FIELD / Legal note 01
Privacy, in plain language.
At a glance
FIELD is designed as a local-first travel diary. Your photo archive is not uploaded or synchronized as a cloud gallery. Original photographs, generated field notes, favourites, coordinates, trip groupings and private notes remain in storage controlled by the FIELD app on your device.
Some features—creating an AI-assisted impression, signing in, validating an address, paying for a postcard and having it printed—need limited cloud processing. FIELD sends only the information needed to complete the action you requested.
This policy applies to the FIELD mobile app and this website. The controller is FIELD Studio. Questions can be sent to support@fieldtravel.app.
What stays on your device
The app’s local database and private files may contain:
- photographs you select or take in FIELD;
- finished field-note compositions, thumbnails and exported copies;
- place names, capture dates, coordinates and photograph metadata you choose to retain;
- favourites, captions, keywords, trip associations and archive filters;
- remembered postcard recipients, drafts, your postcard signature and a local order cache; and
- app preferences and an outbox used to complete actions safely.
This information is separated by signed-in account on the device. Authentication credentials are stored using the iOS Keychain or the corresponding secure store, not inside the photo archive database. Removing the app may remove local data that has not been exported.
When data leaves your device
Account and authentication
FIELD uses your email address to create an account and send a secure magic link. Cloud records may include an internal account identifier, authentication timestamps and security logs needed to protect the service.
Creating a field note
When you ask FIELD to create an impression, the selected photograph and relevant place or capture metadata are uploaded temporarily through protected services. The photograph may be analysed and transformed by AI providers to produce the stamp and completed composition. FIELD does not upload your whole library, and these temporary assets are not used to create a cloud gallery.
Addresses and postcards
When you compose a physical postcard, FIELD processes the recipient name and postal address, your message, the print-ready composition and fulfillment status. Address suggestions and validation may be provided before purchase. The information is used to prepare, print, post, support and reconcile the order.
Payments
Payment details are collected directly by the payment provider. FIELD receives transaction references, price, currency, status and limited billing information, but does not store full card numbers.
Website analytics
This website loads optional, privacy-conscious analytics only after you consent. If configured, the measurements are used to understand aggregate visits and download-button use. No advertising tracker is loaded by default, and declining analytics does not reduce site functionality.
Service providers and purposes
FIELD uses specialist providers only where a feature needs them. Current production integrations may include:
- Supabase for authentication, protected service functions, temporary processing records and secure order infrastructure;
- Google Gemini and OpenAI for photograph analysis and generation of the field-note composition you request;
- an address-validation provider for international address suggestions and validation;
- Stripe for payment processing; and
- MyPostcard for print production, postal fulfillment and delivery-status events.
Providers process information under their own security and privacy obligations and only for the relevant service. Processing may take place outside your country. Where required, FIELD relies on recognized transfer safeguards such as adequacy decisions or contractual protections.
FIELD may also disclose information when required by law, to protect users and the service, or as part of a business reorganisation with appropriate safeguards. FIELD does not sell personal data.
Retention and security
Local archive data remains until you delete a field note, reset the archive or remove the app. Temporary generation uploads and intermediate files are deleted automatically after the processing and safety window. Account, transaction, invoice, order and fulfillment records are kept only as long as needed to provide support, prevent duplicate charges or prints, meet legal obligations and resolve disputes.
FIELD uses encrypted transport, scoped access, row-level access controls, rate limits and protected secret storage. QR links use high-entropy tokens whose server records are stored as one-way hashes; the token itself does not contain a recipient address or order details. No system can promise absolute security, so please keep your device and email account protected.
Your choices and rights
You can choose which photographs to use, review generated details before sharing or ordering, remove local field notes, edit remembered recipients and decline website analytics. You can also request access, correction, deletion, restriction, portability or an objection where the law gives you those rights.
To delete your cloud account, use Account → Delete account in FIELD. If you cannot open the app, email support from the address linked to the account. Account deletion does not automatically remove photographs or exports outside FIELD, and records may be retained where tax, fraud-prevention, payment or consumer-protection rules require it.
FIELD is not directed to children under 13, or the higher minimum age required in their country, and does not knowingly collect their personal data. You may complain to your local data-protection authority if you believe your rights were not respected.
Changes and contact
We may update this policy when FIELD’s features, providers or legal obligations change. Material changes will be highlighted in the app or on this page, and the effective date above will be updated.
Privacy questions and rights requests: support@fieldtravel.app.