Privacy
Privacy Policy
This policy describes how the ARED Field mobile and web apps process information. Where this page and the website policy at ared.design/privacy differ, the website policy prevails for website accounts.
Data we process
- Account: email, display name, authentication tokens, optional profile bio and avatar.
- Library: saved records, bookmarks, collections, notes, and search history when you use those features (synced when signed in).
- Location: approximate and precise coordinates while the app is in use, if you grant permission — used for nearby records, place search, and camera matching.
- Camera / photos: images you capture or choose for “Read this place” matching; profile avatars if you upload one.
- App activity: in-app events such as opening records or sharing (stored on ARED servers for product operation).
- Device / session: app session tokens and a device identifier used for sync and security.
- Email communications: transactional messages (verification, password reset, security) and optional newsletter if you consent.
Photos and AI analysis
Photographs used for place matching are processed temporarily on ARED servers and deleted after analysis (typically within about one hour) unless you explicitly save a private field note on your device. When AI-assisted observation is enabled in production, image content (and related place context) may be sent to Google Gemini solely to help identify place/heritage context. We do not sell photo data. Avatar images you choose for your profile are stored until you change or delete them.
Location
Location is requested only while you use nearby, map, or camera-matching features. We do not request background location. You may deny permission and continue with manual place search.
Accounts, guest mode, and sync
Guest mode lets you browse Explore, Map, Listen, and use camera discovery with OS permissions. Sign-in enables library sync, profile management, and account deletion. Signed-in library data may sync with your ARED website identity when that bridge is configured.
Processors and sharing
We use service providers under agreements that restrict misuse of personal data. Depending on configuration, these may include:
- Vercel — hosting and API delivery
- Neon (Postgres) — application database
- Supabase — authentication and optional avatar storage
- Brevo — transactional email and optional newsletter
- Google — Sign in with Google (OAuth) and Gemini AI when enabled
- Apple — Sign in with Apple when enabled
- Protomaps / OpenStreetMap-family geocoders — map tiles and place search
- Cloud object storage (e.g. Supabase Storage, Cloudflare R2, or Vercel Blob) — avatars when configured
We do not sell personal data. Field builds audited for store submission do not include advertising SDKs or Firebase Analytics.
Retention
- Temporary match images: deleted after analysis, with a short fallback TTL.
- Account and library data: until you delete items or your account.
- Operational logs: short retention for security and reliability.
Your rights and deletion
Depending on your jurisdiction you may request access, correction, deletion, or export. Delete your account in the app under Profile → account / delete, or use Account deletion. Contact: support@ared.design or hello@ared.design.
Children
ARED Field is not directed at children under 13 (or the minimum age required by local law).
Security
Data in transit is protected with HTTPS. Access to account APIs uses authenticated sessions (bearer tokens).
Changes
We will update this policy when processing changes materially.