houby AI

Privacy policy

How Houby AI stores information on your phone and what its online services process.

Effective from 5 October 2026

Service provider: Daniel Hanuš
Business ID: 04148193
Hliník 240/30, 750 02 Bochoř, Czech Republic
support@decadetools.com

1. Controller and scope

The controller of personal data processed through the Houby AI mobile app and houbyai.cz website is Daniel Hanuš, Business ID 04148193, Hliník 240/30, 750 02 Bochoř, Czech Republic. Contact support@decadetools.com with privacy questions, to exercise your rights or to request an assessment of data deletion. The app does not require registration with a username and password or create a public profile. It uses a pseudonymous technical identity to verify access to paid features.

2. Data on your device

The app stores your find photos, recognition history and AI responses, descriptions you enter, favourite species, quizzes and answers, recent searches and settings locally in the device database and storage. This content remains until you delete it. The app lets you export or delete most local data; exports may include photos. System backups depend on your device and operating system. Android app backups are disabled in the current configuration. iOS backups depend on your device settings.

3. Photos and online recognition

When you start recognition, the app sends up to three selected photos, optional text context, a random request ID and the atlas version over an encrypted connection to an API hosted on Cloudflare. Cloudflare resizes and converts images to WebP, removing EXIF metadata. The images and context are then passed to Google Gemini API for analysis and a suggested result. This does not alter the original photos on your phone.

Removing EXIF metadata does not remove information visible within a photo. Only upload images you are entitled to use, and avoid photos of people, documents or confidential information. You can use the atlas and quizzes without sending a photo for recognition.

4. Technical data and service security

Apple App Attest verifies the authenticity of the iOS app using an on-device key and cryptographic proofs. The server stores the installation identifier and public key, a verification counter and a randomly assigned RevenueCat customer ID; the private key does not leave the device. RevenueCat returns the subscription status, product, validity dates and purchase transaction identifier. The service uses this information to verify access and count recognition usage. Verified subscription validity is also saved in the phone’s secure storage for offline access. API requests also involve a random request ID, a hash of the request body, processing status and timestamps. To prevent abuse, the service creates an IP address fingerprint for hourly and daily counters. Our operational logs may contain a request ID, status, response time, model and prompt versions and usage information; app code does not write photos, free text or model responses to these logs. Cloudflare may separately process network and security information when providing infrastructure. Documented measures include encrypted API connections, an installation identifier in system secure storage, request limits, and separation of photos and free text from our operational logs. These measures do not mean every transfer or storage system is absolutely secure. The identifiers are pseudonymous, not anonymous.

5. Mobile app analytics

The mobile app automatically uses Google Firebase Analytics. It processes an app-instance identifier, device and session information, and usage statistics for screens, onboarding, recognition, quizzes and favourite species; Google may infer approximate location from an IP address. Adding or removing a favourite species generates an event containing that species’ ID. Custom events do not send photos, entered context, search terms or individual find IDs. Advertising identifiers and ad personalisation are disabled in the current configuration. The app currently has no separate analytics opt-out setting. Using the app, accepting the safety notice or reading this policy does not constitute consent to analytics. Analytics supports usage statistics and app improvements; where applicable law requires consent or another user action, that must be obtained separately.

6. Purchases, support and permissions

Where a subscription offer is available on iOS, Apple App Store and StoreKit process the payment and subscription. RevenueCat helps verify purchases and unlock paid features. Houby AI does not receive your full payment card number. The available offer, price and conditions are displayed in the App Store. The current Android app does not support subscription purchases. If you contact support, we process your email address and message to respond and handle your request.

Camera and selected-photo permissions let you take or choose pictures. The app does not request access to GPS or the microphone. You can change permissions in your device settings.

7. Website and service providers

The houbyai.cz website is hosted on Vercel. When a page loads, the hosting service processes IP addresses and request, browser and device information needed to deliver and secure it. The website has no form, analytics or advertising measurement, advertising pixels or photo recognition feature. Third-party links are subject to the respective service’s own rules when opened.

We do not publicly publish your photos or find content in the app, and we do not sell personal data. Depending on the feature, recipients or independent providers include Cloudflare (API infrastructure, image processing and technical records), Google (Gemini API and Firebase Analytics), Apple (iOS payments, subscriptions and app authenticity verification), RevenueCat (iOS purchase verification) and Vercel (web hosting). Their information is linked below. Some providers may process data outside the European Economic Area. We do not promise that all data stays in the EU; the contracting entities, locations and transfer safeguards depend on the relevant account and service configuration. Daniel Hanuš remains the controller for processing purposes and means he determines. A provider processing data on his behalf does not take over the controller’s responsibility; a provider may also act independently for its own processing purposes. Each entity’s contractual role depends on the service and applicable agreements.

8. Purposes and legal grounds

Recognition is optional: it requires selecting and sending a photo, while the atlas and quizzes can be used without it. A photo is necessary for requested recognition; additional text context is optional. Technical identifiers, status information and network data are also necessary to establish and secure an online request; we cannot provide online recognition without them. Analytics starts automatically in the current app and cannot be turned off separately. You provide support information voluntarily, but we may be unable to respond without the necessary contact details. We process photos and context to perform the recognition you request. Technical records, identifiers and counters support operation, security, abuse prevention and troubleshooting. Depending on the processing, these activities rely on performance of the service you request, our legitimate interest in secure operation and applicable legal obligations. Purchase information is necessary to process purchases and manage subscriptions; Apple handles payment. Analytics supports app usage statistics. Its legal basis depends on the rules applicable to the device and place of use; this policy is not itself consent. The app does not assess your personal characteristics or make decisions about you with legal or similarly significant effects; automated output suggests a mushroom species.

9. Data retention

Local data remains on your device until you delete it; the app has no fixed automatic deletion period for it. Recognition results cached on the server for request replay are removed after 15 minutes. The associated technical record, containing a pseudonymous purchase-period identifier, request ID and hash, status and timestamps, is not automatically deleted in the current server implementation and may remain without a fixed deadline. Verified installation records and purchase-period usage likewise have no automatic deletion period. The local offline-access record stops granting access when the saved subscription validity expires. Older abuse-prevention counters are cleaned up on later requests; an exact cleanup time is not guaranteed during inactivity. Operational log retention also depends on Cloudflare and Vercel settings.

Google’s Gemini API documentation states that prompts, contextual information and outputs are retained for 55 days for abuse monitoring and required disclosures. This can include content sent for recognition. This is Google’s stated period for that purpose, not a guarantee of the total maximum retention of all data. Google separately offers project API logs with configurable retention of 7, 14, 28 or 55 days; datasets created from those logs may have no set retention period. This is separate from API abuse monitoring and depends on project settings. See Google’s abuse-monitoring documentation and data logging and sharing policy. Providers are responsible for their own processing according to their role and agreements; the controller remains responsible for the processing purposes and means he determines.

10. Deletion, objections and your rights

You can export or delete local records and photos, favourites, quizzes, search history and settings in the app. Local deletion does not send a deletion request to our server or remove the installation identifier in device secure storage, system backups or information already received by providers. Uninstalling the app does not cancel a subscription. To request access, correction, restriction or an assessment of deletion of data we process, contact support@decadetools.com. The server has no self-service account or remote deletion feature. We therefore assess requests using available records and legal obligations, without promising deletion of information we cannot technically locate or control.

Subject to the conditions in the GDPR, you have rights of access, rectification, erasure and restriction, data portability where applicable, and the right to object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it at any time without affecting prior processing. We respond without undue delay, normally within one month. You may also complain to the Czech Office for Personal Data Protection at uoou.gov.cz.

11. Changes to this policy

When app features, providers or processing practices change, we publish an updated policy here and update its effective date. If a change materially affects processing or applicable law requires it, we provide appropriate notice, for example in the app. Without your email address, we cannot promise individual email notices. Policy changes do not retroactively change the lawfulness of previous processing.

Provider and regulator information