Privacy

Your Privacy Policy

No ads. No tracking across other apps. We never sell your data. Here is exactly what we collect, why, and how to get it back or get rid of it.

Effective 16 April 2026 Last updated 31 July 2026
Back to WunderWild

This Privacy Policy explains how Wunderwild ("WunderWild", "we", "us", or "our") collects, uses, shares, and protects information when you use the WunderWild mobile application (the "App"). By creating an account or using the App, you agree to this Privacy Policy. If you have questions or want to exercise any of the rights described below, contact us at privacy@wunderwild.app.

1Who we are

WunderWild is a mobile application that identifies wild and domestic animals from photos you capture or upload. We use artificial intelligence to analyze images and return information about the species, plus optional enrichment content such as descriptions, geographic regions, and safety warnings.

The App is available on the Apple App Store and Google Play, and uses Supabase as our backend data processor and OpenAI as our AI processor. See Section 5 for the full list of third parties.

2Information we collect

2.1 Information you provide to us

  • Account information. When you sign up, we collect your email address and a display name. If you sign in with Apple or Google, we receive your email address and, where permitted, your name from the identity provider. If you use email sign-up, we also collect an encrypted hash of your password (we never store plaintext passwords).
  • Profile information. Optional profile photo, a short bio (if you add one), and any preferences you configure in Settings.
  • Photos you upload. Every photo you capture or select from your device's gallery to identify an animal. Each image is associated with the identification result produced by our AI.
  • Captions and user-generated content. Any captions, notes, or other text you attach to a snap, and any content you choose to make public on the community feed.
  • Reports and feedback. Information you submit when you report a snap, a user, or an incorrect identification, plus messages you send us directly.

2.2 Information we collect automatically

  • Precise location. If you grant permission, the App captures the GPS coordinates of where a photo was taken and performs reverse geocoding to obtain a human-readable place name. Location is used to improve identification accuracy and to show where you captured each snap. You can deny or revoke location permission at any time in your device settings; identification still works without it.
  • Approximate location. Derived from GPS coordinates (e.g. country, region) for display on your snap history and community feed.
  • Device and technical data. Basic device identifiers (operating system, app version, device model), authentication tokens, and crash-related diagnostics when the App is unable to complete a request. Crash diagnostics are processed by Sentry (see Section 5) and are linked to your account ID only — never your email address, and never a screenshot of your screen.
  • Usage data. Which tabs and screens you open, the number of snaps and identifications you have made, streak counts, and achievement progress, stored to power in-app features such as your Dex, achievements, and streaks.
  • Analytics events. We use PostHog (see Section 5) to understand how the App is used: app lifecycle events (app opened, backgrounded, installed, updated) and in-app product events. These events are linked to your account ID only — never your email address. We do not use session recording, and analytics never includes your photos or precise location.
  • Subscription and purchase data. If you subscribe, RevenueCat (see Section 5) records the purchase and its receipt data and links them to your account ID, so we can grant and restore access to paid features. We never receive or store your payment card details — payment is handled entirely by the App Store or Google Play.

2.3 Information we do NOT collect

  • We do not use advertising identifiers (IDFA, AAID).
  • We do not track you across other companies' apps or websites.
  • We do not sell your personal information.
  • We do not knowingly collect information from children under 13 (or the equivalent minimum age in your jurisdiction). See Section 9.

3How we use your information

We use the information we collect to:

  1. Identify animals. Each photo you submit is sent to our backend and then to OpenAI's vision model to produce an identification. A second text-only call to OpenAI enriches the record with a description, regions, and any safety tags.
  2. Save your captures. Snaps, identified animals, tags, and regions are stored so you can view your personal Dex, animal detail pages, streaks, and achievements.
  3. Operate the community feed. If you mark a snap as public, other users can view it on the community feed and in aggregate animal galleries.
  4. Secure your account and the service. Authenticate you, prevent fraud, enforce our Terms of Service, moderate user-generated content, and investigate reports.
  5. Communicate with you. Send you service messages (password resets, security alerts, account-deletion confirmations). We do not send marketing email without your opt-in.
  6. Improve the App. Usage and analytics information (see Section 2.2) helps us improve identification quality, UI, and reliability. We analyze this data in aggregate; individual-level events are used only to diagnose problems and understand feature usage, never for advertising.
  7. Comply with law. Respond to lawful requests, enforce our agreements, and protect the rights, property, or safety of our users or the public.

4How your photos and location are used by AI

Because the AI flow is the core of WunderWild, we want to be explicit about it.

  • When you request an identification, the image is uploaded to our backend (Supabase Storage), and a copy is sent to OpenAI's API through a server-side edge function. The image is analyzed by a vision model (currently gpt-5.6-luna class). The resulting species/subspecies guess is returned to the App.
  • If the animal has not yet been enriched in our database, a second, text-only call is made to OpenAI (currently gpt-5.6-luna class) to generate the description, geographic regions, and safety tags. No image is sent in this second call.
  • Your location, if available, is included in the sanitized prompt sent to OpenAI for the identification call. We remove street-level precision before sending; only the approximate country/region is included to improve accuracy. Reverse geocoding is performed by Apple (on iOS) or Google (on Android) platform APIs, not by OpenAI.
  • OpenAI acts as our data processor for these requests. Per OpenAI's API data usage policy, data submitted through their API is not used to train OpenAI's models by default. OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring, after which they are deleted. See openai.com/policies/api-data-usage-policies for details.

Important — accuracy disclaimer. AI identifications can be wrong. The App is for educational and recreational purposes. Never approach, touch, handle, consume, or otherwise act on an identification without verifying with a qualified expert in person. Some wild animals (venomous, aggressive, electrically dangerous) can cause serious injury or death. Always err on the side of caution.

5Who we share information with

We share limited information with the following categories of third parties, each of whom processes data on our behalf or provides infrastructure that we rely on:

ProcessorPurposeData shared
Supabase (Supabase, Inc.) Authentication, database, file storage, and server-side edge functions Account info, snaps and images, identification and enrichment records, reports, auth tokens
OpenAI (OpenAI, L.L.C.) AI animal identification and enrichment Uploaded photo, approximate location, characteristics text
Apple (Apple Inc.) Sign in with Apple, App Store services, reverse geocoding on iOS Apple ID email/name (when you use Sign in with Apple), device identifier
Google (Google LLC) Google Sign-In, Play Store services, reverse geocoding on Android Google account email/name (when you use Google sign-in), device identifier
RevenueCat (RevenueCat, Inc.) Subscription and in-app purchase management Account ID, purchase history, receipt data
Sentry (Functional Software, Inc.) Crash and error reporting Account ID, device and OS info, app version, technical crash diagnostics
PostHog (PostHog, Inc.) Product analytics Account ID, device and OS info, app version, app lifecycle and in-app usage events

We do not share your information with advertisers, data brokers, or marketing platforms. We do not sell personal information.

We may disclose information if we reasonably believe we are required to do so by law, subpoena, or court order, or to protect the rights, property, or safety of WunderWild, our users, or others.

If WunderWild is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you and provide an opportunity to delete your account before the transfer takes effect.

6Where we store and process your data

Your data is stored by Supabase in data centers operated by their sub-processors (primarily in the United States and the European Union, depending on your region). OpenAI processes requests in the United States. If you access the App from outside these regions, your data will be transferred across international borders. Where required, we rely on Standard Contractual Clauses (for EU/UK residents) or equivalent mechanisms to ensure lawful cross-border transfers.

7How long we keep your data

  • Account data, snaps, and enrichment records are retained for as long as your account is active.
  • Deleted snaps are removed from our database and our storage bucket immediately. Cached copies on CDNs expire within a few hours.
  • Deleted accounts. When you delete your account (see Section 10), we delete your profile, all your snaps and uploaded images, your streaks and achievements, your reports, and your authentication record from our systems, typically within 7 days and at most within 30 days. Some records may be retained for longer in backups or where required by law (e.g. tax or fraud-prevention records); those copies remain protected by this Privacy Policy until they are aged out.
  • OpenAI-side copies of API requests are deleted by OpenAI within 30 days per their API data usage policy, independent of our own deletion.

8Your rights and choices

Depending on where you live, you may have some or all of the following rights regarding your personal information:

  • Access — request a copy of the information we hold about you.
  • Correction — ask us to update information that is inaccurate or incomplete (you can also edit your profile directly in Settings).
  • Deletion — request that we delete your account and associated data (see Section 10).
  • Portability — request your data in a portable, machine-readable format.
  • Objection or restriction — object to or restrict certain kinds of processing.
  • Withdrawal of consent — where we rely on consent, you can withdraw it at any time by revoking permissions (camera, photos, location) in your device settings or by deleting your account.

To exercise any of these rights, email us at privacy@wunderwild.app from the email address linked to your account. We will respond within the timeframes required by applicable law (typically 30 days).

California residents (CCPA / CPRA): you have the right to know what categories of personal information we collect and share, to request deletion, and to opt out of "sales" or "sharing" of personal information. We do not sell or share personal information in the sense defined by CCPA. You also have the right to non-discrimination for exercising your rights.

EEA, UK, and Swiss residents (GDPR): our legal bases for processing are (a) performance of a contract (delivering the App), (b) legitimate interests (security, fraud prevention, service improvement), (c) consent (where required, e.g. camera, photos, and location permissions), and (d) legal obligation.

You also have the right to lodge a complaint with a supervisory authority in your country of residence.

9Children's privacy

WunderWild is not directed to children under 13 (or the equivalent minimum age in your jurisdiction — 16 in parts of the EU, 14 in some regions). We do not knowingly collect personal information from children below that age. If you believe a child has provided us with personal information, contact us at privacy@wunderwild.app and we will delete the account and associated data as quickly as we can.

Users aged 13–17 who use the App should do so with a parent or guardian's permission and should avoid posting publicly identifiable information (their face, home location, school).

10Deleting your account

You can delete your account from inside the App:

  1. Open Settings.
  2. Tap Delete account.
  3. Confirm the deletion.

Deletion removes your profile, all your snaps and uploaded images, your streaks, achievements, likes, reports, and your authentication record. Deletion is permanent and cannot be undone.

If you are unable to access the App, you can also request deletion by emailing privacy@wunderwild.app from the address linked to your account, or via our public deletion page at wunderwild.app/delete-account.

11Security

We use industry-standard measures to protect your information, including HTTPS/TLS in transit, encrypted storage at rest, row-level security on our database, server-side API key handling (no third-party API keys are shipped in the App binary), and least-privilege access for our team.

No system is 100% secure. If we ever become aware of a security incident that affects your information, we will notify you as required by law.

12Third-party services and links

The App may link to external websites (for example, our privacy policy URL, our support page, or a species' Wikipedia article). Those sites have their own privacy practices, and we are not responsible for them. Please read their policies before providing any information.

13Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top and, where required, notify you in the App or by email. Continued use of the App after an update constitutes acceptance of the revised policy.

14Contact

If you have any questions, concerns, or requests related to this Privacy Policy:

PostalNorte 9-A #5030, Mexico City, Mexico
WunderWild is operated by its developer, Wunderwild.