Privacy Policy
The short version
- Wingmark stores your account details and the sightings you log, so it can show them on your map on any device you sign in to.
- Your sightings are private. No one else using Wingmark can see them.
- There are no ads, no third-party analytics tools and no tracking code, and your data is never sold. We only count anonymous totals, such as which birds are logged most.
- You can download your data or delete your account at any time in the app’s Settings. Deleting your account erases your data.
1. Who runs Wingmark
Wingmark is made by Bilgesu Çakır, an individual developer based in Istanbul, Türkiye. We are responsible for your personal data (the “data controller” under Türkiye’s Personal Data Protection Law, KVKK, and the EU General Data Protection Regulation, GDPR): we decide what data Wingmark collects and why, and we put in place the measures that protect it. In this policy, “we” means Wingmark and its developer.
Contact: support@wingmarkapp.com
2. Data we collect
Account details
- Your email address and username.
- Your password, stored only as a secure one-way hash. We can’t see or recover it.
- Your first and last name, if you choose to add them.
- Your profile picture: either one of the built-in avatars, or a photo you upload.
- Your favourite species, language setting.
- Whether you’ve verified your email address, and when you last signed in.
- Which version of this policy you accepted, and when.
Sightings you log
- The species, or a name you give it, and how sure you are of the identification.
- Life stage, sex, and whether the bird is a pet.
- The date and time of the sighting.
- The location: the exact map coordinates where you place the sighting, and a place name.
- Your notes and, if you add one, a photo.
- The badges you earn, which are worked out from your sightings.
Photos
When you add a photo, the app reads its location and capture time on your phone to fill in the sighting form for you. The photo is then uploaded and resized, and the server removes its embedded metadata, including GPS location. The only location saved is the one you confirm for the sighting. A small preview image (about 400 pixels wide) is also created and stored with each photo. Uploaded photos and their previews are stored with our file-storage provider (see Service providers).
Your device’s location
The app asks for your location only while you’re using it, and only when you add a sighting or tap the button to show where you are. It is used to suggest where the sighting happened and is stored only as part of a sighting you save. If you don’t allow location access, you can place sightings on the map by hand.
Technical data
To protect accounts from abuse, the server briefly keeps your IP address in memory to limit repeated attempts, for example at signing in. It is not saved in the database. Our hosting provider may also keep standard server logs, such as IP address and time of request, to run and secure the service.
What we don’t collect
Wingmark has no third-party analytics or crash-reporting tools, no advertising and no third-party tracking code. It does not access your contacts, and it does not use your device’s advertising identifier. We count anonymous totals ourselves, as described in section 4, from sightings you have already saved; no outside analytics service is involved.
3. How we use it
- To run the app: store your sightings, show them on your map and list, keep them in sync across your devices, and award badges. This is needed to provide the service you signed up for.
- To send emails: verifying your email address, password reset codes, and notices when your password changes or your account is deleted. We may email you when you complete all badges. We don’t send marketing emails.
- To keep accounts safe: limiting repeated sign-in attempts, and checking new passwords against lists of known leaked passwords (see section 6). This is our legitimate interest in protecting you and the service.
- To answer you when you contact support.
Location and camera access are only used if you allow them in iOS, and you can withdraw that permission at any time.
4. Anonymous usage statistics
To understand how Wingmark is used, we count anonymous totals from the sightings people already save. For example, which birds are logged most, how many sightings are logged each day or week, and how many people were recently active or are new.
These totals are worked out when we look at them, from data we already hold, and are not stored separately. Location is used only at a coarse level, in areas about 110 km wide. No email address, name, user ID, device or exact location is part of these numbers. A bird, area or group is only counted when at least 5 different people contribute, so no one can be singled out.
5. Who can see your data
Your sightings, notes and profile are visible only to you when you’re signed in. Wingmark has no public profiles, feeds or sharing.
Uploaded photos are kept in a private storage bucket and served by our server at long, random web addresses that are not listed or searchable anywhere. The app only shows them to you, but anyone who had the exact address of a photo could open it.
We never sell your personal data or share it for advertising. We only disclose it if the law requires us to.
6. Service providers
A few providers process data on our behalf to run Wingmark. They may only use it to provide their service to us, and we only work with providers that protect it to the same standard as this policy. Some are located outside Türkiye; where data is transferred abroad, it is done with the safeguards the law requires.
- Render hosts the Wingmark server, in Frankfurt, Germany.
- MongoDB Atlas hosts the database where your account details and sightings are stored, on Amazon Web Services in Frankfurt, Germany.
- Cloudflare R2 stores the photos you upload (sighting photos and profile pictures) and a small preview of each, in the European Union. It receives only these image files, and no email address, sightings, notes or account data. Cloudflare only processes this data to provide storage, and its data processing terms apply.
- Brevo sends our emails, such as email verification, password reset and the email we may send when you complete all badges. It receives your email address and the content of those emails.
- Have I Been Pwned is used to check whether a new password has appeared in known data leaks. Only the first five characters of a scrambled (hashed) version of the password are sent, never the password itself or anything that identifies you.
Some features make your phone connect directly to other services, which then see your IP address. Their own privacy policies apply:
- Apple Maps shows the map and turns coordinates into place names.
- xeno-canto.org provides the bird sound recordings in the species guide.
7. How long we keep it
We keep your data until you delete your account. A sighting you delete, or a photo you remove, is deleted straight away, including the photo from storage.
When you delete your account, your profile, sightings, notes, badges, settings, consent records and sign-in sessions are removed from the live database immediately, your uploaded photos are deleted from storage, and we email you to confirm. We currently keep no database backups, so deleted data is not retained in backups.
An account that has had no activity for 2 years is deleted. One week before that happens, we send a warning email to the address on the account. If there is still no activity by then, the account is deleted and its data is erased in the same way as when you delete your account yourself.
If you sign up but never confirm your email address, the unconfirmed account is deleted after 7 days. We don’t send you an email when this happens.
Password reset codes expire after 15 minutes. Sign-in sessions on a device end after 30 days without use, or straight away when you sign out.
8. Your choices and rights
- See and download your data: Settings → Your Data → Download My Data gives you a copy of everything we store about you.
- Correct it: edit your profile and sightings in the app at any time.
- Delete it: delete single sightings, or delete your whole account in Settings → Your Data → Delete Account. You don’t need to contact us.
- Withdraw permissions: turn off location or camera access in the iOS Settings app.
- Sign out everywhere: Settings → Account → Log Out of All Devices ends every session at once.
Under KVKK (Article 11) and the GDPR, you also have the right to ask what data we hold about you and how it is used, to have it corrected or erased, to object to its processing, and to have it transferred. To use any of these rights, email support@wingmarkapp.com; we will reply within 30 days. You can also complain to Türkiye’s Personal Data Protection Authority (KVKK) or, if you live in the EU, to your local data protection authority.
9. Children
You must be at least 13 years old to use Wingmark. It is not intended for children under 13, and we don’t knowingly collect their data. If we learn that an account belongs to a child under 13, we will delete the account and its data. If you think a child under 13 has created an account, contact us and we’ll delete it.
10. Security
All traffic between the app and the server is encrypted with HTTPS, and the database is encrypted at rest by its provider. Uploaded photos are kept in a private storage bucket that only our server can access. Passwords are stored only as secure hashes. On your phone, sign-in tokens are kept in the iOS Keychain. Sessions are short-lived, repeated sign-in attempts are limited, and only the developer can access the servers.
11. Changes to this policy
When this policy changes, we’ll update the date at the top. If a change affects how your data is used, the app will show you the new version and ask you to accept it before you continue.
12. Contact
Questions about privacy or your data: support@wingmarkapp.com
Bilgesu Çakır, Istanbul, Türkiye
