PRIVACY POLICY
FieldPilot (store name "FieldPilot: Tractor GPS"), for Android and iOS, published by Kirolabs.
Package / bundle identifier: io.kirolabs.fieldpilot
Last updated: 26 September 2026
1. The short version
--------------------
• There is no account. No login, no sign-up, no password, no email address. FieldPilot has no server of its own.
• Your field data stays on your device. Fields, boundaries, jobs, driven tracks, points, lines, markers, implements and receiver profiles are stored in a database inside the app on your phone or tablet. Kirolabs does not receive them and cannot recover them.
• Your position is processed on the device and is never sent to Kirolabs. Analytics never include a coordinate, a boundary or a name you typed. Your position only leaves the device if you set up an NTRIP correction service yourself, and then it goes only to the service you chose (section 3.6).
• Some services do receive technical data. Google Firebase receives anonymous usage events and crash reports. RevenueCat and Apple or Google handle purchases. The map provider receives map tile requests when a map is on screen. You can switch off analytics, crash reports and diagnostics logging under More → Settings.
• Nothing leaves the app through export or sharing unless you do it. Exports, backups and diagnostics are only shared when you tap Share, and only to the place you pick.
2. What stays on the device
---------------------------
FieldPilot helps you measure fields and drive parallel passes with a tractor or other vehicle. It turns positions from your phone's GPS, or from a GNSS receiver you connect, into areas, distances, guidance lines and coverage. All of this is calculated on your device.
The app stores the following in a local SQLite database inside its own private storage on your device:
• your fields and their boundaries, names, notes and areas;
• your jobs (guidance sessions), including the driven track, the guidance lines, coverage and the time and duration of each job;
• saved points, lines and markers, such as obstacles you have marked, with their names and notes;
• your implements (name, working width and offsets);
• your receiver profiles (the name and Bluetooth address of a GNSS receiver you paired) and your NTRIP profiles (caster address, port, mountpoint and username);
• your settings, such as units, map style and privacy choices.
The app also keeps some other files on the device:
• Map tiles. Map images that have been downloaded are cached so the map works with poor or no signal. Offline map regions are stored only if you download one.
• Automatic snapshots. The app keeps a few recent automatic backup snapshots, and a copy of the database before an app update changes its format, so a failed update or a wrong restore can be undone. These stay in the app's private storage.
• The diagnostics log. This is described in section 3.5.
• NTRIP passwords. These are kept apart from everything else, in the Android Keystore (encrypted with a key that cannot leave the device) or the iOS Keychain (stored for this device only). They are never written into a backup or export file.
None of this is uploaded, synced or shared between devices, and Kirolabs cannot read it. If you uninstall the app, it is deleted. We cannot restore it for you, because we never had it. Section 5 explains how to keep your own copy.
Operating system backups. Android Backup and Apple's iCloud device backup can include the app's database and settings in a whole-device backup, depending on your device settings. On Android the encrypted NTRIP password is excluded, so you will need to enter it again on a new device. Google and Apple create, encrypt, store and delete these backups under their own privacy policies, not under this one. Kirolabs cannot access them. If you do not want the app's data in those backups, turn off backup for FieldPilot in your device settings.
Files app on iPhone and iPad. On iOS, FieldPilot's documents folder, which holds exported files and the app's database, is visible in the Files app under "On My iPhone / iPad → FieldPilot". Anyone who can unlock your device can see it there, just like your other files.
Exported and shared files. You can export fields, points, lines and jobs (for example as KML, GeoJSON, CSV or GPX), create PDF reports, and create a full backup as a .fieldpilot file. These files contain your field geometry and names. A file only leaves the app when you share it or save it somewhere with the system share sheet or file picker. After that, whoever holds it is responsible for it: your email provider, messaging app, cloud drive or the person you sent it to. Kirolabs is not part of that transfer and cannot see it. Files you import (KML, KMZ, GeoJSON, CSV, GPX or a .fieldpilot backup) are read on the device and are not uploaded anywhere.
3. What leaves the device, and who receives it
----------------------------------------------
The app sends data to the services listed below. Each section says what is sent and what is never sent. Nothing else is sent anywhere.
3.1 Location
FieldPilot asks for precise location on the last screen of the first-run introduction, after explaining why, when you tap Continue. You can tap Not now; the app then asks the first time you use a feature that needs location. It never asks on later app starts. The app needs location to measure a field by walking or driving around it, to show where you are on the map, to guide you along passes and to record coverage.
• Where positions are used. Positions come from your phone's location service or from a GNSS receiver you connect. They are processed on the device and saved only as part of the fields, tracks, points and jobs you create. They are never sent to Kirolabs. They are not included in analytics or crash reports.
• Background use. Location is only used with the screen off or the app in the background while a guidance job you started is running, so no coverage is lost. On Android this uses a foreground service with a permanent notification for as long as the job runs. On iOS this uses background location updates, which are switched on for the job and off when it ends, and iOS shows its location indicator while this happens. When no job is running, the app does not use location in the background.
• The operating system's location service. On Android, if Google Play services are installed, the app uses Google's fused location provider. Depending on your device settings, Google may process location data for its own location services under Google's privacy policy. On iOS, Apple's Core Location is used under Apple's privacy policy. FieldPilot does not control these services.
• Notifications (Android 13 and later). Together with location, the app asks for permission to show notifications. It uses them only for the "job running" notification while a guidance job records. There are no marketing notifications. On iOS the app shows no notifications and does not ask.
You can turn off location access at any time in your device settings. Measuring by GPS and guidance will stop working, but manual map measurement and all saved data remain available.
3.2 Bluetooth (Android only)
On Android, the app asks for Bluetooth permission only when you open the screen for connecting an external GNSS receiver. It uses Bluetooth only to list the devices already paired with your phone and to connect to the receiver you choose. The Bluetooth scan permission is declared as never used to find your location. The receiver's name and address are saved on the device in your receiver profile. On iOS, the app does not use Bluetooth. A receiver that works with iOS's own location service appears through Core Location instead.
3.3 Map tiles (OpenStreetMap, Esri)
The background map is drawn from images called tiles. These are downloaded from a map tile provider when the map is on screen and the tile is not already stored on the device.
• Standard map: by default, from the OpenStreetMap tile servers (tile.openstreetmap.org), run by the OpenStreetMap Foundation.
• Satellite map: by default, from Esri World Imagery (server.arcgisonline.com), run by Esri.
Kirolabs can change the tile provider through Firebase Remote Config (section 3.9) without releasing an app update. If we move to a provider that is not listed here, we will update this policy.
What the provider receives: a request for each tile, which reveals your device's IP address and the area and zoom level of the map you are looking at. The map usually shows where you are, so the provider can infer your approximate location from this. Each request also includes a technical identifier naming the app and its version ("FieldPilot" and the version number). The providers handle these requests under their own policies: the OpenStreetMap Foundation privacy policy (https://osmfoundation.org/wiki/Privacy_Policy) and the Esri privacy statement (https://www.esri.com/en-us/privacy/overview).
What the provider never receives: your GPS coordinates as such, your field boundaries, field or job names, tracks, or anything else you have stored.
Offline maps. If you download an offline map region, the tiles for that region are fetched once, when you ask, and stored on the device. After that, viewing that region needs no network. You can also choose the blank map style, which downloads no tiles.
3.4 Firebase Analytics (Google)
Firebase Analytics shows us, in aggregate, which features are used and where people get stuck. For example, it shows whether a first measurement succeeds, whether a GNSS receiver connects, and whether exports work. We use this to decide what to fix and improve.
What it sends: event names with a few coarse, non-identifying parameters. These include the kind of measurement (area, distance, point), the method (GPS, map, coordinates), the position source type (phone or external receiver), the fix type (for example "RTK fixed" or "GPS"), the receiver protocol category, the connection type, count and duration ranges (for example "4–9 fields" or "10–60 minutes"), export format, short error categories, paywall and purchase steps, the plan you are on, and which setting was changed. We also set a few coarse properties, such as whether you use Pro, your unit system and a field-count range.
Firebase also collects standard technical information: app version, operating system version, device model, language, a country or region derived from your IP address, session and engagement timings, and a resettable Firebase app instance ID that Firebase generates for this installation. Firebase may also automatically record that an in-app purchase took place, with the product, price and currency, as reported by the store.
What it never sends: coordinates, boundaries, tracks, positions of points or markers, field, job, point or implement names, notes, NTRIP addresses or credentials, file contents or any other text you typed. This is built into the app's code: an analytics event has no field that can carry a coordinate, a boundary or a name. Kirolabs does not use an advertising identifier, does not use analytics data for advertising, and does not sell it.
How to switch it off: More → Settings → Usage analytics. When it is off, no analytics events are collected or sent. Kirolabs can also switch analytics off remotely for everyone. We cannot switch it on for someone who has turned it off.
3.5 Firebase Crashlytics (Google), and the diagnostics log
Crashlytics tells us when the app crashes or hits a serious error, and where in the code it happened, so we can fix it. A crash report contains the stack trace, the app version, the operating system version, the device model, a few technical notes from the moments before the crash, and an installation identifier that Crashlytics uses to group repeat crashes.
What it never sends: your fields, boundaries, tracks, coordinates, names, notes or files. A crash report records where the code failed, not what data you had.
How to switch it off: More → Settings → Crash reports.
The diagnostics log is a separate text log that stays on your device. It records things like GNSS receiver connections and NTRIP errors, so that problems in the field can be investigated. Before anything is written to it, passwords, authorization headers and tokens are removed, and coordinates are rounded to about 1 km, so the log never pinpoints a farm. It is capped in size and older lines are discarded. It only leaves your device if you tap Share on the Diagnostics screen and send it somewhere yourself, for example by email to our support address. You can clear it at any time. To stop the app writing it, use More → Settings → Diagnostics logging.
3.6 NTRIP correction services (only if you set one up)
RTK correction data can be received from an NTRIP caster, a correction service you subscribe to or are given access to. FieldPilot never connects to a caster on its own. It only connects to the caster you enter, using the address, port, mountpoint and credentials you provide.
What the caster receives: your username and password (when the caster requires them), your device's IP address, and an identifier naming the app and its version. If "Send GGA" is on in that NTRIP profile, the app also sends your current position, as a standard NMEA GGA sentence, to that caster every few seconds (every 10 seconds by default) while connected. Network RTK and VRS services need this to calculate corrections for your location. "Send GGA" is on by default in a new profile because most network RTK services require it. You can turn it off if your caster does not need it.
The caster operator processes this data under its own terms and privacy policy, not ours. Kirolabs is not involved and receives nothing from this connection.
Credentials: the NTRIP password is stored in the Android Keystore or iOS Keychain. It is never included in backups or exports, and it is removed from the diagnostics log. If you turn off TLS for a caster, which some casters do not support, the connection, including your password and any GGA position, is sent unencrypted, as the NTRIP protocol does. Use TLS whenever your caster supports it.
3.7 Purchases: RevenueCat, Apple App Store and Google Play
If you buy FieldPilot Pro, Apple or Google processes the payment. RevenueCat (RevenueCat, Inc.) checks the purchase and keeps track of your Pro status.
RevenueCat receives: an anonymous app user ID that RevenueCat generates for this installation, the purchase receipt or token from the store, the product ID, purchase and expiry dates, the platform, the store country and currency, and technical information such as app and operating system version and your IP address. No account is created, and this ID is not linked to your name or email address. The app contacts RevenueCat whenever it checks your Pro status. This includes users who have never bought anything, because that is how the app finds out.
Kirolabs never sees your card number, name or billing address. Apple or Google collect and keep those under their own privacy policies. They are not passed to Kirolabs or RevenueCat.
RevenueCat never receives your fields, tracks, positions or anything else you enter in the app. See RevenueCat's privacy policy (https://www.revenuecat.com/privacy).
3.8 Ratings
After you have used the app for a while, it may ask whether you want to rate it, using Apple's or Google's own rating prompt. Your rating and any review go to the store under the store's policy. Kirolabs only sees what the store publishes.
3.9 Firebase Remote Config (Google)
Remote Config lets us change which features are free or Pro, adjust GPS quality thresholds, change the map tile provider, update the list of compatible receivers, switch features off if a problem appears, and require an update if a build is found to put saved data at risk. The app downloads this configuration from Google about once an hour at most, and keeps the last copy so it works offline.
What it sends: a standard request containing the app ID, app version, platform, language, country and a Firebase installation identifier. These are used to deliver the right configuration.
What it never sends: anything you have stored or measured. It only downloads configuration.
Remote Config cannot be switched off. It is how we stop a build that we have found to damage saved field data.
3.10 Support email
Our support address is labskiro@gmail.com. When you use "Send feedback" in the app, your email app opens a message with the app version and device model filled in. You can edit that before sending. If you write to us, we keep what you choose to send, including your email address and any attachment such as a diagnostics log or an exported file, for as long as we need it to help you and keep a record of the issue. We do not use your address for marketing or add it to any list.
3.11 What the app does not do
• No advertising, and no advertising SDK.
• No tracking across other companies' apps or websites.
• No camera, microphone, contacts or photo library access.
• No sale of personal data.
4. Children
-----------
FieldPilot is a working tool for farmers, contractors and land managers. It is not directed at children under 13, or under 16 in the European Economic Area, and we do not knowingly collect data from them. There is no account or profile, so the app cannot identify any user of any age. If you think a child has sent us something by email, contact us and we will delete it.
5. Your rights
--------------
If you are in the European Economic Area, the United Kingdom or Switzerland, data protection law gives you the rights below. The app is built so that you can use most of them yourself, right away.
Controller. Kirolabs is the controller for the analytics and crash data in sections 3.4 and 3.5, for purchase status handled through RevenueCat in section 3.7, and for emails you send to our support address. Google (Firebase) and RevenueCat process this data for us as processors. The OpenStreetMap Foundation, Esri, Apple, Google (as a store and as a location service) and any NTRIP caster you configure handle data under their own responsibility.
Legal basis.
• Analytics, crash reports and diagnostics logging are switched on when you install the app. We rely on our legitimate interest in keeping a field tool reliable and improving it (Art. 6(1)(f) GDPR). You can object at any time by switching each one off under More → Settings. This takes effect immediately.
• Purchases and Pro status are needed to provide what you bought (Art. 6(1)(b) GDPR).
• Remote Config and map tiles are needed for the app to work as intended (Art. 6(1)(b) and (f) GDPR).
• Support emails: we rely on our legitimate interest in answering you.
Access and portability. Use Backup in the app to create a complete .fieldpilot file of everything the app holds. It contains your data as JSON and your fields as GeoJSON, and it is free, even if your Pro subscription has ended. KML export is also always free. We cannot give you a copy ourselves, because we do not hold one.
Erasure. Delete individual fields, jobs, points and implements in the app, or uninstall the app to delete everything. The analytics and crash data we receive is not linked to your name, email address or any account, so we usually cannot find which records are yours (Art. 11 GDPR). Switching the toggles off stops further collection, and existing records are deleted automatically when their retention period ends (section 6). If you contact us, we will do what we can.
Rectification. You can edit or delete any field, job, point, implement or profile in the app at any time.
Objection and restriction. Use the toggles under More → Settings.
Complaint. You can complain to your local data protection authority.
6. Retention
------------
• Data on your device is kept until you delete it or uninstall the app. It does not expire on its own. Automatic snapshots are limited to the few most recent, and older ones are deleted automatically. The diagnostics log is capped in size and discards older lines.
• Firebase Analytics event data is kept for the data retention period set in our Google Analytics settings, and is then deleted automatically. By default this period is 2 months, and it can be set to at most 14 months. Reports that only contain aggregated totals may be kept longer.
• Crashlytics crash reports are kept for 90 days and then deleted automatically.
• Purchase records held by RevenueCat and by Apple or Google are kept as long as needed to provide your Pro access and to meet accounting and tax obligations.
• Support emails are kept as long as needed to solve your issue and keep a short record of it. We delete them if you ask.
7. Security
-----------
Your data is stored in the app's private storage, which the operating system keeps separate from other apps. It is encrypted by the platform when your device is locked with a passcode. NTRIP passwords are also encrypted with keys held in the Android Keystore or iOS Keychain. Firebase, RevenueCat and the default map providers are contacted over encrypted HTTPS connections.
The main protection in FieldPilot is how it is built: no Kirolabs server holds a copy of your fields, tracks or positions, so there is nothing of yours on our side to breach. The only copies are on your device, in the backups your device makes, and in any files you export yourself. That is why the free backup exists. Please use it.
No storage method is perfectly secure, and we do not claim otherwise.
8. Changes to this policy
-------------------------
If we change this policy, we will update the date at the top. If the change is significant, we will tell you in the app before it takes effect.
One commitment will not change. Kirolabs will not start sending your field boundaries, tracks, positions, or field, job or point names to Kirolabs or to anyone else without your explicit action. If we ever offer something like cloud sync, it will be off unless you turn it on, it will be explained before you do, and this policy will be updated first.
9. Contact
----------
Questions about this policy, your data or the app:
labskiro@gmail.com
https://kirolabs.io/contact