Legal

Privacy Policy

What LizardBox collects, who it goes to, and what happens when you delete your account — written plainly, and true of the app as it ships today.

Last updated

LizardBox is a care tracker for reptiles, amphibians and arachnids. This policy explains what we collect when you use it, why, and what control you have. It covers the marketing site at lizardbox.co, the web app at app.lizardbox.co, and the LizardBox apps for iOS and Android.

LizardBox is built and operated by AJ Esamann. If anything here is unclear, email support@lizardbox.co — a person reads it.

What we collect

Your account. When you sign up we collect:

  • Your first and last name.
  • Your email address and password, or your Google account if you sign in with Google. Credentials are held by Firebase Authentication, a Google service — we never see or store your password.
  • Your device's timezone, so reminders and weekly recaps land at the right local time.

Your preferences. Measurement units, app language, notification settings, favorite species and display choices, all stored against your account.

What you create in the app. This is the bulk of it, and it is yours:

  • Critter profiles — nickname, species, morph, sex, tags, key dates and a photo.
  • Log entries across 35 event types, including free-text notes, weights, measurements and feeding details.
  • Reminders, including their message and which critters or tags they target.
  • Images and files you attach to a log, and the profile photos you upload for a critter.
  • Species corrections, if you report one from a species profile.

Technical data. On iOS and Android, if you leave push notifications on, we store a push token for your device along with whether it is an iOS or Android device — that token is what lets us deliver a reminder. Our servers keep short-lived logs of requests, which include your account identifier and, for reminder and recap emails, the address they were sent to. We also keep counters for the rate limits that protect the service.

Subscription status. Whether you are on Free or Pro, and enough detail to keep that status accurate. Payment card details never touch our systems — see Who we share it with below.

What we don't do

LizardBox runs no analytics, no crash or session recording, no advertising, and no tracking cookies — on the website or in either app. We do not sell your data, do not share it for advertising, and do not build a profile of you. There is no third-party script anywhere on this website.

We say this because it is unusual, and because it constrains us: none of the tools that would quietly change that answer are installed.

How we use what we collect

  • To run the app — store your collection, sync it across your devices, and show it back to you.
  • To send the reminders and weekly recaps you have turned on.
  • To send account emails: verifying your address, resetting your password, confirming an email change, and a single welcome message.
  • To apply plan limits and the rate limits that keep the service affordable to run.
  • To investigate abuse, debug faults and keep the service secure.

We do not use your critters, logs or notes to train AI models, and we do not pass them to anyone except the providers listed below, each of which is doing a specific job on our behalf.

Who we share it with

These are every provider that touches your data, and what each one does:

  • Google (Firebase and Google Cloud) — account authentication, the database holding your collection, file storage for your photos and attachments, our backend, and push notification delivery on mobile. This is where your data lives.
  • Brevo — sends our email. Your address and the contents of that email pass through them.
  • RevenueCat — tracks whether your subscription is active. They receive your LizardBox account identifier, and, if you subscribe through the web app, your email address.
  • Apple and Google — process the payment itself when you subscribe from the iOS or Android app, under their own privacy policies. We never receive your card details.
  • Anthropic — identifies a species from a photo you submit. See the next section.

We may also disclose data if the law requires it, or where it is necessary to protect the rights and safety of our users or ourselves.

Species identification and photos

Species identification is a Pro feature on iOS and Android. When you use it, the photo you take or choose is sent to Anthropic's API, which returns candidate species. We do not store that photo and we do not log it — the image exists only for the length of the request. What we record is limited to a request identifier, your account identifier, how long the request took, which model answered, and its confidence.

Species reference images

Reference photos on species profiles are loaded by your device directly from iNaturalist, an external biodiversity database, rather than served from us. That means iNaturalist can see your IP address and the fact that a request was made when you open a species page. We do not send them anything about your account or your collection.

QR tags are public by design

Every critter has a QR code you can print and put on an enclosure. For a scan to work for whoever is holding the tag — a sitter, a vet, a buyer — that critter's profile has to be readable without signing in, and it is. Anyone with the link sees the photo, nickname, species, morph, sex, tags and key dates for that one animal.

Your logs, notes, reminders, other critters and account details are not reachable from it. Treat the tag as a key: anyone you hand it to can see that profile.

Emails we send, and how to stop them

  • Reminder notifications — only for reminders you created, and only on the channels you chose. Turn email reminders off in Settings.
  • Weekly recap — a Monday summary of the week's logs, for Pro keepers. Turn it off in Settings.
  • Welcome email — sent once, after you verify your address.
  • Account and security emails — address verification, password resets and email-change confirmations. These are not optional while you have an account, because they are how you keep control of it.

We do not send marketing email.

Cookies and local storage

This marketing site sets no cookies, loads no third-party scripts and runs no analytics. Our fonts are served from our own domain rather than a font provider.

The web app stores a few things in your browser so it works the way you left it: your sign-in session, handled by the Firebase SDK; your light or dark theme choice; and your language preference. The mobile apps keep the equivalent on-device. None of it is used for tracking or shared with anyone.

How long we keep it

Your collection stays for as long as your account exists — the point of a care log is that it does not expire. Server logs are short-lived. Rate-limit counters are pruned automatically, or removed when you delete your account.

Exporting your data

You can export everything yourself from Settings, at any time, without asking us. The full JSON export covers your profile, preferences, every critter, every log with its notes and attachment links, and every reminder. You can also export critters, logs or reminders individually as CSV.

Deleting your account

Deleting your account is self-service, in Settings, and it is thorough. We remove your critters, your logs, your reminders, your species reports, your weekly recaps, your device push tokens, your profile and preferences, your usage counters, your subscriber record with RevenueCat, and every file you uploaded. Your login credentials are removed from Firebase Authentication at the same time.

Two honest caveats. Deleting your account does not cancel a subscription bought through Apple or Google — that lives with the store, and you cancel it there. And residual copies can persist in encrypted backups for a short period before those backups age out.

Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, to object to certain processing, and to complain to a data protection authority. In practice the app already gives you most of these directly: you can view and correct everything from Settings, export it in full, and delete it permanently. For anything the app cannot do, email support@lizardbox.co and we will act on it.

We will never charge you for exercising these rights, or treat you differently for doing so.

Children

You must be at least 13 to create an account. Younger keepers are welcome to use LizardBox through an account created and managed by a parent or guardian, who remains the account holder. We do not knowingly collect personal data directly from children under 13. If you believe a child has created their own account, email support@lizardbox.co and we will remove it.

Where your data is processed

Our backend runs in the United States, and our providers may process data in the United States and elsewhere. If you use LizardBox from outside the US, you are sending your data there.

Changes to this policy

If we change how we handle your data, we will update this page and move the date at the top. For a change that materially affects you, we will tell you in the app or by email rather than relying on you to re-read this page.

Contact

Questions, requests or complaints about privacy: email support@lizardbox.co, which reaches AJ Esamann directly.