1. Summary
We've written the detail below in full, but here is the short version:
- An account is optional. Without one, your measurements, places and settings stay on your device and we have no copy of them. If you sign in with Apple or Google, we receive your email address, name and (from Google) profile photo from that provider.
- Signed in, your work syncs to your account. Measurements, places, categories and groups are stored on our cloud database so they are on every device you sign in on. You can turn cloud sync off for a device at any time.
- Teams share work by design. Everyone in a team can see the team's measurements, who made them, and the names, email addresses and profile photos of the other members.
- Share links are public. Anyone who has a share link can see what it contains — including coordinates, names and notes.
- Location is used to measure, not to track. GPS is used on your device to place points where you stand. We do not log a location history.
- We use a few trusted providers to host your account and synced data, render maps, power search, process subscriptions, measure aggregate app usage and crashes, and measure our ad campaigns. These are listed in Section 7.
- We measure our own ads. We share a limited advertising identifier with Meta to see which ads lead to installs and subscriptions — never your survey data. You can turn this off (see Section 10).
- You are in control. You can sign out, delete your account and its cloud data from inside the App, delete data on your device, and control location and ad tracking in your device settings.
2. Who we are
Acrea is operated by Acrea, the developer and operator of the Acrea mobile application (the "Operator", "we", "us" or "our"). For the purposes of the EU/UK General Data Protection Regulation (GDPR), where it applies, we act as the data controller for the processing described in this Policy. You can reach us at hello@dewmina.dev.
Teams are different. A team's owner decides who joins and what the team stores. When a business or other organisation uses a team, that owner — or the organisation they act for — is the controller of the team's work and of the members' details in it, and we process them on the owner's behalf to run the team. Team owners who need a data processing agreement can ask us for one at hello@dewmina.dev.
3. Data we process
What we process depends on which features you use. Without an account, most of it stays on your device (see Section 4).
a. Location data
With your permission, the App accesses your device's GPS location so it can place a survey point at your current position, show your position on the map, and report GPS accuracy. Location is processed on your device. Coordinates are sent to a map provider only when needed to render the map view, perform a search, fetch directions, or generate a map image in a PDF report (see Sections 7 and 9). We do not transmit a continuous location history to ourselves. The positions of points you save become part of your survey content (below), and are stored and shared the way that content is.
b. Survey content you create
Measurements (boundary vertices and the coordinates, area, distance and bearings derived from them), site names, notes, categories, groups and saved places (their coordinates, name, and any address or plus code). This content is always stored on your device. It also leaves your device when:
- you are signed in and cloud sync is on (Section 3(d));
- you save it in a team workspace (Section 3(e));
- you create a share link (Section 3(g)); or
- you export or share a file yourself (Section 8).
c. Account information
Creating an account is optional. If you sign in with Apple or Google, our authentication provider (Supabase — see Section 7) receives from that provider your email address, your name if the provider supplies it, a profile photo link (Google only), and an account identifier issued by the provider. If you use Apple's "Hide My Email", we receive a relay address rather than your real one. We also store when your account was created and when you last signed in. We never receive your Apple or Google password.
To keep accounts secure, our authentication provider also records the IP address and device type of each signed-in session, and the IP address of sign-ins and other account events in a security log (see Section 11 for how long).
d. Cloud sync
When you are signed in and cloud sync is on, the App uploads your survey content (Section 3(b)) to our cloud database and keeps it in step across your devices. With each item we store the workspace it belongs to, the account that created it, and when it was created, changed or deleted. When you delete something, we keep a deletion marker so the deletion reaches your other devices (see Section 11).
- Uploading changes to your Personal workspace requires an Acrea Pro subscription. Without one, anything already in your account still downloads to your devices; new changes stay on the device.
- You can turn cloud sync off for a device in Settings → Data → Cloud sync. While it is off, that device uploads and downloads nothing.
- Work you made on a device before signing in is added to your account only if you agree when the App asks.
e. Teams
If you create or join a team, we store the team's name and any logo, its members and their roles, and the survey content saved in the team's workspace. To invite someone, a team owner or admin creates an invite link, which may be addressed to a specific email address; we store that address, the role offered, who sent the invite, and when it expires and is accepted. A team's access depends on whether one of its owners holds Acrea Pro (see Section 3(i)). See Section 8 for who can see team data.
f. Profile name and photo
You can choose the name and photo that are shown on your account and beside work you add to a team. If you add a photo, it is uploaded to our storage and served from a public web address (see Section 8). If you don't set one, we use the name and photo your sign-in provider supplied.
g. Public share links
When you create a share link for a measurement, place or group, the App sends a copy of it — its geometry and coordinates, name, area or length, notes, category, and any address — to our servers, which store it as a snapshot and return a link. Later edits to the original do not change the link. You can create a link without an account; if you are signed in, the link is associated with your account, and you can see and delete it in Settings → Data → Shared links. To limit abuse, we store a one-way, salted hash of the IP address that created the link, and we count how many times a link has been viewed.
With Acrea Pro, a link's page can also show your branding: the company name and logo you set for PDF reports, or — for a link shared from a team with an active subscription — the team's name and logo. A report logo used this way is uploaded to our servers, and like the rest of the page it can be seen by anyone who has the link.
h. Search queries
When you search for a place or enter coordinates, the query text (and, for nearby results, an approximate location) is sent to our map/search providers to return results.
i. Purchase and subscription data
If you buy an Acrea Pro subscription, the purchase is handled by the Apple App Store or Google Play and our subscription provider (RevenueCat). We never receive your payment-card details. If you are signed out, RevenueCat identifies you by an anonymous subscriber identifier. If you are signed in, your subscription is linked to your Acrea account, so it is recognised on your other devices, and our servers store your subscription status — whether it is active, until when, the product, whether it will renew, and whether the store reported a billing problem.
We use that status to decide whether teams you own are active. If you own a team and your subscription ends, the team becomes read-only for its members. Members are told the team is paused and who can renew it, but not details of your subscription.
j. Usage and diagnostic data
To understand how the App is used and to fix crashes, we collect event-level analytics (for example: that an onboarding slide was viewed, a measurement was saved, or an export was triggered) and crash diagnostics (stack traces, device model, OS version, and app version). These events record that an action happened and non-identifying parameters such as counts, the measurement type, the area value, or the chosen export format. They do not include your coordinates, the names you give your sites, your notes, your email address or your account identifier. This data is keyed to a randomly generated installation identifier, not to your account.
We also collect performance and reliability data via Firebase Performance Monitoring to find slow or failing operations. This measures things like app start-up time, screen rendering, and the response time, size, and success of network requests the App makes to the providers listed in Section 7. Network requests are recorded by their endpoint only, with query parameters stripped — so this never includes your search terms, coordinates, or access keys. To produce these measurements the tool also processes technical data such as your device model and OS, network connection and carrier type, and your IP address, which is used only to derive an approximate country and is not retained long-term (see Section 11). As with the analytics above, this data is keyed to a randomly generated installation identifier, not to your account.
k. Device and technical data
Standard technical information such as device type, operating system version, language/region, and a non-persistent app-instance identifier, used by the diagnostic, analytics, and advertising tools above and by the app stores. When the App or a browser connects to our servers, those servers and our hosting providers process your IP address and similar connection data to deliver the service and keep it secure. These service logs are short-lived (see Section 11).
l. Photos and camera
With your permission, the App opens your photo library or camera only when you choose a profile photo, a team logo, or a logo for a PDF report. Only the image you pick is used; a profile photo or team logo is uploaded as described above, and a report logo stays on your device unless you share a branded link (Section 3(g)).
m. Advertising and attribution data
Because we run Facebook and Instagram ad campaigns to promote Acrea, the App includes Meta's Facebook SDK to measure whether those ads work — for example, whether an install or a subscription came from an ad you saw. For this, a limited set of advertising and device identifiers and events is processed: a Facebook-generated anonymous identifier, your device's advertising identifier where available (Apple's IDFA on iOS, collected only if you allow tracking — see Section 10; the equivalent Advertising ID on Android), the device vendor identifier, and standard technical data. The SDK automatically logs app installs and app sessions, and we log a small number of non-identifying conversion events, such as completing onboarding. These events do not include your coordinates, site names, notes, email address, account identifier, or any survey content. In addition, our subscription provider (RevenueCat) forwards purchase and subscription events to Meta on our behalf, server-side, matched to the same advertising identifiers, so that a subscription can be attributed to a campaign. This data is shared with Meta, which processes it as an independent controller under its own policies. RevenueCat forwards the device and advertising identifiers above and the device's IP address; it does not send Meta your Acrea account identifier, and we don't give RevenueCat your email address. You can limit or switch off this tracking — see Section 10.
4. Where your data is stored
On your device
Always stored locally, in the App's private storage: your measurements, saved places, categories, groups and notes; your preferences and settings (units, coordinate format, theme, map style, onboarding state, cloud sync on or off); and any offline map areas you download. Deleting the App removes this copy.
In your Acrea account
Only if you sign in: your account information, profile name and photo, synced survey content, team memberships and team content, invites, and subscription status. This is stored with our cloud database and storage provider, Supabase, in Frankfurt, Germany, in the European Union. The server functions that create share links, check subscriptions and delete accounts run there too.
Share links
Share link snapshots are stored in the same database, and the logos shown on branded share pages in the same storage, and are shown to anyone who opens the link on our website.
5. How we use data
- To provide the App's core functions — measuring, mapping, saving, searching, and exporting.
- To create and secure your account, sync your work across your devices, and run the teams you belong to.
- To show your name and photo to your team members and on invites you send, and to create and display the share links you ask for.
- To display maps and satellite imagery, and to return search and directions results.
- To unlock and restore Acrea Pro features for subscribers, and to decide whether a team is active.
- To send local reminders you opt into (for example, a notice before a free trial converts) — these are scheduled on your device and are not sent from our servers.
- To diagnose crashes, monitor performance and reliability, and understand aggregate usage so we can improve the App.
- To prevent abuse — for example, rate-limiting the creation of share links.
- To measure and optimise our Facebook and Instagram ad campaigns — that is, to attribute installs and subscriptions to the ads that drove them (see Sections 3(m) and 10).
- To comply with law, and to protect our rights and users.
We do not sell your personal information for money, we do not look through your synced survey content except where needed to run or support the service or where required by law, and we never use your survey content — your measurements, coordinates, site names, or notes — for advertising. We do share a limited advertising identifier with Meta to measure our own ad campaigns, as described in Sections 3(m) and 10; under some US state laws this counts as "sharing" for cross-context behavioral advertising, and you can opt out (see Sections 10 and 14).
6. Legal bases (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to deliver the App, your account, cloud sync, teams, share links you create, and the Pro features you purchase.
- Consent — for access to your device location, photos and camera, for optional notifications, for adding work made before sign-in to your account, and (on iOS) for app-level tracking that uses your device advertising identifier, collected only if you allow it via the App Tracking Transparency prompt. You can withdraw consent at any time.
- Legitimate interests — to keep the App and our servers secure and free of abuse, fix crashes, understand aggregate usage, show team members whether their team is active, and measure the effectiveness of our own advertising, balanced against your privacy.
- Legal obligation — where we must process data to comply with applicable law.
7. Service providers
We use the following service providers (sub-processors). Each processes only the data needed for its function and under its own privacy policy:
- Supabase — authentication (Sign in with Apple and Google), the cloud database for accounts, synced content, teams, invites, subscription status and share links, file storage for profile photos, team logos and share-page logos, and the server functions that create share links, check subscriptions and delete accounts. Privacy policy.
- Apple (Sign in with Apple) & Google (Sign in with Google) — account sign-in, if you choose it. They share with us the account information described in Section 3(c). Apple · Google.
- Vercel — hosts our website, including the pages that show share links and team invites. Privacy policy.
- Mapbox — map rendering, satellite imagery, geocoding/ search, directions, offline tiles, and static map images used in PDF reports. Receives map requests and the coordinates/queries involved. Privacy policy.
- Google Maps Platform & Google Places — map rendering in the App and on share-link pages, the preview image shown when a share link is posted in a chat, and place search/autocomplete. Receives map requests and search queries; a share-link page loads Google's map in the viewer's browser, so Google receives that viewer's connection data. Privacy policy.
- Google Firebase (Analytics, Crashlytics & Performance Monitoring) — usage analytics, crash diagnostics, and app performance/network timing, as described in Section 3(j). Privacy & security.
- RevenueCat — subscription management. Receives an anonymous subscriber identifier, or your Acrea account identifier if you are signed in, and purchase/entitlement status. Where you subscribe, RevenueCat also forwards purchase events to Meta on our behalf, server-side, matched to your advertising identifiers, for ad attribution (see Section 3(m)). Privacy policy.
- Meta Platforms (Facebook SDK / Facebook App Events) — advertising attribution and measurement for our Facebook and Instagram campaigns. Receives a Facebook anonymous identifier, device and advertising identifiers (subject to your tracking choice), app install/session and conversion events, and standard technical data, as described in Section 3(m). Meta acts as an independent controller for this data. Privacy policy.
- Apple App Store / Google Play — app distribution and payment processing for subscriptions. Apple · Google.
Map and search providers may use the requests they receive in accordance with their own terms. We send them the minimum needed to render maps and return results.
8. Who can see your data
Your Personal workspace
Only you, on the devices where you sign in. Teammates cannot see your Personal workspace unless you copy or move something into a team.
Teams
Everything saved in a team's workspace is visible to every member of that team, including view-only members, along with the name of the person who added each item. Members of a team can see each other's names, email addresses, profile photos and roles, and the team's invites, including any email address an invite was sent to. The invite screen says this before you join. When a member leaves, is removed or deletes their account, the work they added stays with the team — without their name, if they deleted their account.
Invite links
Anyone who opens an invite link — before signing in — can see the team's name and logo, how many members it has, the role offered, and the name and profile photo of the person who sent the invite. An invite never shows anyone's email address.
Profile photos and team logos
Profile photos and team logos are stored at public web addresses so they can appear on invite pages to people who are not signed in. Anyone who has the address can view the image.
Share links
A share link is public: anyone who has the link can view everything it contains, without an account, and can pass it on. Share-link pages ask search engines not to index them, but we cannot control where a link is forwarded. Please don't share a boundary, location or note you need kept confidential.
Files you export or share
Acrea lets you export and share your measurements — as a PDF report, a backup file, or in formats such as KML, GeoJSON, CSV, DXF, or Shapefile, and as a metes-and-bounds legal description. When you do this, you are in control of the resulting file and where it goes (email, messaging, cloud storage, another app, etc.). Once you share a file, its handling is governed by the service or recipient you send it to, not by this Policy.
Share links, exported files and PDF reports may contain precise coordinates and any names or notes you added. Please review what they contain, and ensure you have the right to capture and share information about the land in question, before distributing them. See the Terms of Use for your responsibilities regarding consent and third-party land.
Us and our providers
Our service providers process data on our behalf as described in Section 7. We may disclose information where required by law, to enforce our Terms, or to protect the rights and safety of users or others.
9. Location data
The App requests "while in use" location access. You can decline, and you can revoke access at any time in your device settings — the App remains usable for tap-defined and coordinate-defined measurements without it, though GPS-based features will be unavailable. We do not run a background location service and do not build a profile of your movements.
10. Advertising, attribution & your tracking choices
We advertise Acrea on Facebook and Instagram. To understand which ads lead to installs and subscriptions — and to avoid spending on ads that don't work — we use Meta's Facebook SDK and share the limited advertising and attribution data described in Section 3(m) with Meta. We do not use your survey content or account information for this, and we do not show ads inside the App.
You control tracking:
- On iOS, the App shows Apple's App Tracking Transparency prompt (after you finish onboarding). If you choose "Ask App Not to Track", we do not collect your IDFA and no cross-app advertising identifier is used; the SDK still counts anonymous, aggregate installs and events. You can change your choice any time in Settings → Privacy & Security → Tracking.
- On Android, you can reset or delete your Advertising ID, or opt out of ad personalisation, in Settings → Privacy → Ads.
- You can also manage how Meta uses data about you — including off-platform activity — in your Facebook and Instagram account settings.
11. Data retention
- On-device data is retained until you delete it — item by item, with Delete all data, when you sign out or delete your account and choose to remove it, or by uninstalling the App. Deleted measurements stay in Recently deleted on the device for 90 days so you can restore them.
- Account information, synced content, team data and subscription status are retained for as long as your account exists, and deleted when you delete your account (see Section 12). Deleted data leaves our database straight away and any backups within 7 days.
- Items you delete while signed in can be restored for 90 days. After that, their contents — geometry, coordinates, name, notes and address — are erased from our database. An empty marker remains so the deletion still reaches devices that were offline, and is removed when your account is deleted.
- Team data is retained while the team exists. It is deleted when an owner deletes the team, or when its only owner deletes their account. Invites expire 14 days after they are created, and are deleted — with any email address they were sent to — 30 days after they are used or expire.
- Share links created without an account expire after one year and are then deleted. Links created while signed in last until you delete them in Settings → Data → Shared links, and are deleted with your account.
- Profile photos are deleted when you replace or remove them, and when you delete your account.
- Logos on branded share pages are kept while your links may show them, and deleted when you delete your account.
- Security logs of sign-ins and other account events, including IP addresses, are kept for 30 days. A session's IP address and device type are kept until you sign out or the session expires.
- Service logs kept by Supabase and Vercel, which include IP addresses, are kept for no more than 7 days.
- Analytics and crash data are retained by Firebase for the period set in our project configuration (by default, event data is retained for a limited window and then aggregated/deleted per Google's policies).
- Performance data is retained by Firebase Performance Monitoring on a rolling basis — IP-associated records for about 30 days, and de-identified performance data for about 60 days — before deletion, per Google's policies.
- Subscription records are retained by RevenueCat and the app stores for as long as needed to manage your entitlement and meet legal/financial obligations.
- Advertising and attribution data is retained by Meta under its own data policy, for the periods Meta specifies.
12. Signing out & deleting your data
- Turn off cloud sync for a device in Settings → Data → Cloud sync. Nothing is uploaded or downloaded on that device while it is off; data already in your account stays there.
- Sign out from the account screen. You choose whether to remove your data from the device or keep it there; team data is always removed from the device. Signing out does not delete anything from your account.
- Stop sharing a link in Settings → Data → Shared links. The link stops working and its copy is deleted; a page someone opened recently may stay cached for up to an hour.
- Delete all Personal data. While signed in, Settings → Data → Delete all Personal data deletes everything in your Personal workspace, on the device and in your account (subject to the deletion markers described in Section 11). Signed out, Delete all data erases the App's data on the device.
- Delete your account from the account screen. This permanently deletes your account, your Personal workspace and its synced data, your profile photos and share-page logos, your team memberships, and any team where you are the only owner — including that team's data, for all of its members, and the share links you created while signed in. Teams with another owner continue without you, and the work you added to them stays with the team without your name. You choose whether to also erase your data from the device (the default) or keep it there, unlinked from any account. Deleting your account does not cancel an Acrea Pro subscription — cancel it in the App Store or Google Play first.
If you can't use the App, you can ask us to delete your account — see Delete your account.
13. Your rights
Depending on where you live (including under the GDPR/UK GDPR), you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. You can exercise many of these directly in the App: view and edit your content and profile, export your measurements or save a backup file, and delete your data or your account (Section 12). For anything else — for example a copy of the account data we hold, or data held by our providers (analytics, crash, subscription) — contact us at hello@dewmina.dev and we will help action your request, including relaying it to the relevant provider. If a request concerns a team's data, we may need to involve the team's owner. You also have the right to lodge a complaint with your local data protection authority.
14. US state privacy rights
If you are a resident of California or another US state with a comprehensive privacy law, you may have rights to know, access, delete, and correct personal information, and to opt out of its "sale" or "sharing". We do not sell your personal information for money. However, our use of Meta's advertising tools (see Section 10) involves sharing a limited advertising identifier with Meta to measure and optimise our ad campaigns, which may be considered "sharing" for "cross-context behavioral advertising" under the California Consumer Privacy Act (CCPA/CPRA) and similar laws. You can opt out of this at any time: on iOS choose "Ask App Not to Track", and on Android opt out of ad personalisation or reset your Advertising ID (see Section 10). To exercise any right, contact us at hello@dewmina.dev. We will not discriminate against you for exercising your rights.
15. Children
Acrea is intended for professional and general audiences and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.
16. Security
Acrea keeps your data on your device unless you sign in or share it. Data sent to our servers is encrypted in transit (TLS), stored with a provider that encrypts it at rest (AES-256), and protected by access rules that let an account read only its own data and the data of teams it belongs to. For the data handled by our other providers, we rely on their industry-standard security measures. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Share links and invite links work like keys: anyone holding one can use it, so treat them accordingly.
17. International transfers
Your account and synced data are stored in Frankfurt, Germany, in the European Union. Some of our service providers — including Google, Meta, RevenueCat, Mapbox and Vercel — may process data on servers located outside your country, including in the United States. Where required, these transfers are covered by appropriate safeguards (such as the European Commission's Standard Contractual Clauses) implemented by those providers.
18. Changes to this Policy
We may update this Policy as the App evolves or as the law requires. We will revise the "Last updated" date above, and for material changes we will provide a more prominent notice in the App or on this site. Your continued use of the App after an update means you accept the revised Policy.
19. Contact us
For any privacy question or request, contact us at hello@dewmina.dev. We will respond within a reasonable timeframe and in any case as required by applicable law.