall_shown, and dex completion percentage. These are computed locally and do not leave your device unless you enable a future cloud-aggregation opt-in.
2. Why We Use It
- Identify real-world collectibles with AI-assisted recognition.
- Verify real-time capture and reduce gallery/screenshot fraud.
- Build private collection history, approximate geographic footprints, achievements, and rankings.
- Generate traceable educational share posters and encyclopedia links.
- Provide and bill optional Pro subscriptions.
- Measure retention, share rate, and catalog completion.
3. Location Handling (Privacy-First)
Location is requested only when you capture or publish a record. Raw coordinates are used solely for on-device city-level reverse geocoding, then stripped before the capture record is stored. Stored location data is limited to a city/region label and coarse geohash. Shared payloads and public surfaces contain only a city-level or hidden label; the App does not expose a precise spot label.
4. AI Vision Processing
To identify a specimen we send the photo (and minimal context) to a configured vision provider. The default is a self-hosted MiMo endpoint; the fallback is Google Gemini. Photos are processed to return a recognition result and are not retained by us beyond the recognition call. Provider data handling is governed by the provider's own privacy policy (MiMo / Google).
5. Children
The App is rated 4+. It does not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact us and we will delete it.
6. Tracking & Advertising
OmniDex does not track you across other companies' apps or websites, and does not use a third-party advertising or attribution SDK. We do not show an App Tracking Transparency prompt. If we ever add such an SDK, we will update this policy and request consent first.
7. Third-Party Services
- Apple StoreKit / RevenueCat — subscription billing and receipt validation.
- MiMo (default) / Google Gemini (fallback) — AI image recognition.
- Apple MapKit / iOS reverse geocoding — on-device city-level reverse geocode.
- Supabase (Phase 2, opt-in) — cloud sync, leaderboard, and social feed.
Each provider processes only the minimum data needed for the feature you use. See their privacy policies for retention and security details.
8. Data Retention
Local data remains on your device until you delete it via the App's "Delete Account" / "Delete Capture" controls. Cloud-synced data (Phase 2) is retained while your account is active; closing your account triggers a server-side deletion within 30 days, except where retention is required by law (e.g. tax records for paid subscriptions).
9. Your Controls
- Delete account and associated capture records.
- Delete individual captures and share events.
- Hide exact location by default.
- Export personal collection history (planned Phase 2).
- Report public content and block users (when community feed is enabled).
- Restore or cancel subscriptions via Apple's standard subscription settings.
10. Security
Data in transit is encrypted via HTTPS/TLS. Local storage uses the platform's application sandbox. Cloud data (Phase 2) is protected by Supabase Row Level Security; only the row owner can read or write their own records.
11. International Transfers
Cloud providers (Supabase, RevenueCat) may process data in regions outside your home country. We rely on standard contractual clauses and provider certifications for any such transfer.
12. Changes to This Policy
We will post material changes in the App and bump the version number above. Continued use after the effective date constitutes acceptance.
13. Contact
Privacy questions, data requests, or complaints:
Email: privacy@omnidex.app
Entity: OmniDex (个体/工作室, to be filled by legal entity registration)
Response window: within 30 days.
14. Legal Bases (EEA / UK)
Where applicable, we rely on:
- Contract — to provide the App and Pro features you request.
- Consent — for optional cloud sync and any future SDK requiring ATT.
- Legitimate interest — to prevent fraud and abuse.