Privacy Policy
Last updated: 28 September 2026
Animal Detect ("we", "us", "our") is operated by Animal Detect ApS, Danserhøj 40, Brønderslev 9700, Denmark. This policy explains how we collect, use, store, and protect personal data when you use our website, application, API, billing pages, and support channels.
1. Controller and contact
Data controller: Animal Detect ApS, Danserhøj 40, 9700 Brønderslev, Denmark
Contact: info@animaldetect.com
Support: support@animaldetect.com
We have not appointed a Data Protection Officer. For all data protection inquiries, please contact us using the details above.
2. Roles and responsibilities
For account, billing, and operational data, we act as the data controller.
For content you upload and process through the service, you (or the organisation you belong to) act as the data controller, and we act as a data processor on your behalf. For service improvement (Section 4), unless the organisation has turned it off, we act as a controller for the copies we use to train and evaluate our models.
You are responsible for ensuring that you have a valid legal basis for processing any personal data submitted to the service.
Where required under applicable law, a Data Processing Agreement (DPA) may be made available upon request.
3. What data we collect
| Category | Typical items | Source |
|---|---|---|
| Account data | Name, email address, password hash, authentication metadata, and the email addresses of people your organisation invites | Provided by you during sign-up or sign-in, or by your organisation's owner when inviting you |
| Billing data | Wildlife Monitoring licences, upload data allowances, metered API usage, spend cap settings, Stripe customer references, invoices, transaction records | Generated through your organisation's account and payment provider |
| Content data | Uploaded images and videos, captures ingested from connected cameras, generated outputs, review labels and corrections, project metadata, images submitted to the API, request payloads and results | Submitted by you or your organisation through the platform, connected devices, or API |
| Usage and security data | API request logs, rate-limit data, timestamps, device/browser data, IP-related security logs | Collected automatically when you use the service |
| Support and communications data | Emails, support requests, product notices, onboarding and billing communications | Provided by you or sent by us |
Content you upload may include personal data, including images of identifiable individuals. You are responsible for ensuring you have a lawful basis for submitting such data.
4. Private by default, organisation workspaces, and the Privacy Filter
All content is private by default, on every product and on free accounts. We do not review or reuse your content for internal research or any other purpose of our own, except where access is needed to operate, secure, support, or comply with legal obligations, and for service improvement unless your organisation has turned it off (below).
Organisation workspaces are shared. Every account belongs to exactly one organisation, and content in the organisation workspace (uploads, camera captures, processing results) is visible to its members according to their role (owner, member or guest) and project access. The organisation owner controls membership and project access and can hand ownership to another member; if you join an organisation, its owner also controls what happens to content you contribute to it, including after you leave.
The Privacy Filter protects people caught on camera. Wildlife cameras sometimes photograph people and vehicles. When our models detect a person or vehicle in an image, the platform stores and serves a copy with those regions blurred. This filter is on by default for every organisation. The organisation owner can disable it, for example where the organisation monitors its own staffed sites and has a lawful basis to view such imagery; that choice applies to the whole organisation and is the organisation's responsibility as controller. Videos containing detected people or vehicles are withheld behind a placeholder rather than blurred. Detection is automated and not guaranteed: the filter cannot blur a person or vehicle the models fail to detect.
Service improvement is on by default. The organisation owner can turn it off at any time in the organisation settings. While it is on, we may use copies of the organisation's images and videos, and the labels and corrections its members add to them, to train, evaluate and improve our detection models and features. We exclude every image or video in which our models detect people or vehicles, and we remove location, camera make, model and serial number, and all other metadata first, so these copies are not intended to contain personal data. Detection is automated, so if a person or vehicle is found in a copy later, we delete that copy.
Where content is stored. Uploaded and ingested media, including images submitted to the Detection API, are stored in Google Cloud Storage within the European Economic Area, with both the original and, where the Privacy Filter applies, the blurred variant retained. Originals of protected images are only served when the organisation owner has disabled the filter. Detection API images are stored without the Privacy Filter and are not shown in the workspace.
Your content belongs to you. We do not sell personal data to data brokers or advertisers, we do not use uploaded wildlife content for advertising networks or ad targeting, and we do not share your content with third parties for their own purposes. It is disclosed only to the service providers listed in Section 7, to the extent needed to operate the platform.
5. Why we process your data
| Purpose | Lawful basis | Examples |
|---|---|---|
| Provide the service you requested | Contract | Account creation, organisation membership, team invitations and project access, uploads, camera ingestion, API processing, usage metering, billing portal access, result retrieval, re-processing, support |
| Process payments and maintain records | Contract and legal obligation | Licence invoicing, upload data purchases, metered API charges, invoices, accounting retention |
| Secure the service and prevent abuse | Legitimate interests | Rate limiting, fraud checks, abuse prevention, incident investigation |
| Improve and evaluate the product | Legitimate interests | Aggregate usage analysis, product analytics, docs and onboarding improvements |
| Service improvement | Legitimate interests; the organisation owner can object at any time by turning it off in settings | Training, evaluating and improving our detection models and features on copies of images and videos and the labels added to them, with those containing detected people or vehicles excluded and location and camera metadata removed |
| Communicate with you | Contract and legitimate interests | Transactional emails, billing notices, support replies, migration announcements |
We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.
6. Billing and usage specifics
We process billing and usage data to operate per-product entitlements. This includes tracking Wildlife Monitoring licence status and connected cameras, upload data granted and consumed, metered API request counts, free allowance counters, spend cap settings, and feature access decisions.
If a licence or entitlement changes state, we update the organisation's access accordingly. If a payment fails, we may pause the affected paid usage until payment is recovered, as described in our Terms of Service.
7. Sub-processors and service providers
We use third-party providers to operate Animal Detect, including infrastructure, analytics, billing, and email delivery vendors.
- Google Cloud Platform for image and video storage (Google Cloud Storage), processing, and supporting infrastructure
- Supabase for database, authentication, and platform data services
- Stripe for billing, invoices, and payment processing
- Resend for transactional and account communications
- PostHog (EU-hosted) for product analytics
- Umami for privacy-conscious website analytics
Some providers may process limited personal data outside your country or the EEA. Where that happens, we rely on appropriate safeguards such as adequacy decisions or the European Commission's Standard Contractual Clauses (SCCs), together with supplementary measures where required.
Our primary infrastructure is hosted within the European Economic Area (EEA), unless otherwise stated.
8. Communications
We may send service and account communications related to security, billing, product changes, legal notices, support, onboarding, and migration of your account. You cannot opt out of strictly necessary service messages while maintaining an active account.
These service communications may include usage and upload data notices, spend cap notices, licence renewal notices, billing recovery reminders, migration notices, and other messages necessary to help you keep service working as expected.
Where we send optional product updates or similar non-essential communications, we will provide a way to stop receiving them when required by applicable law or the sending channel.
These communications are sent based on our contractual obligations and legitimate interests in operating the service.
9. Cookies and analytics
We use limited cookies and similar technologies necessary for authentication, security, and basic analytics.
On the public website we use privacy-focused analytics designed to avoid tracking individuals across websites. Inside the product we use PostHog, hosted in the EU, to understand how features are used; this covers events such as onboarding steps and feature usage, not the content of your images. Where required by applicable law, we will request consent before using non-essential cookies.
10. Data retention
| Data type | Retention period |
|---|---|
| Account and billing records | As long as the account exists, plus statutory retention where required for invoices, accounting, disputes, and compliance |
| Content you submit and results we generate (uploads, camera captures, images submitted to the API, request payloads, generated outputs, review labels) | 12 months after processing, unless deleted earlier by you or your organisation, removed with the related project, or deleted on request to support@animaldetect.com. After that period we offer export, renewal or deletion |
| Service-improvement copies | Until the organisation turns service improvement off, then deleted within 30 days. Models already trained are not affected |
| Raw operational, API, and usage logs | Retained only as needed for security, billing, support, and abuse prevention, then deleted or aggregated; raw usage logs are deleted after 90 days |
| Aggregate usage and billing records | May be retained longer than raw request/result payloads to support account history, billing, support, abuse prevention, and legal obligations |
| Support and transactional communications | Retained as needed to support the account relationship and compliance obligations |
We periodically review stored data and delete or anonymize data that is no longer necessary for the purposes described in this policy.
When you delete your account, we will delete or anonymize your personal data within a reasonable period, except where retention is required for legal, accounting, or security purposes.
11. Security
We use technical and organizational measures designed to protect the service and the data we process, including encrypted transport, access controls, infrastructure hardening, and operational logging.
While we implement appropriate safeguards, no system can be guaranteed to be completely secure.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, the affected users, in accordance with applicable law.
12. Your rights
Subject to applicable law, you may have the right to:
- access the personal data we hold about you
- request correction or deletion
- object to or restrict certain processing
- withdraw consent where processing is based on consent
- object to processing based on legitimate interests
- receive a portable copy of certain data
- lodge a complaint with your supervisory authority
To exercise these rights, email info@animaldetect.com.
You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet).
We aim to respond to requests within one month, as required by applicable law.
13. Children
The service is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children.
14. Changes to this policy
We may update this policy when the service, billing model, or legal requirements change. Material updates will be reflected here and will be communicated where appropriate by email or within the product prior to taking effect.
Did we convince you?
Start now