Legal
Privacy Policy
Last updated: 23 April 2026
This privacy policy explains how Stockulate Ltd ("we", "us", "our") collects, uses, and protects personal data when you use the HabitatTracker Android app and this website (www.habitattracker.co.uk). We are the data controller for the information described below.
Controller: Stockulate Ltd, 12 Lansbury Road, Sutton-In-Ashfield, Nottinghamshire, NG17 5DL, United Kingdom. Company number 15893175.
Contact: ashgreggors@gmail.com
1. What data we collect and why
We only collect what we need to run the app. Specifically:
- Account data — your email address and a display name, captured when you sign in via Firebase Authentication. We use this to create your account and keep your data separate from other users.
- Animal records — everything you enter about your animals: names, species, morphs, sex, birth or hatch dates, and photos. Used to provide the core logging service.
- Care logs — feeding events, misting events, shed records, weight measurements, and free-form notes. Used to deliver reminders and produce trends.
- Prey inventory — items you log in your prey freezer, used to produce low-stock alerts.
- AI chat messages — the text of prompts and responses exchanged with the in-app care assistant. Used to generate replies.
- Daily prompt-usage counter — a running count of AI prompts you've sent today. Used to enforce the free-tier daily limit.
- Subscription status — a
proUntiltimestamp showing whether your Pro subscription is active. Used to unlock Pro features. - Notification sound preference — stored locally on your device only; not uploaded to our servers.
- Crash reports — stack traces and device metadata (model, OS version, language) when the app crashes, tied to a randomly-assigned user identifier. Used to diagnose and fix bugs.
2. Lawful basis for processing (UK-GDPR Article 6)
- Performance of a contract — for account creation, core logging features, reminders, subscription management, and anything else required to deliver the service you've signed up for.
- Legitimate interests — for crash diagnostics and abuse protection. We've balanced these against your rights and believe the impact on you is minimal.
- Consent — for AI chat content, because it is processed by a third-party provider. You provide consent by choosing to send a message to the care assistant. You can withdraw consent at any time by not using the feature.
3. Third-party processors
We use a small number of carefully chosen providers to run the service. Each is bound by a data processing agreement.
- Google LLC — Firebase Authentication, Cloud Firestore, Cloud Storage, and Crashlytics. Hosts your account, synced data, photos, and crash reports. Data may be processed in the United States and the European Union. Google is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses apply to transfers outside the UK/EEA.
- Anthropic PBC — provides the Claude API that powers the AI care assistant. When you send a message, the text is transmitted to Anthropic in the United States and a reply is generated. Anthropic does not train its models on API inputs by default. A Data Processing Addendum is in place; Standard Contractual Clauses cover the transfer.
- API Ninjas — used only to look up publicly available species metadata (taxonomy, typical size). No personal data is sent.
4. International transfers
Some of your data leaves the United Kingdom and is processed in the United States by the providers named above. We rely on the EU-US Data Privacy Framework (where applicable) and the UK extension to it, together with Standard Contractual Clauses approved by the UK Information Commissioner's Office, to ensure an equivalent level of protection for your data.
5. How long we keep your data
- Account and app data — retained for as long as your account is active.
- On account deletion — primary data removed immediately; residual copies may persist in encrypted Firebase backups for up to 30 days before they expire.
- Crash reports — retained for up to 90 days, then aggregated or deleted.
- Billing records (via Google Play) — retained as long as UK tax law requires (currently six years from the end of the relevant accounting period).
6. Your rights under UK-GDPR
You have the right to:
- Access a copy of the personal data we hold about you.
- Rectify inaccurate data — most fields are editable in-app.
- Erase your data — use Manage your data or the in-app "Delete account" option.
- Restrict processing in certain circumstances.
- Portability — request a machine-readable export.
- Object to processing based on legitimate interests.
- Withdraw consent for any consent-based processing (e.g. the AI assistant) at any time.
To exercise any of these rights, email ashgreggors@gmail.com from the address associated with your account. We'll respond within one month.
7. Children's data
HabitatTracker is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, please email us and we'll delete it.
8. Complaints
If you're unhappy with how we've handled your data, you can lodge a complaint with the UK Information Commissioner's Office at https://ico.org.uk. We'd appreciate the chance to resolve your concerns directly first — please email us before escalating.
9. Security
Data in transit is encrypted via TLS. Data at rest in Firebase is encrypted at the provider level. Access to production data is limited to authorised personnel at Stockulate Ltd.
10. Changes to this policy
When this policy changes, we'll update the page and revise the "Last updated" date at the top. Material changes will be surfaced in-app before they take effect.
11. Contact
Questions? Email ashgreggors@gmail.com or write to Stockulate Ltd, 12 Lansbury Road, Sutton-In-Ashfield, Nottinghamshire, NG17 5DL, United Kingdom.