Catchumup is a tool for recording wildlife you encounter. We collect only what’s needed to make the app work, store it securely, and never sell it or use it for advertising. This document explains what we collect, why, and what you can do about it.
01 — Who we are
Catchumup is operated by Helgo Labs. For questions about your data, contact us at privacy@helgolabs.com.
We are subject to UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
02 — What we collect
We collect four categories of data when you use Catchumup:
| Category | Examples | Why |
|---|---|---|
| Account | Email address, display name, hashed password | To authenticate you and attribute your records to you |
| Sighting records | Species, date, count, life stage, sex, habitat, behaviour, notes, OS grid reference, vice county | The core function of the app — recording wildlife observations |
| Location | GPS coordinates and accuracy radius at the time of a sighting | To place your sighting on a map and calculate grid references |
| Photos | Images you attach to a sighting | To store evidence alongside your record |
We do not collect continuous location data. Location is only read at the moment you log a sighting, and only if you choose to include it.
03 — Lawful basis
Under UK GDPR, we rely on contract as our lawful basis — processing your data is necessary to provide the service you signed up for. We do not rely on consent for any core functionality. Where we process data for legitimate interests (such as preventing abuse), we have assessed that this does not override your rights.
04 — How we use your data
We do not share your data with third parties for marketing, sell it, use it to train AI models, or run advertising of any kind.
Darwin Core / NBN Atlas exports are generated only when you explicitly request them from within the app. You control what gets submitted.
05 — Storage & security
Your data is stored on servers provided by Railway (infrastructure as a service). Sighting records are held in a PostgreSQL database; photos are stored in S3-compatible object storage. Both are encrypted in transit (TLS) and at rest.
Passwords are hashed using bcrypt before storage — we never hold your password in plain text. Authentication tokens expire after 7 days.
Railway’s infrastructure may be located in the United States or the European Union. Where data is transferred outside the UK, we rely on standard contractual clauses or adequacy decisions.
06 — Retention
We retain your data for as long as your account is active. When you delete your account, your sighting records, photos, and account data are permanently deleted within 30 days. Anonymised aggregate statistics (species totals, regional counts) that cannot identify you may be retained indefinitely.
07 — Your rights
You have the following rights regarding your personal data:
To exercise any of these rights, email privacy@helgolabs.com. We will respond within one calendar month.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection.
08 — Children
Catchumup is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with their data, please contact us and we will delete it promptly.
09 — Changes
If we make material changes to this policy, we will notify you via the app before the changes take effect. The effective date at the top of this page always reflects the current version.
10 — Contact
For any privacy-related questions or requests: