Mammaling is a citizen-science app for recording the mammals you see. What you record leads two lives: it is your own field diary and, at the same time, scientific material that helps show where each species lives and how it is faring.
This policy sets out what we collect, why, and what control you have. It is written to be read; if anything is unclear, that is our fault, so write to us and we will fix it.
What changed on 3 September 2026. Mammaling no longer carries advertising and does not intend to: it is funded by voluntary subscriptions. We have added the section explaining what is sent to a Google AI service when you ask for help identifying a photo — and what is not sent. And we have named three providers that were missing: Stripe, MapTiler and Resend.
The controller of your personal data is:
Ángel Dolón Viejo
Capel Place, Midleton, Co. Cork, P25 X535, Ireland
Email: [email protected]
Mammaling is governed by the General Data Protection Regulation (GDPR) and by Irish data protection law. The competent supervisory authority is the Data Protection Commission of Ireland.
| Category | What it includes | When |
|---|---|---|
| Account | Email address, password (encrypted), display name, @username, profile photo and biography if you add them. | When you sign up |
| Observations | Species, date, time, number of individuals, coordinates of the site, site name, protocol, duration, distance, number of observers, evidence, behaviour, sex, age and your notes. | Each time you record a checklist |
| Photos and sounds | The images and recordings you upload and their technical metadata (capture date, camera model, and coordinates if your phone embeds them). This metadata is stripped from the public copy and kept only in the archive copy, which is never published — section 6 explains this in full. | When you upload a photo or a recording |
| Location | Your approximate or precise position, only if you press the GPS button or allow geolocation. | When you ask for it |
| Community | Contacts, checklists shared with companions, comments, private messages between users, and the reports you send when you flag content or query an identification. | When you use those features |
| AI identification | The reduced photo, the country and the month of the observation, your notes if you wrote any, and the list of possible species. Sent to a Google service, and only when you press the button. Section 7 covers it in full. | Only if you ask for help with a photo |
| Subscription | If you subscribe, we store only two Stripe identifiers (customer and subscription) and the fact that your account is active. The payment itself is handled by Stripe on its own pages. | Only if you subscribe |
| Technical use | IP address, device and browser type, pages viewed, application errors. | Automatically |
| Purpose | Lawful basis (GDPR art. 6) |
|---|---|
| Creating and maintaining your account, storing your checklists and your life list | Performance of a contract |
| Showing your public observations to the community | Performance of a contract and legitimate interests |
| Using observation data for scientific and conservation purposes | Legitimate interests, and scientific research purposes (art. 89) |
| Reading your location by GPS | Consent (given in the browser, and withdrawable there) |
| Sending your photo to an AI service to help identify it | Consent: it happens only when you press the button, and not using the feature costs you nothing |
| Managing your subscription and checking that it is active | Performance of a contract |
| Preventing fraud, abuse and false records; moderating content | Legitimate interests |
| Sending you notices about your account, your photos or your messages | Performance of a contract |
In Mammaling, observations are public by default, because that is precisely where their scientific value lies: they only help conservation if they can be consulted and analysed. But the precision is yours to set.
Sensitive species. For some species threatened by poaching or collecting, Mammaling obscures the location automatically even if you chose public. Publishing the exact coordinates of a lynx or a pangolin can cost the animal its life. This protection cannot be turned off.
By recording a public observation, you agree that the associated data — species, date, location (at the precision you chose), number of individuals and sampling effort — may be used to:
Scientific records carry your username as the observer, unless your profile is in anonymous mode. Observation data is released under an open licence (CC0 or equivalent), and that release is irrevocable: once a record has entered a scientific dataset and other researchers have used it, withdrawing it would break their work. This is standard practice in biodiversity repositories.
If you delete your account, your observations are detached from your identity but remain in the scientific record anonymously. Your profile data, your messages and your photos are deleted.
Your photographs remain yours. You keep the copyright in everything you upload.
By uploading them you grant us a worldwide, non-exclusive, royalty-free licence to host them, display them within Mammaling, generate reduced versions, and use them to promote the app.
All photographs are also published under Creative Commons Attribution-NonCommercial (CC BY-NC): anyone may reuse them with credit to you, but nobody may sell them or profit from them without your permission. It is a single licence for the whole app; there is nothing to configure. If you would rather not publish a photograph on those terms, do not upload it — the observation is recorded either way.
The full terms are in the Terms of use.
When you upload an image, Mammaling keeps two versions, and the difference between them matters:
| Copy | What it is | Who sees it |
|---|---|---|
| Public | An optimised version, generated on your own device. That process always strips every EXIF field: coordinates, capture date, camera model. | This is the one shown in the app, and the only one ever shared. |
| Archive | The file as it came out of your camera, at full quality. It keeps the original metadata, which may include the exact coordinates of the site. | Never published, never shared. Accessible only to the project's controller. |
Why we keep the original. Downsizing an image is irreversible: a photograph compressed today cannot be recovered tomorrow, and by then you will probably have cleared it off your phone. Keeping it means that image can later serve a scientific paper, a printed guide or a conservation campaign at the quality those uses demand. Without the archive file, an Iberian lynx photographed today would be no use for a book next year.
Why the original is not published. Precisely because it retains the location. Serving it openly would let the geoprivacy protection on your checklists leak out the back door: there would be no point obscuring an observation's location if the exact point travelled hidden inside the image file. Access to the original is therefore restricted technically, not merely by internal rule.
If you delete a photograph, both copies are deleted.
You can delete your photographs at any time. A moderator may remove photographs that breach the rules (other people's content, animal cruelty, unrelated material); if that happens you will receive a message explaining why.
When you do not know what you have seen, Mammaling can help. There are two different kinds of help, and one of them sends your photograph to a third party. It is worth knowing which is which.
The first kind ranks the possible species by where and when you are, using public records for the area. It does not look at the photograph and sends nothing anywhere. There is also an image-recognition model that downloads and runs inside your own browser: it looks at the photograph on your device, and the image is not uploaded at all.
If you press that button, the photograph is sent to an artificial-intelligence service run by Google — the Gemini model, through the Generative Language API — so that it can rank the candidate species. It is a separate, clearly labelled button: this never happens automatically, and never merely because you uploaded a photo.
| What is sent to Google | What is NOT sent |
|---|---|
|
|
Why the request goes through our server rather than straight from the app. Because the key to the service is paid for by the project's controller, and a key sitting inside a web page's JavaScript can be read by anyone. The request is made from a function hosted on Supabase; the key is not in the app you download.
What we keep of the result. We store the species the model proposed, its confidence, and the sentence in which it says which feature it claims to have seen in the image. That is stored deliberately, so the suggestion can be checked against the photograph rather than taken on trust from a percentage. We also count how many identifications you have requested, in order to apply the monthly limit.
An identification is help, not a decision. The species that ends up recorded is always the one you choose. This data reaches scientific repositories, and an identification filled in by a machine and never checked is exactly the kind of error nobody catches afterwards.
If you would rather not use it, don't. You can record observations, upload photographs and use the whole app without touching this feature. There is no way for your photograph to reach Google unless you press that button.
The text of the species accounts — written by us, not by users — is translated into English by an AI service (the same Google one, with Cloudflare's as a fallback). Your own data never goes through it: your notes, your comments and your messages are not translated.
Mammaling is free and carries no advertising. No adverts, no advertising identifiers, no advertiser cookies, no profiling to sell space to anyone. This is not a phase; it is a decision about what kind of app this should be.
It is funded by voluntary subscriptions from people who want to support it. Subscribers get conveniences — more AI identifications per month, no per-species photo cap, the ability to start conversations — and help pay for the servers and the expeditions. Everything that gives the project reach and scientific value is free for everyone: recording observations, reading the species accounts, the articles and the maps.
Payments are processed by Stripe, on its own pages:
If another source of funding ever appears — institutional sponsorship, for instance — it will be announced in advance. Selling your personal data is not among the options, now or later.
Mammaling uses no third-party or tracking cookies. What it stores on your device is what the app needs in order to work, and nothing else:
None of this requires consent, because without it the app does not work. The full list, name by name, with what each one is for and how long it lasts, is on the cookies and storage page. All of it stays on your device and is cleared if you clear the browser's data, uninstall the app, or open the repair page.
YouTube videos. Some species accounts carry a video. It is embedded
from youtube-nocookie.com, which is the version of YouTube made
for exactly this: it sets no advertising tracking cookies until you press
play. It is still a Google service, so loading the account reveals your IP
address to it, and if you play the video YouTube's own terms and privacy
policy apply. If you would rather not load it, simply don't open that species
account or don't press play.
Maps, place search and species reference data are requested from external services (MapTiler, OpenStreetMap, CARTO, iNaturalist, GBIF, Wikipedia). Those requests reveal your IP address to them and, in the case of place search, the text you type into the search box and the part of the map you are looking at — as happens whenever you use a map on any website. We do not send them your identity or your account data.
| Provider | What for | What it receives |
|---|---|---|
| Supabase | Database, user accounts, and hosting for photos and audio | Everything you store in the app |
| Cloudflare | App hosting, security, images and translation of species accounts | Your IP address and the requests you make |
| Google (Gemini · Generative Language API) | Identifying the photo you send, and translating species accounts | The reduced photo, country, month and your notes. No exact coordinates and no identity. See section 7 |
| Stripe | Collecting the subscription | Your payment details, directly and without passing through us. See section 8 |
| Resend | Sending account emails (confirming sign-up, resetting your password) | Your email address and the content of that message |
| MapTiler, OpenStreetMap, Nominatim, Photon, CARTO | Maps and place search | Your IP, the map area, and what you type when searching for a place |
| iNaturalist, GBIF, Wikipedia/Wikidata, IUCN | Species information and distribution data | Your IP and the species or area you are looking at |
| Scientific institutions | Observation data, under an open licence | See section 5 |
These providers process data on our instructions and may not use it for their own purposes, with two exceptions that act as independent controllers under their own policies: Stripe, for anything to do with payment, and Google, for the provision of the AI service.
There is no advertising or third-party analytics provider on this list, and that is not an oversight: we do not use any.
Some of these providers are in the United States. Those transfers rely on the Standard Contractual Clauses approved by the European Commission, or on adequacy decisions such as the EU-US Data Privacy Framework.
| Data | Retention |
|---|---|
| Account and profile | While the account is active. Deleted when you delete it. |
| Photos and audio | Until you delete them or delete your account. |
| Private messages | Until you delete your account. |
| Observations (the scientific part) | Indefinitely, anonymously once the account is deleted. |
| AI suggestions stored with an observation | As long as the observation. Anonymised with it. |
| Stripe identifiers and the count of identifications used | Deleted when you delete your account. Stripe keeps its own records under its policy and tax law. |
| Technical logs | Up to 12 months. |
You may exercise your rights of access, rectification, erasure, restriction, portability and objection at any time, and withdraw any consent you have given.
Many of them you exercise yourself in the app: editing your profile, changing your privacy, deleting checklists or photos, stopping using AI identification, cancelling your subscription, and deleting your account. For the rest, write to [email protected]. We will reply within one month at the latest.
If you believe we have not handled your data properly, you can complain to the supervisory authority:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
Mammaling is intended for people aged 16 or over, which is the age of digital consent in Ireland. If you are younger, a parent or guardian needs to create the account and supervise it.
If we find an account belonging to a child without that authorisation, we will delete it. If you are a parent or guardian and believe your child has created an account, write to us and we will remove it.
Passwords are stored encrypted and never in plain text. All traffic goes over HTTPS. Access to the database is protected by row-level security policies, so each user can only read and write what belongs to them. Keys for external services live in server-side secrets and are not inside the app you download.
No system is infallible. If a breach occurred that affected your rights, we would notify you and the Data Protection Commission within 72 hours, as the GDPR requires.
If we change something material, we will say so inside the app and update the date at the top. Changes affecting your rights will not be applied retroactively.