Fallcast Privacy Policy
Effective date: 2026-09-09
"Fallcast," "we," "us," and "our" refer to the Fallcast iOS application (the "App") and the service provided through it by its developer. This Policy describes the App's data practices as of the effective date above.
Contact: fallcastapp@gmail.com
In short
Fallcast has no accounts, no sign-in, no analytics, no advertising, no crash reporting, and no third-party code libraries of any kind — it is built solely on Apple's frameworks. Nearly everything it does happens on your device.
Three things go from your device to us, and you begin every one of them yourself, one at a time: a color rating you save, a photograph you submit for a place, and a photograph you submit to teach Foliage ID. There is a fourth request, which stores nothing: a check on whether a username you are typing is already claimed.
Your location is never transmitted to us or to anyone else. It leaves your device in one direction only — into your own Apple account, if you use iCloud, as part of a species sighting you saved.
What stays on your device
Location. If you grant "While Using the App" access, your coordinates are used on the device to show your local forecast, suggest a trip starting point, order the Field Guide by what grows near you, and inform Foliage ID. The App asks for coarse, kilometer-level accuracy, asks only when a feature first needs it, and every one of those features also works with a location you pick by hand. Nothing is stored and nothing is sent.
Nearby Alerts are optional and off by default. Turning them on is what triggers the iOS "Always" location request. iOS then watches regions around your saved places at a radius you choose, and when you enter one, the App decides on the device whether that place is worth telling you about and schedules a local notification. No location data leaves the device for this feature. Turning it off, or revoking the permission in iOS Settings, stops the monitoring.
No widget reads your location. Widgets read a snapshot file the App prepares; they take no position fix, rank nothing, and make no network requests.
Camera and Foliage ID. Camera access is requested only when you tap "Take Photo." Choosing a library photo uses Apple's out-of-process picker, so the App receives the one photo you picked and has no access to your library. Identification runs on the device against a model bundled with the App. For a library photo, embedded location and date are read in memory to inform the result and are not kept unless you save the sighting.
What you create. Sightings, trips, journal notes and photos, favorites, pins, ratings and preferences are stored in the App's own storage on your device. Notifications are all local — scheduled on your device, composed on your device, with no push service involved. The counters that decide when to show Apple's rate-this-app prompt stay on the device too.
What you can send us
Each of the three is a deliberate act. Nothing is sent in the background, and there is no setting that sends for you.
A color rating. Saving a rating submits it — there is no separate send step and no device-only mode. It contains the place you rated, the visit date, the rating on our six-class scale, the App and model versions, the timestamp, and a random identifier. It contains no name, email, device identifier, photo, username, or location.
> Ratings cannot be withdrawn. We keep submitted ratings > indefinitely and offer no deletion-by-request route, because a stored > rating carries no name, email, device or account — there is nothing > that would let us establish which submissions are yours, and nothing > that would let you point at them. You can delete your own copy > (Preferences → "Your Ratings", swipe), which does not recall what was > already sent. If you would rather a rating not be stored by us at > all, the control is not to rate the place.
A photograph for a place. You open one of your own journal photos, read what you are agreeing to, and confirm with a switch that you took it or hold the rights. It travels with the place you chose, the date taken, an optional caption, the acknowledgement version, the App version, an identifier, and — only if you choose to be credited — your username. The image file carries no location: it is stripped when the photo enters your journal, checked again before sending, and rejected by the receiving service if any GPS tag survives.
A submitted photograph is not public. It lands in private storage with no public address and goes to a review queue a person reads. Nothing is displayed unless it is accepted; if it is, it appears as a photograph of that place credited to your username or to "a Fallcast user," and nothing else about you is shown with it. A declined photograph is kept out of the queue so the decision can be reconsidered. Deleting the photo from your journal removes your copy but does not withdraw the submission — to withdraw one, email fallcastapp@gmail.com.
A photograph to teach Foliage ID. When Foliage ID names a species wrongly, you can pick the right name and send the photo with that label. Same acknowledgement, every time. It travels with the species you picked, which model was wrong and what it answered, the date taken, the acknowledgement and App versions, an identifier, and your username only if you choose to be credited. The image is re-encoded so no embedded location survives, and is verified before sending. There is no place identifier and no caption — the receiving service refuses a submission carrying either.
Training photographs are never published in the App. They are kept apart from the place-photo queue as material for training a future model, and retained indefinitely for that purpose. Sending one does not change the model on your phone. To ask for one to be removed, email fallcastapp@gmail.com.
A username is optional, is a credit line for photographs and nothing else, and gates no feature. You are asked once, at your first submission, and declining is a real answer. While you are typing one, the App asks our photo service whether the name is already claimed; that request carries the name and your identifier, writes nothing, and is advisory. For each claimed name we hold one entry: the name, and a one-way hash of the identifier that claimed it.
The identifiers a submission carries
Two, both randomly generated by the App, neither derived from your device, neither displayed anywhere in the App:
an install identifier, which accompanies ratings and Foliage ID training photos. It is per installation, never synced, and reset when you delete and reinstall the App; a person identifier, which accompanies place-photo submissions and the username check. It is kept in your own iCloud account so your credit line is the same on every device you own — which means reinstalling does not reset it, and photos from your phone and iPad are recognisable as one person's. Signing out of iCloud leaves the App with a device-only value again.
Both are replaced by a one-way keyed hash before anything is stored, so the identifier itself is never written down. Stated precisely, because the difference matters: that is pseudonymisation, not mathematical anonymity. We hold the key, so if someone supplied a particular identifier the matching records could be recomputed. Nobody is in a position to supply one — the App never displays it and sends it nowhere else — but the honest claim is that the identifier is not stored, not that the records could never be linked.
Submissions are stored in our own storage on Cloudflare. Nothing is added to what you sent beyond the time it arrived: no IP address, no device or browser identification, no other request metadata. As with any internet request, your IP address is visible to the hosting provider in transit, subject to Cloudflare's own practices; we do not use such logs to identify anyone.
iCloud sync
If you are signed in to iCloud, the things you save sync across your devices through your own Apple account, which we cannot read. That covers favorites and pins, preferences, your ratings, your trips, your species sightings, your journal notes, your journal photographs, and your username with the identifier described above.
Two consequences worth stating plainly:
Location-derived data syncs to your Apple account. A sighting records the locality name — and, for a Foliage ID sighting, the coordinates — at the moment you logged it. Those go into your account and nowhere else. Journal photographs use your iCloud storage, not ours. They sync through CloudKit's private database, which Apple bills to the account that owns it and which we cannot see, list, or access. Location is stripped from every journal photo's image file; the App keeps the place and capture date as ordinary fields on its own record, inside your account. Deleting a photo, or its trip, deletes it everywhere.
Photos attached to species sightings never sync at all — they stay on the device that took them, and a sighting arriving on another device shows a placeholder.
Not synced: the install identifier, whether Nearby Alerts is on, and device-local bookkeeping such as which alerts a device has shown.
Other network activity
Besides the submissions above, the App downloads forecast data, map tiles and species photographs from our static file server on Cloudflare R2 — unauthenticated requests carrying no account, identifier or personal data. Map screens use Apple's MapKit; prices and purchases use Apple's StoreKit; both are governed by Apple's privacy policy. Tapping "Map it!" hands a route to Apple Maps or Google Maps at your choice, after which that app's policy governs; Google Maps is offered only if it is already installed, and the App does not itself contact Google.
The App makes no calls to third-party weather services. Forecast inputs are gathered and processed on our own infrastructure, and the App downloads only the finished files.
Purchases
Season Pass is an auto-renewing annual subscription, processed entirely by Apple. We do not receive your payment details, name, or Apple ID. The App reads your subscription's status on the device through Apple's StoreKit framework to decide which features are unlocked, and stores only the resulting flags locally; that status is not transmitted to us. Apple provides us standard aggregated sales reporting that does not identify individual customers.
App Store privacy label
Apple defines "collected" as data transmitted off the device in a way we or our partners can access. On that definition the App collects data through the three submissions above and through nothing else, in three of Apple's categories: user content, identifiers, and usage data (limited to the App and model versions and timestamps that travel inside a submission).
All three are declared linked to you, because nothing we receive arrives without the identifier that can hold a username claim — a name shown in public beside an accepted photograph. Submitting anonymously keeps your username off that particular submission; it does not change what the label says about the data type. None of it is used for tracking, and the App neither reads the vendor identifier nor requests the advertising identifier.
Location is not collected: it is processed on the device, no submission of any kind carries it, and the sync described above goes into your own Apple account, which Apple does not make available to us.
Permissions at a glance
| Permission | When requested | Required? |
|---|---|---|
| Location — While Using | First time a location-aware feature is used | No — you can pick a location by hand |
| Location — Always | Only when you turn on Nearby Alerts | No — used solely for that feature |
| Camera | When you tap "Take Photo" in Foliage ID | No — library photos work without it |
| Notifications | When you turn on alerts | No |
Children
The App is not directed at children and collects no personal information — no name, email, or other contact detail — from any user. A username, where one is set, is a handle you choose and can change or clear at any time.
Your choices
Revoke location, camera, or notification permission in iOS Settings. Turn off Nearby Alerts in Preferences; this stops all background region monitoring. Turn off iCloud for Fallcast in iOS Settings. Delete the App to remove all of its local data. Delete one of your own ratings: Preferences → "Your Ratings", swipe the row. This clears your device and iCloud copies, not a submission already sent. Decide each time whether to rate a place at all — that decision is the only control over what we receive, because saving is submitting and a submitted rating cannot be withdrawn. Decide each time whether to submit a photograph, and whether to be credited or to submit anonymously. Ask for a submitted photograph of either kind to be withdrawn, by emailing fallcastapp@gmail.com. * Set, change, or clear your username in Preferences.
We keep no server-side account or profile about you. The only thing we hold that came from your device is what you submitted, and we neither sell it nor share it with third parties.
Changes to this Policy
This Policy describes the App as of the effective date. If a future version changes any practice described here, the Policy will be updated before or together with that change: the effective date revised, the change recorded below, and material changes noted in the App's release notes.
Change log
- 2026-09-09 — Rewritten to be read rather than waded through; no practice changed. One correction: the previous version described Season Pass as a one-time purchase with a permanent unlock, which stopped being true when it became an auto-renewing annual subscription on 2026-09-09.
- 2026-09-08 — First version.
Contact
Questions about this Policy: fallcastapp@gmail.com