Privacy Policy
Last updated: 12 July 2026
This policy explains how Ephemeros handles personal information across the Ephemeros website (ephemeros.app), the Ephemeros mobile app, and our APIs. It is written to comply with the South African Protection of Personal Information Act 4 of 2013 ("POPIA") and, for users elsewhere, with the EU/UK General Data Protection Regulation ("GDPR") and similar international laws.
1. Who is responsible
The responsible party (POPIA) and data controller (GDPR) is Ephemeros, operated by Willem van Zyl t/a "CLC Agency", based in South Africa, who also acts as Information Officer. For anything in this policy — questions, requests, complaints — email hello@ephemeros.app.
2. What we collect
- Account details — name, surname, username, email address, password (stored hashed), and an optional avatar photo.
- Photos and capture metadata — photos you capture with the in-app camera, together with the technical data recorded at capture time: GPS coordinates and accuracy, altitude, compass heading, device pitch and roll, air pressure, device model, and capture timestamp. EXIF metadata is stripped from every image we serve; capture metadata is stored separately in our database.
- Derived data — historical weather for the capture time and place (from a public weather archive), an AI-generated description and tags for moderation and research (see section 5), and a perceptual hash used to detect duplicates.
- Activity and content — spots and lists you create or join, captures, points and badges, friendships, notifications, and moderation history.
- Device and technical data — push-notification tokens and device identifiers you register for notifications; on Android, the device's advertising ID, used only for ad install attribution (section 11); IP addresses, request logs, and security logs when you use the website, app, or API.
- Communications — messages you send us (contact form, takedown requests, support email).
- Cookies and analytics — see section 10.
We collect this information directly from you and from your device when you use the service. We do not collect special-category personal information, and we do not sell your contact details.
3. Why we use it and our legal grounds
- Operating the service (accounts, capture alignment, ghost overlays, timelapses, lists, points, notifications, offline sync) — performance of our contract with you (GDPR art. 6(1)(b); POPIA s 11(1)(b)).
- Moderation, capture integrity, and security (content review, trust scoring, duplicate detection, rate limiting, bot protection, fraud prevention) — our legitimate interests in keeping the platform safe and the dataset trustworthy (GDPR art. 6(1)(f); POPIA s 11(1)(f)).
- Open data and research datasets — building a long-term, open scientific record of visual change is a core, stated purpose of the platform; approved public photos and capture metadata are openly licensed (CC BY 4.0, see the Terms of Use) and shared with researchers and the public, with your identity limited to your username or "Anonymous" (consent given at registration, and our and the public's legitimate interest in scientific research; GDPR arts. 6(1)(a)/(f) and 89).
- Communications — service and security email (contract); optional digests and non-essential notifications, which you can switch off (consent / legitimate interest with opt-out).
- Website & app analytics — understanding aggregate usage (consent where required, otherwise legitimate interest; see section 10).
- Ad install attribution — measuring, in aggregate, how many app installs our advertising brings in (our legitimate interest in promoting the service, with the opt-outs described in section 11; GDPR art. 6(1)(f); POPIA s 11(1)(f)).
- Legal compliance — responding to lawful requests, takedown handling, record-keeping (legal obligation; GDPR art. 6(1)(c); POPIA s 11(1)(c)).
You give two explicit consents at registration: to this policy, and to the content-rights licence described in the Terms of Use. Where processing rests on consent, you may withdraw it (section 8), without affecting processing already carried out.
4. Photos, location, and what is public
- Spots exist to be re-photographed, so an approved spot's location and photos are public by design — on the map, on spot pages, in the app, and in research exports. Approved public photos and their capture metadata are also openly licensed under CC BY 4.0 (see the Terms of Use), which means anyone may reuse them with attribution and copies already obtained by others cannot be recalled. Do not create a spot anywhere you would not want publicly known.
- Spots you mark private are visible only to you and excluded from public pages, lists, nudges, and exports.
- Your username appears next to your contributions. You can control your public profile page, leaderboard participation, nearby discoverability, and friend-activity sharing in your profile settings; content from deleted accounts shows as "Anonymous".
- Your precise realtime location is used on-device for the map, nearby spots, and capture validation. The server receives the coordinates of your captures and the location you report when creating a spot — not a continuous location track.
- EXIF metadata (including embedded GPS) is stripped from all served images.
5. AI review and automated processing
Uploaded photos may be analysed by an AI vision service (currently OpenAI) to generate a description and tags that assist moderation and enrich the research dataset. Only the photo is sent — never your name, email, or account details — and our agreement with the provider does not permit it to use the images to train its models. Moderation decisions that affect you (declining content, suspending accounts) are made or reviewed by humans; we do not make solely automated decisions with legal or similarly significant effects.
6. Who we share it with
We use a small set of service providers (operators under POPIA, processors under GDPR) bound by contract to protect your information:
- BunnyCDN (Bunny.net, EU) — stores and delivers photos, avatars, timelapses, map tiles, and encrypted backups.
- OpenAI (US) — AI photo review (photos only, as in section 5).
- Open-Meteo — historical weather lookup; receives only coordinates and a timestamp, never account data.
- Google Firebase (US) — push-notification delivery (device tokens).
- Google Analytics (US) — website & app usage analytics (section 10).
- Meta Platforms (US) — ad install attribution in the Android app: the Meta SDK reports app-launch events with your device's advertising ID so we can measure which installs came from our ads (section 11).
- Cloudflare Turnstile / Google reCAPTCHA — bot protection on registration, login, and contact forms, where enabled.
- Email delivery provider — transactional and notification email.
We also share:
- Researchers and dataset licensees — approved photos with capture metadata, weather, and AI tags. Contributor identity is limited to username or "Anonymous"; your email and contact details are never included.
- The public — approved content as described in section 4, including under the open CC BY 4.0 licence.
- Authorities — where a law or valid legal process requires it.
- A successor operator — if the service is transferred or restructured, under the same protections, with notice to you.
7. International transfers
We are based in South Africa and some providers above process data in the EU and the United States, so your information may be transferred across borders. We only transfer personal information as POPIA section 72 and GDPR chapter V allow: to recipients subject to laws or binding agreements providing an adequate level of protection (for EU/UK data, the EU–US Data Privacy Framework or Standard Contractual Clauses), or otherwise with your consent or as necessary to provide the service you requested.
8. Your rights
Subject to applicable law, you have the right to:
- access the personal information we hold about you, and request a copy (your profile and public pages already show most of it);
- correct or update inaccurate information (largely self-service in your profile);
- delete your account and personal information (see section 9 for what deletion means here);
- object to processing based on legitimate interests, and withdraw consent where processing rests on consent;
- opt out of non-essential email and notifications (profile settings and unsubscribe links) — we do not send third-party direct marketing;
- for EEA/UK users: restriction of processing and data portability (we will export your data in a machine-readable format on request);
- lodge a complaint with a supervisory authority.
To exercise any right, email hello@ephemeros.app. We may need to verify your identity, and we respond within the time limits of the applicable law (one month under GDPR; as soon as reasonably possible under POPIA). If you are unhappy with our response, you may complain to the South African Information Regulator (inforegulator.org.za, complaints.IR@inforegulator.org.za) or, for EEA/UK users, to your local data-protection authority.
9. Account deletion and retention
Deleting your account (self-service in the app, or by email) anonymises you: your name and username become "Anonymous", your email address is removed, and your avatar, devices, push tokens, friendships, and notifications are deleted. A one-way hash of your email address is kept solely to prevent abuse of re-registration; it cannot be reversed into your address. Photos and spots you contributed are retained and displayed as "Anonymous" — the long-term record is the purpose of the platform, and you accept this at registration and again in the deletion confirmation. Copies of photos already released under the open CC BY 4.0 licence remain licensed to those who obtained them and cannot be recalled.
Retention periods:
- Approved photos and capture metadata — indefinitely (scientific record).
- Declined photos — permanently purged 30 days after decline (the window allows appeals).
- Account details — until you delete your account (then anonymised as above).
- Encrypted backups — rotated on a 14-daily / 8-weekly / 12-monthly schedule, after which deleted data ages out of backups too.
- Security and request logs — kept for a limited period for security and abuse prevention.
10. Cookies and analytics (website)
The website uses essential cookies for signing in and security (session and CSRF cookies) — these are required for the site to work. It also uses Google Analytics to understand aggregate usage: pages visited, approximate location derived from your IP address, and device/browser information. Google sets its own cookies and processes this data on our behalf; we do not link analytics data to your account. You can block analytics cookies in your browser or with Google's opt-out browser add-on. Where forms are protected by Cloudflare Turnstile or Google reCAPTCHA, those services process technical signals from your browser to distinguish humans from bots.
11. The mobile app: permissions and on-device data
- Camera — required for capturing spot photos (in-app camera only) and optionally for avatars.
- Location — required to show nearby spots, create spots, and validate that captures happen at the spot.
- Motion and pressure sensors — compass, orientation, and barometer readings recorded with each capture for alignment and research.
- Notifications — optional; a device token is registered with Firebase if you enable them.
- Photo library — only if you choose an avatar from your gallery, save a captured photo, or save a QR code.
- On-device storage — the app caches spots, baseline images, offline areas, and your pending uploads (outbox) locally; pending captures upload when you are back online. Uninstalling the app deletes this local data.
Meta app events (ad install attribution). The Android app includes the Meta (Facebook) SDK so that we can measure how many app installs our advertising on Meta's platforms brings in. On each app launch the SDK sends an app-activation event to Meta together with your device's advertising ID and basic device information — this happens for every user, on every launch, whether or not you arrived through an ad. It is used solely for install attribution and aggregate ad measurement; we do not send your name, email, account details, photos, or location to Meta, and we do not use it to build advertising profiles of you inside Ephemeros. Meta processes this data as described in its own privacy policy. You can limit this on your device: in Android settings under Privacy → Ads you can delete or reset your advertising ID, which removes or unlinks the identifier the SDK reports.
12. Security
We protect your information with, among other measures: encrypted connections (HTTPS) everywhere, hashed passwords, hashed API keys, signed expiring URLs for original-resolution images and password resets, EXIF stripping and image re-encoding on upload, rate limiting, role-restricted admin access with activity logging, and encrypted off-site backups. No system is perfectly secure; if a breach creates a risk to you, we will notify you and the Information Regulator (and other authorities where required) as the law demands.
13. Children
The service is not directed at children under 13, and we do not knowingly process their personal information. Users under 18 require the consent of a parent or guardian (a "competent person" under POPIA). If you believe a child is using the service without such consent, contact us and we will remove the account.
14. Changes to this policy
We may update this policy as the service or the law changes. For material changes we will notify you (email or in-app notice) before they take effect; the "Last updated" date above reflects the current version. Where a change requires fresh consent under applicable law, we will ask for it.
15. Contact
Ephemeros — operated by Willem van Zyl t/a "CLC Agency", South Africa (Information Officer).
Email: hello@ephemeros.app
Takedown requests: ephemeros.app/takedown