Privacy
This page covers both our homes — the walk at app.saveourfields.com and the campaign site at www.saveourfields.com. They share the same promise, so they share this page.
"Hello. It's me. Rusty. Scarecrow, narrator, professional stander. I'm also the one who keeps the ledgers round here, so it falls to me to talk about privacy — not some fellow in a necktie. I'll keep it plain."
The short version
- No accounts, no email, no password. Nothing is required to walk the field.
- Photos never leave your phone. Ever. There's a burn-the-photos button for a reason.
- We don't sell anything about you. No advertising, no tracking networks, no Google or AI clouds harvesting the walk. I used to work for the sort of firm that did that. We don't.
- Analytics are pseudonymous, and your IP address is never stored. Only a scrambled, one-way hash of it, so we can't read it back.
- The one honest exception: if you type your name and email into a form on the campaign site — to contact us or report a bug — we read it, we answer, and then we delete it on a timer. More below.
What we keep, and what we never see
On the walk (app.saveourfields.com)
- GPS is off by default — you opt in, and the GPS button on the field unit switches it off again at any moment. When it's on, it's used only to notice when you reach a stop. Your exact position is never recorded or sent. At each stop we send a deliberately coarse spot — rounded to about a kilometre — so the field team can see, as a blurry heatmap, where people tend to wander. Nothing finer, and never tied to a name. With location off, nothing about where you are leaves the phone.
- Camera shows you the creatures and nothing else. The feed is never recorded, stored or sent anywhere. Photos you snap stay on your device.
- Field Ranger name (optional) — if you claim a name, we keep a scrambled, one-way hash of your secret word, not the word itself, plus the public name you chose. That's what runs the Roll of Honour and carries your badges across devices. Forget me wipes it whenever you ask.
- How busy is the meadow? If you choose to, you can leave a one-tap word — "quiet", "a few" or "busy", and how the ground is ("fine", "muddy", "flooded", "blocked"). It's shown to other walkers only as a vague vibe — never a live headcount and never who. To check a report really comes from the field, your phone sends its position once; we confirm it's inside the meadow and throw it away. Nothing is stored, nothing is shown to anyone, and it's never tied to a name. The signal only appears because someone chose to say it, and it fades on its own (condition 24 hours, busyness 6 hours). You can take your word back ("burn" it) any time, and "forget me" wipes it.
- Analytics — a random visitor number created on your device, your device type, and things like "creature sighted." No names, no emails, no precise locations. It's pseudonymous — never linked to a name — and you can switch it off in the app. Kept about a year.
- Weather — we send the meadow's coordinates to a free, tracker-free weather service. Never yours.
On the campaign site (www.saveourfields.com)
- Analytics — page visits and the odd "they clicked the button" note. The visitor id is a random number kept in your browser (no cookies), your IP is hashed, and we only see which site sent you, never the page you came from. You can switch it off from the footer (and Do Not Track is honoured too). Kept 13 months.
- Contact form — this is the real stuff, so I'll be plain. If you write to us we keep your name, email, location and message in a locked inbox, seen only by the field team, and it auto-deletes after 30 days whether you ask or not. The "suggest a field" and "join the field team" buttons just pre-fill this same form.
- Bug bounty — name, email, your report, and (only if you want the 3D-printed swag) a postal address. Deleted after 12 months. The address exists only to post your swag.
The servers
- Raw IP addresses appear only in ordinary server access logs, which live outside the websites, rotate automatically, and are never public. The database never holds a raw IP.
- Nightly backups are encrypted and mirrored off-site. A small band of suppliers (OVH, BunnyCDN, Ionos, Let's Encrypt, BetterStack, rsync.net) run and secure the sites; none of them get to rummage through anything for their own ends.
Your choices
- Forget me — in the app, one tap wipes your identity and the telemetry linked to it. If you never claimed a name, "forget this device" wipes the walk history on the device you're using — email us for anything beyond it. For contact messages or bug reports, email hello@saveourfields.com.
- Switch analytics off — use the switch in the app's journal, or the footer switch on the website. Do Not Track is honoured too.
- Location — off by default. You switch it on in the app, and the GPS button on the field unit turns it off at any moment. With it off you can still browse everything — the map, the creatures' stories — just without the live "creature steps out at your feet" bit. Camera — the phone asks first, and the walk still works without one (it goes to the storybook version).
The small print (the precise version, no poetry)
Who we are. Save Our Fields is operated by Vivid Atom Limited (ICO registration ZB010144), the data controller for both app.saveourfields.com and www.saveourfields.com. You can reach us at hello@saveourfields.com for anything on this page.
What we process, why, and for how long:
| Data | Purpose | Legal basis (UK GDPR) | Retention |
|---|---|---|---|
| App analytics (random visitor id, device type, walk events, coarse ~1 km zone) | Improve the walk; see where people wander | Legitimate interests, Art. 6(1)(f) — data is pseudonymous; raw IP hashed on receipt | ~12 months |
| Website analytics (hashed visit id, hashed IP, host-only referrer, page/CTA) | See what's read and clicked | Legitimate interests, Art. 6(1)(f) | 13 months |
| Contact messages (name, email, location, message) | Answer your enquiry | Legitimate interests, Art. 6(1)(f) — you asked us to respond | 30 days (auto-deleted) |
| Bug-bounty reports (name, email, report, optional postal address) | Fix the bug; post your swag | Legitimate interests, Art. 6(1)(f) | 12 months |
| Field reports (condition / busyness — no location, no name) | Tell others the meadow's vibe and underfoot right now | Your choice — entirely optional, self-declared | 24h condition / 6h busyness (auto-expires) |
| Field Ranger identity (one-way hash of your secret + chosen display name) | Roll of Honour; carry progress across devices | Your choice — entirely optional | Until you "forget me" |
| Friend meetings (hashed tokens, method, day) | Face-to-face meet-and-greet | Your choice — self-declared (both phones scanning the same field) | 2 years (auto-deleted) |
| Security & rate-limit records (hashed IP buckets) | Stop abuse and robots | Legitimate interests, Art. 6(1)(f) | Pruned |
| Erasure log (counts only, no personal data) | Report how many erasures we've honoured | — (not personal data) | Kept |
| Field team recon surveys (the team's own fieldwork, admin-only) | Run the field walks | Internal operations | Kept (backed up) |
Who sees your data. Nobody for advertising — we have none. Personal data (contact messages, bug reports) is visible only to the field team through a locked admin area (authenticated, rate-limited, behind a second password gate). A small set of infrastructure suppliers (hosting, CDN, DNS, monitoring, encrypted backup) process limited technical data on our behalf under contract; they don't get to use it for their own purposes. We never sell or rent personal data.
Your rights. You have the right to access a copy of what we hold on you; have it corrected; have it erased (in-app "forget me", or email us); restrict or object to processing; and data portability. We respond to requests at hello@saveourfields.com and aim to act within one month. Nothing here affects those rights.
Complaints. If you're unhappy with how we've handled your data, tell us first — but you also have the right to complain to the UK regulator, the Information Commissioner's Office (ico.org.uk).
Cookies & similar technology. We don't use advertising or tracking cookies, and no consent banner is needed. The anonymous visitor numbers use your browser's local storage (not a cookie), and they're wiped if you clear your browser. The app's offline "kit" uses the browser's service-worker cache so the walk works with no signal.
Children. The walk is a family walk, but we collect no personal data from anyone just for taking part — no chat, no messaging, no purchases, and a parent can watch the whole thing. The only time we'd hold a child's data is if someone (child or adult) writes to us through the contact form, which auto-deletes after 30 days.
Where data goes. Your data is stored and processed on servers in the UK and European Union. Backups are encrypted with a key held only in the UK before they leave, and our off-site backup supplier holds only that encrypted copy — never a readable one. Our status-page monitor only checks that the sites are up and receives no personal data. We'll say plainly if that ever changes.
Changes. If we change anything material here, we'll update this page. The honest record of every data point lives in our internal privacy ledger, and this page is its mirror.
"There. That's the lot — every scrap of it, and the scraps we don't take. If you'd like any of it gone, say the word and I'll fetch the matches myself. A promise, not a feature.— Rusty"
← Back to the meadow