privacy
your original sightings are stored on your own account. we also keep a rebuildable public index so people can browse them. this page explains what that means, who else sees what, and the small amount we do keep.
last updated: 6 october 2026
what is public
every sighting you log — the species, the notes, when and roughly where you saw it, and any photo, video or recording you attach — is written to your own AT Protocol account as a public record. anyone can read it, with or without an account, using birds.place or any other app on the network. this is how the protocol works, and it is the point: your sightings are yours and they outlive us.
so treat every sighting you log today as public. deleting one removes it from your account, but copies may already exist elsewhere on the network.
"today" is doing work in that sentence. private records are being added to the protocol itself — permissioned data — and there are servers running it already. it is experimental and not yet something most accounts can use, so nothing here is private yet. when the server holding your account supports it, we intend to let you keep a sighting to yourself. we will say so here when that is real rather than planned.
where you saw it
a sighting can carry coordinates. you choose city (about 10 km), neighborhood (about 1 km, the default), or exact spot (about 110 metres). coordinates are rounded to that grid before saving the sighting. location is optional — you can clear it before logging or edit it out afterwards. place names and anything visible in your media can reveal more than the rounded coordinates alone.
when a photo or video already knows where it was taken, we read that from the file on your device and offer it as a starting point. the app asks for your photos and your location only for this, and only while you are logging a bird.
what we keep
original records and media live on your account provider. we keep a rebuildable index of public sightings: species, observation dates, notes, rounded coordinates and place names, media references, and observer identifiers/profile metadata. our media delivery proxy may cache copies of media. we also keep the state needed for sign-in and moderation:
- your sign-in. birds.place is the app your account authorises, so the access it granted us is held on our server rather than on your device. your device holds only a random string that points at it. we never see your password: the sign-in happens on your own account's server.
- when you first signed in, so we can tell somebody new from somebody coming back. the first time, the person who runs birds.place gets a private message saying an account joined; it is never posted anywhere.
- announcement preferences and history, to remember whether you want new sightings announced by @birds.place and avoid announcing the same sighting twice.
- moderation records, including reports, takedowns and moderators' species verdicts.
- who you have muted, so we can hide them from you. this is private and is never shown to the person muted.
- reports you send us, including what you wrote and who you are, so we can act on them and answer you. reports are private and are never shown to the person reported.
blocks are different: a block is a public record on your own account, so it travels with you and works in other apps. anyone can see who you have blocked, the same as on the rest of the network.
signing out deletes the session, and once no session of yours is left we tell your account to revoke our access.
who else is involved
to show you anything, your device or our renderer talks to a few services. each of them sees the request, including your IP address, in the ordinary way any web service does:
- Cloudflare — serves birds.place and stores what is listed above
- microcosm — finds who has logged a bird, and where their account lives
- typeahead — looks up handles, display names and avatars
- Photon — searches for a place by name and resolves coordinates to place names
- OpenStreetMap and OpenFreeMap — supply web maps. native maps use Apple Maps on iOS and Google Maps on Android
- Wikipedia / Wikimedia and iNaturalist — supply species reference material. separate species pages may load a reference photo from its source host, with photographer and license shown beside it. sighting photographs remain the observer's own
- your PDS, and the PDS of anyone whose sighting you are looking at, which hold the records and the media
bird facts are prepared offline; the app does not call the iNaturalist API while you browse. reference photo hosts still receive image requests. apple provides TestFlight, which reports crashes and install counts to us while birds.place is in testing.
your account is yours
your records live wherever your account is hosted — bsky.social, your own server, somewhere else — and that host's policy governs them. you can revoke birds.place's access at any time from your account, and take your sightings with you. our create-account button opens the chosen provider's registration flow; that provider handles the password. signing out disconnects this session; it does not delete your account, sightings, or all of the moderation/preferences data described above. contact hello@birds.place about retained birds.place data.
children
birds.place is not intended for children under 13, and we do not knowingly collect anything from them.
changes
if this changes materially, the date above changes and the new version appears here.
contact
questions, or something that looks wrong: hello@birds.place.