Skip to content
Mycoverse
Features Privacy Safety Support Norsk
← Back to the home page

Privacy Policy

Last updated July 27, 2026.

AVAGA HOLDING AS, organization no. 829 544 482, is the data controller for Mycoverse. Its registered address is Onsøyveien 38, 1614 Fredrikstad, Norway. Privacy questions can be sent to rl@avaga.no.

In short

Mycoverse is a private mushroom journal by default. You can voluntarily share a safe copy of a finding with the community; exact locations and private notes are never shared there. You can also create an expiring private link for one finding and deliberately choose an approximate or exact position. Live safety trips are created only when you start them and expire automatically. We do not sell personal data or use it for advertising, profiling or tracking.

Data we process

  • Email address, password-based sign-in and name are required to create and protect an account. Supabase provides authentication.
  • Area and experience level are optional profile data.
  • When you use the journal, we process up to eight photos you select per finding, date, your provisional name label, notes and location. If a selected photo contains a location and you choose to use it, we also process that photo location. At least one photo and a location are required to save a finding.
  • When you explicitly request possible image matches, we process the selected finding photos, an area reduced to roughly 5 km and the returned suggestions. The result is an uncertain probability estimate, not confirmed species identification or food-safety advice.
  • Mushroom Outlook processes an area reduced to roughly 5 km and environmental data such as weather, rainfall, temperature, soil conditions, tree species and terrain. Personal feedback about findings is stored on your account. If you enable alerts, we store a push token, selected coarse area and threshold.
  • Ordinary Trip Mode uses precise location while active and remains locally on the device. If you explicitly start a Safety Trip, route points, expected return and timestamps are stored with Supabase so they can be shown through the private safety link.
  • For a private finding link, we store the finding reference, selected location precision, expiry and a cryptographic hash of the secret link token. The raw token is not stored. The link shows up to eight photos, label, date, habitat and an approximate position by default. Exact location is shared only after the owner explicitly chooses it.
  • Community reports and blocks are stored when used. Technical security and incident data may include time, IP address, device type, request and error information.

Purpose and legal basis

Account, journal, synchronization, optional possible image matches, Mushroom Outlook, community features, private finding links, export and account deletion are provided under our agreement with you (GDPR Article 6(1)(b)). Image analysis occurs only after a clear action by the user. Limited operational, moderation, error and security data is processed for our legitimate interest in securing and supporting the service (Article 6(1)(f)). Data may be retained where a legal obligation requires it (Article 6(1)(c)).

Camera, photos and location

Camera and photo access are used only when you choose to document a finding. Location is obtained when you request it, choose a photo location, or use Map, Mushroom Outlook or Trip Mode. Environmental and identification providers receive only an area reduced to roughly 5 km. The precise Trip Mode route remains on your device unless you explicitly start a Safety Trip. Background location is used only while that share is active. Permissions can be withdrawn in iPhone Settings. Possible image matches never confirm a species or whether a mushroom is safe to eat.

Voluntary community sharing

Findings are private by default. When you enable sharing, only the primary photo, provisional label, date, habitat, first name or alias, and a location rounded to a grid of roughly 5 km are published. Exact coordinates, notes and additional photos remain private. You can stop sharing at any time. Reports and blocks support moderation.

Private finding links

You may explicitly create a secret link for one finding, choose a position rounded to roughly 500 metres or the saved exact position, and set a 7- or 30-day expiry. Anyone with the link can view the limited finding until it expires or you withdraw it. Private links never include notes, account identity or Trip Mode routes.

Optional live safety trips

When you explicitly start a Safety Trip, one private bearer link is created with your exact breadcrumb route, current or last position, update time, expected return and trip status. The link contains no findings, species labels, notes or account identity. Anyone who receives or forwards it can view the route until it is withdrawn or expires. The raw token is not stored; only a cryptographic hash is retained. The link expires no later than 12 hours after expected return and within 48 hours of starting. Mycoverse is not an emergency service and cannot guarantee coverage, updates or rescue.

Subscriptions and purchase data

Apple processes subscription payment details. RevenueCat receives an app-specific user identifier, product, purchase status, expiry and storefront environment so we can unlock Premium and restore purchases. Mycoverse does not receive your card or Apple ID payment details. Purchase records are retained while needed to provide and document access, then deleted or anonymized subject to accounting and legal duties.

Providers and transfers

Production data is stored with Supabase in the EU. Maps on iPhone are provided by Apple Maps. Mushroom Outlook uses MET Norway, NIBIO, Kartverket, OpenStreetMap, GBIF and may use a configured Open-Meteo service, with a coarse area. Artsobservasjoner contributes Norwegian occurrence records through GBIF. Name and licensed image searches may query GBIF. Expo Push Service and Apple Push Notification Service process the push token and alert content when alerts are enabled. Apple processes subscriptions and RevenueCat synchronizes Premium status.

When you explicitly request possible matches, up to eight finding photos and a coarse area are sent through our protected server to Kindwise Mushroom.id. The provider key is never stored in the app. We request deletion of Kindwise’s copy immediately after the result is received; the suggestions are stored with your Supabase account. Any necessary transfer outside the EEA must use a valid transfer mechanism, such as an adequacy decision or EU Standard Contractual Clauses.

Retention, export and deletion

Active account data, saved match suggestions and Mushroom Outlook feedback are retained while your account exists. Private links remain until withdrawn, their 7- or 30-day expiry, finding deletion or account deletion. Safety Trip links stop at withdrawal or expiry, and routes are deleted with the account. You can export your data and delete findings, photos or your account from Profile. Account deletion removes active profile data, findings, links, suggestions, feedback and stored photos. Deleted database data may remain in Supabase encrypted daily backups for up to seven days; stored photos are not included in those database backups. Security and support data is deleted or anonymized within 30 days unless an ongoing incident or legal requirement applies.

Your rights

You may request access, correction, deletion, restriction and data portability, object to processing based on legitimate interests, and complain to the Norwegian Data Protection Authority. Contact rl@avaga.no.

Mycoverse
PrivacyTermsSupport
AVAGA HOLDING AS · organization no. 829 544 482rl@avaga.no+47 484 08 702