Privacy Policy
Digital Beekeeping Journal ("we", "the app", "the service") is committed to protecting your privacy. This policy explains what data we collect, how it is used, where it is stored, and what rights you have regarding your data.
Important: The app is designed offline-first: it works fully without an internet connection, and all data is saved on your device first. When an internet connection is available, data may be automatically synchronized with a cloud backup server (Cloudflare), as described below, to protect your data from loss and allow restoring it on another phone. By using this app, you agree to the collection and use of the data described in this policy.
1. Data We Collect
1.1 Data You Provide
- Apiary names and locations — name, location description
- Hive data — name, health status, queen status, queen birth year, color code, frame count, notes
- Beekeeping activities — activity type (inspection, harvest, treatment, feeding, frame change), date, quantities, treatment details, notes
- Inventory — equipment and consumables (name, quantity, category)
- Varroa records — checks and treatments against varroa mites
- Notification preferences — inspection frequency, treatment alerts, health alerts, queen age threshold
- Theme preference — light/dark theme
- Contact details (contact form) — if you use the contact form in Settings → About, your name, email address, selected category (bug, suggestion, question, other) and message are transmitted. These are used exclusively to respond to you and to improve the app
1.2 Location Data (GPS)
- GPS coordinates (latitude, longitude) — saved only if you press the "GPS location" button when creating/editing an apiary
- The app does not access location in the background
- GPS coordinates are part of the apiary data and, if cloud sync is enabled, are transmitted together with the rest of the data to the backup server (Cloudflare), as described in section 2.2
1.3 Device Identifiers
- Anonymous device identifier (UUID) — randomly generated, not linked to your personal identity
- Android identifier (ANDROID_ID) — stored as a hash (SHA-256), never in raw form
- Recovery code — a code generated by the app that you can use to restore your data on another phone
These identifiers do not contain names, email addresses, or other personal data.
1.4 Usage and Diagnostic Data
- Crash reports (Firebase Crashlytics) — on an error, anonymous technical information is collected (error type, device model, app version) to help fix issues
- Push notification tokens (FCM) — a technical identifier generated by Google's notification service, used exclusively to deliver push notifications to your device
- Purchase data (Adapty) — when activating Premium, the Adapty payment processor confirms your subscription/one-time purchase status. The app never sees or stores your bank card details
2. How Data Is Stored
2.1 Local Storage
All data is saved on your device first. The app uses:
- Local SQLite database (Drift) — for apiaries, hives, activities, inventory and settings. The database file is stored in the app's private directory
- SharedPreferences — for theme preferences, premium status and the sync queue
2.2 Cloud Sync (Backup)
The app includes a cloud sync service that may transmit data to an external server to protect it against loss and allow restoration on another phone:
- Provider: Cloudflare (D1 service — managed database, and KV — rate-limit storage), through the app's cloud Worker
- What is transmitted: all data entered in the app (apiaries, hives, activities, treatments, harvests, inventory, varroa records, notification settings), including apiary GPS coordinates, together with the anonymous device identifier (UUID)
- When: automatically, at regular intervals, when the device has an internet connection. Local data keeps working without internet
- Why: automatic backup, sync between multiple devices, and data restoration after reinstalling or losing the phone (via recovery code)
- Protection in transit: all transmissions use HTTPS; API access is protected with an authentication key and limited by rate limiting per IP address and per user
- Disabling: there is currently no option to disable sync from the interface; data is transmitted only to Cloudflare, not to other parties
2.3 Access to Data
- Data is accessible by the app on the device where it is stored and, when sync is enabled, by the Cloudflare server mentioned above
- Data is never sold, rented, or shared with advertisers or other companies
- No employee or third party has access to your data beyond the technical processing required to run the backup service
2.4 Backup and Export
You can manually export your data in CSV, JSON or PDF format through the export feature in the Settings menu. The exported file is saved on your device and can be shared through the system's share sheet (e.g., email, Google Drive). Transferring these files is at your own initiative.
3. How We Use the Data
3.1 Purpose of Data Collection
- Managing apiaries and hives — data is used exclusively to let you keep track of your apiaries, hives and beekeeping activities
- Notifications — reminders and alerts help you not to miss inspections, treatment withdrawals or health issues
- Statistics — activity and harvest data is aggregated to display charts in the statistics section
- Backup and restoration — cloud sync protects your data against loss and allows restoring it on another phone via recovery code
- Improving the app — anonymous crash reports help us identify and fix bugs
3.2 Data Sharing
Your data is never sold or shared with advertisers. Data is transmitted only to the technical providers required for the app to work:
- Cloudflare — backup storage (D1 database) and API delivery
- Google Firebase — push notifications (Firebase Cloud Messaging) and anonymous crash reports (Crashlytics)
- Adapty — verifying your Premium subscription status
- Telegram — messages sent through the contact form (name, email, message) are forwarded to the developer via the Telegram messaging service, exclusively to respond to the user and improve the app
- OpenStreetMap / Google Maps — displaying the apiary map and directions (only at your request, by opening the map)
3.3 Data Retention
Local data is stored on the device for as long as it is kept in the app. Cloud backup data is retained to allow restoration, including after reinstalling the app on the same or a new phone. To request deletion of cloud backup data, contact us at the email address below.
4. System Permissions
4.1 Location
- ACCESS_FINE_LOCATION — used to obtain precise GPS coordinates when creating/editing apiaries (only when pressing the "GPS location" button)
- ACCESS_COARSE_LOCATION — used as a fallback when fine location is unavailable
- Location is never accessed in the background
4.2 Notifications
- Local notifications — reminders and alerts are scheduled locally on the device and displayed by the system
- Push notifications (FCM) — certain alerts (for example, treatment withdrawal) are also scheduled on the backup server, which delivers them via Firebase Cloud Messaging, even when the app is closed
- To work correctly, the app asks for permission to send and display notifications
4.3 Other Permissions
- Camera — for QR code scanning and attaching photos to hives (only at your request)
- Microphone — for voice dictation (Premium, only at your request)
- Internet — for backup sync and push notifications
5. Data Security
- Data is stored in a local database (SQLite) with access restricted to the app
- Transmissions to the backup server use HTTPS exclusively
- The sync API is protected with an authentication key and rate limiting
- The Android identifier is stored only as a hash, never in raw form
- Passwords and credentials are not stored in the app
- The app does not use cookies, tracking pixels or targeted advertising
6. Third-Party Services
The app interacts with the following third-party services:
- Cloudflare — data backup (D1) and sync API
- Google Firebase — push notifications (FCM) and crash reports (Crashlytics)
- Adapty — processing Premium purchases
- Telegram — receiving messages sent through the contact form (name, email, message); messages are sent only at the user's initiative, through the form
- OpenStreetMap — displaying the apiary map (when the map is opened)
- Google Maps — when opening directions to an apiary, the coordinates are transmitted as a URL to the Google Maps app (at your request)
- Email client — when tapping the email address, the email client opens with the address pre-filled; no content is sent automatically
- iwan.ro — when tapping the website, the site opens in the browser
Each third-party service applies its own privacy policy. We recommend you review them.
7. Google Play Data Safety
- Data collection: user-provided data (apiaries, hives, activities), GPS location (on explicit request), contact data (name, email, message — only through the contact form), device identifiers (UUID, hashed Android ID, FCM token), diagnostic data (anonymous crashes), purchase data (Premium status)
- Data sharing: data is transmitted to Cloudflare (backup), Google Firebase (push notifications, crashes), Adapty (purchases) and Telegram (contact form messages) for essential app functionality; it is never shared with advertisers
- Data deletion: data can be deleted by the user from the app interface or by uninstalling; to delete the cloud backup, contact us by email
8. Your Rights
- You have the right to access, modify and delete your data at any time from the app
- You have the right to request an export of all your data in CSV or JSON format
- You have the right to revoke location, notification, camera and microphone permissions at any time from your phone settings
- You have the right to request deletion of your data, including the cloud backup, by contacting us at the email address below
GDPR Rights: As an EU user, you have rights to access, rectification, erasure ("right to be forgotten"), restriction, portability, and objection. Contact us to exercise these rights.
9. Changes to This Policy
We will update this policy periodically to reflect new app features, changes in applicable law, or user feedback. We will notify you of significant changes through an in-app notification or email (if provided).
10. Contact
11. Applicable Legislation
- GDPR — General Data Protection Regulation (EU)
- LGPD — Romanian personal data protection law
- CCPA — California Consumer Privacy Act (USA)
Last updated: August 13, 2026
Version 1.6.4