Privacy Policy

Cool Bear Discovery

Effective date: 2026-10-04

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Cool Bear Discovery stores the name and role you optionally enter, language preference, animal profiles, encounter and care records, welfare observations, seasonal notes, reminder titles and dates, text regions and attached photographs locally on your iPhone. It does not collect precise coordinates or require an account. The system photo picker provides only the photographs you choose. Camera photographs and selected images are re-encoded as local JPEG attachments without copying their original location metadata. Optional synchronization sends an automatically generated installation identifier, an authorization secret over HTTPS, an encrypted journal snapshot and an update timestamp to the backend. The snapshot includes records, animal profiles and procedure schedules, but excludes photographs and your local profile and language settings. The server stores the identifier, a bcrypt hash of the secret, the encrypted snapshot and its timestamp in PostgreSQL. The original secret remains in the device Keychain. When the app or a browser requests the hosted service, Railway infrastructure receives request information such as IP address, request path, timing and HTTP status. Application error logs contain a random request identifier and event category, not journal contents or authorization credentials.

How we use information

Local information supports the offline species reference, your personal journals, animal associations, photo archive and manually scheduled care reminders. Notifications are scheduled locally through iOS, with the procedure title you enter. Optional encrypted synchronization keeps the latest installation-specific journal snapshot and retries interrupted uploads. The installation secret authorizes access to that installation's data and derives the client-side encryption key. Infrastructure and minimal application logs support service operation and diagnosis. No advertising, behavioral analytics, sales of data or outbound email delivery are implemented.

Service providers and sharing

The backend and its PostgreSQL database are hosted on Railway, which processes network requests and infrastructure logs as the hosting provider. The app uses Apple's device frameworks for Keychain, photo selection, camera access and local notifications; it does not upload photos to this backend or send notification content to a remote push service. There are no third-party advertising or analytics SDKs in the app. The service uses Express, pg, bcryptjs, Helmet and an in-process rate limiter, with no additional messaging or analytics provider. The operator can access server records and operational logs, but the journal blob is encrypted on the device and no decryption key is stored by the backend. Opening reference or privacy links in your browser sends normal browser requests to the selected website, which has its own privacy practices. Information may also be disclosed when legally required.

Data retention

Local records remain until you remove them or use Delete all installation data. Removing a record deletes its associated local photo files. Uninstalling the app removes its application storage, but iOS Keychain items can persist; use the in-app deletion action before uninstalling if you also want server deletion. The server retains the latest encrypted snapshot and installation authorization hash until an authorized deletion request succeeds; there is no automatic expiration period. There is no app-controlled server backup or separate historical journal archive. Device backups are governed by your Apple backup settings and may contain local application data. Railway infrastructure retention and any provider-managed backup copies follow the provider's configured practices; this application does not promise a fixed duration or immediate erasure of provider backups or logs.

Deleting your information

You can edit or delete individual records in the app. When synchronization is enabled, changes replace the latest server snapshot after a successful sync. Settings offers Delete all installation data, which removes local journals, profile, attached photographs and pending or delivered reminders and requests removal of the installation row and encrypted snapshot from the server. If the server is unavailable, local data is deleted immediately and the authorization secret is retained only to retry server deletion on connectivity or app activation; further uploads are blocked until deletion finishes. The secret is removed from Keychain once the server deletion is acknowledged. Keep the app installed and open it with a connection to complete a pending deletion. Deletion cannot retract copies in existing device backups or immediately erase infrastructure logs or provider backup copies. Losing the installation secret prevents access to the encrypted server data, and there is no account-based recovery or transfer feature.

Permissions and your choices

Camera access is requested only when you choose Take a photo. You may decline and use the photo picker instead. The native photo picker lets you share selected photos without granting broad photo-library access. Local notification permission is requested when you save an enabled future procedure reminder. If permission is denied, the schedule remains available and the app explains how to enable notifications. You can withdraw camera or notification permission in iOS Settings at any time; this does not automatically delete previously saved photographs or records. You can disable optional synchronization in the app while continuing to use all local journals. No location, contacts or tracking permission is requested.

Your privacy rights

You can review, correct and delete your local records and disable optional synchronization or permissions. Depending on your jurisdiction, you may have rights to access, correction, deletion, restriction, objection or complaint to a data protection authority. For privacy questions or requests, contact olwen.baskerville@icloud.com. This address is a public privacy contact, not an app account or a built-in email sending feature. Do not email your installation secret. Because the service has no account or email identity, the operator cannot identify an encrypted installation snapshot from your email address alone or recover its encryption secret.

Security

The client encrypts journal snapshots with AES-GCM using a key derived from a cryptographically random installation secret. HTTPS protects deployed client-server transport. The backend verifies the installation identifier and bcrypt-hashed secret before reading, updating or deleting private data. Secrets are installation-specific, stored in Keychain and never embedded as shared credentials. Local journal and JPEG writes use iOS file protection and atomic writes; the SQLite retry queue contains encrypted snapshots. Payload validation, request size limits, rate limiting and parameterized SQL reduce abuse and data access risks. No method of storage or transmission guarantees absolute security; protect your unlocked device and backups.

Children’s privacy

Cool Bear Discovery is designed for adult wildlife observers and personnel of licensed care organizations. It is not directed at children, does not create child accounts and does not intentionally solicit children's personal information. Avoid putting children's identifying information in notes or photographs. If you believe a child has submitted personal information to the service, contact olwen.baskerville@icloud.com for assistance.

Changes to this policy

This policy describes the application and service as of its effective date. If data processing changes, the operator will update this page and its effective date. Review the Privacy Policy link in Settings for the current version. Material changes will be described in the updated policy or application release information.