Welcome to Zetta, the insect growth documentation app for naturalists and enthusiasts who track insect lifecycles through photo journals and handwritten field notes. This Privacy Policy ("Policy") describes how Zetta ("we," "our," or "us") collects, uses, stores, shares, and protects your personal information when you use our mobile application and all related services (the "Service"). By using Zetta, you agree to this Policy. If you do not agree, please discontinue use of the Service.
I
Information We Collect
1.1 — Account & Profile Information

When you create a Zetta account, we collect information you provide: your display name, email address, date of birth (to verify you are 18 years of age or older), profile photo, country of residence, and any bio you choose to add. If you register via Apple Sign-In or Google, we receive a limited profile dataset authorized by you and that provider.

1.2 — Insect Observation Records

The core function of Zetta is building a personal insect growth journal. When you create an observation record, we collect the information you manually enter: species name or description, developmental stage (egg, larva, pupa, adult, etc.), observation notes and behavior descriptions, date and time of observation, and any custom tags or categories you assign. See Section 3 for full details on how observation data is handled.

1.3 — Photos & Media

You may upload one or multiple photos per observation to document insect growth stages. These photos are stored on our secure cloud servers and associated with your observation records. EXIF metadata embedded in uploaded photos (including location data) is handled as described in Sections 3 and 4.

1.4 — Location Data

You may optionally attach a location to each observation to document where a sighting occurred. Location data is collected only with your permission and only when you choose to add it to a specific observation. See Section 4 for full details.

1.5 — Device & Technical Information

We automatically collect device model, operating system version, unique device identifiers, IP address, mobile carrier, app version, crash logs, and performance diagnostics to maintain service quality and diagnose technical issues.

1.6 — Usage & Behavioral Data

We record how you use the Service: features accessed, observation frequency and patterns, content you interact with, and session duration. This data informs product improvements and optional personalization.

1.7 — Communications & Support Data

If you contact our support team, submit a content report, or complete a survey, we retain the content and metadata of those communications for the purpose of resolving your inquiry and improving the Service.

1.8 — Payment & Transaction Data

All payments are processed exclusively by Apple App Store or Google Play. We do not store your payment card details. We receive only anonymized transaction confirmation tokens and purchase entitlement data to activate in-app features such as expanded storage or premium journal tools.

II
How We Use Your Data
2.1 — Operating the Service

We use your information to authenticate your account, store and display your observation records, manage your photo journals, sync data across devices, enforce content policies, process purchases, and deliver all core Service functions.

2.2 — Observation Journal Functionality

Your observation records, photos, notes, and location tags are used to build and display your personal insect field journal, generate growth timelines across linked observations, and enable search and filtering within your journal. This data is yours and is not shared with third parties for commercial purposes without your explicit consent.

2.3 — Community & Discovery

Where you choose to share observations publicly, your submitted content populates community feeds, enables discovery by other users, and fosters connection between naturalist enthusiasts. Public observation data may be aggregated to display species distribution trends within the community.

2.4 — Product Improvement

Aggregated and de-identified usage data and observation patterns are analyzed to improve journal features, community tools, and overall platform performance. Individual personal data is not shared externally for research without your consent.

2.5 — Safety & Content Integrity

We process behavioral signals and user reports to detect and prevent prohibited content, harassment, and policy violations within community features.

2.6 — Marketing & Communications

With your consent where required by applicable law, we may send promotional communications about new features, seasonal observation challenges, and platform updates. You may withdraw consent at any time via in-app settings or the unsubscribe link in any email.

2.7 — Legal Compliance

We process personal data as necessary to comply with applicable laws, respond to valid legal process, enforce our Terms of Service, and protect the safety of our users and the public.

III
Observation & Photo Data
3.1 — Your Field Journal Belongs to You

Your insect observation records — including written notes, developmental stage logs, growth timelines, and all uploaded photos — constitute your personal field journal on Zetta. This data is yours. We store it on your behalf to deliver the journaling experience, and we do not sell, license, or otherwise transfer your personal observation data to third parties for their independent commercial use.

3.2 — Photo Storage & EXIF Handling

Photos you upload are stored on our secure cloud infrastructure. They may contain embedded EXIF metadata including GPS coordinates, device model, and capture timestamp. Zetta handles EXIF data as follows:

  • Private observations: EXIF data is preserved as uploaded and accessible only to you.
  • Public observations: GPS/geolocation EXIF data is automatically stripped before your photo is made visible to other users, protecting your observation location from unintended disclosure.
3.3 — Growth Timeline Linking

Zetta allows you to link multiple observation records of the same specimen across time to build a visual growth timeline. This linking is performed manually by you and linked observation data remains within your private journal unless you explicitly choose to share it publicly.

3.4 — Observation Visibility Controls

Each observation record can be set to Private (visible only to you) or Public (visible in the community feed). You may change the visibility of any observation at any time from record settings. The default visibility for new observations is configurable in your account preferences.

3.5 — Data Export

You may request an export of all your observation records in a structured, portable format from your account settings or by contacting us at service@zettas.net. We strongly encourage regular exports as a backup practice.

IV
Location Data
4.1 — Location Is Optional

Attaching a location to an observation is entirely optional. Zetta does not require location access to function. You may log observations with no location information, or with a manually typed label (e.g., "Back garden") rather than GPS coordinates.

4.2 — GPS Permission

If you use the GPS feature to auto-tag an observation, Zetta requests "While Using the App" access only — never background location access. You may revoke location permission at any time via device settings without affecting your ability to log observations.

4.3 — Location in Shared Observations

When sharing publicly, you control location display: exact coordinates, approximate area (district or city level), or hidden. GPS EXIF data is always stripped from publicly shared photos regardless of your location display setting.

4.4 — Community Species Maps

Where users choose to share location data publicly, Zetta may aggregate this to display community species distribution maps. These maps display aggregated, anonymized data and do not identify individual users or precise observation locations unless you explicitly set location visibility to "exact."

4.5 — Sensitive Location Considerations
We encourage users to use approximate or hidden location settings when documenting observations at ecologically sensitive or protected sites, where precise location disclosure could have negative conservation consequences.
V
User-Generated Content
5.1 — Collection & Storage

Observation notes, photos, species descriptions, and growth logs you create constitute User-Generated Content (UGC). UGC is stored on our secure cloud servers associated with your account. You retain full ownership of all original content you create and submit to Zetta.

5.2 — License Grant

By publishing UGC publicly, you grant us a non-exclusive, worldwide, royalty-free, sublicensable license to host, store, reproduce, display, and distribute your content within the Service and in connection with promoting Zetta, subject to your visibility settings. This license does not grant Zetta any right to sell your observations or photos to third parties for their independent commercial use.

5.3 — Content Moderation

Community-shared UGC is subject to automated screening and human review for compliance with our Community Guidelines. Violations will result in content removal and may lead to account suspension or termination.

5.4 — Content Deletion

You may delete any observation record or photo at any time. Deleted content is removed from public view within 48 hours, from production servers within 30 days, and from backup archives within 90 days.

VI
Community Features
6.1 — Community Feed

Public observations appear in Zetta's community feed for other users to discover and engage with. Public observations include your display name, photos (EXIF location stripped), species information, developmental stage, and observation notes you have not marked as private.

6.2 — Comments & Reactions

Other users may comment on or react to your public observations. Comments are associated with the commenter's display name. You may moderate comments on your own observations and delete them at any time.

6.3 — Species Discussions & Forums

Where Zetta offers species-specific discussion spaces or community forums, your display name and post content are visible to all participants. Forum posts are subject to our Community Guidelines.

VII
Personalization
7.1 — How It Works

Zetta may use your observation history, species interests, and engagement patterns to surface relevant content in the community feed, suggest related species, and highlight seasonal observation opportunities relevant to your documented interests.

7.2 — No Advertising Profiling

Your observation data, species interests, and location history are not used to build an advertising profile or shared with advertising networks. Personalization on Zetta is used solely to improve your in-app journaling and discovery experience.

7.3 — Opting Out

You may disable personalized content suggestions at any time in Settings > Privacy > Personalization. Core journaling features are unaffected.

VIII
Information Sharing & Disclosure
8.1 — Service Providers

We share personal information with trusted third-party service providers: cloud infrastructure, CDN services for photo delivery, payment processors, analytics platforms, customer support tools, and content moderation systems. All are contractually bound to process your data only on our instructions and in compliance with applicable data protection law.

8.2 — No Sale of Personal Data

We do not sell your personal information, observation records, photos, or location data to any third party, including research institutions, entomology databases, ecological data brokers, or advertising networks.

8.3 — Citizen Science & Research Partnerships
If Zetta enters partnerships with scientific research institutions, your individual personal data and identified observation records will not be shared without your explicit, separate, informed consent. Only aggregated, anonymized species occurrence data (with no personal identifiers) may be shared with research partners for ecological and entomological research purposes.
8.4 — Business Transfers

In the event of a merger, acquisition, or asset sale, your data may transfer to the acquiring entity. We will notify you in advance before your data becomes subject to a materially different privacy policy, giving you the opportunity to request account deletion.

8.5 — Legal Disclosure

We may disclose your information to law enforcement or government authorities when required by applicable law, valid legal process, or where necessary to protect the safety of any person. Where legally permitted, we will notify affected users prior to such disclosure.

IX
Third-Party Services
9.1 — Mapping Services

Where Zetta displays observation locations on maps, third-party mapping services process location data to render map tiles. These providers are governed by their own privacy policies and process only the data necessary for mapping functionality.

9.2 — Analytics SDKs

Mobile analytics SDKs measure app performance and feature engagement, configured with privacy-preserving settings including anonymized event collection and suppression of advertising identifiers absent your consent.

9.3 — Photo Storage & CDN

Observation photos are stored on cloud infrastructure and delivered via CDN providers to ensure fast, reliable loading. These providers process delivery metadata as technical intermediaries under data processing agreements.

9.4 — Authentication Providers

Apple Sign-In and Google authentication are governed by their own terms and privacy policies. Our use of data from these services is limited to account creation and basic profile population.

X
Data Retention
10.1 — Active Account Data

We retain your personal information and observation journal for as long as your account is active. Accounts with no login activity for 24 consecutive months will receive a dormancy notice; following the notice period, inactive data may be anonymized or deleted.

10.2 — Observation Records & Photos

Your observation records and photos are retained for the life of your account to preserve your field journal. You may delete individual observations or your entire journal at any time. Deleted observation data is removed from production servers within 30 days and from backup archives within 90 days.

10.3 — Transaction Records

Financial transaction records are retained for a minimum of seven years to comply with applicable accounting, tax, and consumer protection obligations.

10.4 — Safety & Moderation Records

Records of content moderation actions, user reports, and enforcement decisions are retained for up to 36 months after account closure.

10.5 — Anonymized Analytics

Aggregate, irreversibly anonymized usage data may be retained indefinitely for product research and development.

XI
Data Security
11.1 — Technical Safeguards

We implement TLS 1.2+ encryption for all data in transit, AES-256 encryption for stored data at rest, strict role-based access controls, and automated anomaly detection. Photo uploads and observation data are transmitted and stored over encrypted channels.

11.2 — Organizational Safeguards

Data access is restricted on a need-to-know basis, requires multi-factor authentication, and is comprehensively audit-logged. All personnel with data access receive data protection training and sign confidentiality agreements.

11.3 — Vulnerability Management

We conduct regular security assessments and third-party penetration testing. Report security vulnerabilities responsibly to service@zettas.net.

11.4 — Breach Notification

In the event of a personal data breach posing risk to your rights and freedoms, we will notify relevant supervisory authorities within 72 hours where required by law and inform affected users without undue delay.

XII
Tracking Technologies
12.1 — In-App Technologies

Zetta uses session tokens, local storage, and analytics SDKs (not traditional browser cookies) to maintain your authenticated session, remember preferences, and sync observation data across devices.

12.2 — Advertising Identifiers

On iOS, we request ATT consent before accessing your IDFA. On Android, we respect your opt-out via device advertising settings. Advertising identifiers are used only to measure our own user acquisition campaigns and are not shared for third-party behavioral advertising.

12.3 — Web Properties

Our website may use standard browser cookies for session management and analytics, manageable via your browser settings.

XIII
Cross-Border Data Transfers
13.1 — Global Infrastructure

Zetta operates cloud infrastructure across multiple regions. Your personal data and observation records may be stored and processed in countries other than your country of residence, which may have different data protection standards.

13.2 — Transfer Safeguards

For transfers from the EEA, UK, or Switzerland to countries lacking an adequacy decision, we rely on EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum (IDTA). Equivalent safeguards apply to other cross-border transfers.

13.3 — Data Localization

Where applicable national laws impose mandatory data localization requirements, we take reasonable steps to store and process the required data categories within the mandated territory.

XIV
Your Privacy Rights
14.1 — Access

Request a copy of personal data we hold, including your full observation journal metadata, via in-app settings or by emailing service@zettas.net with subject "Data Access Request."

14.2 — Rectification

Correct inaccurate personal information directly in account settings. For data that cannot be self-corrected, contact us and we will action the correction within 30 days.

14.3 — Erasure

Request deletion via Settings > Account > Delete Account or by emailing us. See Section 20 for full account deletion details.

14.4 — Portability

Request your complete observation journal — including all records, notes, and photo metadata — in a structured, machine-readable format (JSON or CSV) suitable for archiving or transfer to another platform.

14.5 — Objection & Restriction

Object to or request restriction of processing in certain circumstances. We pause relevant processing while assessing your objection.

14.6 — Consent Withdrawal

Withdraw consent for marketing, personalization, or citizen science data sharing at any time via in-app settings or by contacting us, without affecting prior lawful processing.

14.7 — How to Submit

Email service@zettas.net with "Privacy Rights Request" in the subject, your registered email, and a description of your request. We verify your identity and respond within applicable legal timeframes.

XV
GDPR — EEA & UK Users
15.1 — Data Controller

For EEA and UK users, Zetta acts as the data controller of your personal information under the GDPR and UK GDPR respectively.

15.2 — Legal Bases

We process your data under: (a) contractual necessity (to provide the Service); (b) legal obligation (regulatory compliance); (c) legitimate interests (safety, service improvement, fraud prevention), where not overridden by your rights; and (d) consent (for marketing, personalization, and citizen science data sharing).

15.3 — Supervisory Authority

You may lodge a complaint with your national data protection supervisory authority if you believe your data has not been handled lawfully. We encourage you to contact us first to attempt direct resolution.

XVI
CCPA / CPRA — California
16.1 — California Rights

California residents have rights under the CCPA as amended by the CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. Zetta does not sell personal information and does not share it for cross-context behavioral advertising.

16.2 — Non-Discrimination

Exercising your California privacy rights will not result in denial of services, different pricing, or reduced quality of experience.

16.3 — Authorized Agents

California residents may designate an authorized agent by providing written proof of authorization. We verify both agent and resident identity before processing any request.

XVII
Brazil — LGPD
17.1 — Rights Under LGPD

Brazilian users have rights under the Lei Geral de Protecao de Dados (LGPD) including confirmation, access, correction, anonymization, deletion, portability, and withdrawal of consent.

17.2 — Legal Bases

We process Brazilian users' data based on contract performance, legal obligation, and consent where applicable.

17.3 — ANPD Complaints

Brazilian users may lodge complaints with the Autoridade Nacional de Protecao de Dados (ANPD) where they believe data processing violates the LGPD.

XVIII
Children's Privacy & CSAE Policy
18.1 — Age Restriction

Zetta is designed for users who are 18 years of age or older. We implement date-of-birth verification at registration and apply additional detection measures to accounts suspected of being operated by minors. Confirmed underage accounts are immediately and permanently terminated with all associated data deleted.

18.2 — Parental Notification

If you are a parent or guardian and believe a minor has created a Zetta account, contact us immediately at service@zettas.net. We will investigate and, where confirmed, permanently delete the account and all associated data without delay.

18.3 — Child Sexual Abuse and Exploitation (CSAE)
Zero tolerance — absolute and without exception. Zetta enforces an unconditional zero-tolerance policy toward any content, conduct, or activity that constitutes, facilitates, promotes, or glorifies Child Sexual Abuse and Exploitation (CSAE) in any form. Prohibited conduct includes without limitation: child sexual abuse material (CSAM); grooming, solicitation, or exploitation of individuals under 18; and any content depicting, targeting, or endangering persons under 18.

We deploy automated CSAM hash-matching on all uploaded media, AI-assisted content analysis on community posts, and dedicated human safety reviewers. Upon confirmed detection or credible report: all associated content is immediately and permanently removed; the responsible account is permanently terminated and all associated identifiers are blocked; a mandatory report is filed with the NCMEC CyberTipline or the legally required equivalent national authority; and we cooperate fully with all resulting law enforcement investigations. CSAE-related terminations carry no right of appeal.

To report: use the in-app Report function on any content or user profile, or email service@zettas.net immediately with subject "CSAE Report."
XIX
In-App Purchases
19.1 — Payment Processing

All in-app purchases are processed exclusively through Apple App Store or Google Play. Zetta does not store your payment card details. We receive only anonymized transaction confirmation tokens and entitlement data.

19.2 — Premium Features

If Zetta offers premium features (such as expanded photo storage, unlimited observation records, or advanced journal tools): access is non-transferable between accounts; non-refundable except as required by applicable law or app store policy; and may be forfeited upon account termination for cause.

19.3 — Transaction Records

Transaction records are retained for a minimum of seven years to satisfy applicable accounting, tax, and consumer protection requirements.

XX
Account Deletion & Data Erasure
20.1 — How to Delete

Delete your account at any time via Settings > Account > Delete Account, or by emailing service@zettas.net with subject "Account Deletion Request."

20.2 — What Is Deleted

Upon confirmed account deletion, your profile, all observation records, uploaded photos, growth timelines, community posts, and comments are removed from public view within 48 hours and from production servers within 30 days. Backup archives are purged within 90 days.

20.3 — Export Before Deletion
We strongly encourage you to export your observation journal before deleting your account, as deletion is permanent and field records cannot be recovered after the deletion period has elapsed. Export your data at any time from Settings > Data > Export Journal.
20.4 — Retained Data

Certain data is retained where required by law: transaction records (up to 7 years); safety and moderation records (up to 3 years); data subject to a legal hold. All retained data is isolated and processed only for the specific legal purpose requiring its retention.

XXI
Governing Law & Disputes
21.1 — Applicable Law

This Policy is governed by applicable international data protection law and the laws of the jurisdiction in which Zetta is incorporated, except where mandatory local law in your country of residence imposes higher standards that cannot be contractually excluded.

21.2 — Regulatory Recourse

If our response to a direct complaint has not resolved your concern, you retain the right to escalate to the relevant data protection supervisory authority in your country of residence.

XXII
Policy Updates
22.1 — Notification

Material changes are communicated at least 14 days before taking effect via in-app notice, push notification, and/or email to your registered address. Non-material corrections may be made without advance notice.

22.2 — Continued Use

Continued use of Zetta after any revised Policy's effective date constitutes acceptance. If you do not agree, delete your account before the changes take effect.

22.3 — Version Archive

Prior versions are available upon request at service@zettas.net.

XXIII
Contact Us
23.1 — Privacy Inquiries

For questions, data rights requests, or privacy concerns:

We acknowledge inquiries within 5 business days and respond within 30 days.

23.2 — CSAE & Child Safety Reports

Use the in-app Report function on any content or user profile, or email service@zettas.net immediately with subject "CSAE Report." These are our highest-priority safety matter, actioned without delay.

© 2025 Zetta. All rights reserved. Home · Privacy Policy · v1.0 · June 4, 2025