4est
Privacy Policy
This Privacy Policy explains how 4est handles personal data when you use the iOS app, account sync, support or this website.
1. Who operates 4est
4est is operated by Uģis Karulis, an individual based in Latvia.
Privacy and support contact: support@4est.app
Effective date: 13 September 2026
2. What 4est is
4est is a local-first iPhone application for keeping a private history of forest observations, mushroom findings, saved places, photographs and related context. Local-first means ordinary interaction is designed to work from data on your device, while account and cloud services support backup and synchronization.
3. Data we handle
- Account and authentication information. Sign in with Apple is the initial authentication provider.
- Findings and observation data you create, such as dates, categories, notes, species selections and related metadata.
- Precise or approximate location information associated with Findings, saved Spots and other forest history.
- Photos and media you choose to add. When account sync is used, supported photos can be backed up privately to server-hosted object storage.
- Technical sync information such as stable record identifiers, timestamps, versions and deletion state.
- Limited operational information needed to secure and troubleshoot the service, such as request timestamps, errors and network/security logs.
4. Photos and private locations
Backed-up photos and user-created forest locations are private account data. They are not published as a public map or social feed, are not sold, and are not used for advertising. 4est does not use your private photos to train an AI model unless a future feature asks for separate, clear permission and this policy is updated first.
5. Device permissions
4est may request access to Photos and Location when a feature needs it. iOS presents and controls these permissions. You can change them in iOS Settings. Denying a permission can limit the feature that depends on it.
6. Local data and cloud backup
The app keeps primary working data locally for speed and offline use. When you use an account and cloud sync, supported structured data is synchronized to server-side storage and supported photos can be backed up to private object storage. The current cloud architecture uses DigitalOcean infrastructure in the fra1 (Frankfurt) region, including PostgreSQL for structured data and object storage for media.
7. Why we use data
- To save, organize and display your forest history.
- To back up and synchronize supported account data and photos.
- To authenticate accounts and provide security, export and deletion functions.
- To provide location-aware history, maps, navigation and decision-support features you choose to use.
- To operate, secure and troubleshoot 4est.
- To respond to support and privacy requests.
8. Service providers
We use service providers only where needed to operate 4est. Apple processes information when Sign in with Apple and Apple platform services are used. DigitalOcean hosts the cloud database, API infrastructure and private media storage. Vercel hosts this public website. Those providers process data under their own terms and privacy commitments as applicable to the services we use.
9. Retention
Your synced account data and private media are retained while your account is active, unless you delete individual content sooner. Operational security logs are intended to be retained for no longer than 30 days unless a longer period is required to investigate abuse, security incidents or comply with law. Support correspondence may be retained for up to 24 months so we can resolve follow-up issues and maintain a reasonable support record.
10. Account deletion
You can initiate deletion from the account settings in the released iOS app. Deleting your account removes the cloud account, backed-up photos and user-linked synced history, including Findings and associated location metadata. We may retain information only when legally required, or retain genuinely anonymized data that can no longer be linked back to you. Residual copies may remain in infrastructure backups until normal backup rotation completes, for no longer than 30 days. If Sign in with Apple was used, the associated authorization tokens are revoked as part of the deletion process.
11. Data export
4est’s backend supports account export. The exact released user interface for requesting or downloading an export will be documented when the app’s release UI is finalized. You can also contact support@4est.app for assistance.
12. Your choices and rights
Depending on where you live, including in the EU/EEA, you may have rights to access, correct, delete, restrict or receive a copy of personal data, object to certain processing, and complain to a data-protection authority. You can contact us at support@4est.app. You can also manage iOS permissions and use the account controls provided in the app.
13. Children
4est is a general-audience outdoor application and is not directed specifically to children. We do not knowingly design the account service to collect personal data from children who cannot legally consent to that processing in their country without appropriate authorization.
14. Website analytics
The website does not ship with Google Analytics, Meta Pixel, Hotjar or advertising trackers. If we enable Vercel Web Analytics, we will use it as a first-party, privacy-oriented traffic measurement tool and update this policy if the implementation materially changes our data practices.
15. Security
We use technical and organizational measures intended to protect synchronized account data and private media. No internet-connected system can guarantee absolute security, so we do not promise that data loss or unauthorized access is impossible.
16. Changes
We may update this policy as 4est changes. Material changes will be communicated in an appropriate way and the effective date above will be updated.
17. Contact
Privacy and support: support@4est.app
Operator: Uģis Karulis, Latvia