Loading...

Privacy Policy

Last updated: July 27, 2026

Animal Detect ("we", "us", "our") is operated by Really A Robot ApS, Danserhøj 40, Brønderslev 9700, Denmark. This policy explains how we collect, use, store, and protect personal data when you use our website, application, API, billing pages, and support channels.

1. Controller and contact

Data controller: Really A Robot ApS, Danserhøj 40, 9700 Brønderslev, Denmark
Contact: info@animaldetect.com
Support: support@animaldetect.com

We have not appointed a Data Protection Officer. For all data protection inquiries, please contact us using the details above.

2. Roles and responsibilities

For account, billing, and operational data, we act as the data controller.

For content you upload and process through the service, you (or the organisation you belong to) act as the data controller, and we act as a data processor on your behalf.

You are responsible for ensuring that you have a valid legal basis for processing any personal data submitted to the service.

Where required under applicable law, a Data Processing Agreement (DPA) may be made available upon request.

3. What data we collect

CategoryTypical itemsSource
Account dataName, email address, password hash, authentication metadataProvided by you during sign-up or sign-in
Billing dataMonitoring licences, dataset processing quotas, metered API usage, spend cap settings, Stripe customer references, invoices, transaction recordsGenerated through your organisation's account and payment provider
Content dataUploaded images and videos, captures ingested from connected cameras, generated outputs, project metadata, API request payloads and resultsSubmitted by you or your organisation through the platform, connected devices, or API
Usage and security dataAPI request logs, rate-limit data, timestamps, device/browser data, IP-related security logsCollected automatically when you use the service
Support and communications dataEmails, support requests, product notices, onboarding and billing communicationsProvided by you or sent by us

Content you upload may include personal data, including images of identifiable individuals. You are responsible for ensuring you have a lawful basis for submitting such data.

4. Private by default, organisation workspaces, and the Privacy Filter

All content is private by default, on every product and on free accounts. We do not review or reuse your content for service improvement, model training, or internal research, except where access is needed to operate, secure, support, or comply with legal obligations.

Organisation workspaces are shared. Every account belongs to an organisation, and content in the organisation workspace (uploads, connected-camera captures, processing results) is visible to the organisation's members according to their roles. The organisation controls its own membership; if you join an organisation, its owners and admins also control what happens to content you contribute to it.

The Privacy Filter protects people caught on camera. Wildlife cameras sometimes photograph people and vehicles. When our models detect a person or vehicle in an image, the platform stores and serves a copy with those regions blurred. This filter is on by default for every organisation. The organisation owner can disable it, for example where the organisation monitors its own staffed sites and has a lawful basis to view such imagery; that choice applies to the whole organisation and is the organisation's responsibility as controller. Videos containing detected people or vehicles are withheld behind a placeholder rather than blurred. Detection is automated and not guaranteed: the filter cannot blur a person or vehicle the models fail to detect.

Where content is stored. Uploaded and ingested media are stored in Google Cloud Storage within the European Economic Area, with both the original and, where the Privacy Filter applies, the blurred variant retained. Originals of protected images are only served when the organisation owner has disabled the filter.

Your content belongs to you. We do not sell personal data to data brokers or advertisers, we do not use uploaded wildlife content for advertising networks or ad targeting, and we do not share your content with third parties for their own purposes — it is disclosed only to the service providers listed in Section 7, to the extent needed to operate the platform.

5. Why we process your data

PurposeLawful basisExamples
Provide the service you requestedContractAccount creation, organisation membership, uploads, camera ingestion, API processing, quota and usage metering, billing portal access
Process payments and maintain recordsContract and legal obligationLicence invoicing, quota purchases, metered API charges, invoices, accounting retention
Secure the service and prevent abuseLegitimate interestsRate limiting, fraud checks, abuse prevention, incident investigation
Improve and evaluate the productLegitimate interestsAggregate usage analysis, product analytics, docs and onboarding improvements
Communicate with youContract and legitimate interestsTransactional emails, billing notices, support replies, migration announcements

We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.

6. Billing and usage specifics

We process billing and usage data to operate per-product entitlements. This includes tracking monitoring licence status and camera slots, dataset processing quota granted and consumed, metered API request counts, free allowance counters, spend cap settings, and feature access decisions.

If a licence or entitlement changes state, we update the organisation's access accordingly. If a payment fails, we may pause the affected paid usage until payment is recovered, as described in our Terms of Service.

7. Sub-processors and service providers

We use third-party providers to operate Animal Detect, including infrastructure, analytics, billing, and email delivery vendors.

  • Google Cloud Platform for image and video storage (Google Cloud Storage), processing, and supporting infrastructure
  • Supabase for database, authentication, and platform data services
  • Stripe for billing, invoices, and payment processing
  • Resend for transactional and account communications
  • PostHog (EU-hosted) for product analytics
  • Umami for privacy-conscious website analytics

Some providers may process limited personal data outside your country or the EEA. Where that happens, we rely on appropriate safeguards such as adequacy decisions or the European Commission's Standard Contractual Clauses (SCCs), together with supplementary measures where required.

Our primary infrastructure is hosted within the European Economic Area (EEA), unless otherwise stated.

8. Communications

We may send service and account communications related to security, billing, product changes, legal notices, support, onboarding, and migration of your account. You cannot opt out of strictly necessary service messages while maintaining an active account.

These service communications may include usage and quota notices, spend cap notices, licence renewal notices, billing recovery reminders, migration notices, and other messages necessary to help you keep service working as expected.

Where we send optional product updates or similar non-essential communications, we will provide a way to stop receiving them when required by applicable law or the sending channel.

These communications are sent based on our contractual obligations and legitimate interests in operating the service.

9. Cookies and analytics

We use limited cookies and similar technologies necessary for authentication, security, and basic analytics.

On the public website we use privacy-focused analytics designed to avoid tracking individuals across websites. Inside the product we use PostHog, hosted in the EU, to understand how features are used; this covers events such as onboarding steps and feature usage, not the content of your images. Where required by applicable law, we will request consent before using non-essential cookies.

10. Data retention

Data typeRetention period
Account and billing recordsAs long as the account exists, plus statutory retention where required for invoices, accounting, disputes, and compliance
Uploaded content and generated outputsUntil deleted by you or your organisation, removed with the related project, or deleted under our retention controls; processed datasets are stored for 12 months after processing, after which we offer export, renewal, or deletion
API result payloads and request artifactsAvailable for result retrieval for 30 days; compact operational request state is deleted after 45 days
Raw operational, API, and usage logsRetained only as needed for security, billing, support, and abuse prevention, then deleted or aggregated; raw usage logs are deleted after 90 days
Aggregate usage and billing recordsMay be retained longer than raw request/result payloads to support account history, billing, support, abuse prevention, and legal obligations
Support and transactional communicationsRetained as needed to support the account relationship and compliance obligations

We periodically review stored data and delete or anonymize data that is no longer necessary for the purposes described in this policy.

When you delete your account, we will delete or anonymize your personal data within a reasonable period, except where retention is required for legal, accounting, or security purposes.

11. Security

We use technical and organizational measures designed to protect the service and the data we process, including encrypted transport, access controls, infrastructure hardening, and operational logging.

While we implement appropriate safeguards, no system can be guaranteed to be completely secure.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, the affected users, in accordance with applicable law.

12. Your rights

Subject to applicable law, you may have the right to:

  • access the personal data we hold about you
  • request correction or deletion
  • object to or restrict certain processing
  • withdraw consent where processing is based on consent
  • object to processing based on legitimate interests
  • receive a portable copy of certain data
  • lodge a complaint with your supervisory authority

To exercise these rights, email info@animaldetect.com.

You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet).

We aim to respond to requests within one month, as required by applicable law.

13. Children

The service is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children.

14. Changes to this policy

We may update this policy when the service, billing model, or legal requirements change. Material updates will be reflected here and will be communicated where appropriate by email or within the product prior to taking effect.

Forgot password

Did we convince you?

Start now