Privacy Policy
Cool Bear Exhibit
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Cool Bear Exhibit stores the observations you create: optional photographs, observation date, manually entered approximate region, bear species or an unidentified species selection, observed behavior and notes. It also stores exhibition titles, ordered species or observation references, captions and Habitat Curator progress. These records and an offline mutation queue are saved in the app's protected local storage and synchronized to our backend. Language, the last opened hall and the current game step are stored locally. A cryptographically random installation secret is stored in the iOS Keychain and sent with API requests; the backend stores its hash to separate installations, rather than a user account. The app does not request your email, name, password, contacts or device location. Selected or captured photographs are converted to JPEG, and the server removes metadata such as EXIF. Servers nevertheless receive network information, including IP addresses, request paths, timestamps and technical request information when the app or the public website connects.
How we use information
We process this information to display and preserve your private observation journal, photograph archive, ordered exhibitions and game progress; provide updated educational content; support offline use and synchronization; authorize access for your installation; and operate, protect and diagnose the service. We do not add advertising or behavioral analytics SDKs, send messages or emails, or make your collections publicly accessible.
Service providers and sharing
The API, public website and PostgreSQL database are hosted on Railway. Railway processes network requests and infrastructure logs as the hosting provider. The application's runtime dependencies include Express, PostgreSQL client libraries, multipart parsing, rate limiting and Sharp image processing; these run inside our backend and do not transmit your collections to separate analytics or image-processing services. Apple provides iOS Keychain, the camera and the system photo picker on your device. Opening an external educational reference or this privacy page sends the usual web request to its host. Service administrators may access stored data and limited operational diagnostics when operating the service. We do not sell your data or share your photographs with other app users. We may disclose information when legally required.
Data retention
Your local records remain until you delete them or remove the app's local data. Your server records and photographs remain until you delete individual records or use Delete all personal data and that operation reaches the server. Removing the app alone does not send a server deletion request. The Keychain secret may remain after uninstalling, depending on iOS behavior. The application does not implement a scheduled expiry period. Infrastructure logs follow Railway's hosting configuration; we have not established a fixed retention duration for those logs or provider-managed backup copies. A deletion removes records from the active application database; any infrastructure backup copies are subject to the provider's lifecycle and are not immediately erased by the app's deletion request.
Deleting your information
You can delete individual observations and exhibitions in the app. Deleting an observation also removes its associated photograph when no remaining observation uses it, and removes its references from exhibitions. Removing or replacing a photograph removes the old server photograph after synchronization. Settings offers Delete all personal data to clear observations, photographs, exhibitions and game progress on this device and the active server database. When offline, the app clearly queues server deletion until connectivity returns; use Sync now and wait for Up to date to confirm synchronization. Deletion cannot be undone. The app does not provide account recovery or cross-device sign-in: if the installation secret is lost, we cannot promise restoration or locate the installation from an email address. For privacy questions or assistance with a data request, contact ihorkaplenkov14@gmail.com without sending sensitive photographs or the installation secret.
Permissions and your choices
Camera access is optional and is requested only when you choose Take photo. You may deny or withdraw it in iPhone Settings and still use the guide and create observations without photographs. The system Photos picker allows you to select individual images without granting the app general access to your photo library. The app does not request location access and regions are typed manually. Withdrawing permission prevents future capture or selection as applicable but does not automatically delete photographs already saved locally or synchronized; use the deletion controls to remove them.
Your privacy rights
Depending on the laws that apply to you, you may have rights to access, correct or delete personal data, restrict or object to processing, or request portability and complain to a relevant privacy authority. You can view and edit your observations and exhibitions in the app and delete stored data through Settings. Contact ihorkaplenkov14@gmail.com for other privacy requests. We will assess requests under applicable law and may need information sufficient to verify control of an installation. No user account or email identity is maintained, so an email address alone cannot identify your stored records. We do not require you to send your installation secret by email.
Security
The app uses HTTPS for the deployed API. Each installation receives a random secret stored in Keychain with device-only accessibility, and server authorization partitions every private query by its hashed secret. Private photo responses are not public links and use no-store caching. The local archive uses atomic writes and iOS file protection. The backend validates references, limits payload and storage sizes, uses parameterized database queries and transactions, and does not log secret headers or photograph contents in its application logs. Hosting administrators and infrastructure remain part of the trust boundary. No storage or transmission system can be guaranteed completely secure; anyone who obtains an installation secret may access that installation's data.
Children’s privacy
The educational content is intended for wildlife enthusiasts and families, including children with appropriate adult guidance. The app does not require accounts, advertising profiles or contact details. Adults should supervise photography and notes and avoid entering identifying information about children or other people. If you believe a child's personal information has been included in a collection improperly, use the in-app deletion controls or contact ihorkaplenkov14@gmail.com for a privacy request. The app's educational observation tips do not replace local wildlife safety rules.
Changes to this policy
We may update this policy when the app's processing or hosting practices change. The current policy is available through Settings and the public privacy page, with its effective date. Material changes will be reflected in the published policy and relevant app information. The public privacy contact is ihorkaplenkov14@gmail.com.