Privacy Policy
Last updated: 5 August 2026
This policy explains what IndianJungleLogs collects, why, where it is stored, and how you get it back or delete it. It is written to be read, not skimmed past. If anything here is unclear, email indianjunglelogs@gmail.com and we will explain it.
1. Who we are
IndianJungleLogs ("we", "us") runs indianjunglelogs.com and the IndianJungleLogs mobile app — a free platform for logging and sharing wildlife sightings across India's national parks and sanctuaries. For the purposes of India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the information described below.
2. What we collect, and why
We collect only what a logbook needs to work. Each item below is tied to the reason we hold it.
- Account details — your name, email address, and a securely hashed password. If you sign in with Microsoft, we receive your name and email from Microsoft instead, and never see your Microsoft password. Why: to create your account, sign you in, and contact you about your account.
- Optional profile details — username, bio, and links to your Instagram, X, Facebook or WhatsApp. Why: so other naturalists can credit and find you. These are shown publicly only if you choose to make your profile public; social links have their own separate visibility switch.
- Sightings you log — species, date and time, the park and zone, notes, counts, and any photographs you upload. Why: this is the core of the service, and it is what appears on your checklists and, if you publish them, in the community feed.
- Photographs — the images themselves. Why: to display your sightings. See section 4 for what happens to the data embedded inside your photos.
- Approximate location — only when you tap "Near me" or "Current location", and only after your device asks your permission. Why: to show which parks are closest to you and to centre the map. We use it in the moment and do not build a location history from it.
- Technical and usage data — IP address, browser or device type, and which pages were served, collected by our hosting providers. Why: to keep the service running, diagnose faults, and prevent abuse.
We do not collect payment details, government identifiers, or contact lists. We have no advertising trackers and no third-party ad networks.
3. Children
The platform is not directed at children under 18. We do not knowingly create accounts for, or collect personal data from, children. If you believe a child has given us personal data, email us and we will delete it.
4. Photographs and embedded data
Camera files often carry hidden EXIF metadata — GPS coordinates, camera body, serial number, and the exact capture time. Two things are worth knowing:
- Photos are resized and re-encoded in your browser or on your phone before upload, which strips most embedded metadata as a side effect. You should not rely on this as a guarantee — if a photograph would reveal something you would rather keep private, remove the metadata before uploading.
- Precise nest, den and kill-site locations can put animals at risk. We deliberately record sightings against a park and zone rather than exact coordinates. Please do not defeat this by putting precise coordinates in your notes for sensitive or threatened species.
5. What is public and what is not
You control this, and the default is private.
- Your email address and password are never shown to other users.
- Draft checklists are private to you until you submit them.
- Your profile, gallery and submitted checklists are visible to other signed-in users only when your profile is set to public.
- A checklist you share by link can be opened by anyone holding that link, including people without an account. Treat a share link as public.
- If you delete your account, sightings previously featured on the site are kept but re-attributed to "Anonymous Scout" and unlinked from you.
6. Cookies and similar technologies
We use a small number of cookies and equivalent browser storage. When you first visit, we ask you to choose:
- Essential — keeps you signed in, remembers your consent choice, and allows the app to work offline. These cannot be switched off without breaking sign-in.
- Anonymous diagnostics — aggregate traffic and error counts so we can tell whether pages are loading and failing. Optional; declining costs you nothing.
We do not use advertising or cross-site tracking cookies. You can change your choice at any time by clearing site data.
7. Who processes your data on our behalf
We do not sell, rent or trade personal information — ever. We do rely on a small set of infrastructure providers to run the service, each handling data only on our instructions:
- Amazon Web Services (Mumbai, India) — runs the application server.
- Supabase — the database holding your account and sightings.
- Cloudflare — serves the website and stores uploaded photographs (R2).
- Brevo and Resend — send account email such as verification, password resets and safari invitations.
- Mapbox and OpenStreetMap — supply map tiles. Your browser contacts them directly to fetch map imagery.
- Microsoft — only if you choose to sign in with a Microsoft account.
Our application server runs in the AWS Mumbai region. Some providers above may process or back up data outside India. Where that happens, it is done under those providers' standard data-protection terms.
We may also disclose information where the law requires it, or to protect wildlife — for example, cooperating with a forest department over a credible poaching threat.
8. How long we keep it
- Account and sightings — for as long as your account exists.
- After you delete your account — your personal data is removed promptly. Featured sightings are anonymised rather than deleted, as described in section 5.
- Server and diagnostic logs — retained for a short period (currently 14 days) and then deleted automatically.
- Email records — delivery records are kept by our email providers for their own limited retention periods.
9. Security
Passwords are stored hashed, never in plain text. Traffic is encrypted in transit over HTTPS. Sessions use short-lived tokens that rotate, and changing your password or deleting your account signs out every device. Access to the production database is limited to the people who operate the service.
No online service can promise perfect security. If we ever discover a breach affecting your personal data, we will notify you and the Data Protection Board as required by law.
10. Your rights
You can exercise all of these — most without asking us:
- Access and correction — view and edit your details in your profile settings.
- Deletion — delete your account from your profile settings. This removes your account and personal data.
- Control over visibility — switch your profile, social links and badges between public and private at any time.
- Withdraw consent — revoke location permission in your device settings, or decline diagnostics cookies.
- Complain — write to us first; you also have the right to complain to the Data Protection Board of India.
If you cannot reach a setting or the deletion does not work, email us and we will action it manually.
11. Changes to this policy
If we change how we handle your data in a way that materially affects you, we will update the date at the top of this page and, where the change is significant, tell you by email or in the app.
12. Contact and grievances
For any privacy question, correction, deletion request or complaint, contact our Grievance Officer at indianjunglelogs@gmail.com. We aim to respond within 30 days, and usually much sooner.