Privacy Policy
Last updated:
This policy explains what personal data ForagePal processes, why, on what lawful basis, and what rights you have over it. It covers both the ForagePal app and this website. The app sections describe the current production service and client behavior; the website sections describe this public site.
Who is the data controller
Echofold Ltd (trading as ForagePal), Dublin, Ireland, is the data controller for your personal data. Our company details are below.
For anything to do with privacy or data protection, contact privacy@foragepal.com. For everything else, contact support@foragepal.com. Both are monitored mailboxes hosted by Proton, a Swiss-hosted (EU adequacy decision) mail provider — Switzerland is covered by a European Commission adequacy decision, so it is adequacy-decision territory rather than the EU/EEA itself.
Our lead supervisory authority is the Data Protection Commission (https://www.dataprotection.ie). You can lodge a complaint with them at any time — see "Your rights" below.
ForagePal is a product of Echofold, Dublin, Ireland.
Registered name: Echofold Ltd · CRO company number:786573 · Registered office:Unit 1, Richview Business Park, Clonskeagh, Dublin, D14 W6X6, Ireland
Questions or requests? support@foragepal.com
Who can use ForagePal (18+)
The ForagePal app is intended for adults only: the Terms set an 18-or-older eligibility rule. The current build does not ask for an age declaration and does not technically gate account creation by age, so this is a contractual eligibility rule rather than implemented age assurance.
We do not knowingly collect personal data from anyone under 18. If we become aware that we hold data about a person under 18, we will delete it. The age threshold exists because foraging involves potentially lethal wild organisms and because the app can process precise location data.
Our lawful basis for processing
Most app processing is necessary to provide the service you asked for — your account and authentication, the service email we send you about it, your logbook and observations, approximate find coordinates, photo identification, and your subscription entitlements all rely on performance of a contract (GDPR Article 6(1)(b)).
The app has two centrally versioned optional consent purposes (GDPR Article 6(1)(a)): exact-coordinate storage and usage analytics. They are presented separately, each is off by default, and each can be withdrawn without losing the core service. No analytics service is enabled and no product-analytics events are collected today, so the analytics choice currently authorises no event collection; we would update this policy and name the recipient before enabling one. Identify also has a separate, off-by-default, subject-scoped rough-area choice described below.
A small amount of processing relies on our legitimate interests (GDPR Article 6(1)(f)), balanced against your rights and disclosed here rather than buried: coarse, region-grain weather and soil context attached to an observation, short-lived operational logs, usage counters, and keeping accounts and the paid service secure against abuse.
Keeping a record of the consents you gave, declined or withdrew is necessary to meet our legal obligation under GDPR Article 7 to demonstrate and honour those choices (GDPR Article 6(1)(c)). Responding to data-subject requests also relies on our legal obligations under GDPR.
What we collect and why
Account data: your email address and authentication data, processed to create and secure your account. Authentication is provided by Amazon Cognito.
Device preferences and caches: the home county or region, onboarding-complete flag, privacy and agreement state, and other subject-scoped app caches are stored on that device. They are not observation-sync rows. Confirmed account deletion clears them for that subject; ordinary sign-out does not.
Email we send you: we use your email address for the transactional messages the service currently supports — account-verification codes and password-reset messages generated through Amazon Cognito. These are service messages, not marketing: there is no newsletter and we send no promotional email. Trial eligibility, billing prompts and renewal notices are handled by the App Store or Google Play, not by us. We do not claim to send a deletion-confirmation or subscription email that has not been built.
Where those addresses come from: we only ever email an address the account holder gave us when they created a ForagePal account. We never buy, rent, scrape or otherwise acquire email addresses, and we never share yours with anyone for their own marketing. Because we run no mailing list there is nothing to unsubscribe from — the service messages above stop when your account is deleted.
Find locations: the coordinates attached to an observation. If you have consented to exact coordinates, the precise latitude and longitude are stored so you can return to your own finds. If you have not, an approximately 1 km grid-snapped location is stored instead so the logbook and map still work.
Optional Identify area: production Identify is enabled. A rough area is sent only after the signed-in subject explicitly turns on the separate "Share a rough area" choice, which is off by default and scoped to that subject. The app rounds a lifted photo location to a 0.1-degree grid on the device before any request; the ForagePal API verifies that subject's choice and re-coarsens the value before it can reach Kindwise. That is roughly an 11 km north-south cell in Ireland, remains personal location data, and is not the exact photo or observation coordinate.
Photos: mushroom photos you deliberately take for identification or attach to an observation. Camera and photo-library access apply only to the photo you choose — never in the background — and the app does not browse or upload anything else. Saved observation-photo bytes stay in the device photo store; observation sync sends only the database photo key. For live production Identify, the app strips EXIF metadata from the selected photo and the ForagePal API strips it again before Kindwise receives the image. Private S3 photo storage is versioned; confirmed account deletion removes every current and older version and delete marker before the account database and Cognito identity are deleted.
Observations: species, notes, dates, a has-photo flag, coordinates at whichever precision applies, and structured conditions such as forage kind, substrate, host tree, abundance and habitat — your personal life list. When you are signed in and sync is configured, these rows (but not saved photo bytes) sync automatically; there is no separate cloud-backup consent. Alongside an observation we may store coarse, region-grain weather and soil context, never pin-grain context, for the logbook and forecast.
Consent history: a record of your decisions for the two implemented purposes — exact_coordinates and analytics — and when each was given, declined or withdrawn, so we can prove and honour your choices. This is not a species-dataset contribution consent, and accepting the Terms or Privacy Policy is recorded separately as a contract agreement.
Subscription data: purchase status, store, expiry and trial state, an app-user identifier, and the event identifiers needed to reconcile access. The database entitlement and a separate subscription/access mirror are distinct stores. We never see or hold your card details — payment and external purchase history are handled by the App Store or Google Play.
Usage and quota records: counts of the identifications and map lookups you make, and when, kept so we can enforce the trial allowance, meter unlimited usage for abuse detection, and prevent misuse of paid services. They record counts and windows, not the photo or species suggestion; the current counters expire through a time-to-live rule 35 days after their usage window closes.
Operational logs: AWS CloudWatch receives short-lived route, response-status, request-id, timing and error records. Identification logs may include image byte size and quota-window data; map success logs include coordinates rounded to about 1 km, not the requested exact point. These logs are configured for 14-day retention. They are not Sentry crash reports, and no app device-model or product-analytics event stream is collected today.
We do not ask the AI identification provider for edibility information, we never store or display an edibility verdict, we do not sell your personal data, and we do not use it for third-party advertising. We do not collect your device's advertising identifier, we run no advertising SDK, and we do not track you across other apps or websites.
Precise location — how consent works
Precise find locations are sensitive. They can reveal your movements and habits, and for rare or protected species they can create a real conservation risk. So we treat this consent differently from everything else.
The exact-coordinates consent is separate and unbundled from every other choice, it is off by default, and you can withdraw it at any time in Settings — as easily as you gave it (GDPR Article 7(3)).
If you decline it, or later withdraw it, the app still works. Coordinates are stored snapped to an approximately 1 km grid. That reduces precision but does not make an account-linked observation anonymous. Coarsening is applied at the moment of capture on every save path, and our server re-applies it from your recorded consent state as a defence in depth — we do not rely on the app alone.
Your find locations are private to your account and are never shown to other users. Until a final sensitive-taxa list exists, every find location is treated as restricted. Dedicated auditing of privileged row reads and the final sensitive-taxa workflow are not implemented, and this policy does not describe those controls as complete.
The location permission you grant your phone's operating system is a separate thing from this consent. Allowing your phone's location while declining exact-coordinate storage is a valid, fully supported combination.
How we record your consents
Every consent decision is recorded with its value, the moment you made it, and the version of the notice that was in force at that moment. Every change appends a new, immutable line rather than overwriting the last one, so the full history of what you agreed to is preserved. This is what GDPR Article 7 calls demonstrating consent, and it is why we keep it.
Accepting these policies is recorded as a contract agreement, deliberately kept as a separate record from any privacy consent — one action can never set both. Skipping a consent screen leaves that purpose unanswered rather than recorded as a refusal you did not make.
Where your data lives
ForagePal application data is stored and processed in the EU — Amazon Web Services' EU (Ireland) eu-west-1 region, in Dublin — wherever possible.
This site is static content served from Amazon Web Services (an Amazon S3 origin behind Amazon CloudFront), and ForagePal application data is held in the AWS EU (Ireland) eu-west-1 region. CloudFront caches these public pages at edge locations worldwide, so we do not claim that nothing ever leaves the EEA.
We make no blanket promise that your data never leaves the EU/EEA. AWS may use global support and subprocessors; CloudFront caches these public pages at edge locations worldwide; Proton is in Switzerland under the European Commission adequacy decision; and Apple and Google process store records under their own global privacy arrangements. Kindwise receives the stripped Identify photo and, only after the subject-scoped choice described above, the coarsened area. We do not promise that Kindwise stores or processes those submissions only in a named EU/EEA region. RevenueCat's production receiver and credential are deployed, but there is no live store product or purchase flow and therefore no live purchase-event stream today.
Processors and other recipients
Amazon Web Services is enabled. It hosts the app database, private versioned photo storage, compute, authentication through Amazon Cognito, short-lived operational logs through CloudWatch, and this website. Primary app resources are configured in EU (Ireland), eu-west-1, while AWS may use global subprocessors and support.
Production Amazon Cognito uses a verified Amazon Simple Email Service (Amazon SES) identity for account-verification and password-reset messages and sends from no-reply@foragepal.com. SES and Cognito do not receive your photos, coordinates or observations as part of sending those messages.
Kindwise (mushroom.id) is the live third-party suggestion provider behind the production ForagePal API. The app strips EXIF metadata from the selected image and the API strips it again. A rough area accompanies it only when the signed-in subject has explicitly enabled "Share a rough area"; the API verifies that subject-scoped choice and re-coarsens the value before forwarding it. Exact photo and observation coordinates are not sent to Kindwise. We do not claim a separately negotiated retention or transfer arrangement beyond the provider terms that apply to the service.
RevenueCat is present in the production subscription infrastructure: the webhook receiver and Secrets Manager credential are deployed. No live store product or native purchase flow is active yet, so no live purchase events are being used to grant access today. When billing goes live, the planned data is an app-user identifier and purchase status. Apple and Google will process store identity, payment and purchase history as independent store operators. There is no other payment provider and no web checkout — see the Terms.
Proton is enabled for messages you choose to send to our support or privacy mailboxes. It is Swiss-hosted; Switzerland is outside the EU/EEA but covered by a European Commission adequacy decision. We do not state a fixed mailbox retention period beyond the configured mailbox handling.
Sentry, Aptabase and Better Stack are not enabled. We send them no crash, analytics or uptime data. No product-analytics processor is named as active because no analytics service is wired into the app or this website; we would update this policy, name the recipient and honour the separate analytics choice before enabling one.
Production map tiles come from OpenStreetMap through a first-party CloudFront and Lambda proxy. Requests are bounded to Ireland and cached for seven days. The browser does not contact OpenStreetMap directly: OpenStreetMap receives the proxy IP address, a fixed user-agent and the requested tile, rather than the user's IP address or browser user-agent. No alternate direct-to-provider tile path is used in production.
The statuses above distinguish services that are active from integrations that are deployed but do not yet carry live purchase or analytics events. Published provider terms do not by themselves prove that a separate negotiated arrangement exists, and we do not claim one where none is recorded.
How long we keep it
Account, observation, consent and database-entitlement rows are kept while the account is active. Confirmed in-app account deletion first removes every current and older private S3 photo-object version and delete marker for that subject, then hard-deletes the active Postgres account and its cascading rows. The client clears that subject's SQLite observations, sync cursor, raw legacy-import backups, saved local photos, consent, agreement and privacy caches, home county or region, onboarding state and other covered device caches; the Cognito identity is then deleted. There is no 30-day undo period. Ordinary sign-out does not perform this deletion.
That automated transaction is not a claim of complete erasure across every store. It now also deletes the subscription/access mirror and your identification and map quota counters. It does not delete pseudonymised usage-analytics entries, RevenueCat records, or purchase records controlled by the App Store or Google Play. Contact privacy@foragepal.com for manual handling of records Echofold controls. Store purchase history and store-account rights are handled by the relevant store, and account deletion does not cancel a subscription.
Aggregate usage-analytics entries are recorded against a keyed pseudonym rather than your account identifier, and the automated deletion does not remove them today; they expire 35 days after their daily or annual usage window closes. Security and rate-limit counters that are not account-scoped also remain and expire through DynamoDB time-to-live.
AWS CloudWatch operational logs are configured for 14-day retention. Encrypted RDS automated backups use a seven-day rolling window and age out rather than being edited in place. Any production restore must replay prior erasures and coordinate re-coarsening before user traffic resumes so erased or over-precise data is not reintroduced.
Consent history is kept for the life of the account as proof that we honoured your choices, then removed by the active-database cascade. We do not currently copy account-linked observations into a training or contributed-species dataset. A future secondary use would need its own documented purpose, lawful basis, retention decision and notice before collection.
This website has no application database, login, checkout or submission form. Serving a page still requires AWS and CloudFront to process connection metadata such as your IP address, requested URL and browser headers. We run no website analytics service and create no website visitor profile; see "This website" below.
Your rights
Under GDPR you have nine rights over your personal data, listed below. To exercise any of them, contact privacy@foragepal.com, use the in-app controls, or use the account-deletion request page on this site.
Access and export: you can download a copy of your data — including your exact coordinates and your full consent history — from Settings in the app.
Erasure: the in-app "Delete account" control automatically deletes every private S3 photo-object version and delete marker before the active database and Cognito identity, and clears the subject-scoped device data described above, with no undo. It also deletes the subscription/access mirror and your identification and map quota counters. If you have uninstalled the app, the account-deletion page shows how to make a manual request by email. Pseudonymised usage-analytics entries, non-account-scoped security counters, RevenueCat records and independent store purchase records remain outside the automatic transaction. Deletion does not cancel a subscription; manage that in the App Store or Google Play because the store is the merchant.
Response times: we respond to rights requests within one month. For complex requests that can be extended to three months, and we will tell you if that happens.
Complaints: if you are not satisfied, you can complain to the Data Protection Commission (https://www.dataprotection.ie).
- Access. Ask what personal data we hold about you and get a copy of it.
- Rectification. Ask us to correct personal data that is inaccurate or incomplete.
- Erasure. Ask us to delete your personal data ("the right to be forgotten").
- Restriction. Ask us to limit how we use your data while a query about it is resolved.
- Data portability. Ask for your data in a structured, commonly-used, machine-readable format.
- Objection. Object to processing we carry out on the basis of legitimate interests.
- Withdraw consent. Withdraw your consent at any time, without affecting the lawfulness of processing carried out before you withdrew it.
- No solely-automated decisions. Not be subject to a decision based solely on automated processing that produces a legal effect or similarly significantly affects you.
- Lodge a complaint. Complain to the Data Protection Commission (https://www.dataprotection.ie) if you believe your rights have been infringed.
To exercise any of these rights, contact privacy@foragepal.com (or support@foragepal.com), use the account deletion request page, or see Support. You can also lodge a complaint with the Data Protection Commission at https://www.dataprotection.ie.
Data Protection Officer
Echofold Ltd has not appointed a statutory Data Protection Officer, and no final statutory-appointment determination is recorded.
Because we can process precise location data, we operate a dedicated privacy contact: privacy@foragepal.com. The scoped data-protection impact assessment is an engineering record, not a claim that a statutory Data Protection Officer has been appointed.
AI transparency
Photo identification in the ForagePal app is AI-assisted: it returns confidence-scored species suggestions together with relevant toxic lookalikes — this is not a verdict. Never eat anything based on an app ID alone.
When you use that feature you are interacting with, and viewing the output of, an AI system operated by a third party (Kindwise mushroom.id). Its results are AI-generated suggestions, not identifications, and they can be wrong — including confidently wrong. We never ask that service for edibility information, and no output of ForagePal determines the edibility or toxicity of any organism.
We provide that notice as a safety and transparency measure. We do not claim that the one-shot photo-suggestion flow falls within the direct-interaction duty in Article 50(1) of Regulation (EU) 2024/1689: the European Commission's July 2026 guidance says a genuine two-way exchange is one of four cumulative criteria.
The fruiting forecast is rule-based — built from habitat and season rules, never a black-box model.
How we protect your data
We use encryption in transit and at rest for the primary AWS stores, least-privilege access controls, private S3 access, and client-and-server coarsening wherever exact coordinates have not been consented to. Operational logs are minimised and time-limited as described above; Sentry is not part of this control set.
Dedicated auditing of privileged location-row reads and a final sensitive-taxa list and workflow are not implemented; while that remains true, every find location is treated as restricted. The production map uses the proxy described above. Any backup restore must replay account erasures and coordinate re-coarsening before traffic resumes.
No system is perfectly secure. If a breach affecting your rights and freedoms occurs, we will notify the Data Protection Commission and, where required, you, in line with GDPR Articles 33 and 34.
This website
This website is static: pre-built pages served from storage behind a content-delivery network. It sets no cookies, runs no tracker, and loads nothing from a third-party domain. There is no login, no account area and no checkout on this site — the app is distributed only through the App Store and Google Play.
There is no form on any page of this site — nothing to sign up for and nothing to submit into a website database. As with any website, your device sends connection metadata such as its IP address, the requested URL and browser headers to AWS and CloudFront so the page can be delivered. We do not use that traffic to build a visitor profile or run analytics.
The only deliberate way to send us content from this site is to email support@foragepal.com or privacy@foragepal.com, which reaches the Proton-hosted mailboxes described above. An email may contain whatever personal data you choose to put in it, so please do not include passwords or payment-card details.
Amazon Web Services is the hosting and content-delivery processor for this site, and it is the only processor involved in serving these pages to you.
Changes to this policy
We may update this policy when the service, recipients or applicable requirements change. The "Last updated" date above always reflects the current version.
If we make material changes, we will present the updated policy in the app and, where required, ask you to accept it again before continuing.