Petaltrail Privacy Policy (draft)
Version 2026-09-29 · This is a draft. Have it reviewed by a lawyer before launch.
Petaltrail ("the Service") lets you photograph plants, build a personal field guide, and share your finds on a map. This document explains what the Service collects, why, who it is shared with, and what you can ask us to do.
1. What we collect
| Item | Detail | When |
|---|---|---|
| Account | Email address; name and profile supplied by your social login | On sign-up |
| Nickname | Chosen by you (initially derived from your account name) | Sign-up, and when changed |
| Photos | Plant photos taken inside the app | When you take and register one |
| Location | Coordinates of where the photo was taken, and the accuracy | When you take a photo |
| Time | When the record was registered (server clock, not your device clock) | On registration |
| Activity | Likes, comments, name and species suggestions, reports | When you do these |
| Friendships | Friend requests and acceptances | When you send or accept one |
| Language | The language shown in the interface | When set |
There is no way to upload a photo from your gallery. Only photos taken inside the app are registered, and as a result the stored files carry no EXIF metadata from your camera.
2. Why we collect it, and on what basis
- Identifying plants and building your guide — necessary to provide the Service (performance of a contract)
- Showing records on the map and sharing them with others — your consent
- Handling inappropriate content — legitimate interest in handling reports and protecting the Service
- Preventing abuse — limiting identification requests (performance of a contract)
3. Who the data goes to
To run the Service, information is passed to the following providers.
| Provider | What they receive | Purpose |
|---|---|---|
| Supabase | All Service data — accounts, photos, coordinates | Database, storage, authentication |
| Cloudflare | Request information | Serving the website |
| Login information such as your email | Social sign-in | |
| PlantNet | The photo you took | Plant identification |
| Google (Gemini) | Text such as scientific names | Writing guide entries |
| GBIF | Scientific names | Looking up common names per language |
| OpenStreetMap | The map area being viewed | Map tiles |
Your photo is sent to PlantNet in order to identify the plant. That is the only path by which a photo leaves the Service. Guide entries are written from the scientific name only — no photo is sent for that.
These providers' servers may be located outside the Republic of Korea, so using the Service necessarily involves international transfer of your data.
4. What becomes visible to others
If a record is public, other users can see:
- The photo, the plant name, and when it was registered
- Where it was taken (subject to the setting below)
- Your nickname (we recommend not using your real name)
Public plant pages (search engines)
Photos from public records also appear on plant pages that anyone can open (for example petaltrail.com/en/plant/…), and those pages may show up in search engines such as Google and Naver. They carry the photo, the plant name, and aggregate statistics only, such as sightings per month. Nicknames, coordinates, notes and comments are never shown there.
- Turn off "Show my photos on public plant pages" on the *My* screen and your photos are removed from these pages. Visibility inside the app is unchanged.
- Making a record private, or deleting it, removes it too.
- Copies already cached by a search engine disappear on that engine's own schedule.
Location detail is set on the *My* screen.
- Rough (default) — only the blurred value, roughly 1 km, is stored. The exact coordinates never reach the server. Your neighbourhood remains visible; your building does not.
- Exact — the measured coordinates are stored and published as-is.
- Do not record — no coordinates are stored, and the record does not appear on the map.
The default is deliberate. Someone who never opens the setting should not end up publishing the exact location of their home or workplace. In rough mode the app does not turn on high-accuracy GPS either, since it is not needed — which also saves battery.
A note about photo files
Photo files are held in storage that can be fetched directly over the web. If you make a record private, it disappears from the Service's screens and the map, but anyone who knows the file's address can still open it. The address is a long random value and is hard to guess, but this is not a complete barrier. Please do not upload photos of sensitive places or of people.
5. Photos containing other people
Do not upload photos showing faces, licence plates, or anything else that identifies a person. If you upload a photo in which someone is identifiable, you are responsible for it. Anyone can use the report button to ask for such a photo to be taken out of public view.
6. How long we keep it
- For as long as your account exists.
- When you delete a record, the record and its photo file are both deleted.
- A photo you have taken but not yet named is uploaded straight away and kept in a waiting list until you pick its name or press *Discard*.
- If you ask us to delete your account, all records and photos linked to it are deleted.
- Reporting history may be retained for a period after account deletion, so that repeated abuse can be dealt with.
7. Your rights
You can do these yourself on the *My* screen.
- Download my data — your account, records, comments and likes as a JSON file.
- Delete all my records — removes every record you have added, and the photos.
- Change location detail — at any time. It applies to new records only, so delete existing records if you want their location removed.
Account deletion is not available on screen. Contact us using the details below and we will delete your account and all of its data. Use the same contact for any other request, such as restricting or objecting to processing.
8. Age
You must be 14 or older to use the Service. This is confirmed at sign-up.
9. Security
- The database uses row-level security; you can reach only your own data and data that has been made public.
- Traffic is encrypted with HTTPS.
- Administrator rights are held in a separate list that users cannot grant themselves.
10. Changes
If this policy changes, we will say so inside the Service and ask you to agree again. The version you agreed to is recorded.
11. Contact
- Operator: Changho Kim (김창호)
- Phone: +82 10-2316-5048