Privacy Policy
Last updated: 1 October 2026
The short version
- No account. The app never asks for your name or email.
- Our server knows the app only by a random ID created on your phone.
- Photos you scan go through our server to our identification provider, Kindwise. Our server doesn’t keep them.
- Your location is used only if you allow it, rounded to about 10 km, and our server doesn’t keep it.
- “Bugs near you”, sighting maps and seasons come from public records on GBIF.org. Our server asks GBIF for you, so GBIF never sees your IP address or app ID.
- No ads, no tracking, no selling of data, no third-party analytics.
- Your bug album (with the rough places of your finds, if you allowed location), streak, XP and lesson progress are stored on your device and, if “Sync with iCloud” is on, in your own private iCloud, which we can’t access.
- You can delete your data at any time in the app: Me → Delete my data.
1. Who we are
BugWiz is published by Anas Alradhwan, an independent developer based in Kuwait and the seller shown on its App Store page (“we”, “us”). You can reach us with the contact form on our Support page. This policy covers the BugWiz app (on iPhone, iPad, Mac and Apple Vision Pro), the server it talks to and this website.
2. What we collect and why
An anonymous app ID
When you first open BugWiz, the app creates a random ID on your phone. It isn’t linked to your name, email, phone number or Apple Account. The app sends it with each request so our server can count your identifications, apply your subscription and stop abuse. RevenueCat (see “Purchases”) uses the same ID.
Photos you scan
When you identify a bug, the photos you choose (one to three photos of the same bug for each identification) and the date are sent through our server, which runs on Cloudflare, to Kindwise s.r.o. (Czech Republic), the company behind insect.id. Kindwise identifies the bug. The app saves a fresh copy of each photo before sending it, so the location and other details stored inside the original photo file aren’t sent. Our server passes the photos on and doesn’t keep them. Kindwise receives them from our server, not from your phone, so it doesn’t see your IP address, and our server doesn’t send it your app ID.
Kindwise’s licence to your photos. Under Kindwise’s terms, Kindwise receives a non-exclusive, irrevocable licence to use the photos it is sent, for example to improve its models and to show them to other users as similar images. Kindwise keeps identifications for up to 6 months. Please don’t photograph people, documents or anything private.
Your permission first. Before your first identification, the app shows who receives your photos (Kindwise) and asks for your permission. If you decline, no photo is sent.
Location (optional)
BugWiz uses your location only if you turn on “Use my rough location” (on the photo consent screen, in Me, or on the “Bugs near you” and “My map” screens) and allow it. The app rounds your location on your iPhone to about 10 km (one decimal place of latitude and longitude) before it’s used anywhere, and uses it in three ways:
- Identification. Knowing roughly where a bug was found helps identify it, so the rounded location is sent with the photos, through our server, to Kindwise.
- Bugs near you and sighting maps. The rounded location is sent to our server, which asks GBIF (see below) for public bug records around it. Our server passes it on and doesn’t keep it.
- My map. The rounded location of each new find is saved with that find on your iPhone, so you can see your finds on a map. It isn’t sent anywhere. You can remove a find’s place, or all places, in the app at any time.
Our server never keeps your location. Your location is never sent to RevenueCat. If you don’t allow location, identification, the album, seasons and everything else still work. Switch it on or off at any time with “Use my rough location” in Me, or in your iPhone’s Settings.
Bugs near you, sightings and seasons (GBIF)
“Bugs near you”, the sighting maps, “What’s active now” and the months when a bug is out and about use public biodiversity records from GBIF, the Global Biodiversity Information Facility (GBIF Secretariat, Denmark). For these, our server sends GBIF a scientific name and, for nearby bugs and sighting maps, your location rounded to about 10 km (only if you allowed location). GBIF receives these from our server, not from your phone, so it doesn’t see your IP address, and our server never sends it your app ID. To keep the app fast, Cloudflare caches GBIF’s answers for up to 30 days, filed only under the bug’s name or the rounded area, never under your app ID or IP address. We only use GBIF records that their publishers released under CC0 or CC BY 4.0, and the app credits “Data: GBIF.org”. The records show where and when other people saw bugs; the app never shows who recorded them.
“Not quite? Pick the right match”
If you tap “Not quite? Pick the right match” on a result and choose a different bug, the app sends the scan’s reference and the name of the bug you picked through our server to Kindwise, marking the first answer as wrong, so identifications can improve. Kindwise may keep this feedback under its terms. Our server passes it on and doesn’t keep it.
Photos shown on a result
Reference photos on a result are loaded through our server, so your phone never contacts Kindwise or the sites that host those photos, and nothing about you is sent to them. Each photo is credited in the app with its Creative Commons licence.
Support messages
If you write to us with the contact form on our Support page, we keep your email address, your message and anything else you add (such as your name or app version) so we can answer you. We keep a support message for 12 months, and we delete it sooner if you ask. Cloudflare adds the country your message came from. To limit spam, a scrambled (hashed) form of your network address is kept for one hour.
Purchases
Subscriptions are sold and billed by Apple. We never see your payment details. RevenueCat, Inc. (USA) receives your purchase history from Apple and your anonymous app ID, so it can manage your subscription and tell our server whether you have BugWiz Pro.
App integrity
BugWiz uses Apple’s App Attest to check that requests come from the genuine app, which helps prevent fraud. This uses a security key created on your device and contains no personal information.
Statistics from Apple
If you have chosen to share analytics with app developers in your iPhone’s settings, Apple may give us anonymous, combined statistics about app usage and crashes.
3. What stays on your device and in your iCloud
Your bug album (with its photos and, if you allowed location, the rough place of each new find), streak, XP and lesson progress are stored on your device. We don’t receive them.
Sync with iCloud. If your device is signed in to iCloud, BugWiz also keeps this data in your own private iCloud (Apple’s CloudKit private database and iCloud key-value storage), so it’s backed up and appears on your other iPhone, iPad or Mac. That copy belongs to your Apple Account: Apple stores it under its own privacy policy, only you can access it, and we can’t see it. You can switch it off in the app under Me → Sync with iCloud; your data then stays on that device only.
Photos waiting for a connection. If you snap a bug while you’re offline (after you’ve allowed bug IDs with Kindwise), the photo waits on your device and is sent as described in section 2 once you’re back online with BugWiz open. It’s never sent with your location, it isn’t synced to iCloud, and it’s deleted from the waiting list when you add the result to your album or remove it.
Home Screen widget. The widget shows your streak, today’s goals and the bug of the day from a small file the app keeps on your device. It doesn’t use the internet.
More Wiz apps. To list only our apps that are on sale in your country, the app asks Apple’s public App Store lookup, sending only those apps’ store numbers and your device’s region code. Nothing about you is sent.
4. What our server keeps, and for how long
Our server never stores your photos or your location, and its logs don’t record IP addresses or the contents of the app’s requests. Cloudflare processes IP addresses briefly to protect the service and to apply rate limits. Public answers from GBIF are cached as described above, without your app ID or IP address.
| Data | Why | How long |
|---|---|---|
| Anonymous app ID | Connects the records below | As long as those records exist |
| Identification counts | The free identification and the fair-use limits | Hourly and daily counts: about 2 days. Total count: until you delete your data |
| Scan reference (Kindwise’s ID for an identification) | Send “Not quite? Pick the right match” feedback, and ask Kindwise to delete your identifications when you delete your data | 180 days |
| Subscription status (Pro or not, plan, trial, expiry date) | Unlock BugWiz Pro | While relevant, and up to 180 days after it ends |
| App Attest key and counter | Check that requests come from the genuine app and prevent fraud | Until unused for 180 days |
| One-time security codes | Set up App Attest | 5 minutes |
| IDs of processed subscription updates from RevenueCat | Apply each update only once | 60 days |
| Image-signing key (not linked to anyone) | Make sure our server only loads the result photos it chose | While the service runs |
| Support messages (email address, message, what you add, country) | Answer you | 12 months, or sooner if you ask |
| Hashed network address | Limit contact-form spam | 1 hour |
5. What we don’t do
- No advertising and no advertising SDKs.
- No tracking across other companies’ apps or websites.
- No selling or sharing of personal information.
- No third-party analytics.
6. Legal bases
Where laws such as the EU or UK GDPR apply, we process data to provide the service you ask for (identifications, nearby bugs and your subscription), on your consent for sending photos to Kindwise and for location, for our legitimate interests in keeping the service secure and free of abuse and in improving identifications through your feedback, and to meet legal obligations.
7. Where data is processed
Our service providers process data in the United States (Cloudflare, RevenueCat) and the European Union (Kindwise, and GBIF in Denmark for public bug records), and Cloudflare’s network operates worldwide. Where required, these transfers are covered by appropriate safeguards, such as the European Commission’s Standard Contractual Clauses.
8. Your choices and rights
- Delete my data. In the app, go to Me → Delete my data. This erases the records our server keeps for your app ID and the BugWiz data on your device (including your finds’ rough places and photos waiting to be identified), and deletes BugWiz’s copy in your private iCloud (devices that sync with it remove it too when they next sync), and the app starts again with a new anonymous ID. Before our server erases its records, it asks Kindwise to delete your identifications too; we do this on a best-effort basis, and Kindwise handles photos it has received under its terms. If your phone is offline at the time, the app sends the request to our server again the next time it’s online.
- Subscriptions. Deleting your data doesn’t cancel a subscription. To manage or cancel it, open Settings on your iPhone, tap your name, then Subscriptions. Apple and RevenueCat keep purchase records under their own policies.
- Your rights. Depending on where you live, you may have the right to access, correct, delete or port your data, to object to or restrict its use, to withdraw your consent, and to complain to your data protection authority. Because we don’t know who you are, “Delete my data” is the quickest route. For anything else, use the contact form on our Support page.
9. Children
BugWiz is for people 18 and over only (it’s rated 18+ on the App Store). It isn’t directed to children, and we don’t knowingly collect personal information from anyone under 18. If you believe someone under 18 has sent us personal information, contact us and we will delete it.
10. Security
All connections are encrypted (HTTPS). Secret keys for our providers stay on our server and are never in the app, and App Attest lets our server check that requests come from the genuine app.
11. Changes
If this policy changes, we will post the new version here with a new date.
12. Contact
Write to us with the contact form on our Support page. We reply by email.