Last updated: April 3, 2026
Buberry Worldwide ("we," "us," or "our") operates buberryworldwide.com and citizen.buberryworldwide.com. This Privacy Policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
Account Data
- Email address, display name, and password (bcrypt hashed).
- If you sign in with Google OAuth: name, email, and profile photo only. We do not request access to your contacts, calendar, Google Drive, or any other Google services.
Citizen Science Data
- Tree GPS coordinates, species observations, photos, and device location (only with your permission).
Learning Data
- Course enrollment, lesson progress, XP, levels, achievements, and streaks.
Blockchain Data (Optional)
- Your public Hedera wallet address only. We never store or have access to your private keys.
2. How We Use Your Data
- Operate and maintain the platform.
- Display your contributions (tree observations, citizen science data).
- Power gamification features (XP, levels, achievements, streaks).
- Verify species identifications via the PlantNet API (photos only are sent; no personal data is included).
- Prevent fraud and enforce our terms.
3. Third-Party Services
We share data with these services only as described:
- Google OAuth — Authentication only. We receive your name, email, and profile photo.
- PlantNet API — Photos are sent for automated species identification. No personal data is included.
- Vercel — Frontend hosting. No analytics or tracking is enabled.
- Cloudflare — API proxy and DDoS protection.
We do not sell your data. We do not serve ads. We do not use tracking pixels. We do not use third-party analytics.
4. Cookies & Local Storage
We use only essential cookies:
- Session cookie — Keeps you logged in.
- CSRF token — Protects against cross-site request forgery.
We also use localStorage for UI preferences such as theme and sidebar state. These are not cookies and are never sent to our servers.
We do not use tracking cookies of any kind. For full details, see our Cookie Policy.
5. Data Storage & Security
- Data is stored in self-hosted PostgreSQL and MinIO instances located in the United States.
- Passwords are hashed with bcrypt before storage.
- All connections use HTTPS.
- Authentication is handled via signed JWTs.
6. Your Rights
- Access — Request a copy of your personal data.
- Correction — Update inaccurate information.
- Deletion — Request deletion of your account and data by contacting us.
- Export — Export your tree observation data.
Citizen science data you contributed may be retained in anonymized form for ongoing research after your account is deleted.
7. Children
Buberry Worldwide is designed for users of all ages. We do not knowingly collect personal data from children under 13 without parental consent. If you believe a child under 13 has provided us personal data without consent, please contact us so we can remove it.
8. Data Retention
- Account data is retained until you request deletion.
- Anonymized citizen science data is kept indefinitely for research purposes.
- Blockchain transactions are immutable and cannot be deleted.
9. Jurisdiction
This Privacy Policy is governed by the laws of the United States.
10. Contact Us
For privacy questions or requests, contact us at privacy@buberryworldwide.com.