Legal
Privacy policy
PigeonKeeper is a local-first record keeper. This policy explains what stays on your device and the limited technical information processed to operate accounts, synchronization, subscriptions and reliability.
Updated 10 September 2026
Who is responsible
PigeonKeeper is provided by WHO DEVELOP LTD, a company registered in England and Wales (09096989), at 124 City Road, London, EC1V 2NX. Contact [email protected] for privacy questions.
Your loft stays local-first
Bird identities, ring numbers, names, pedigrees, breeder details, notes, photographs, breeding history, care records, condition checks, race records, inventory and loft settings are stored in the app database on your device. PigeonKeeper does not require an account. If you explicitly enable optional cloud synchronization, an encrypted connection uploads the selected loft records and attachments to your private account so your trusted members and devices can remain synchronized.
Information processed by services
- Accounts and synchronization: Supabase processes the display name, email address and authentication information needed for an optional Plus account. After first sign-in, PigeonKeeper requires you to review and accept the current Terms before any cloud access or synchronization. Supabase stores the accepted Terms version and server timestamp with your account. Once accepted, synchronization starts automatically unless you must first choose between an existing cloud loft and this device’s local loft. Supabase stores the selected loft records, compressed attachments, membership roles and synchronization history needed to keep permitted devices current.
- Product analytics: PostHog receives anonymous app-interaction and screen-view events, aggregate cloud-operation counts and outcome categories, an SDK-generated installation identifier, app version, operating-system version and device type. On this website, it receives page-view and store-button events with the page language and campaign label in the link. Website measurement uses a temporary page identifier and does not set an analytics cookie or retain it between visits. It does not receive email addresses, account or loft identifiers, bird or loft names, ring numbers, notes, photographs, breeder details, precise location, file paths or advertising identifiers. GeoIP enrichment, user profiles and session replay are disabled.
- Purchases: Apple, Google and RevenueCat process subscription transactions and an anonymous app identifier so the app can check and restore access. PigeonKeeper does not receive your complete payment-card details.
- Reliability: Sentry may receive crash reports, device and operating-system information, app version, performance diagnostics and a pseudonymous identifier. Reports are filtered and must not include your bird records, photos, notes, loft name or ring numbers.
- Weather: when you explicitly capture conditions for a release point, its latitude and longitude are sent over an encrypted connection to Open-Meteo solely to return the current weather and wind. PigeonKeeper does not send your loft records with this request.
- Support: if you email us, we receive the address and information you choose to include.
We do not sell personal information, show third-party advertising, build advertising profiles or use cross-app tracking.
Photos, camera, location and notifications
Photo-library and camera access is used only when you choose a bird image or scan a PigeonKeeper passport. Location is requested only when you choose to capture release-point conditions or calculate a distance. The selected coordinates remain in your local loft record; the weather request is described above. Notifications are used for the reminders you enable. These permissions can be changed in your device settings.
Sharing, retention and deletion
Your loft information leaves the app only when you choose to synchronize, export, back up, print or share it. You control the destination and any copies created there. Local records remain until you delete them or remove the app. Account and synchronized cloud data remain until the account or relevant cloud data is deleted, subject to short operational backups and legal requirements. Anonymous purchase and diagnostic information follows the retention controls of the relevant provider. You can erase local records from Settings → Data, delete an optional cloud account from Account & sync, or use our data deletion page.
Your choices and rights
You can use the core local record without an account, refuse optional permissions, export your records, delete local data and contact us about diagnostic or support information. Depending on where you live, you may also have rights to access, correct, erase, restrict or object to processing and to complain to your data-protection authority.
Processors and changes
Technical services may process information in other countries using lawful transfer safeguards. Relevant providers include Apple, Google, RevenueCat, Sentry and Open-Meteo. We may update this policy when the app or legal requirements change; the date above identifies the current version.