Privacy Policy
In short: Boletus is a local-first foraging journal. Your precise routes, find locations, notes, and mushroom photos are stored on your device and are not uploaded to us. The App connects to OpenFreeMap for maps, uses Google Firebase for analytics and remote configuration, and may use Google AdMob and advertising partners to display and measure ads. The Android Advertising ID (AD_ID) may be used for advertising, attribution, and analytics. Android may also back up App data to your Google account if device backup is enabled.
1. Who We Are
Boletus (the “App”) is developed and published by Mondrus CCS Inc (“Mondrus”, “we”, “us”, or “our”). This Privacy Policy explains how the Android version of the App accesses, uses, stores, and transmits information.
Privacy questions and requests may be sent to contact@garny.io.
2. Scope and Key Distinctions
The App does not require or provide a Mondrus account. We do not receive your name, email address, precise GPS route, find coordinates, photos, or notes merely because you use the App. If you email us for support, we will receive the information you choose to include in that message.
Some information nevertheless leaves your device when the App loads online maps, uses Firebase, creates an Android system backup, or shares a file at your direction. Those cases are described below.
3. Information Stored on Your Device
3.1 Precise location, routes, and finds
When you grant location permission, Boletus uses precise or approximate device location to show your position, record a foraging outing, draw its route, and save the location of a find. A recording begins only after you start it. Once started, it may continue through an Android foreground service while the screen is off or the App is not visible; Android displays an ongoing notification while this happens. The App does not request the Android background-location permission and does not start a route recording on its own.
Recorded GPS points, route geometry, find coordinates, timestamps, species, quantities, habitat details, and notes are stored in the App’s local database. We do not upload these records to our servers or to Firebase.
3.2 Photos
If you choose to attach a photo to a find, the App opens the device’s camera application and stores a resized copy in the App’s private storage. Boletus does not request access to your photo library. Photo files and their metadata are not uploaded to us or to Firebase.
3.3 Preferences, offline maps, and local statistics
Your language, theme, GPS profile, favourite species, notification choices, onboarding state, locally calculated statistics, and downloaded offline map regions are stored on your device. Season reminders are calculated locally from the bundled catalogue and your local history.
4. Information That Leaves Your Device
| Data or activity | Recipient | Purpose |
|---|---|---|
| Map tile coordinates, map style and font requests, IP address, and standard network/device request information | OpenFreeMap and its delivery providers, including Cloudflare where used | Display online maps and download an offline map region you request |
| App interactions, technical app/device information, approximate location derived from IP, app-instance and installation identifiers, and an Advertising ID when available | Google Firebase / Google Analytics | Measure feature use, diagnose product-level failure patterns, attribution, advertising measurement and audiences, and improve the App |
| Advertising ID, app and installation identifiers, IP address, approximate location, device and network information, consent signals, and ad impressions, clicks, or other ad interactions | Google AdMob and advertising technology partners involved in serving an ad | Request, select, personalize where permitted, deliver, limit the frequency of, measure, attribute, secure, and prevent fraud in advertising |
| Firebase installation identifier and configuration request information | Google Firebase Remote Config | Retrieve operational settings such as GPS tuning, download limits, analytics kill switches, and the current map endpoint |
| GPX route or ZIP backup selected by you | The application, person, or storage location you choose in the Android share or document interface | Complete your requested export or backup |
| Eligible App data, potentially including the local database, preferences, and photos | Google’s Android backup service and your Google account, if device backup is enabled | Restore App data on this or a replacement device |
4.1 Online map requests
The default map provider is OpenFreeMap. A tile request identifies the portion of the map being viewed or downloaded. This can reveal an approximate area of interest, which is often near the user, but the request does not contain your saved route, find database, photos, or notes.
OpenFreeMap states that it does not store IP addresses in its regular server logs, may temporarily enable IP logging for security incidents for up to 30 days, and may use Cloudflare. Its current practices are described in the OpenFreeMap Privacy Policy. Remote Config allows us to replace the tile endpoint if necessary to keep maps available; if the provider changes, the replacement will receive the same types of request data and we will update this Policy.
4.2 Firebase Analytics
In a production build configured with Firebase, Analytics collection is enabled when the App starts unless we remotely disable it for all installations. Google Analytics automatically collects information such as sessions, approximate geolocation derived from an IP address, app and device information, and an app-instance identifier. The Android SDK may also collect the device’s Advertising ID when it is available.
We use Firebase Analytics for product analytics, attribution, advertising measurement, audience creation, and improving the App. When Firebase and AdMob are linked, Analytics events and properties may be used to measure ad performance and, where permitted by your consent and settings, help select or personalize advertising.
Our custom analytics events may include:
- screens viewed and actions performed;
- permission results and short technical error categories;
- GPS profile, theme, language, and whether photo attachment is enabled;
- outing duration, distance, point and find counts, GPS-quality ranges, and battery-use ranges;
- catalogue species identifiers, quantities, and whether optional find fields were used;
- offline-map download size and outcome; and
- GPX or backup success and aggregate item or size counts.
We do not put precise latitude or longitude, route geometry, town names, photos, note text, user-entered outing names, file paths, GPX content, or backup content into Analytics events. Google describes its default mobile Analytics collection in its Analytics data collection documentation.
4.3 Advertising and AD_ID
The App may display advertisements supplied by Google AdMob and advertising technology partners that participate in an ad request. Depending on your region, consent choices, device settings, and the type of ad available, ads may be personalized, non-personalized, limited, or based only on the App’s current context.
For advertising, the Google Mobile Ads SDK and participating partners may process the Android Advertising ID (AD_ID), Firebase or publisher identifiers, the App name and version, IP address and approximate location derived from it, device model and operating system, language, network information, ad request data, consent signals, and information about ad impressions, views, clicks, and conversions. These data may be used to select and deliver ads, personalize ads where allowed, limit repetition, measure reach and effectiveness, attribute installs or actions, detect invalid traffic and fraud, and maintain security.
Where applicable law requires consent, the App will use a Google-certified consent flow before requesting personalized advertising or accessing advertising storage for that purpose. Where required, the App will also provide a privacy-options entry point so you can revisit your choices. Refusing personalized advertising does not necessarily remove ads; you may receive non-personalized or limited ads instead.
You can reset or delete the Advertising ID and adjust advertising privacy settings in Android. Google explains how information from partner apps is used at How Google uses information from sites or apps that use our services. The vendors available for a particular consent request are identified in the consent interface.
4.4 Firebase Remote Config
Remote Config uses a Firebase installation identifier to return and cache configuration values for the App. It does not receive your routes, finds, photos, or notes. Firebase’s processing and retention information is available in Privacy and Security in Firebase.
4.5 User-directed exports
A GPX file contains the route you choose to export. A ZIP backup may contain routes, finds, notes, preferences, and photos. These files are created only when you request them and are handed to Android’s share or document interface. The destination you choose receives the file and applies its own privacy terms. We do not receive a copy.
4.6 Android Auto Backup
The App currently permits Android backup. If backup is enabled in your device and Google account settings, Android may copy eligible App data to your Google account. This transfer is performed by Android, not by a Mondrus server. You can manage or delete device backups through your Android and Google account settings. Google’s privacy terms apply to that service.
5. Device Permissions
| Permission or capability | How Boletus uses it |
|---|---|
| Precise and approximate location | Show your position, record a route you start, and attach a location to a find. |
| Foreground location service | Continue an outing you started while the screen is off or the App is not visible, with an ongoing Android notification. |
| Notifications | Show the active-outing control notification and optional local season reminders. |
| Internet and network state | Load maps, download offline regions, retrieve Remote Config, send Analytics events, and request and display advertising. |
| Camera application | Capture a photo you request through the device camera. Boletus itself does not request the Camera permission or photo-library access. |
You can revoke Android permissions in system settings, but related features may stop working.
6. How and Why We Use Information
We process information to provide the features you request, preserve your settings, display maps, maintain App reliability, understand feature use, improve the product, deliver and measure advertising, perform attribution, prevent advertising fraud, answer support requests, comply with law, and protect our rights and users.
Where the GDPR or UK GDPR applies, our legal bases are performance of our agreement with you for requested App functions; our legitimate interests in operating, securing, measuring, funding, and improving the App where those interests are not overridden by your rights; compliance with legal obligations; and consent for personalized advertising, advertising storage, or other processing where consent is required. You may withdraw consent through the App’s privacy options where available and may object to processing based on legitimate interests by contacting us.
7. Service Providers and Disclosure
We do not sell your personal information. We disclose or make data available only as described here:
- Google LLC: Firebase Analytics, Firebase Installations, Firebase Remote Config, Google AdMob, Google Play distribution, and optional Android backup. See Google’s Privacy Policy.
- Advertising technology partners: identifiers, consent signals, device/network data, and ad interaction data may be made available to the vendors involved in selecting, delivering, measuring, or securing an ad. The applicable vendors are shown in the consent interface where required.
- OpenFreeMap / Hyperknot Software Kft. and delivery providers: online map content and fonts.
- Your chosen export destination: only when you direct Android to share or save a GPX or ZIP file.
- Authorities or transaction parties: when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a merger, financing, acquisition, or sale, subject to appropriate safeguards.
The App may use advertising networks as described above. It does not currently use Firebase Crashlytics, Firebase Performance Monitoring, a payment processor, or a Mondrus cloud account service.
8. Retention and Deletion
- Local App data: remains until you delete individual finds, outings, photos, or offline regions, clear the App’s storage, or uninstall the App. An Android backup may remain separately under your Google account’s backup settings.
- Analytics: user-level event data is retained for no longer than 14 months under our Analytics retention settings, unless a shorter period applies. Aggregated or de-identified reports may remain longer.
- Advertising data: retention depends on the advertising provider, the purpose, consent status, and applicable law. AdMob and participating vendors publish their own retention practices. We retain publisher reports only for as long as needed for advertising measurement, fraud prevention, accounting, disputes, and legal obligations.
- Firebase installation identifiers: Google retains them until deletion is initiated. Firebase states that after deletion begins, associated data is removed from live and backup systems within 180 days.
- Support correspondence: is kept only as long as reasonably necessary to answer the request, maintain support records, resolve disputes, and meet legal obligations.
Boletus has no user account, so there is no account to delete. To stop future App collection, you may uninstall the App. You may reset or delete the Android Advertising ID in your device’s privacy settings. For a request concerning data controlled by us, email contact@garny.io. Because Analytics is pseudonymous and is not linked to an account, we may need information that reasonably identifies the relevant installation; if we cannot associate data with you, we will explain that limitation.
9. Your Privacy Rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection; withdraw consent where processing is based on consent; and complain to a data-protection authority. We will not discriminate against you for exercising a privacy right.
California residents may request information about categories of personal information collected, sources, purposes, and recipients, and may request access, correction, or deletion as provided by law. We do not sell personal information for money. The disclosure of identifiers and activity data to advertising partners for personalized or cross-context behavioural advertising may be considered “sharing” under some US state laws. Where those laws apply, you may opt out through the App’s privacy options and applicable Android advertising settings, or contact us at contact@garny.io. We may take reasonable steps to verify a request.
10. International Processing
Google, OpenFreeMap, their delivery providers, and Mondrus may process information in countries other than yours. Where required, transfers are protected through contractual safeguards, adequacy decisions, or other legally recognized mechanisms. Third-party providers publish further information in their own privacy materials linked above.
11. Security
Data sent by the App to Firebase, advertising providers, and the default map provider is transmitted using encrypted network connections. Local data is protected by Android’s application sandbox and your device security. Exported files are protected by the destination you select. No storage or transmission method is completely secure, so we cannot guarantee absolute security.
12. Children
Boletus is intended for adults and is not directed to anyone under 18. Advertising requests are not intended to be treated as child-directed. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact contact@garny.io.
13. Changes to This Policy
We may update this Privacy Policy as the App, providers, or law changes. We will post the revised version at this URL and update the “Last updated” date. Where required, we will provide additional notice in the App.
14. Contact Us
- Privacy contact: contact@garny.io
- Developer and publisher: Mondrus CCS Inc
- Application: Boletus for Android