PhenoMap — Privacy notice
PhenoMap is a citizen-science project for recording plant phenology — what an individual plant is doing, and when. This notice says what it collects about you, who can see it, and what you can ask for. It is written to be short and accurate rather than exhaustive.
1. Who is responsible
PhenoMap is a personal project run by Yilun Li. It is not run, endorsed or backed by any university or institution, and nothing here should be read as institutional research.
Contact for anything in this notice, including access and deletion requests: phenomap@cpelab.net.
2. What is collected
- Your email address, from the account you sign in with (GitHub, or an email and password issued to you).
- A credit name you choose. This is published as the credit for your records under the CC-BY licence. It is public and it cannot be changed afterwards. It does not have to be your real name, and we suggest it is not.
- The observations you record: photographs, the exact location of the plant, the date and time, the phenological stages you score, any notes and place descriptions you write, and whether you marked the plant as indoors or cut.
- Your sharing setting and the record of the consents you gave, with their dates and versions.
- When you last opened the app, and on what kind of device — one of five words such as "Android · installed app" or "Computer · browser", overwritten each time, never a history. Your task's lead sees it beside your last submission so they can tell who has gone quiet. No browser or device identifier is stored.
- The result of the automatic photo check described in section 3, kept with each photograph: the model's description of the picture (which can include text it reads in it), the reasons for the result, which model and prompt produced it, and who reviewed it and when.
- Reports you make about other people's photographs: the category, the reason you wrote, and what became of the report.
What is deliberately not collected: your real name, phone number, postal address, date of birth, or any identity document. There is no analytics or advertising tracking of any kind.
3. Photographs
Photographs are re-encoded in your browser before upload, which removes EXIF metadata — including any camera-embedded GPS position. Two things are read from the file before that, in your browser and nowhere else: the capture time, which is used to suggest the observation's date and time, and the GPS position if the camera recorded one, which is used to suggest where to put the pin. You see both on the form and can change them. The time and location stored with an observation are the ones shown on the form and the map; nothing from the file itself is uploaded.
Photographs are stored in a private bucket and are served through short-lived signed links.
Every photograph is checked automatically after you submit it. Its small 400-pixel copy is shown to an AI model run by Cloudflare (Workers AI), which describes what is in it; fixed rules in our code, not the model, then decide the result. A photograph passes if it shows a plant as its main subject and nothing listed in section 5 of the terms of use. People and faces alone are not a reason to fail. Until the check passes, the whole record is hidden from others in your task — usually for about a minute. If a photograph is flagged, or cannot be checked that day, the record stays hidden from them until a task lead or the administrator reviews it, or a check the next day passes. You will see a "Sensitive" label on your own record while it is held. The check is automated and can be wrong; a person makes the final decision.
4. Approximate location for the map
When you open the map, Cloudflare tells the page the approximate city your internet connection appears to be in, so the map opens somewhere useful. It is rounded to about a kilometre, used only to position the map, and not stored.
When recording a plant you have observed before, you can press Sort by distance from me to put the nearest plants at the top of the list. Your browser asks your permission first. That position is used inside the page to order the list and nothing else: it is not stored, not attached to the record, and never sent to us.
5. Who can see your records
- You — always, in full.
- The lead of your task and the site administrator — always, in full, including exact locations, notes and photographs, whether or not you turn sharing on. This is how mistakes get corrected and how anything harmful is removed. There is no setting that hides your records from them.
- Other people in your task — only records you made while your sharing setting was on. The setting is off unless you turn it on, and it is stamped onto each record when you make it, so changing it later moves future records and not past ones unless you ask for that as well. A record held by the photo check in section 3 is not shown to them, even with sharing on.
- The general public, not signed in — a scattered map of displaced points and three totals. Nothing else: no photographs, no notes, no dates, no species, no names.
Task leads and the administrator also see the result of the photo check for the records they can see. If you report someone else's photograph, your name, the category and your reason are seen by the task's leads and the administrator, and never by the person who posted it. You are told whether the report was upheld, but not who decided. The person who posted it is not told about the report.
Public points are deliberately moved before they leave the database — by roughly 200 m where plants are clustered and up to about 3 km where they are isolated. The real coordinates are never sent to a browser that is not signed in, and the public map cannot be zoomed in far enough to imply a precision the published data does not have.
6. Publication and licence
Records you choose to share are published under CC-BY-4.0, credited to your chosen credit name. Publication is not reversible. Once data has been published under an open licence, other people may have copied it, and it cannot be recalled from them. You can stop future publication and ask for your records to be removed from this service, but not from anyone who has already taken a copy.
7. Where the data is, and who else touches it
Named plainly, because a general statement would be misleading:
- Supabase — database and accounts. The data is held in Seoul, South Korea.
- Cloudflare — serves the app and provides the approximate city described in section 4. It stores the photographs, and its AI service (Workers AI) checks every photograph you submit, as described in section 3.
- GitHub — if you sign in with GitHub, it confirms your email address to us. We do not receive your password or your repositories.
- Pl@ntNet — if you ask for a species suggestion, that photograph is sent to Pl@ntNet for identification. This only happens when you request it.
- Brevo — sends account emails, such as confirmation and password reset.
- OpenFreeMap — supplies the map background; your browser fetches map tiles directly from them.
- GBIF — when you accept a suggested species name, your browser asks GBIF what growth form that species has, so the capture form can show you what is on record. Only the species identifier is sent, never your location, your photograph or anything about you. It does not happen for a name you type yourself.
- Open-Meteo — when you press the locate button, the map shows the weather where you are. Your position is rounded to about a kilometre and sent to Open-Meteo to ask for that forecast. It is sent by our server, not by your browser, so they receive neither your address nor anything identifying you, and nothing is stored there. It happens only when you press locate, never in the background, and you can switch it off under Settings → Weather. Pressing the thermometer beside a plant on My species or All records also asks Open-Meteo, through our server, for that year's temperatures at the plant's recorded location, rounded to about ten kilometres — never yours.
8. How long it is kept, and how to have it removed
Records are kept while the project runs. Accounts that never record anything may be removed after a period of inactivity.
You can delete your own account at any time from Settings → Delete account. Your sign-in is closed and your credit name is removed; your observations stay in the project, credited to "Account deleted", because removing them would leave gaps in a series other people's work depends on. Signing up again later gives you a new account without them.
Write to phenomap@cpelab.net to see what is held about you, to correct it, or to ask for your records to be removed as well as your account. Please allow a reasonable time — this is a personal project, not a staffed service. The limit on deletion is the one in section 6: anything already published under CC-BY may already have been copied.
9. Age
You must be 16 or older to create an account. If you believe someone under 16 has registered, write to the address above and the account will be removed.
10. Photographs of people
Do not upload photographs in which a person is identifiable, unless that person has agreed. Records containing identifiable people will be removed.
11. Changes
This notice is versioned. If it changes materially you will be asked to read it again before continuing to contribute. The version you agreed to is recorded with your account.
物候志 — 隐私声明
物候志是一个记录植物物候的公众科学项目——记录某一株植物正在发生什么,以及发生的时间。本声明说明我们收集关于你的哪些信息、谁能看到、以及你可以提出什么要求。我们力求简短准确,而非面面俱到。
1. 责任人
物候志是 Yilun Li 的个人项目,并非由任何大学或机构运营、认可或支持,也不应被理解为机构研究。
与本声明有关的任何事项,包括查阅与删除请求,请联系:phenomap@cpelab.net。
2. 收集的信息
- 你的电子邮件地址,来自你用于登录的账户(GitHub,或发给你的邮箱与密码)。
- 你选择的署名。它将依 CC-BY 许可作为你记录的署名公开发布。它是公开的,且此后无法更改。它不必是真实姓名,我们也建议不要使用真实姓名。
- 你记录的观测:照片、植株的精确位置、日期与时间、你评定的物候期、你写下的备注与地点描述,以及你是否将该植株标记为室内或切花。
- 你的分享设置,以及你所作同意的记录及其日期与版本。
- 你最近一次打开应用的时间,以及所用设备的类型——五个词之一,例如“Android · 已安装应用”或“电脑 · 浏览器”,每次覆盖,不保留历史。你所在任务的组长会在你的最近提交旁看到它,以便了解谁已停下。不会存储任何浏览器或设备标识。
- 照片自动检查的结果(见第 3 节),与每张照片一同保存:模型对画面的描述(可能包括它从画面中读到的文字)、得出该结果的原因、所用的模型与提示词版本,以及由谁、在何时复核。
- 你对他人照片提出的举报:类别、你写下的理由,以及举报的处理结果。
刻意不收集的信息:真实姓名、电话号码、通讯地址、出生日期或任何身份证件。本站没有任何分析统计或广告追踪。
3. 照片
照片在上传前会在你的浏览器中重新编码,因而移除 EXIF 元数据,包括相机嵌入的 GPS 位置。在此之前,只在你的浏览器中读取两项内容:拍摄时间,以及相机记录的 GPS 位置(如果有),后者用于建议地图标记的位置。你会在地图上看到该标记,可以移动或清除。与观测一同存储的位置是地图上显示的那个;文件本身的内容不会被上传。
照片存放于私有存储空间,通过短期有效的签名链接提供。
每张照片在你提交后都会被自动检查。照片 400 像素的小图会交给 Cloudflare 运行的 AI 模型(Workers AI),由它描述画面内容;之后由我们代码中的固定规则(而非模型)决定结果。若照片以植物为主体,且不含使用条款第 5 节所列的任何内容,即为通过。仅有人物或面孔不构成不通过的理由。在检查通过之前,整条记录对同一任务中的其他人隐藏——通常约一分钟。若照片被标记,或当天无法检查,该记录会继续对他们隐藏,直至任务负责人或管理员复核,或次日的检查通过。记录被暂扣期间,你会在自己的记录上看到“敏感”标签。检查由程序自动进行,可能出错;最终决定由人作出。
4. 用于地图的大致位置
打开地图时,Cloudflare 会告知页面你的网络连接大致所在的城市,以便地图打开在有用的位置。该信息精度约为一公里,仅用于定位地图,不会被存储。
记录以前观察过的植株时,你可以按按距离排序,把最近的植株排在列表前面。浏览器会先征求你的许可。该位置只在页面内用于排序:不会被存储,不会附加到记录上,也不会发送给我们。
5. 谁能看到你的记录
- 你自己——始终可见全部内容。
- 你所在任务的负责人与网站管理员——始终可见全部内容,包括精确位置、备注与照片,无论你是否开启分享。这是纠正错误、移除有害内容的方式。没有任何设置可以对他们隐藏你的记录。
- 同一任务中的其他人——仅限你在分享设置开启期间所作的记录。该设置默认关闭,且在你创建每条记录时即被写入该条记录,因此日后更改只影响之后的记录,除非你另外要求一并更改。被第 3 节所述照片检查暂扣的记录,即使开启分享,也不会向他们显示。
- 未登录的公众——一张由偏移点位构成的地图与三个总数。除此之外没有任何内容:没有照片、备注、日期、物种或姓名。
任务负责人与管理员也能看到他们可见记录的照片检查结果。如果你举报他人的照片,你的名字、类别与理由会被该任务的负责人与管理员看到,发布者绝不会看到。你会得知举报是否成立,但不会得知由谁决定。发布照片的人不会被告知有人举报。
公开的点位在离开数据库之前就已被刻意偏移——植株密集处约 200 米,孤立处最多约 3 公里。真实坐标绝不会发送给未登录的浏览器,公开地图也无法放大到超出已发布数据实际精度的程度。
6. 发布与许可
你选择分享的记录将依 CC-BY-4.0 发布,并标注你所选的署名。发布不可撤回。数据一经以开放许可发布,他人可能已经复制,无法从他们手中收回。你可以停止今后的发布,并要求从本服务中移除你的记录,但无法要求已取得副本的人删除。
7. 数据所在地,以及还有谁接触它
逐一列明,因为笼统的说法会造成误导:
- Supabase——数据库与账户。数据存放于韩国首尔。
- Cloudflare——提供本应用,并提供第 4 节所述的大致城市。它存储照片,且其 AI 服务(Workers AI)会检查你提交的每张照片,详见第 3 节。
- GitHub——如果你用 GitHub 登录,它会向我们确认你的电子邮件地址。我们不会取得你的密码或代码仓库。
- Pl@ntNet——如果你请求物种识别建议,该照片会被发送至 Pl@ntNet 进行识别。此事仅在你主动请求时发生。
- Brevo——发送账户邮件,例如确认信与密码重设。
- OpenFreeMap——提供地图底图;你的浏览器会直接向其获取地图瓦片。
- GBIF——当你采用建议的物种名称时,你的浏览器会向 GBIF 查询该物种的生长型,以便在记录表单中显示已有记载。只会发送物种标识符,不会发送你的位置、照片或任何与你有关的信息。自己手动输入的名称不会触发此查询。
- Open-Meteo——当你按下定位按钮时,地图会显示你所在位置的天气。你的位置会被精确到约一公里后发送给 Open-Meteo 以查询天气预报。该请求由我们的服务器发出,而非你的浏览器,因此对方既不会取得你的网络地址,也不会取得任何可识别你的信息,且不会留存。此事仅在你按下定位时发生,不会在后台进行;你也可以在设置 → 天气中将其关闭。在“我的物种”或“全部记录”中按下植物旁的温度计按钮,也会经由我们的服务器向 Open-Meteo 查询该年份在植物记录位置(精确到约十公里)的气温——绝不会是你的位置。
8. 保存多久,以及如何要求删除
记录在项目运行期间予以保存。从未记录任何内容的账户可能在一段时间不活跃后被移除。
你可以随时在设置 → 删除账号中自行删除账号。你的登录会被关闭,署名会被移除;你的观察记录会保留在项目中,署名为 "Account deleted",因为移除它们会在其他人工作所依赖的序列中留下空缺。之后再注册,将得到一个不含这些记录的新账号。
请写信至 phenomap@cpelab.net,以查阅我们持有关于你的哪些信息、更正它,或要求连同账号一并删除你的记录。请给予合理的处理时间——这是个人项目,并非配备人手的服务。删除的限制见第 6 节:已依 CC-BY 发布的内容可能已被复制。
9. 年龄
你必须年满 16 岁才能开立账户。如你认为有未满 16 岁者已注册,请写信至上述地址,该账户将被移除。
10. 涉及人物的照片
请勿上传可辨识出个人的照片,除非该人已同意。包含可辨识人物的记录将被移除。
11. 变更
本声明有版本编号。若发生实质变更,我们会在你继续贡献之前请你重新阅读。你所同意的版本会与你的账户一同记录。
物候誌 — 隱私聲明
物候誌是一個記錄植物物候的公眾科學項目——記錄某一株植物正在發生什麼,以及發生的時間。本聲明說明我們收集關於你的哪些資料、誰能看到、以及你可以提出什麼要求。我們力求簡短準確,而非面面俱到。
1. 責任人
物候誌是 Yilun Li 的個人項目,並非由任何大學或機構營運、認可或支持,亦不應被理解為機構研究。
與本聲明有關的任何事項,包括查閱與刪除要求,請聯絡:phenomap@cpelab.net。
2. 收集的資料
- 你的電郵地址,來自你用於登入的帳戶(GitHub,或發給你的信箱與密碼)。
- 你選擇的署名。它將依 CC-BY 授權作為你紀錄的署名公開發布。它是公開的,且此後無法更改。它不必是真實姓名,我們亦建議不要使用真實姓名。
- 你記錄的觀測:照片、植株的精確位置、日期與時間、你評定的物候期、你寫下的備註與地點描述,以及你是否將該植株標記為室內或切花。
- 你的分享設定,以及你所作同意的紀錄及其日期與版本。
- 你最近一次開啟應用程式的時間,以及所用裝置的類型——五個詞之一,例如「Android · 已安裝應用程式」或「電腦 · 瀏覽器」,每次覆寫,不保留歷史。你所在任務的組長會在你的最近提交旁看到它,以便了解誰已停下。不會儲存任何瀏覽器或裝置識別碼。
- 照片自動檢查的結果(見第 3 節),與每張照片一同保存:模型對畫面的描述(可能包括它從畫面中讀到的文字)、得出該結果的原因、所用的模型與提示詞版本,以及由誰、在何時覆核。
- 你對他人照片提出的檢舉:類別、你寫下的理由,以及檢舉的處理結果。
刻意不收集的資料:真實姓名、電話號碼、通訊地址、出生日期或任何身分證件。本站沒有任何分析統計或廣告追蹤。
3. 照片
照片在上傳前會在你的瀏覽器中重新編碼,因而移除 EXIF 中繼資料,包括相機嵌入的 GPS 位置。在此之前,只在你的瀏覽器中讀取兩項內容:拍攝時間,以及相機記錄的 GPS 位置(如果有),後者用於建議地圖標記的位置。你會在地圖上看到該標記,可以移動或清除。與觀測一同儲存的位置是地圖上顯示的那個;檔案本身的內容不會被上傳。
照片存放於私有儲存空間,透過短期有效的簽署連結提供。
每張照片在你提交後都會被自動檢查。照片 400 像素的小圖會交給 Cloudflare 運行的 AI 模型(Workers AI),由它描述畫面內容;之後由我們程式碼中的固定規則(而非模型)決定結果。若照片以植物為主體,且不含使用條款第 5 節所列的任何內容,即為通過。僅有人物或面孔不構成不通過的理由。在檢查通過之前,整筆紀錄對同一任務中的其他人隱藏——通常約一分鐘。若照片被標記,或當天無法檢查,該紀錄會繼續對他們隱藏,直至任務負責人或管理員覆核,或翌日的檢查通過。紀錄被暫扣期間,你會在自己的紀錄上看到「敏感」標籤。檢查由程式自動進行,可能出錯;最終決定由人作出。
4. 用於地圖的大致位置
開啟地圖時,Cloudflare 會告知頁面你的網路連線大致所在的城市,以便地圖開在有用的位置。該資訊精度約為一公里,僅用於定位地圖,不會被儲存。
記錄以前觀察過的植株時,你可以按按距離排序,把最近的植株排在清單前面。瀏覽器會先徵求你的許可。該位置只在頁面內用於排序:不會被儲存,不會附加到記錄上,也不會傳送給我們。
5. 誰能看到你的紀錄
- 你自己——始終可見全部內容。
- 你所在任務的負責人與網站管理員——始終可見全部內容,包括精確位置、備註與照片,無論你是否開啟分享。這是糾正錯誤、移除有害內容的方式。沒有任何設定可以對他們隱藏你的紀錄。
- 同一任務中的其他人——僅限你在分享設定開啟期間所作的紀錄。該設定預設關閉,且在你建立每筆紀錄時即寫入該筆紀錄,因此日後更改只影響之後的紀錄,除非你另外要求一併更改。被第 3 節所述照片檢查暫扣的紀錄,即使開啟分享,也不會向他們顯示。
- 未登入的公眾——一張由偏移點位構成的地圖與三個總數。除此之外沒有任何內容:沒有照片、備註、日期、物種或姓名。
任務負責人與管理員亦能看到他們可見紀錄的照片檢查結果。如果你檢舉他人的照片,你的名字、類別與理由會被該任務的負責人與管理員看到,發布者絕不會看到。你會得知檢舉是否成立,但不會得知由誰決定。發布照片的人不會被告知有人檢舉。
公開的點位在離開資料庫之前就已被刻意偏移——植株密集處約 200 公尺,孤立處最多約 3 公里。真實座標絕不會傳送給未登入的瀏覽器,公開地圖亦無法放大到超出已發布資料實際精度的程度。
6. 發布與授權
你選擇分享的紀錄將依 CC-BY-4.0 發布,並標註你所選的署名。發布不可撤回。資料一經以開放授權發布,他人可能已經複製,無法從他們手中收回。你可以停止日後的發布,並要求從本服務中移除你的紀錄,但無法要求已取得副本的人刪除。
7. 資料所在地,以及還有誰接觸它
逐一列明,因為籠統的說法會造成誤導:
- Supabase——資料庫與帳戶。資料存放於韓國首爾。
- Cloudflare——提供本應用程式,並提供第 4 節所述的大致城市。它儲存照片,且其 AI 服務(Workers AI)會檢查你提交的每張照片,詳見第 3 節。
- GitHub——如果你用 GitHub 登入,它會向我們確認你的電郵地址。我們不會取得你的密碼或程式碼儲存庫。
- Pl@ntNet——如果你要求物種辨識建議,該照片會被傳送至 Pl@ntNet 進行辨識。此事僅在你主動要求時發生。
- Brevo——發送帳戶郵件,例如確認信與密碼重設。
- OpenFreeMap——提供地圖底圖;你的瀏覽器會直接向其取得地圖圖磚。
- GBIF——當你採用建議的物種名稱時,你的瀏覽器會向 GBIF 查詢該物種的生長型,以便在記錄表單中顯示已有記載。只會傳送物種識別碼,不會傳送你的位置、照片或任何與你有關的資訊。自己手動輸入的名稱不會觸發此查詢。
- Open-Meteo——當你按下定位按鈕時,地圖會顯示你所在位置的天氣。你的位置會被精確到約一公里後傳送給 Open-Meteo 以查詢天氣預報。該請求由我們的伺服器發出,而非你的瀏覽器,因此對方既不會取得你的網路位址,也不會取得任何可識別你的資訊,且不會留存。此事僅在你按下定位時發生,不會在背景進行;你也可以在設定 → 天氣中將其關閉。在「我的物種」或「全部記錄」中按下植物旁的溫度計按鈕,也會經由我們的伺服器向 Open-Meteo 查詢該年份在植物記錄位置(精確到約十公里)的氣溫——絕不會是你的位置。
8. 保存多久,以及如何要求刪除
紀錄在項目運行期間予以保存。從未記錄任何內容的帳戶可能在一段時間不活躍後被移除。
你可以隨時在設定 → 刪除帳號中自行刪除帳號。你的登入會被關閉,署名會被移除;你的觀察紀錄會保留在專案中,署名為 "Account deleted",因為移除它們會在其他人工作所依賴的序列中留下空缺。之後再註冊,將得到一個不含這些紀錄的新帳號。
請寫信至 phenomap@cpelab.net,以查閱我們持有關於你的哪些資料、更正它,或要求連同帳號一併刪除你的紀錄。請給予合理的處理時間——這是個人項目,並非配備人手的服務。刪除的限制見第 6 節:已依 CC-BY 發布的內容可能已被複製。
9. 年齡
你必須年滿 16 歲才能開立帳戶。如你認為有未滿 16 歲者已註冊,請寫信至上述地址,該帳戶將被移除。
10. 涉及人物的照片
請勿上傳可辨識出個人的照片,除非該人已同意。包含可辨識人物的紀錄將被移除。
11. 變更
本聲明有版本編號。若發生實質變更,我們會在你繼續貢獻之前請你重新閱讀。你所同意的版本會與你的帳戶一同記錄。