# Privacy Policy for Species AI
**Effective date:** 18 July 2026
This Privacy Policy explains how **Vaibhav Vishal** ("we", "us", or "our") collects,
uses, shares, and protects your information when you use the **Species AI** mobile application
(the "App"). By downloading, creating an account in, or using the App, you agree to the practices
described in this policy.
If you do not agree with this policy, please do not use the App.
---
## 1. Who we are
Species AI is an AI-powered species identification app. You take or upload a photo of a plant,
flower, tree, bird, animal, insect, fish, or reptile, and the App returns an identification and
educational information about the subject.
The data controller responsible for your information is **Vaibhav Vishal**. You can reach
us at **vaibhav.iboy@gmail.com**.
---
## 2. Information we collect
We collect only what the App needs to work. This falls into three groups.
### 2.1 Information you provide when you create an account
To create a Species AI account you provide, and we store:
- **Your email address _or_ your phone number** (you choose one), which we verify by sending a
link (email) or a one-time code (SMS).
- **A password**, which you set to secure your account.
- **Your full name.**
- **Your date of birth.** We use this only to confirm you meet our minimum age requirement
(see Section 12) and to display it in your profile. We do not use it for advertising.
- **A profile photo** (optional). You may skip this, and you may remove or change it at any time.
### 2.2 Photos you submit for identification
When you ask the App to identify a subject, you provide a **photo** taken with your camera or
chosen from your device gallery. How this photo is handled is described in detail in Section 4.
### 2.3 Information collected automatically
**The App contains no analytics, advertising, or tracking SDK.** We do not collect an advertising
ID, we do not build a usage profile, and we do not collect your location — precise or approximate.
The App does not request location permission, and it does not hold the `AD_ID` permission.
The only automatic collection is what is technically unavoidable when your device talks to a
server: our service providers (Section 5) observe your **IP address** and basic connection
metadata in order to route the response back to you and to protect their services from abuse.
Neither we nor they use it to derive your location for our purposes, and we do not store it.
An earlier version of this policy described analytics collection. That SDK has been removed from
the App and this section has been corrected to describe what the App actually does.
### 2.4 Subscription information
If you purchase Species AI Pro, our payment providers process your subscription status. We do
**not** receive or store your full payment-card details (see Sections 5 and 6).
### 2.5 Summary — what leaves your device
This table is the complete list, and it matches our Google Play **Data safety** declaration
exactly. "Shared" means transferred to a third party for that party's own purposes — which we do
not do; the companies listed below process data only on our instructions as service providers.
| What | Collected | Shared | Required | Who receives it | Why |
|---|---|---|---|---|---|
| Email address | Yes | No | Yes | Google (Firebase Authentication, Cloud Firestore) | Create, verify and sign in to your account |
| Phone number | Yes | No | Yes | Google (Firebase Authentication, Cloud Firestore) | Create, verify and sign in to your account |
| Name | Yes | No | Yes | Google (Cloud Firestore) | Your profile |
| User ID | Yes | No | Yes | Google (Firebase), RevenueCat | Link your account to your data and subscription |
| Date of birth | Yes | No | Yes | Google (Cloud Firestore) | Minimum-age check and your profile |
| Purchase history | Yes | No | No | RevenueCat, Google Play, Google (Cloud Firestore) | Unlock and restore Species AI Pro |
| Photos | Yes | No | No | Google (Gemini API); Google (Cloud Storage) for your profile photo | Identify the subject; display your avatar |
All of it is transmitted over an encrypted (HTTPS/TLS) connection. You can delete all of it at any
time — see Section 10.
**Note on phone numbers.** Because Firebase Authentication has no "phone number + password"
sign-in method, an account created with a phone number is given an internal sign-in address
derived from that number (for example, `p919912345678@phone.speciesai.app`). It is never used to
send you mail and is never shown to you, but it does mean your phone number is transmitted to
Google Firebase whenever you sign in or change your password. We disclose this rather than leave
it implied.
---
## 3. How we use your information
We use your information to:
- Create, secure, and manage your account and authenticate your sign-in.
- Provide the core service — identifying the subjects in your photos and returning species
information.
- Save your identification history and generate PDF reports at your request.
- Provide, restore, and manage your Species AI Pro subscription and your free-credit allowance.
- Verify that you meet the minimum age requirement.
- Maintain the security and integrity of the App and prevent fraud and abuse.
- Diagnose problems, understand aggregate usage, and improve the App.
- Communicate with you about your account, verification, and important service changes.
We do **not** sell your personal information, and we do **not** use your identification photos or
your profile data to serve third-party advertising.
**Legal bases (for users in the EEA/UK).** We process your data to perform our contract with you
(providing the App), on the basis of your consent (e.g. optional profile photo and camera
access), to comply with legal obligations, and for our legitimate interests in securing and
improving the App.
---
## 4. How your identification photos are processed (please read)
This section describes the most important data flow in the App.
- When you request an identification, the photo you capture or select is **transmitted to
Google's Gemini API** (operated by Google LLC) for the sole purpose of analyzing the image and
generating an identification and related species information. This processing is subject to
**Google's Privacy Policy** and Google's applicable API terms.
- We send the photo to Google **only** to fulfil your identification request. We do not use it to
build a marketing profile of you, and we do not sell it.
- A copy of the photo, together with the result, is saved **locally on your device** as part of
your identification history so you can view it again offline. This on-device history is **not**
uploaded to our servers. It remains on your device until you delete the entry, clear the App's
data, or uninstall the App.
- Your **identification photos are not stored on our Firebase servers.** (Your optional
**profile photo** is different — it is stored as described in Section 7.)
Because identification requires sending your photo to Google's Gemini API, you should avoid
submitting photos that contain sensitive personal information you do not wish to be processed by
Google.
---
## 5. How we share information and the third parties we use
We share information only with the service providers below, who process it on our behalf to make
the App function, and only as needed. We do not sell your personal information.
- **Google Firebase (Google LLC)** — we use Firebase for:
- *Firebase Authentication* — to create and secure your account and manage sign-in. Your
password is handled by Firebase and stored only in hashed form; we never see your plain-text
password.
- *Cloud Firestore* — to store your profile (name, date of birth, verified email or phone,
profile-photo link, authentication method, account dates, subscription status, and free-credit
count).
- *Cloud Storage for Firebase* — to store your optional profile photo.
- **Google Gemini API (Google LLC)** — to analyze the photos you submit for identification, as
described in Section 4.
- **RevenueCat, Inc.** — to manage and validate subscriptions, if you subscribe to Species AI Pro.
RevenueCat receives a pseudonymous account identifier and your subscription status. It does
**not** receive your name, email address, or phone number.
- **Google Play Billing (Google LLC)** — to process subscription payments. Google, not us,
handles your payment method.
Each of these acts as our **service provider**: they process your data on our instructions, to
deliver the App's features, and not for their own independent purposes. We do not sell your
personal information and we do not share it with third parties for their own use.
We may also disclose information if required to do so **by law**, to comply with legal process, or
to protect the rights, safety, and property of our users, the public, or us.
If we ever undergo a business transfer (merger, acquisition, or sale of assets), your information
may be transferred as part of that transaction; we will notify you of any such change and of any
choices you may have.
---
## 6. Subscriptions and payments
Species AI offers optional auto-renewing subscriptions (Species AI Pro). Payments are processed
through **Google Play Billing**. We never receive your full card number or bank details. We store
only your subscription **status** (active/inactive), plan type, and renewal or expiry date so the
App can unlock premium features. You can manage or cancel your subscription at any time in
**Google Play → Subscriptions**.
---
## 7. Where your data is stored and international transfers
Your account and profile data, and your optional profile photo, are stored on Google's cloud
infrastructure. Our Firebase project's data is hosted in **Google data centers in the United
States**. Your identification history and any locally saved photos and reports are stored **on
your own device**.
If you access the App from outside the United States, your information will be transferred to and
processed in the United States and other countries where our service providers operate. These
countries may have data-protection laws different from those in your country. Where required, our
providers rely on appropriate safeguards (such as Standard Contractual Clauses) for these
transfers.
---
## 8. Data retention
- **Account and profile data** are retained for as long as your account exists.
- **On-device identification history, photos, and reports** are retained on your device until you
delete them, clear the App's data, or uninstall the App.
- **Subscription records** are retained as required for accounting, tax, and legal purposes.
- When you delete your account (see Section 10), we delete or de-identify your associated
personal data within **30 days**, except where we are required to retain certain records by law.
---
## 9. Your rights and choices
Depending on where you live, you may have the right to:
- **Access** the personal information we hold about you.
- **Correct** inaccurate information. You can edit your name, date of birth, and profile photo
directly in the App's Profile screen, and change your password at any time.
- **Delete** your account and personal information (see Section 10).
- **Object to or restrict** certain processing, and **withdraw consent** where processing is based
on consent (for example, by revoking camera permission in your device settings).
- **Data portability** — receive a copy of certain information in a portable format.
If you are in the **European Economic Area or United Kingdom**, you also have the right to lodge a
complaint with your local data-protection authority.
If you are a **California** resident, you have rights under the CCPA/CPRA, including the right to
know, delete, and correct, and the right not to be discriminated against for exercising them. We
do **not** sell or "share" (as defined by California law) your personal information.
To exercise any of these rights, contact us at **vaibhav.iboy@gmail.com**. We will respond within the
timeframe required by applicable law.
---
## 10. Account and data deletion
You can delete your Species AI account and its associated personal data at any time, without
contacting us.
**In the App (immediate):** open **Profile → Delete account**, confirm with your password, and
tap **Delete permanently**. This immediately and irreversibly deletes:
- your authentication account (your verified email address or phone number, and your password);
- your profile document (your name, date of birth, verified email address or phone number, profile
photo link, and subscription status);
- your stored profile photo in Cloud Storage;
- your saved identification history, photos, and reports on this device.
**By email (alternative):** send a deletion request to **vaibhav.iboy@gmail.com** with the subject
line "Delete my account", from the email address on your account or including the phone number on
your account. We will complete the deletion within **30 days** and confirm when it is done.
**What is not deleted automatically.** Your subscription record with RevenueCat and Google Play is
keyed to a pseudonymous account identifier and contains no name, email address, or phone number;
we retain subscription and payment records where accounting and tax law requires it. Deleting your
account does **not** cancel an active subscription — cancel it in **Google Play → Subscriptions**
first, or you will continue to be charged. If you want your RevenueCat record erased as well,
email us at the address above and we will remove it.
---
## 11. Security
We take reasonable technical and organizational measures to protect your information, including:
- Encryption of data in transit using industry-standard TLS.
- Storage of passwords only in hashed form by Firebase Authentication — we never store or view
your plain-text password.
- Server-side access rules (Firebase Security Rules) that restrict each account so it can read and
write only its own data.
- Restricting profile-photo uploads to your own account.
No method of transmission or storage is completely secure, and we cannot guarantee absolute
security. Please keep your password confidential and notify us at **webhub.iboy@gmail.com** if you
believe your account has been compromised.
---
## 12. Children's privacy
Species AI is **not directed to children under 13**, and we do not knowingly collect personal
information from children under 13. During sign-up we require you to confirm a date of birth
indicating you are at least 13 years old (or older, where a higher minimum age applies under local
law — for example, 16 in parts of the European Economic Area). If you believe a child has provided
us with personal information, please contact us at **webhub.iboy@gmail.com** and we will delete it.
---
## 13. Third-party services and links
The App relies on the third-party services named in Section 5, each of which has its own privacy
policy governing its handling of data:
- Google (Firebase, Gemini API, Google Play) — see Google's Privacy Policy at
https://policies.google.com/privacy
- RevenueCat — see https://www.revenuecat.com/privacy
We are not responsible for the privacy practices of these third parties, and we encourage you to
review their policies.
---
## 14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update
the "Effective date" above and, where appropriate, notify you within the App or by other means.
Your continued use of the App after an update means you accept the revised policy.
---
## 15. Contact us
If you have questions, requests, or concerns about this Privacy Policy or your personal
information, contact us at:
**Vaibhav Vishal**
Email: **vaibhav.iboy@gmail.com**
Jurisdiction: **India**