1. Controller
LIFECO GmbH
Forsthausgasse 16-20/13/7, 1200 Vienna, Austria
Company register: 502150g · UID: ATU73826167
Privacy contact: kontakt@fungifind.org
2. What we process
- Account data: email, hashed password, username, display name, avatar, optional Google ID
- Session cookie (
ff.sid): keeps you logged in (~14 days) - Guest score limit (abuse protection): pseudonymous guest id (cookie
ff_guest_id) and a hashed daily IP value (HMAC-SHA256with a daily rotating salt; the IP is not stored in plain text). Purpose: limit free guest score lookups and prevent circumvention. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Retention: max. 48 hours, then automatic deletion. Logged-in users are not subject to this limit. - Location data: coordinates for saved spots, mushroom finds, weather alerts
- Community content: photos, notes, comments, votes, friend connections, chat messages
- Push notifications: Web Push subscription keys (with your consent)
- Emails: welcome, password reset, optional weather alerts, feedback replies
- Device storage: language, map view, theme, first-party attribution (
ff_first_touch,ff_anon_id), disclaimer acceptance, UI preferences; IndexedDB weather/score cache (ff_wx_v1) and chat gallery - First-party product events: event name, timestamp, anonymous session id, optional user id after login (stored as
product_events) for product improvement — no third-party analytics trackers
We do not use third-party analytics trackers (no Google Analytics, Matomo, etc.).
No automated decision-making with legal or similarly significant effects (Art. 22 GDPR).
2a. First-party attribution
On first visit we store landing path, referrer host, UTM tags, derived channel, and device class in localStorage (ff_first_touch). On signup these are saved once to your account (user_first_touch) and not overwritten. Purpose: measure acquisition channels without third-party tracking. Legal basis: Art. 6(1)(f) GDPR. Deleted with the account or on request.
3. Purposes & legal bases
Processing is based on contract performance (Art. 6(1)(b) GDPR), consent where required (e.g. push, Google sign-in, sensitive content unlock), and legitimate interests (security, service operation, guest score-limit abuse protection with hashed IP — see section 2, and first-party acquisition measurement).
4. Recipients
- Hetzner — hosting & infrastructure (processor agreement required)
- SMTP mail — transactional emails from noreply@fungifind.org
- Let's Encrypt — TLS certificates
- Open-Meteo — weather forecasts (coordinates sent, no account data)
- CARTO — map basemap tiles via Leaflet
- EEA Corine — optional habitat WMS layer
- Paddle.com — Merchant of Record for paid plans (checkout & billing)
- Wikimedia Commons — reference species images
- Google (optional) — OAuth sign-in and user-initiated Google Lens
- cdnjs — delivery of libraries (e.g. Leaflet)
5. Your rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Contact kontakt@fungifind.org.
You may lodge a complaint with the Austrian Data Protection Authority (DSB): www.dsb.gv.at
6. Sensitive & psychoactive content
Educational distribution data for psychoactive species requires age confirmation (18+) and acknowledgment of legal risks before unlock.
Version: September 2026. Full details: German Datenschutzerklärung. Localized summaries: ES · FR · IT · PL · CS · HU · FI · SV · RO · RU.