Antkeeping
Privacy

What this app stores about you

Written to satisfy Articles 13 and 14 of the GDPR, in the plainest language we could manage. Last reviewed 11 August 2026.

Who is responsible

Controller
Julian De Plukker
Contact
[email protected]

What is stored, and why

Your account
Email address, username and a hashed password. Needed to give you an account and to keep your journal yours. Legal basis: performance of a contract, Art. 6(1)(b)
Your journal
Colonies, log entries, climate readings, worker counts and photos — whatever you type or upload yourself. Legal basis: performance of a contract, Art. 6(1)(b)
A password reset you asked for
If you ask for a reset link, the app records that your account asked and when, so it can be shown to whoever runs this instance — the server cannot send mail, so a person hands the link over. A link that is issued is stored as a fingerprint and never as something that can be used; the whole record is thrown away thirty days after the link is used or expires. Legal basis: performance of a contract, Art. 6(1)(b)
Failed logins
Your IP address is counted in memory for fifteen minutes to slow down password guessing. It is never written to disk and disappears when the server restarts. Legal basis: legitimate interest in security, Art. 6(1)(f)

Cookies

Three cookies, all strictly necessary for a service you asked for, which is why there is no consent banner: a session cookie that keeps you logged in for 30 days at a time, a CSRF token that stops other sites acting in your name, and a short-lived cookie that carries a confirmation message across one page load. Your light or dark theme choice is kept in your own browser's local storage and never reaches the server.

There is no analytics, no tracking, no advertising and no third-party content. Fonts are served from this server rather than from Google, so loading a page does not hand your IP address to anyone else.

Photos

Uploaded photos are rebuilt from their pixels before being saved, which removes EXIF, XMP and ICC metadata — including the GPS coordinates most phones write into a picture. Only the image itself is kept.

Sharing a journal

A journal is private until you create a share link yourself. That link makes that one colony's journal and its photos readable by anyone who has it, without logging in. Revoking the link in the app makes it dead immediately, though anything already copied or cached elsewhere is beyond our reach.

Notifications

Reminders are off until you switch them on yourself, per browser. When you do, this app stores the address your browser hands out for notifications and the two keys that go with it — nothing about you beyond which account it belongs to. Switching reminders off, in that same browser, deletes that record immediately.

The same channel lets whoever runs this server send an occasional message of their own, such as notice of downtime. That is a person deciding to write, not the app doing something automatically, and it stops when you switch reminders off. Nothing about your colonies is read to decide who gets such a message.

Delivery runs through the notification service of whoever made your browser, and that service is often outside the European Economic Area. The message itself is encrypted for your browser before it leaves this server, so that service can pass on the reminder without being able to read it — but it does see that a message was sent, and when. Leaving reminders off avoids this entirely.

Who can see it from the inside

Whoever runs this server administers the accounts on it. That administration page shows the username, email address and sign-up date of each account, how many colonies it has, and a button to delete an account. It deliberately does not show anyone's colonies, log entries, readings or photos. Someone with access to the server itself can of course reach the database directly — no application setting can prevent that, on any service.

How long it is kept

Until you delete it. Deleting a colony removes its log entries, readings, counts and photo files. Deleting your account removes everything, including the account itself.

Backups are kept for 30 days. Anything you delete is gone from the running system straight away, and disappears from the last backup copy within that window.

Your rights

Under the GDPR you may see your data, correct it, have it erased, take it with you, restrict its use, or object to it. Three of these you can exercise yourself, right now, without asking anyone:

For anything else, email the contact above. If you think your data is being handled wrongly, you can complain to the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels (gegevensbeschermingsautoriteit.be).

Where it runs

The data lives in this application's own database and file storage. It is not sold, shared or handed to advertisers. Two things do leave this server, and both are yours to switch on or off: a share link, and the notifications described above — which are the only case where anything routinely goes outside the European Economic Area.