Privacy Policy
Last updated: September 9, 2026
Scope and Summary
Section titled “Scope and Summary”This Privacy Policy covers the NAHPU application on its supported platforms and the NAHPU website at nahpu.app. It does not cover third-party websites, apps, or services that you choose to open or use from NAHPU.
NAHPU works without an account. The NAHPU project does not operate a service that receives or stores your catalog records, and the app does not include advertising. The NAHPU team does not use your app records for analytics, advertising, cross-app tracking, or marketing.
Your records and files are stored locally unless you choose to export, back up, or share them. Some optional features contact third-party services. Those connections are described below.
Information You Provide or Generate
Section titled “Information You Provide or Generate”NAHPU can store information that you enter, import, or create, including:
- project, personnel, and taxon information, which may include names, contact details, affiliations, ORCID identifiers, notes, and personnel photographs;
- sites, precise localities, coordinates, collecting events, field notes, environmental observations, and specimen or sample records;
- photographs, videos, audio recordings, associated files, and their metadata; and
- app settings, custom fields, templates, fonts, export presets, and local map layers.
You decide what information to record. Natural-history records can contain sensitive information, including personal contact details and exact locations of vulnerable species. Review records before exporting or sharing them.
Device Permissions and Local Processing
Section titled “Device Permissions and Local Processing”NAHPU requests device access only when a feature needs it:
- Location: NAHPU can read your current location when you ask it to add coordinates. Your device’s location services determine the position under your operating-system and account settings, and NAHPU stores the returned coordinate locally. It does not continuously track your location or create a background location history.
- Camera and photos: NAHPU can capture photographs or videos, import media, and scan QR codes or barcodes. Camera access starts when you open one of these features.
- Microphone: NAHPU can record audio and the audio track of videos when you start a recording.
- Files and storage: NAHPU can import files and save exports or backups in a location that you select.
Imported media is copied into NAHPU’s local app storage. Original files may contain embedded metadata, including date, camera, device, or location details. NAHPU reads selected image metadata such as capture date, camera and lens, and exposure information; the copied original may retain other embedded metadata.
You can deny or revoke permissions in your device settings. The related feature may not work without its permission.
Local Storage, Backups, and Retention
Section titled “Local Storage, Backups, and Retention”NAHPU stores its database, media, associated files, settings, templates, fonts, and local maps in app-managed storage on your device. The operating system protects this storage using its app sandbox and device security controls.
Your operating system or a file provider may include app data or files in a device or cloud backup, depending on your device and account settings. NAHPU does not control those backup services.
Data remains until you delete it in NAHPU, remove the corresponding app files, or uninstall the app, subject to your operating system’s backup and restoration behavior. Exports, backups, QR codes, and files that you shared or saved outside NAHPU remain wherever you placed them and are not removed when you delete the original record or the app.
Online Maps
Section titled “Online Maps”NAHPU provides an offline Natural Earth basemap and an option to show no basemap. Neither option requests map styles or tiles from an online map provider. On macOS and Windows, the software that draws the map is still loaded from a content delivery network, which the next section describes.
If you select an online basemap, NAHPU requests map styles and tiles from OpenFreeMap. NAHPU does not upload your catalog records or its local point layer to OpenFreeMap. Map requests do reveal the requested tile area and zoom level, and ordinary network information can be visible to OpenFreeMap, its hosting providers, and network intermediaries.
OpenFreeMap states that it collects anonymized server information such as browser or client type, referring pages, timestamps, and operating system. It does not log IP addresses by default, but may temporarily log them for up to 30 days during a security incident. OpenFreeMap may use Cloudflare as a content delivery network. See the OpenFreeMap Privacy Policy for its current practices.
To avoid requests to an online map provider, choose Natural Earth (Offline)
or None as the basemap.
How Maps Are Drawn on macOS and Windows
Section titled “How Maps Are Drawn on macOS and Windows”On Android and iOS, NAHPU draws maps with a map renderer built into the app. On macOS and Windows, it draws them inside a system web view instead, and that web view loads the MapLibre GL rendering library, its stylesheet, and a supporting tile-reading library from the unpkg content delivery network.
This request happens whenever a map is drawn on those platforms, including
when the basemap is set to Natural Earth (Offline) or None, because the
rendering library has to load before any map can appear. Your operating
system’s web view may cache these files, so the request does not necessarily
repeat for every map.
The request reveals ordinary network information, including your IP address, to unpkg and its hosting providers. It does not include your catalog records, your coordinates, your map layers, or anything else about what the map shows. unpkg serves files from the public npm registry and may use Cloudflare as a content delivery network.
If the rendering library cannot be loaded, NAHPU falls back to the bundled Natural Earth map, which is drawn entirely on your device. Working offline on macOS or Windows therefore produces a map with no network requests, after a short wait while NAHPU determines that the library is unreachable. On Linux, the bundled map is the only renderer and no rendering library is requested.
While a map is on screen on macOS or Windows, NAHPU also opens a connection on
your device’s loopback interface (127.0.0.1), on a port assigned by the
operating system, so that the app and the web view can exchange map data. This
connection stays on your device, is not reachable from other devices, and is
not used to send anything off your device.
QR and Barcode Scanning on Android
Section titled “QR and Barcode Scanning on Android”On Android, NAHPU uses Google ML Kit for QR and barcode recognition. Camera images, barcode contents, and recognition results are processed on the device and are not sent to Google by ML Kit.
Google states that ML Kit may contact its servers for bug fixes, model updates, and hardware compatibility information. It also collects limited device and app information, per-installation identifiers, API configuration, performance metrics, and API usage metrics for diagnostics and usage analytics. Google states that this information is encrypted in transit and is not shared with third parties. See Google’s ML Kit Terms and Privacy, ML Kit Android data disclosure, and Privacy Policy.
Exports, Sharing, and External Links
Section titled “Exports, Sharing, and External Links”NAHPU exports or shares data only when you start the action. When you use the system share sheet, file picker, cloud drive, email, messaging app, or another destination, that provider receives the information you selected and handles it under its own privacy terms.
NAHPU also contains user-initiated links to resources such as the NAHPU website, ORCID profiles, and Google Fonts. Opening a link transfers you to your browser or another app, whose privacy practices apply. NAHPU does not send your catalog records when opening these links.
The NAHPU Website
Section titled “The NAHPU Website”The NAHPU website at nahpu.app, including this page and the documentation, is a static site published through GitHub Pages. It sets no tracking cookies, carries no advertising, embeds no third-party content, and runs no analytics script. We do not receive a record of who visits it.
As the host, GitHub receives ordinary network information for each request, including your IP address, browser type, and the pages requested, and uses it to serve the site and to protect it. See GitHub’s Privacy Statement for its practices. Following a link from the site to another website takes you to that site, whose own privacy practices apply.
Security
Section titled “Security”NAHPU relies on your operating system’s app sandbox, permission system, and device security. Keep your device, backups, and exported files secure, especially when they contain personal information or sensitive locality data. No storage or transmission method can be guaranteed to be completely secure.
Your Choices and Data Control
Section titled “Your Choices and Data Control”Because the NAHPU project does not hold your catalog records on its servers, you control those records on your device. You can:
- review, edit, export, or delete records in the app;
- remove app-managed files or uninstall NAHPU;
- revoke camera, microphone, photo, file, or location permissions in device settings;
- use an offline basemap or no basemap; and
- choose whether, where, and with whom to share exports and backups.
For information held by a third-party service, contact that provider or use the controls described in its privacy policy.
Children
Section titled “Children”NAHPU is a field and collection tool intended for research, teaching, and curatorial work, and it is not directed to children. It is meant for users aged 13 and older, or older where your country sets a higher age for consent.
We do not knowingly collect personal information from children. The app has no account, no sign-up, and no service that could receive such information. Where a student or a minor uses NAHPU in a class, field course, or supervised project, the supervising adult or institution is responsible for the records entered and for any permission or consent the project requires.
Changes to This Policy
Section titled “Changes to This Policy”We may update this Privacy Policy when NAHPU’s features or third-party services change. The updated policy will be posted on this page with a revised date.
Contact Us
Section titled “Contact Us”For questions or suggestions about this Privacy Policy, contact support@nahpu.app.