Privacy Policy
Last updated: July 27, 2026
Animal Detect ("we", "us", "our") is operated by Really A Robot ApS, Danserhøj 40, Brønderslev 9700, Denmark. This policy explains how we collect, use, store, and protect personal data when you use our website, application, API, billing pages, and support channels.
1. Controller and contact
Data controller: Really A Robot ApS, Danserhøj 40, 9700 Brønderslev, Denmark
Contact: info@animaldetect.com
Support: support@animaldetect.com
We have not appointed a Data Protection Officer. For all data protection inquiries, please contact us using the details above.
2. Roles and responsibilities
For account, billing, and operational data, we act as the data controller.
For content you upload and process through the service, you (or the organisation you belong to) act as the data controller, and we act as a data processor on your behalf.
You are responsible for ensuring that you have a valid legal basis for processing any personal data submitted to the service.
Where required under applicable law, a Data Processing Agreement (DPA) may be made available upon request.
3. What data we collect
| Category | Typical items | Source |
|---|---|---|
| Account data | Name, email address, password hash, authentication metadata | Provided by you during sign-up or sign-in |
| Billing data | Monitoring licences, dataset processing quotas, metered API usage, spend cap settings, Stripe customer references, invoices, transaction records | Generated through your organisation's account and payment provider |
| Content data | Uploaded images and videos, captures ingested from connected cameras, generated outputs, project metadata, API request payloads and results | Submitted by you or your organisation through the platform, connected devices, or API |
| Usage and security data | API request logs, rate-limit data, timestamps, device/browser data, IP-related security logs | Collected automatically when you use the service |
| Support and communications data | Emails, support requests, product notices, onboarding and billing communications | Provided by you or sent by us |
Content you upload may include personal data, including images of identifiable individuals. You are responsible for ensuring you have a lawful basis for submitting such data.
4. Private by default, organisation workspaces, and the Privacy Filter
All content is private by default, on every product and on free accounts. We do not review or reuse your content for service improvement, model training, or internal research, except where access is needed to operate, secure, support, or comply with legal obligations.
Organisation workspaces are shared. Every account belongs to an organisation, and content in the organisation workspace (uploads, connected-camera captures, processing results) is visible to the organisation's members according to their roles. The organisation controls its own membership; if you join an organisation, its owners and admins also control what happens to content you contribute to it.
The Privacy Filter protects people caught on camera. Wildlife cameras sometimes photograph people and vehicles. When our models detect a person or vehicle in an image, the platform stores and serves a copy with those regions blurred. This filter is on by default for every organisation. The organisation owner can disable it, for example where the organisation monitors its own staffed sites and has a lawful basis to view such imagery; that choice applies to the whole organisation and is the organisation's responsibility as controller. Videos containing detected people or vehicles are withheld behind a placeholder rather than blurred. Detection is automated and not guaranteed: the filter cannot blur a person or vehicle the models fail to detect.
Where content is stored. Uploaded and ingested media are stored in Google Cloud Storage within the European Economic Area, with both the original and, where the Privacy Filter applies, the blurred variant retained. Originals of protected images are only served when the organisation owner has disabled the filter.
Your content belongs to you. We do not sell personal data to data brokers or advertisers, we do not use uploaded wildlife content for advertising networks or ad targeting, and we do not share your content with third parties for their own purposes — it is disclosed only to the service providers listed in Section 7, to the extent needed to operate the platform.
5. Why we process your data
| Purpose | Lawful basis | Examples |
|---|---|---|
| Provide the service you requested | Contract | Account creation, organisation membership, uploads, camera ingestion, API processing, quota and usage metering, billing portal access |
| Process payments and maintain records | Contract and legal obligation | Licence invoicing, quota purchases, metered API charges, invoices, accounting retention |
| Secure the service and prevent abuse | Legitimate interests | Rate limiting, fraud checks, abuse prevention, incident investigation |
| Improve and evaluate the product | Legitimate interests | Aggregate usage analysis, product analytics, docs and onboarding improvements |
| Communicate with you | Contract and legitimate interests | Transactional emails, billing notices, support replies, migration announcements |
We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.
6. Billing and usage specifics
We process billing and usage data to operate per-product entitlements. This includes tracking monitoring licence status and camera slots, dataset processing quota granted and consumed, metered API request counts, free allowance counters, spend cap settings, and feature access decisions.
If a licence or entitlement changes state, we update the organisation's access accordingly. If a payment fails, we may pause the affected paid usage until payment is recovered, as described in our Terms of Service.
7. Sub-processors and service providers
We use third-party providers to operate Animal Detect, including infrastructure, analytics, billing, and email delivery vendors.
- Google Cloud Platform for image and video storage (Google Cloud Storage), processing, and supporting infrastructure
- Supabase for database, authentication, and platform data services
- Stripe for billing, invoices, and payment processing
- Resend for transactional and account communications
- PostHog (EU-hosted) for product analytics
- Umami for privacy-conscious website analytics
Some providers may process limited personal data outside your country or the EEA. Where that happens, we rely on appropriate safeguards such as adequacy decisions or the European Commission's Standard Contractual Clauses (SCCs), together with supplementary measures where required.
Our primary infrastructure is hosted within the European Economic Area (EEA), unless otherwise stated.
8. Communications
We may send service and account communications related to security, billing, product changes, legal notices, support, onboarding, and migration of your account. You cannot opt out of strictly necessary service messages while maintaining an active account.
These service communications may include usage and quota notices, spend cap notices, licence renewal notices, billing recovery reminders, migration notices, and other messages necessary to help you keep service working as expected.
Where we send optional product updates or similar non-essential communications, we will provide a way to stop receiving them when required by applicable law or the sending channel.
These communications are sent based on our contractual obligations and legitimate interests in operating the service.
9. Cookies and analytics
We use limited cookies and similar technologies necessary for authentication, security, and basic analytics.
On the public website we use privacy-focused analytics designed to avoid tracking individuals across websites. Inside the product we use PostHog, hosted in the EU, to understand how features are used; this covers events such as onboarding steps and feature usage, not the content of your images. Where required by applicable law, we will request consent before using non-essential cookies.
10. Data retention
| Data type | Retention period |
|---|---|
| Account and billing records | As long as the account exists, plus statutory retention where required for invoices, accounting, disputes, and compliance |
| Uploaded content and generated outputs | Until deleted by you or your organisation, removed with the related project, or deleted under our retention controls; processed datasets are stored for 12 months after processing, after which we offer export, renewal, or deletion |
| API result payloads and request artifacts | Available for result retrieval for 30 days; compact operational request state is deleted after 45 days |
| Raw operational, API, and usage logs | Retained only as needed for security, billing, support, and abuse prevention, then deleted or aggregated; raw usage logs are deleted after 90 days |
| Aggregate usage and billing records | May be retained longer than raw request/result payloads to support account history, billing, support, abuse prevention, and legal obligations |
| Support and transactional communications | Retained as needed to support the account relationship and compliance obligations |
We periodically review stored data and delete or anonymize data that is no longer necessary for the purposes described in this policy.
When you delete your account, we will delete or anonymize your personal data within a reasonable period, except where retention is required for legal, accounting, or security purposes.
11. Security
We use technical and organizational measures designed to protect the service and the data we process, including encrypted transport, access controls, infrastructure hardening, and operational logging.
While we implement appropriate safeguards, no system can be guaranteed to be completely secure.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, the affected users, in accordance with applicable law.
12. Your rights
Subject to applicable law, you may have the right to:
- access the personal data we hold about you
- request correction or deletion
- object to or restrict certain processing
- withdraw consent where processing is based on consent
- object to processing based on legitimate interests
- receive a portable copy of certain data
- lodge a complaint with your supervisory authority
To exercise these rights, email info@animaldetect.com.
You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet).
We aim to respond to requests within one month, as required by applicable law.
13. Children
The service is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children.
14. Changes to this policy
We may update this policy when the service, billing model, or legal requirements change. Material updates will be reflected here and will be communicated where appropriate by email or within the product prior to taking effect.
Did we convince you?
Start now