PermaPasture / private Android alpha
PermaPasture Privacy Policy
Android app, shared service and account-deletion website · Effective date: 2026-10-01
PermaPasture is an independently developed homestead record-keeping app, currently offered in a U.S.-only closed alpha. During the alpha, Pedro handles privacy and lost-access inquiries at pedropozo@protonmail.com. This notice describes information involved in using the app, the shared service, the deletion page and the support contact.
Effective date: 2026-10-01
1. Account information and shared farm records
Accounts and access. The service handles your email address, display name, account identifier, role, homestead membership, invitations, sign-in sessions and accepted Terms version and date. It receives your password when verifying sign-in or a deletion request and stores a salted password hash for authentication rather than the password itself. Access-protection and rate-limit information can include a connecting IP address. These details support authentication, membership management and protection against repeated attempts.
Farm information. Records you add can include property and paddock boundaries, fence issues, herds, animals, moves, chores and completions, animal health and event histories, notes and selected photos. The app uses these records for the farm features you choose and for synchronization with the shared homestead. People who belong to that homestead can see its shared records and photos.
Notes, mapped boundaries and visible photo content can identify people or places. Removing an account’s name or identifier from system attribution does not necessarily remove personal information from the shared content itself. Only add information you are authorized to share.
2. Location, maps and photos
Location. A location feature can request foreground location permission to use your position while you use that feature. A saved move can include coordinates and accuracy. Boundaries you draw, import or save from a GPS walk can also identify a property. Saved location information can become shared farm data and sync to other homestead members. Not every use of a map requires you to grant GPS permission. You can manage app permissions in your phone’s settings; removing a permission does not itself delete information already saved.
Maps. The Android map uses Google Maps. Map requests are handled by Google’s map service as well as the app. Permission to use your location and the map service’s own handling of requests are different things; declining a GPS permission is not a promise that no map request is sent.
Photos. You can select animal and fence-issue photos from your device library. For a fence issue, you can also choose to take a photo and grant camera permission. The app re-encodes selected uploads, but do not rely on that process to remove every embedded detail, such as location, capture time or device information. A visible image may reveal personal details even without embedded metadata.
A photo’s farm record and its file can upload separately. Uploading a photo does not remove the original from your device library.
3. Diagnostics, notifications and support
Diagnostics. Selected sync failures and crashes can cause diagnostic reports to be captured automatically and uploaded when the app can sync. Reports can include device, build or installation context, connectivity and sync state, error text, logs and support notes. They are used to investigate and understand problems. Filtering common sensitive patterns does not guarantee that every sensitive detail has been removed. Do not put passwords or codes in support notes.
Creating, uploading or sharing a diagnostic report does not start an account-deletion request, and successful transmission does not mean that someone has read the report or will reply.
Notifications and invitations. When enabled, a device push token supports notification delivery through Firebase Cloud Messaging. Notification preferences, delivery records and routing information support that feature. Alerts can include farm-related text that may appear on a lock screen, depending on your phone’s settings. Invitation email can be sent through a mail-delivery service when that delivery is configured.
Support correspondence. When you email Pedro, the sending address, contact details and information you choose to include are received through the support mailbox. Support messages and contact details are currently kept for handling and following up on alpha requests. No fixed retention period for that correspondence has been established. Do not send unnecessary family information, identity documents, passwords, sign-in codes, access tokens or private deletion-status tokens.
4. The account-deletion website
The self-service deletion form uses the account email address and current password to verify sign-in. Signing in on the page is not itself a deletion request. After the warnings, a separate final confirmation requires the current password again and the exact phrase for the action selected.
The page uses sign-in credentials in page memory while carrying out verification. It stores a private request-status token in this tab’s session storage before sending the deletion request, so an uncertain result can be checked without sending deletion again. That token is a read-only status capability, not permission for a new deletion. Keep it private. Closing the tab or clearing browser storage can remove the saved copy, so save the displayed token privately if the outcome is pending or unknown.
The service receives the chosen action, confirmation and information needed to verify its current scope. It can retain pending photo-cleanup records and limited completion/status information to finish an accepted deletion and report its result. A status check does not start a new deletion.
5. Who can receive or see information
- Other homestead members can see the shared records and photos, including content you contributed before leaving.
- People authorized to operate or secure PermaPasture may need access to information in the service to investigate problems and handle requests.
- Services involved in delivery include Google Maps, Firebase Cloud Messaging when enabled, invitation-email delivery when configured, and the support mailbox receiving messages you choose to send. Hosting infrastructure holds the shared service’s records and uploaded files; recovery copies may exist separately.
- Recipients you choose can receive exports, original images or support files you share outside the app. Those copies are not remotely erased by a PermaPasture account-deletion request.
6. Storage, security and retention limits
The app keeps an offline copy in a local SQLite database and device files. Unsynced work may exist only on that phone. The active shared service holds account information, shared records and uploaded photo files. Authentication uses password hashes and access checks; destructive account actions require additional verification of the password and scope. These measures are not a guarantee against every security risk.
The following distinctions matter when information is removed:
| Information | What deletion does and does not cover |
|---|---|
| Active account identity and access | Personal deletion removes the requesting account and sign-in and removes or replaces known system attribution. Limited deletion-status information can remain separately. |
| Shared farm rows and photos | They remain for other members after a personal exit, including contributed notes or visible image details. The separate whole-homestead action removes the selected farm’s active records and live uploaded photo files when completion is confirmed. |
| Pending photo cleanup and status records | Pending records support physical file removal; limited completion records support later status checks. Status information is not a permanent receipt. “Not found” does not establish that no deletion occurred. |
| Support correspondence | Messages and contact details are currently kept for alpha follow-up. No fixed retention period has been established. Account deletion is not a statement that the separate support mailbox has been erased. |
| Recovery backups, diagnostic and service records | Do not assume every older or separately retained copy disappears with active account deletion. We cannot give a verified blanket removal period for these categories. |
| Offline phones, device-library originals and exports | A server request cannot remotely erase these copies. Local cleanup is separate, and copies held by other people may remain. |
Older recovery backups may contain information removed from the active service. Encryption, where used, does not mean that information has been erased. A verified maximum removal time for every backup and an end-to-end deletion-aware restore procedure have not been established. Restoring an older copy without reapplying later deletions could make deleted information available again.
These limits describe what an active-service confirmation covers; they are not a statement that all retained information is anonymous or that it can be kept without limit. You can raise a question about a particular record through the privacy contact.
7. Delete your account or a homestead
In Settings → Account, Delete my account and Delete homestead are separate choices. The outside-app deletion page offers the same distinction. Both require warnings and verification; neither signing out nor choosing an action alone is deletion.
Personal exit. An eligible ADMIN, OWNER or MEMBER can delete their account while other members remain. An ADMIN or OWNER must first arrange another ADMIN or OWNER if their departure would leave the others without a manager. Known system attribution is removed or replaced, but shared records and photos remain. If there is no current homestead, the account-only path can remove the identity after checks for historical shared-data links.
Whole-homestead deletion. An eligible ADMIN can explicitly choose this action even when other members remain. The last account of any role must choose this separate action if it wants to delete in that state; an account-only request does not silently expand. Once completion is confirmed, the requesting account and the selected homestead’s active records and live uploaded photos are removed. Everyone loses access to that farm, but other members’ separate account identities remain.
Pending or unknown result. An accepted whole-homestead request can remain pending while live photo files are removed. If a response is lost or unconfirmed, deletion may already have started or finished. Use the private request token to check status rather than resubmitting. “Status not found” is not proof that nothing happened. A confirmation covers the request’s active-service scope, not immediate erasure of older backups or copies on other devices.
8. Lost access, personal information in shared content and other requests
Email pedropozo@protonmail.com to start a manual privacy or deletion inquiry, including if you cannot sign in or want personal details in a shared note or photo reviewed. You can send an inquiry without reinstalling the app or creating a new account. Start with a brief description; do not attach sensitive records.
Email alone does not establish account ownership or authority over a shared homestead. An independent lost-access verification procedure has not yet been established. If the requester or the permitted scope cannot be established safely, an irreversible deletion cannot proceed. Sending a message is not confirmation that the request was received, verified or completed. No response or completion time is promised here.
Depending on the law that applies, you may have rights to access, correct or delete personal information, or other privacy rights subject to conditions and exceptions. You can use the same contact for a rights request or a question about a child’s information. You do not need to close an account or accept revised Terms merely to send a privacy inquiry.
9. Reports and changes to this notice
Settings → Data tools offers limited paddock-boundary GeoJSON and grazing-move CSV reports from records on the phone. These reports are not a full homestead or account export, are not a substitute for a privacy-rights response, and cannot restore the app. Preserve important unsynced work and official records independently.
A revised policy will identify its effective date. We will bring material changes to users’ attention in the app before relying on them for materially different handling of information, and seek a separate choice where required. Updating a notice does not itself record acceptance of Terms v1.2 or grant a device permission.
Privacy contact: Pedro · pedropozo@protonmail.com