Privacy Policy
Last updated: 20 July 2026
This policy explains what personal data PodLog collects when you use PodLog, why we collect it, and what rights you have over it. We are the data controller for that data. If you have any question about this policy, contact us at privacy@podlog.co.uk.
Summary
You can browse the map without an account and without giving us anything. If you create an account we store your email address so that you can sign in. If you report a sighting, that sighting is published publicly on the map, including its location, its time and any photograph attached to it. We do not use analytics, advertising or tracking cookies, and we do not sell your data to anyone.
What we collect
Account data. Your email address, a securely hashed password (we never store the password itself), your display name, and an optional avatar image. If you sign in with Google we receive your email address and basic profile information from Google. We never receive your Google password.
Sighting reports. The species, the date and time, and the location you give us, which may be chosen on the map, taken from your device's GPS, or read from the photograph you upload. Photographs are stored and shown publicly. Please note that photographs often contain embedded location data (EXIF GPS). We read it in order to place your sighting accurately, and you can always place the sighting manually instead. You may post a sighting anonymously, in which case your name is not shown alongside it, although we still associate it with your account internally so that you can manage it.
Content you post. Anything you write in community groups, including posts, comments and reactions, along with who wrote it and when.
Technical and anti-abuse data. To stop spam and abusive submissions we store a one-way hash of your IP address rather than the address itself, together with the time of the request. We cannot recover your IP address from that hash. We also use Cloudflare Turnstile to tell humans from bots when you submit a sighting.
Communication preferences. Whether you have subscribed to the newsletter or to sighting alerts, and any geographic alert zones you have drawn on the map.
Why we use it, and our lawful basis
To provide the service: creating your account, signing you in, and showing your sightings and logbook. Lawful basis: performance of a contract with you.
To publish sighting data: the map, the pod tracks and the forecast are built from submitted sightings, and this data may also be used in aggregate for conservation and research purposes. Lawful basis: legitimate interests (operating a public wildlife-recording service).
To keep the service safe: rate limiting, bot checks, moderation, and blocking abusive users. Lawful basis: legitimate interests (preventing abuse and protecting our users and data quality).
To send you emails you asked for: sighting alerts, digests and the newsletter. Lawful basis: consent, which you can withdraw at any time using the unsubscribe link in any email or in your notification settings.
Who we share it with
We do not sell your personal data. We use a small number of service providers who process data on our behalf, under contract:
- Cloudflare: hosting, content delivery, file storage and bot protection.
- Neon: the database that stores accounts and sightings.
- Resend: sending transactional email and alerts.
- Roboflow: automated image classification, to check that an uploaded photograph plausibly shows a cetacean.
- Google: only if you choose to sign in with Google.
- OpenFreeMap: serves the base map tiles your browser loads.
Some of these providers may process data outside the UK. Where that happens, transfers are covered by appropriate safeguards such as the UK International Data Transfer Agreement or adequacy regulations.
What is public
Sightings are a public record. The species, the location, the time, any photograph, and your display name unless you post anonymously, are visible to anyone, including people who are not signed in, and may be indexed by search engines. Please think before uploading a photograph that shows identifiable people, a vehicle registration, or your home. Content you post in groups is visible to the members of that group.
How long we keep it
Account data is kept until you delete your account. Sighting records are retained indefinitely as part of the scientific record, though we will disassociate them from your account on request. In-app notifications and hashed IP records are pruned automatically on a rolling basis, as they are only needed for recent activity and abuse prevention.
Your rights
Under UK GDPR you have the right to access a copy of your data, to have inaccurate data corrected, to have your data erased, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent, you can withdraw it at any time. To exercise any of these, email privacy@podlog.co.uk.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, though we would appreciate the chance to put things right first.
Cookies and local storage
We use no analytics, advertising or tracking cookies of any kind. We set a single strictly-necessary cookie to keep you signed in, and we store your sign-in token and some interface preferences in your browser's local storage. Cloudflare Turnstile may set a short-lived cookie when you submit a sighting, purely to verify that you are not a bot. Because all of these are strictly necessary to deliver a service you have asked for, we do not ask for consent for them. You can clear them at any time in your browser settings, which will sign you out.
Children
PodLog is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of this page, and tell you by email if the change materially affects how we use your data.