The short version
Bird detection is metadata-only by default. Audio is analyzed on-device, continuous audio is never uploaded, and owner-enabled detection clips require a deliberate choice. Blind research sampling is currently disabled while we build a versioned opt-in consent flow.
Information we handle
Account and service information
When you create an account, we handle account and profile information such as your email address, display name, avatar, authentication state, account identifiers, settings, subscription or complimentary Plus status, and security information for email verification and optional two-factor authentication. When you use Sign in with Apple, the app sends Apple’s identity token to our backend; after verification, we store the stable Apple subject and email Apple provides, which may be a private relay address. We also keep notification and watchlist preferences, public-yard follows, and box-waitlist membership and subscription or unsubscribe dates. If you contact support, we receive your email address, message, and any attachments or diagnostic information you choose to provide.
Detections and location
We handle bird candidates, species, confidence scores, timestamps, model and decision information, embeddings, corrections, and station or device identifiers. With permission, the handheld app may use precise location and reverse-geocoded place information for a result. A box uses its registered exact location for your private atlas and for local and cloud plausibility checks. An embedding is a numeric representation of an analyzed sound, used for matching and evaluation; it is not a recording, but it can still be associated with your observations or station.
Device and operational information
We handle app and device platform details, push notification tokens and preferences, box firmware and health, connectivity and update state, queue depth, error and security events, and ordinary request information such as IP address and browser details. QR, camera, Bluetooth, and nearby Wi-Fi access are used during box setup. A Wi-Fi password is sent over the local encrypted Bluetooth setup channel to your box; Birds Heard does not need it for ordinary cloud service.
Local and offline data
The mobile app stores its session securely on your device and may keep account scope, a pending-save queue, bird candidates, time, location, and embeddings locally so a save can finish after connectivity returns. Anonymous pending saves can be assigned to the account that next signs in on that device; pending saves belonging to a different account are quarantined.
Data kept on a Birds Heard box
A box keeps local records for detection metadata, embeddings, candidate scores and decisions, and delivery state so it can operate and retry during outages. Current defaults prune detailed candidate records after 14 days. Forwarded or dropped metadata is count-capped rather than guaranteed a fixed time retention, so how long it remains depends on detection volume. Service logs and a quarantined copy of a corrupt database do not currently have a repository-defined automatic expiry. The local Wi-Fi profile remains on the box until it is removed at the operating-system level. These implementation defaults and limits may change as the appliance is hardened; current customer audio choices remain as described below.
Audio: handheld and box
Handheld identification
Handheld bird identification analyzes recordings on-device. Bird candidates, confidence, time, and location may be sent to Birds Heard to improve the match. Handheld recordings are uploaded only when you explicitly choose to save the sound. A temporary recording may remain on your device until the operating system or app storage is cleared. Saved handheld sounds remain in your account until you delete the observation or account; the box clip-retention setting does not apply to them.
Birds Heard box
The box analyzes short windows locally and normally sends detection metadata, not audio. Continuous audio is never uploaded. If an owner explicitly enables detection clips, a short clip around a detection may be screened on-device and uploaded for private playback. Blind research samples are a planned separate short-audio program and are currently disabled pending a versioned, explicit opt-in consent flow; enabling detection clips or Plus does not provide that consent. Audio screening is designed to keep clips containing speech, people, pets, vehicles, or music on the box, but no automated screen is perfect.
When a workspace owner enables detection clips, an authorized workspace member whom Birds Heard has granted correction access may play those clips in the correction workflow. Birds Heard staff and external labelers cannot review or listen to ordinary correction clips without a separate, explicit research opt-in consent.
Location and public yards
Your exact location is private and is not published as coordinates on a public yard page. Publishing a yard is opt-in and may show its label and handle, bird names, counts, activity, and the location detail you select. Saved audio is not public. “City” uses generalized approximate coordinates rounded to one decimal degree, rather than your exact position or necessarily the city center, and the public city name you enter separately in Privacy settings. We do not use your private saved place description as the public location label. If you leave the public city blank, the label falls back to a recognized state or province when available. Before publishing, the app previews your public label, handle, and location text. “Region” uses a state or province label and, where available, an approximate regional map point. “Hidden” shows no map location. If you enable live public activity, recent bird activity and timestamps may appear publicly. Otherwise individual detection timestamps are reduced to a date; counts and filtered activity can still change as new detections arrive. The public label and handle are text you choose, so avoid including your address or other information you want to keep private. Public information can be copied or combined with other information by people who view it.
Authorized members of your account can see private account and yard data. Platform administrators use privacy-bounded operational summaries and limited account records to secure, support, or operate the service. That role alone does not grant access to private detection history, precise location, audio, or customer exports. Correction records require separate correction access within the authorized workspace; public-yard content can be seen by anyone.
How we use information
- Provide sign-in, bird identification, saved finds, private atlases, public yards, notifications, exports, box setup, and software updates.
- Enrich and evaluate bird matches, improve models and decision systems, maintain the authorized correction workflow, and—only if separately enabled in the future—operate the research workflow described above.
- Protect accounts, diagnose failures, prevent abuse, maintain audit records, and support users.
- Understand use of our marketing and product surfaces only when analytics consent permits it.
- Comply with law and enforce our Terms of Service.
Who can access information and why
We do not give everyone listed below unrestricted access. Access depends on the feature you use and is limited to the information reasonably needed for the stated purpose.
- K3 Technologies, LLC and Birds Heard administrators. Authorized personnel may access account details, subscription and correction-access status, box operational summaries, administrative audit records, and support correspondence when needed to secure, support, or operate Birds Heard. Customer content is processed by our service infrastructure; access through the ordinary platform administration role remains limited as described above. Administrative or infrastructure access does not authorize staff to listen to ordinary correction clips or override the audio limits below.
- Authorized account members and correction reviewers. Members can access private information available within their workspace. Correction users can access correction records and only the detection clips made available within the authorized correction workflow. Birds Heard staff and external labelers cannot listen to ordinary correction clips without a separate, explicit research opt-in.
- The public. Anyone may see information you deliberately publish through a public yard, including the selected handle, bird activity, and the city-, region-, or hidden-level location you choose. Exact private coordinates, saved recordings, private yards, and account information are not included in a public yard.
- Cloudflare. Cloudflare processes web and API requests, IP address and browser or device request information, account and service data stored in our databases, and security and delivery information for hosting, infrastructure, databases, object storage, delivery, and security. A saved sound recording is uploaded to Birds Heard and stored in Cloudflare object storage only when you choose to save it or an owner has enabled eligible box detection clips. Transactional email can include the recipient address, subject, message body, and delivery metadata.
- Apple. Apple may process Sign in with Apple identifiers and authentication activity. When the app uses Apple device services, Apple may also process device, location, reverse-geocoding, and related service information under Apple’s policies.
- Expo, APNs, and FCM. For push notifications, Birds Heard sends the Expo push token, notification title and body, and custom data to Expo, which forwards it to Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM) as applicable. A notification may contain a bird species, yard or box label, counts, timing or offline status, a station identifier, an in-app destination, and a public bird-image URL. Your device may display this information on its lock screen according to your notification settings. Expo Application Services may also process device and operating-system details, app and update identifiers, randomized installation or update-download tokens, and ordinary update-request metadata to build, deliver, or update the mobile app. Software-update delivery is separate from optional usage analytics. Expo says push-message contents are kept only as needed for delivery, although its personnel may see them while debugging the delivery service.
- Google. We use Google for maps and geocoding on our web surfaces (the iOS app uses Apple’s map and geocoding services, described under Apple above) and for Gemini AI or machine-learning features such as regional plausibility checks, approximate place resolution, generated bird information, and generated bird art. Map requests from your browser or device can include coordinates or a place query plus IP address and ordinary request information. Gemini receives species, region, place-query, and requested-content context, but not detection audio or account identity. Web fonts are self-hosted by Birds Heard and served through Cloudflare without contacting Google. Google handles its requests under its Privacy Policy.
- GBIF. This independent biodiversity-data service receives species and a geographic region or a coarse coordinate bounding box when our servers request taxonomy, occurrence, or seasonal reference information. These requests do not include your account identity, audio, or raw precise coordinates.
- Open-Meteo. Our current weather connection sends exact station latitude and longitude, dates, and requested weather variables from our server to Open-Meteo, an independent weather-data service. We do not include your name, account or station identifier, or detection audio in that request. Its privacy notice says request logs may contain coordinates and are deleted after 90 days.
- ClickClacks, operated by K3 Technologies, LLC. ClickClacks is our own analytics system, hosted on Cloudflare. On our websites, when you opt in and no enabled DNT or GPC signal blocks analytics, it receives page views, referrers, clicks, scroll depth, and browser-generated person and session identifiers. Click records can include the text of unmasked links or buttons, such as a bird name, plus element tags, selectors, classes, IDs, click position, and viewport size. Configured heatmaps record element geometry and structural details, not screenshots, form-field values, or session recordings. We mask account-name and email controls. On the authenticated web app, it also receives an opaque internal user ID, limited tenant and station IDs, and a Tenant Role trait; we do not send your name or email as analytics identity traits. With the same consent, Birds Heard servers send the account and box events described in “Cookies and optional analytics,” keyed to that user ID, with plan, number-of-boxes, and sign-up-date traits; these server events are sent from our servers and do not include your IP address or user agent. Its cross-domain identifier connects visits between birdsheard.com and app.birdsheard.com. In the mobile app, a separate opt-in controls the screen views, feature events, random identifiers, and account-linked pseudonymous identifier described above. Mobile analytics does not send tenant or station IDs, referrers, or page-element details. For all three sources, the service receives the requesting IP address and user agent and adds a country and browser, operating-system, and device categories to events. Recording the raw IP address in analytics event records is turned off; infrastructure request logging is separate.
- Anthropic. If authorized personnel use ClickClacks’ AI investigation feature to diagnose product usability issues, it sends their questions, selected analytics findings, and requested analytics records to the Anthropic API. These can include page paths, click targets, event properties, country or device categories, pseudonymous person identifiers, and associated activity. This is a separate processing step for analytics collected under your analytics choice. It does not send detection audio. Anthropic’s commercial terms govern this API use; its standard API retention is up to 30 days, subject to agreed settings and safety or legal exceptions.
- Legal, safety, and business recipients. We may disclose information to courts, regulators, law enforcement, advisers, insurers, or transaction participants when required by law, reasonably necessary to protect rights or safety, or involved in a merger, financing, reorganization, or sale. Where permitted, we will limit the disclosure and require appropriate confidentiality.
Audio boundary. Continuous microphone audio is not uploaded or disclosed to these recipients. A saved sound or eligible owner-enabled box clip reaches Birds Heard and Cloudflare only through the deliberate upload paths described in “Audio: handheld and box.” Google, GBIF, Open-Meteo, ClickClacks, Anthropic, and push providers do not receive detection audio through the current product flows.
Provider protections. We require service providers acting on our behalf and receiving app data to use it only for the contracted purpose and provide the same or equivalent privacy protection described in this policy and required for the app. If we learn that a provider cannot meet those requirements, we will take reasonable steps to stop and remediate the processing. Independent services, including Apple device services, Google Maps, GBIF, and the current Open-Meteo connection, also process requests under their own terms and privacy notices; they do not all act solely on our instructions. Their specific roles and data are described above.
Collection across websites and services. Birds Heard does not use its own service to collect information about your activities over time across unaffiliated websites. Third parties may collect or combine information about online activities over time and across websites or services as described in their own privacy policies. In particular, Google Maps may receive IP address, device or browser information, coordinates or place queries, and information about the page request. Web fonts are self-hosted by Birds Heard and served through Cloudflare without contacting Google. We do not authorize third parties or service providers to use Birds Heard data for cross-site behavioral advertising.
Storage, retention, deletion, and export
We keep account and service data while needed to provide the service, meet security and legal needs, and resolve disputes. A daily scheduled process applies the workspace owner's selected retention window to eligible box detection clips: the default is 30 days, configurable from 1 to 365 days. This window does not automatically expire saved handheld sounds, detection metadata, or embeddings. A failed deletion may be delayed and retried. Provider recovery copies, if any, are not returned to ordinary use and age out under the provider's recovery controls. Operational logs and privacy-minimized audit records may be retained after other content is deleted when needed for security, integrity, legal obligations, or proof of an administrative action.
Analytics records and heatmap data are stored separately from your Birds Heard account. Turning analytics off or deleting the account does not automatically erase previously received analytics records. We do not currently enforce a fixed automatic expiry for those records; contact us to request access or deletion, and we will explain any verification, technical, or legal limits. ClickClacks’ persisted Cloudflare Worker logs can contain request URLs and operational details and have a provider retention limit of up to 7 days. This log limit does not apply to the analytics event store, account data, or separately retained security and support records.
The account data export, available in the signed-in web app, is a limited JSON export of profile, boxes, preferences, the newest 10,000 detections (box detections only), and the newest 1,000 heartbeats. It excludes audio clips and may not include handheld finds, derived model data, internal security records, or information we cannot disclose about others. Separately, the mobile app can prepare an eBird-format CSV of your own observations (species, counts, dates, and the location precision you chose) and hand it to the iOS share sheet; it goes only where you choose to send it, and Birds Heard does not submit anything to eBird for you.
Delete your account
In the mobile app, open your account button, then Settings → Delete account and follow the verification steps. Apple-authenticated accounts may be asked for a fresh Apple authorization instead of a Birds Heard password. In the web app, use the account deletion control in settings where available. You can also email [email protected] from your account email to begin a verified deletion request.
For a member, deletion permanently deletes only that member’s profile, handheld finds, and account access. The workspace, its boxes or stations, bird data, and other members remain. For an owner, deletion permanently deletes the entire workspace, including its boxes or stations, shared bird data, and every member’s access. Deletion remains subject to retry, backup, fraud-prevention, legal, and minimized audit-record limits described above. Before deleting, use the export control in the signed-in web app if you want the available JSON copy; the export excludes audio.
Deleting your cloud account does not factory-reset a box or erase its local database, logs, or Wi-Fi profile. It also does not remove copies you exported, files retained on your phone or in device backups, or public information already copied by someone else. Remove local data separately when transferring or disposing of a device. Contact support if you need help with these steps or with separately stored analytics and correspondence.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, object to or restrict certain processing, or withdraw consent. You can manage many choices in settings. To make a privacy request, email [email protected]. We may need to verify that the request belongs to you. You may also have the right to appeal our response or contact your local privacy authority.
Children's privacy
Birds Heard is only available to people 18 years of age or older. People under 18 may not create an account or use Birds Heard, and we do not knowingly collect their personal information. If you believe a person under 18 provided personal information, contact us so we can investigate and delete it as appropriate.
Security and international processing
We use organizational and technical safeguards, including access controls, encrypted transport, and privacy-limited administrative tools, and rely on our infrastructure providers for physical data-center safeguards. No system is perfectly secure. Our providers may process information in the United States and other countries, which may have different data-protection rules.
Changes and contact
We may update this policy as Birds Heard changes. We will update the date above. For a material change, we will provide a prominent in-service notice and, when appropriate, notify account holders by email before the change takes effect. Questions, requests, or concerns can be sent to [email protected].