Back to FungiFind
FungiFind

Privacy Policy

Information pursuant to Art. 13/14 GDPR

The legally authoritative version for Austria is the German privacy policy. This page provides an English summary for international users.

1. Controller

LIFECO GmbH

Forsthausgasse 16-20/13/7, 1200 Vienna, Austria

Company register: 502150g · UID: ATU73826167

Privacy contact: kontakt@fungifind.org

2. What we process

  • Account data: email, hashed password, username, display name, avatar, optional Google ID
  • Session cookie (ff.sid): keeps you logged in (~14 days)
  • Guest score limit (abuse protection): pseudonymous guest id (cookie ff_guest_id) and a hashed daily IP value (HMAC-SHA256 with a daily rotating salt; the IP is not stored in plain text). Purpose: limit free guest score lookups and prevent circumvention. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Retention: max. 48 hours, then automatic deletion. Logged-in users are not subject to this limit.
  • Location data: coordinates for saved spots, mushroom finds, weather alerts
  • Community content: photos, notes, comments, votes, friend connections, chat messages
  • Push notifications: Web Push subscription keys (with your consent)
  • Emails: welcome, password reset, optional weather alerts, feedback replies
  • Device storage: language, map view, theme, first-party attribution (ff_first_touch, ff_anon_id), disclaimer acceptance, UI preferences; IndexedDB weather/score cache (ff_wx_v1) and chat gallery
  • First-party product events: event name, timestamp, anonymous session id, optional user id after login (stored as product_events) for product improvement — no third-party analytics trackers

We do not use third-party analytics trackers (no Google Analytics, Matomo, etc.).

No automated decision-making with legal or similarly significant effects (Art. 22 GDPR).

2a. First-party attribution

On first visit we store landing path, referrer host, UTM tags, derived channel, and device class in localStorage (ff_first_touch). On signup these are saved once to your account (user_first_touch) and not overwritten. Purpose: measure acquisition channels without third-party tracking. Legal basis: Art. 6(1)(f) GDPR. Deleted with the account or on request.

3. Purposes & legal bases

Processing is based on contract performance (Art. 6(1)(b) GDPR), consent where required (e.g. push, Google sign-in, sensitive content unlock), and legitimate interests (security, service operation, guest score-limit abuse protection with hashed IP — see section 2, and first-party acquisition measurement).

4. Recipients

  • Hetzner — hosting & infrastructure (processor agreement required)
  • SMTP mail — transactional emails from noreply@fungifind.org
  • Let's Encrypt — TLS certificates
  • Open-Meteo — weather forecasts (coordinates sent, no account data)
  • CARTO — map basemap tiles via Leaflet
  • EEA Corine — optional habitat WMS layer
  • Paddle.com — Merchant of Record for paid plans (checkout & billing)
  • Wikimedia Commons — reference species images
  • Google (optional) — OAuth sign-in and user-initiated Google Lens
  • cdnjs — delivery of libraries (e.g. Leaflet)

5. Your rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Contact kontakt@fungifind.org.

You may lodge a complaint with the Austrian Data Protection Authority (DSB): www.dsb.gv.at

6. Sensitive & psychoactive content

Educational distribution data for psychoactive species requires age confirmation (18+) and acknowledgment of legal risks before unlock.

Version: September 2026. Full details: German Datenschutzerklärung. Localized summaries: ES · FR · IT · PL · CS · HU · FI · SV · RO · RU.