Your privacy and the anonymity of your cultivation and botanical research activities are fundamental priorities for the PhenoHunting team. This Privacy Policy describes how we collect, use, store, process and protect your personal and cultivation data in compliance with the General Data Protection Regulation (GDPR), Brazil's General Data Protection Law (LGPD) and other international privacy regulations.
1. Data Collected by the Platform
We collect only the information strictly necessary to ensure the secure and efficient functioning of the application:
- Authentication Data: Email address and access credentials provided by secure third-party identity providers (such as Google Auth or Apple Identity).
- Cultivation & Cataloging Data (UGC): Plant journals, flower and trichome images voluntarily submitted by the User, textual phenotype descriptions and sensory effect evaluations.
- Metadata & Technical Logs: Access logs (masked IP addresses), software crash history (via Crashlytics) and Firebase Installation ID for performance analysis and debugging.
2. Image Privacy & EXIF Metadata Processing
We recognize the critical risk that geolocation data embedded in home cultivation photographs poses to our users' personal safety.
Local EXIF Stripping
Before any image is sent from your mobile device to our cloud servers, the Platform executes an automated script that irreversibly strips and deletes all embedded metadata from the file (including EXIF, IPTC and XMP tags, such as GPS geographic coordinates, camera model, capture date and time).
PhenoHunting does not store your plant geolocation coordinates in your cultivation journal in any way, unless such sharing is voluntarily authorized by you in a public regional macro-genetic mapping section, in an aggregated and non-traceable manner.
3. Data Provision for Artificial Intelligence
Your phenotype cataloging data is used to feed our Paraconsistent AI Engine (ParaSense), whose objective is to generate global taxonomic strain and phenotype consensus. The data used for AI model training undergoes an irreversible anonymization process.
If you choose to set your cultivation profile to "Private", your posts and journal images will not be publicly displayed to other community users and will not be associated with your real identity in any AI training database visible to third parties.
4. Data Sharing with Public Authorities
We will not sell or commercialize your personal data or cultivation journals to third parties under any pretext.
We will only provide personal identification data of our Users to law enforcement or judicial authorities upon presentation of a valid subpoena or court order, issued by a competent court with legal jurisdiction over our parent company, and after rigorous review by our legal team.
5. Right to Data Erasure (Right to Be Forgotten)
In strict alignment with Article 17 of the GDPR and Article 18 of the LGPD, you have the inalienable right to request the permanent deletion of all your personal and cultivation information from our technological ecosystem. When you trigger the account deletion button in the app settings menu, our system executes the following automated data erasure flows:
- Firebase Authentication: Your user profile and login credentials are deleted, definitively revoking future access.
- Firestore Database: Personal user documents, profiles and private journals linked to your unique user identifier (UID) are physically deleted. Public forum posts that remain active are irreversibly anonymized.
- Firebase Storage: All photos and cultivation files associated with your UID are definitively deleted from cloud storage buckets.
- Firebase Installations: The application programmatically invokes FirebaseInstallations.delete(), cleaning residual telemetry data and technical installation IDs.
This deletion process is completed in our production systems within 72 (seventy-two) hours of your in-app request.
6. Security & Encryption
All personal data and cultivation journals processed by PhenoHunting are protected using advanced encryption. Data at rest on our servers is encrypted using AES-256 military-grade cryptographic standard. All data traffic between the mobile application and our cloud back-end infrastructure is transmitted exclusively through channels protected by state-of-the-art SSL/TLS protocols via HTTPS connections.