Privacy policy
FieldMaps is an app research teams use to record observations at a study site: an observer marks a point on a site map and answers the study’s questions, often without a signal. This policy explains what the app collects, why, who can see it and what you can do about it. It covers the FieldMaps app for Android and iOS and the server it uploads to.
In short
- We collect your sign-in email address and the observations you record.
- The app does not read your device’s location (GPS), contacts, photos, camera or microphone.
- There are no ads, analytics or tracking, and we never sell data.
- What you upload is seen by your research project team and the people who run FieldMaps. Our hosting provider stores it for us.
- You can ask us to delete your account and data.
Who we are
FieldMaps is run by the DECA Lab at Cornell University, led by Professor Janet Loebach, which is responsible for the data described here (“we”, “us”). The app is built and maintained by Pratyush Sudhakar. Each study is run by a research project team. The project team decides what its study records and uses the observations for its research.
What we collect
| Data | What it is | Why |
|---|---|---|
| Account details | Your email address and password when you sign in. The app sends your password only to our sign-in provider and never stores it; if you use a password manager, your device may offer to save it there. Our administrators create accounts for research team members. The app has no sign-up screen, and an account can upload only after an administrator adds it to a project. | To sign you in. |
| Account ID | A random identifier our sign-in provider gives your account. It is stored with each record on your device and each observation you upload. | To keep each person’s records separate on a shared device, to record who uploaded each observation, and to control access. |
| Observations | The point you place on the site map, the time, your initials, and your answers to the study’s questions, such as a count of the people present and your notes. The server also records when each upload arrives. | This is the research data the app exists to collect. |
| Study details | The study site, zone and round you choose before observing. | To file each observation under the right part of the study. |
| Connection and sign-in information | Your IP address, the address of each request, and basic details your device sends with it, such as the app and operating system version. Our sign-in provider also records the time, IP address and device details of each sign-in against your account. | To run the service securely and fix problems. |
Signed in or not
You can use the app without signing in. Records you make while signed out stay on your device and are never uploaded, even if you sign in later. Records you make while signed in upload to your project, including those on the “Sample garden practice” training map.
The map point is not your GPS location
You place each point yourself by tapping the site map. The app never reads your device’s location and does not ask for location permission. A point still shows where on the study site something was observed. Because you record it while you are on site, it also shows roughly where you were at the time.
Observations about other people, including children
Studies often record what an observer sees people doing, and some studies observe children at play. FieldMaps does not ask for the names, photos or other identifying details of the people you observe; it asks only for your own initials as the observer. Some study forms record general details such as a child’s age range and the kind of play. Please do not write names or other identifying details in free-text answers. Answers from study forms that are still being finalised stay on your device and are not uploaded. We will update this policy before any new kind of observation is uploaded.
What stays on your device
- Every observation is saved on your device first, so you can keep working without a signal. If you are signed in and the study’s form is accepted for upload, it uploads when you are online and the app is open. Uploaded observations also stay on the device.
- Unfinished observations are saved as you answer, so they survive the app closing. They stay until you save or discard them.
- The app has no way to delete a saved record. Records stay on the device until you uninstall the app or, on Android, clear its storage in Settings.
- Records are kept in the app’s private storage, labelled with your account ID and project. Other apps cannot read it, but the app does not add encryption of its own on top of your device’s, so use a screen lock.
- Your sign-in session, which includes your email address and account ID, is kept in secure storage. On Android it is encrypted with a key held in the Android Keystore and is not backed up. On iPhone and iPad it is kept in the iOS Keychain, which is included in encrypted device backups and is not removed when you delete the app.
- On Android, records are not included in cloud backups. On iPhone and iPad they are part of your device backups, like other app data.
How we use it
- To sign you in and keep each account’s records separate on a shared device.
- To store your uploaded observations in the FieldMaps database, filed under your project.
- So your project team can analyse the observations, for example on maps and in GIS tools such as QGIS.
- To keep the service secure and working.
We do not use your data for advertising or profiling, and we do not sell it or share it for anyone else’s marketing.
Who can see it
- Your research project team. The team can see the observations uploaded to its project, including your initials, the points you placed and your answers, using read-only GIS tools such as QGIS. The app does not show one member’s observations to other members, and other members and GIS analysts do not see your email address.
- The people who run FieldMaps. Our administrators create accounts and manage the database, so they can see all accounts and observations, including which account uploaded each observation.
- Our service providers. Supabase runs our sign-in service and hosts the database, on Amazon Web Services servers in the United States (US East, Northern Virginia). Our upload server is hosted by a cloud hosting provider in the United States. They process the data on our behalf to provide those services.
- A connectivity check on iOS. While an account is on the device and the app is open, the iOS app checks whether the device is online by sending an empty request to a Google connectivity-check address, about once a minute and more often while offline. Google receives your IP address and standard technical details, such as the app and iOS version, but no account or observation data.
- When the law requires it. We may disclose data if we are legally required to, or to protect the safety of people or the service.
How we protect it
- The app connects to our sign-in service and server only over encrypted connections (HTTPS).
- Every upload must carry a valid sign-in token, and the database accepts an upload only from an account an administrator has added to that project as an observer or manager.
- Your password is never sent to our own server; it goes only to the sign-in provider.
No system is perfectly secure, but we work to protect your data and fix problems quickly.
How long we keep it
- Records stay on your device until you uninstall the app. On iPhone and iPad, copies may remain in earlier device backups, and your sign-in may remain in the iOS Keychain unless you sign out first.
- Accounts and uploaded observations are kept while the study runs, and afterwards for as long as the study’s approved research protocol and Cornell University policy require, usually three years after the study ends. We delete an account when its holder leaves the research team, or sooner if they ask.
- Server request logs and our sign-in provider’s record of sign-ins are kept for up to 90 days.
- Deleted data can remain in our provider’s backups for a limited time, until they are overwritten.
Your choices and rights
- Use the app without signing in. Nothing you record while signed out is uploaded.
- Sign out in Account and synchronisation. If you have been offline for a while, you may need a connection before the Sign out button appears. Signing out removes your sign-in from the device but deletes nothing you recorded.
- Uninstall the app to delete your records from the device. On iPhone and iPad, sign out first: iOS can keep your sign-in in the Keychain after the app is deleted.
- Ask us for a copy of your data, or to correct or delete it: how to delete your account and data.
Depending on where you live, you may have other rights over your personal data, such as the right to object or to complain to a data protection authority. Contact us to use them.
Children
FieldMaps is a tool for adult researchers and is not directed at children. Our administrators create accounts only for members of research teams. We do not knowingly collect personal information from children who use the app. If you think a child has an account, contact us and we will delete it.
Changes to this policy
If we change what the app collects or how we use it, we will update this page and its effective date. We will tell project teams before a significant change takes effect.
Contact us
- Privacy questions and requests, including deletion: Professor Janet Loebach, DECA Lab at Cornell University, j.loebach@cornell.edu.
- Technical questions about the app: Pratyush Sudhakar, its developer, pratyushsudhakar03@gmail.com.