Privacy Policy

Effective date: [effective date] · Last updated: [effective date]

Applies to the Snake Identifier mobile app (“Snake Identifier”, the “App”) and the website at snakeidentifier.bulpara.com.

Snake Identifier is published by Bulpara Teknoloji Limited Şirketi (“Bulpara”, “we”, “us”, “our”). This policy explains what personal information the App collects, why, who processes it on our behalf, how long we keep it, and the choices and rights you have. It is governed by the laws of [jurisdiction] and is written to be consistent with Apple’s App Store requirements, the EU/UK GDPR, and the California Consumer Privacy Act as amended (CCPA/CPRA).

Snake Identifier is an educational snake-identification aid. It is not a medical device, a diagnostic tool, or an emergency service, and it never confirms that a snake is safe or harmless. Nothing in this Privacy Policy changes the safety terms in our Terms of Use. If you may have been bitten, contact local emergency services immediately — do not rely on the App.

1. The short version

2. Information we collect and why

2.1 The snake photo

What: The photograph you capture or select to identify a snake.
Why: It is sent to our backend and to our AI inference provider so the model can return a venom-risk assessment, regional look-alikes, and related educational information.
Important — location metadata: Before your photo is uploaded, the App re-encodes the image and strips EXIF metadata, including any embedded GPS coordinates. The precise location of the photo is not transmitted.
Legal basis (GDPR): performance of our contract with you / provision of the service you request (Art. 6(1)(b)).

2.2 Coarse region (locale-derived — NOT precise location)

What: A coarse, country/region-level string such as “United States”, derived from your device’s locale/region setting.
Why: Venom risk and dangerous look-alikes are regional. The model uses your coarse region to rule out species that do not occur where you are and to surface the correct regional look-alikes.
What it is NOT: It is not GPS, not your address, not your city, and not precise location. The App does not request the iOS location permission and does not read Core Location, Wi-Fi, or IP-based geolocation for this purpose.
Legal basis (GDPR): performance of the service you request (Art. 6(1)(b)).

2.3 Scan history (stored locally on your device)

What: Your past scans and their result cards (risk class, look-alikes, follow-up chat, and the associated result data).
Where: Stored locally on your device using on-device storage (SwiftData). We do not keep a server-side copy of your history.
Optional iCloud sync: If you have enabled it, your history may sync through your own iCloud key-value store, which is controlled by your Apple ID and your iCloud settings — not by us. We cannot read your iCloud data.
Legal basis (GDPR): performance of the service (Art. 6(1)(b)); processing occurs on your device.

2.4 Purchases and subscriptions

What: Whether you hold an active Premium subscription, and purchase/restore events.
How: Purchases are handled by Apple through StoreKit and the App Store. We never receive or store your payment card, billing address, or Apple ID. Apple provides us only with the transaction/subscription status needed to unlock Premium and to validate entitlements. Apple’s handling of your payment information is governed by Apple’s Privacy Policy.
Legal basis (GDPR): performance of the contract (Art. 6(1)(b)); our legitimate interest in preventing fraud and abuse (Art. 6(1)(f)).

2.5 Advertising identifier (non-subscribers only)

What: If you are not a subscriber, we show ads via Google AdMob. If — and only if — you grant permission through Apple’s App Tracking Transparency (ATT) prompt, the advertising identifier (IDFA) and related ad-interaction signals may be used to serve and measure ads.
If you decline tracking: No IDFA is used to track you across apps and websites; you may still see non-personalized (contextual) ads.
Why: To fund the free tier of the App.
Legal basis (GDPR): your consent (Art. 6(1)(a)), collected via the ATT prompt and, where required, a consent dialog; you can withdraw it at any time (see §7).

2.6 Technical and log data

What: When your device contacts our backend, our servers transiently process standard technical data such as IP address, request timestamps, and a device-generated API key/rate-limit token.
Why: To route requests, apply rate limits, prevent abuse, secure the service, and debug errors. This data is used for operational security and is not used to build a profile of you.
Legal basis (GDPR): our legitimate interest in operating and securing the service (Art. 6(1)(f)).

We do not collect your name, email address, contacts, health records, phone number, or precise location.

3. How your photo is processed (the pipeline)

4. Third parties who process data for us

We share the limited data below with the following processors only to provide the App. Each is contractually bound to process data on our instructions. We do not sell your personal information and we do not share it for cross-context behavioral advertising beyond what §2.5 describes.

ProcessorWhat it receivesPurposeNotes
Replicate (Replicate, Inc.)The snake photo and the coarse region stringRuns the vision model openai/gpt-5-mini for inference and returns the resultDoes not train on your content — inference only.
Cloudflare R2 (Cloudflare, Inc.)The uploaded snake photoTemporary object storage of the photo (auto-deleted after 30 days)S3-compatible storage.
Google AdMob (Google LLC)For non-subscribers who allow tracking: advertising identifier (IDFA) and ad-interaction dataServing and measuring in-app adsGoverned by your ATT choice.
Apple (Apple Inc.)Purchase/subscription transactionsProcesses payments and manages your subscriptionWe never receive your card details.

We may also disclose information if required by law, to respond to lawful requests, or to protect the rights, safety, and property of our users, the public, or Bulpara.

5. Retention and deletion

6. No sale of data; no model training on your content

7. Your choices and controls

8. Your legal rights

8.1 GDPR / UK GDPR (EEA, UK, and similar jurisdictions)

Where the GDPR applies, you have the right to: access the personal data we hold about you; request rectification of inaccurate data; request erasure (“right to be forgotten”); restrict or object to processing; data portability; and, where processing is based on consent, withdraw consent at any time without affecting prior processing. Because we operate the App without accounts, most of your data is either on your device (which you control directly) or is short-lived server-side photo storage that you can delete via §5. To exercise a right against data we control, contact us at privacy@snakeidentifier.bulpara.com. You also have the right to lodge a complaint with your local data protection authority.

International transfers: our processors may process data in the United States and other countries; where required, such transfers are covered by appropriate safeguards (for example, Standard Contractual Clauses).

8.2 CCPA / CPRA (California)

California residents have the right to know/access the categories and specific pieces of personal information collected, the right to delete, the right to correct, the right to opt out of the “sale” or “sharing” of personal information, and the right not to be discriminated against for exercising these rights. As described in §6, we do not sell your information for money; the only “share” that may occur is the advertising identifier for personalized ads when you allow tracking, which you can opt out of via ATT (§7). To make a California rights request, contact privacy@snakeidentifier.bulpara.com.

Categories of personal information (CCPA): identifiers (a device-generated API/rate-limit token, IP address; IDFA only with consent); internet/network activity (ad-interaction data, only with consent); commercial information (subscription status); and visual information (the snake photo you submit). We disclose these categories to the processors listed in §4 for the business purposes stated there.

9. Children

Snake Identifier is not directed to children and is not designed for children. Given its safety-critical subject matter, it is age-rated 13+ (reflecting infrequent/mild medical or treatment information) and is not a “kid-safe” or 4+ app. We do not knowingly collect personal information from children under 13 (or under 16 where a higher age applies). If you believe a child has provided us information, contact privacy@snakeidentifier.bulpara.com and we will delete it.

10. How your Apple App Privacy label maps to this policy

If there is any conflict between the on-store label and this policy, this policy governs; we will keep them aligned.

11. Security

We use industry-standard measures to protect your data, including encryption in transit (HTTPS/TLS), authenticated API access, rate limiting, and short storage retention. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect your information and to limit what we collect in the first place.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide notice in the App or on snakeidentifier.bulpara.com. Your continued use of the App after an update takes effect constitutes acceptance of the revised policy.

13. Contact us

If you may have been bitten by a snake, do not use the App to decide what to do — call your local emergency services immediately.