Privacy
Last updated: 2026-08-04
Short version: UFFDA knows your email and what you type into forms. That's mostly it. We don't run ads, don't sell your data, don't run analytics or tracking cookies of our own, and don't use your account or contact data to train models. Things you actively contribute — field boundaries, submissions, feedback — may help improve UFFDA.
◆ The short version
- We collect your email when you sign in or send us anything, and whatever you choose to write into a form. That's mostly it.
- No tracking cookies of ours. No analytics. No advertising pixels.
- Maps and address search load from other organizations' servers. Those servers see the internet address your device connects from, and what you asked for. Section 5 names every one of them.
- The typefaces this site is set in come from our own server. Reading a page doesn't tell a font company you were here.
- We use Supabase, Netlify, and Resend to run the site and send email. All US-based.
- Email hello@uffda.ag to see, correct, or delete what we have on you. You can also delete your account from your profile page — it asks whether to leave the field boundaries you contributed on the map or delete them with the account.
Detail below for anyone who wants it.
1. What we collect
- Email address — when you sign in, request access, redeem an invite, send a contact note, or suggest a source.
- Sign-in password — only if you choose to set one. Signing in by emailed link is the default and always works; a password is optional. Supabase, our sign-in provider, stores it scrambled (hashed) — UFFDA never stores or sees the password you typed.
- What you write into a form — name, role, organization, location, message text, dataset URL. We collect what you give us; everything is optional unless the form marks it.
- Account profile (Pioneers only) — handle and any profile fields you fill in.
- Saved selections (Pioneers only) — if you save a group of fields, we store the field IDs and the name you chose.
- Field boundaries you confirm or fix (Pioneers only) — the shape you save, its version history, any note you write with it, and whether you left the “OK to add to the open map” switch on. Section 6 covers this in full.
- Server logs — the internet address your device connects from (its IP address), browser type, page requested, timestamp. Standard. Used for keeping the site running and catching abuse. Held briefly (see section 8).
- Browser preferences (local, not sent to us) — theme, layer-drawer state, unit toggle. These live in your browser, not on our servers.
- Your sasquatch sightings count — browser-local — also shown on your profile page. Lives in your browser, not on our servers.
- Your tractorsquatch rides count — browser-local — also shown on your profile page. Lives in your browser, not on our servers.
What we don't collect: precise location, payment info, biometrics, anything from a third-party tracker, anything you didn't give us.
2. Why we use it
- To run the site: keep you signed in, remember saved farms, show you the map.
- To reply when you write to us.
- To send account notices you actually need (an invite, a sign-in link, something that affects you directly).
- To debug, stay secure, and catch abuse.
- To respond to data requests from you.
What we don't use it for: advertising (we run none), selling or sharing for marketing (we do neither), or training models on your account or contact data.
If you contribute something actively — a field boundary, a source suggestion, a correction — we may use that to improve UFFDA's tools and data.
3. Cookies and tracking
UFFDA runs no tracking cookies, no analytics service, and no advertising pixels.
That covers what we run. It isn't a claim that nobody else sees you here: loading a page pulls map tiles, weather, and address results from other organizations' servers, and each of those sees the internet address your device connects from. Section 5 names every one and says what it receives.
On our own side we do use:
- A session entry in browser local storage so you stay signed in. Strictly necessary.
- Browser local storage for UI preferences (theme, units, layer state). These don't leave your machine.
We run no tracking of our own, so a Do Not Track or Global Privacy Control signal has nothing on our side to act on.
4. Who handles your data on our behalf
These companies hold or move your data for us, on our instructions. They are not the same thing as the outside services your browser talks to directly — those are in section 5.
- Supabase — database and authentication. US-hosted. supabase.com/legal/dpa
- Netlify — static hosting and global CDN. US-based. netlify.com/privacy
- Resend — transactional email. US-hosted, EU-US Data Privacy Framework certified. resend.com/legal/dpa
- GitHub — code repositories. Not used for processing your personal data.
If we add another processor, we'll update this page first.
5. Outside services your browser contacts
These aren't working for us and aren't holding your account data. Your browser fetches from them directly while a page loads, which means each one sees the internet address your device connects from and what you asked it for — a map tile, a weather reading, an address lookup. We don't control what they keep.
- Esri — the satellite basemap — the default background on the map. Sees which map tiles you're looking at, which is roughly where you're looking.
- The US Geological Survey (The National Map) — the hybrid and topographic basemaps, if you switch to them.
- OpenStreetMap Foundation — the streets basemap, if you switch to it.
- Terrascope, run by the Belgian research institute VITO — the European Space Agency's WorldCover and WorldCereal land-cover layers, if you turn one on.
- MapLibre demo server — the fonts used for labels drawn on the map itself.
- Hugging Face — the map tiles behind the irrigated-fields layer, which are too big to serve from our own host.
- Source Cooperative (on Amazon Web Services) and a Microsoft Azure host — the Fields of The World boundary tiles.
- Open-Meteo — the weather shown on a field card. Receives the location it's fetching weather for.
- US Census Bureau geocoder and Nominatim (OpenStreetMap Foundation) — address search, and only when you use it. Worth naming plainly: these receive the address you type, which is more revealing than a map tile.
If we wire up another outside service, it gets added here in the same release.
6. Field boundaries you contribute
Field Lab is the part of the map where a Pioneer can confirm a field's shape, redraw it, or split it into the pieces it really is. When you save, we store the shape itself, its version history, any note you typed, and the setting of the “OK to add to the open map” switch.
That switch starts on. Leaving it on records that you're fine with the boundary being published openly. Turning it off before you save keeps the boundary visible only to you. Either way, nothing has been published yet — there is no open-map release running today. If that changes, we'll say so on the site before it does, not after.
Saved boundaries stay with the field record, so deleting your account asks you what to do with them. Your notes and your review history go either way.
- Leave them on the map — the option we start you on. The shape and its version history stay in the field record; your account comes off it.
- Delete them too — a field goes only if you're the only Pioneer who ever touched it — shape, version history, the lot. If someone else drew, saved or reviewed it, or it's tied to a field that's staying, it stays.
For a single boundary — one you want out without closing your account, or one that stayed behind — email hello@uffda.ag and we'll sort it by hand.
7. Where your data lives
Primarily in the United States — Supabase and Resend are US-based; Netlify uses a global CDN. For EU/UK transfer-safeguard details (SCCs, DPF certifications), email hello@uffda.ag.
8. How long we hold it
- Account data — for the life of your account. When you delete, your sign-in, your notes and your review history go; contributed field boundaries follow the choice you make at deletion (section 6). Some backups age out within a short window.
- Server logs — short. They roll off within weeks.
- Contact notes, access requests, source submissions — as long as they're useful for triage. Email us to delete a specific one.
- Anything we're legally required to hold — only as long as required.
9. Your rights
Wherever you are, you can see what we have on you, correct what's wrong, and delete it. Email hello@uffda.ag with the subject “Data request.” We may ask you to confirm you control the email on file. We'll respond within a month, sooner where law (GDPR, CCPA) requires.
You can also delete your account directly from your profile page. That flow asks what you want done with any field boundaries you contributed — section 6 spells out both answers.
If you're in California: you have the rights above plus the right to opt out of sale or sharing (we do neither) and the right to limit use of sensitive personal information (we collect none beyond auth credentials). We don't discriminate for exercising any of these.
If you're in the EU or UK: GDPR and UK GDPR cover you. Lawful bases: (a) contract — running your account; (b) legitimate interests — basic operation, security, replying to messages; (c) consent where you gave it. You can withdraw consent at any time and complain to your local data-protection authority.
10. Children
UFFDA isn't built for kids. We don't knowingly collect data from anyone under 13 (COPPA) or under 16 (GDPR). If you think a child has signed up, email hello@uffda.ag.
11. Security
HTTPS everywhere. Data encrypted in transit. Signing in by emailed link is the default, so most accounts have no password at all. If you set one, Supabase — the service that runs our sign-in — stores it scrambled (hashed); UFFDA never holds your password in readable form. If a breach affects you, we'll tell you what happened and what to do as quickly as we can.
12. Successor entity
UFFDA is currently run by a person, not a company. When a formal entity is set up to run UFFDA, your data transfers under the same commitments. We'll update this page and post a site-wide notice.
13. Changes to this notice
We'll update this notice as the site changes. When something material changes we'll post a notice on the site; check back if you care about the specifics.
14. Contact
Questions, data requests, security disclosures: hello@uffda.ag. We read every message.