Herpository

Herpository Privacy Policy

Effective dateSeptember 5, 2026
Version2026-09-05-us-only-vendors-public-feedback

This policy explains what information Herpository ("the app", "we", "us") collects, why, and what rights you have over it. Herpository is operated by Herpository LLC ("the Developer"), 146 Woodside Rd, Simpsonville, SC 29680, United States. If you have questions, contact support@herpository.app.

1. Information We Collect

Account and service-region information. Your email address, email-verification status, United States or outside-United-States residence selection and attestation time, and a securely hashed password (we never store or see your plain-text password). Verification and password-reset links use securely generated, single-use tokens that expire. We collect only the service-region selection needed to enforce current availability, not a precise location.

Security information. We process your IP address and basic browser or app identification during requests to limit abuse. Sign-in sessions also record the associated IP address, browser or app identification, creation time, and recent activity so sessions can be revoked and suspicious access can be investigated. On the web, a strictly functional cookie stores only a yes-or-no sign-in hint so herpository.app can send a signed-in browser directly to the app. It does not contain your token, email address, user ID, or animal data.

Billing information. If paid billing is enabled and you subscribe to Premium or Breeder, the payment provider depends on where you purchase. Herpository stores or receives the provider and store, customer and subscription identifiers, product and price identifiers, transaction identifiers, entitlement and payment status, billing-country result, and renewal, trial, expiration, cancellation, refund, and dispute information. Stripe receives your email address, billing name and address, payment credentials, tax-related information when enabled, and a Herpository account identifier directly through Stripe Checkout. For native purchases, Apple or Google receives payment credentials and billing information, while RevenueCat receives a pseudonymous Herpository account identifier plus app, store, product, purchase, transaction, subscription, and entitlement information needed to validate and restore access. Herpository does not receive or store your complete card, bank account, or app-store payment credentials.

Content you create. Information you enter about your animals and their care: names, species, morphs, dates, vivarium details, and logs (feeding, weight, shedding, health, behavior, cleaning, environment readings, and breeding records). This is the core data the app is built to store on your behalf.

Photos and custom images. If you add a profile photo, animal photo, vivarium photo, animal gallery photo, or custom dashboard banner, the image is uploaded to our cloud image provider so it can appear across your devices. These images are private by default and delivered through time-limited signed links. If you place an animal on a public Animals For Sale page, that animal's profile photo is intentionally made visible on the public listing for as long as the listing remains enabled.

Public listing contact information. When you enable your public Animals For Sale page, the separate contact information you enter for that listing is intentionally published so visitors can contact you. You may provide an email address, an HTTPS page, or other contact instructions. Your Herpository account email is not published unless you choose to enter that same address as your public contact. The page also publishes the animal details and photos you choose to list. Anyone with the public link may view, copy, or share that information. Disabling the listing removes it from the current Herpository page, but it cannot remove copies or screenshots previously made by other people.

Feedback you submit. If you use the in-app or public website feedback form, we collect the category you select, your message, an email address for follow-up, and basic technical context such as device platform, operating-system or browser information, and app version. The public form also requires the same United States-residency attestation used for current service availability.

Listing safety information. If you report a listing or seller, we collect the report category, details, listing and animal identifiers, an optional contact email, and any records you later provide. We record moderation decisions, takedowns, seller listing suspensions, appeals, and user blocks. Public visitors who block a seller receive a browser cookie that stores only the blocked seller identifier. Signed-in blocks are stored with the account.

Usage information. We collect lightweight, first-party usage events -- which screens of the app you open and when -- so we can understand which features are used and prioritize improvements. We do not track your activity outside this app, and we do not use this data for advertising.

Notification information. If you allow push notifications, we store an Expo push token associated with your account and device platform. We use your reminder settings and care dates to schedule feeding and UVB-replacement notifications. The token identifies an app installation for message delivery; it does not give us access to other content on your device.

We do not collect: your complete payment card or bank account number, precise location, contacts, or data from other apps or websites.

2. Why We Collect It

• To provide the core functionality of the app (storing and displaying your animal-care records).

• To respond to feedback and bug reports you submit.

• To understand which features are used, so we know where to focus development effort.

• To deliver feeding and UVB-replacement reminders you have enabled.

• To verify account email addresses and deliver password-reset links.

• To confirm that an account is eligible for the service's current United States-only availability.

• To process paid-plan purchases, maintain subscription status, restore purchases, and provide billing support.

• To filter public listing content, investigate reports, prevent abusive users from reappearing, communicate outcomes, and enforce the Terms of Service.

• To maintain the security and reliability of the service.

3. United States Availability

Herpository is currently offered only to United States residents and uses a residence attestation to enforce that limitation. We do not offer localized storefronts, currencies, advertising, or promotions outside the United States. An account created before this restriction may confirm United States residence or, if the account holder resides elsewhere, use a limited offboarding mode to export information, manage an existing subscription, log out, or delete the account.

We do not use service-region information for advertising and do not send marketing or advertising messages.

4. Who We Share Data With

We do not sell your data, and we do not share it for advertising purposes. We use the following service providers ("processors") to operate the app:

Render -- runs the backend and stores the primary application database, including account, animal-care, billing-entitlement, and moderation information.

Cloudflare Images -- stores, processes, and delivers photos and custom images you upload. Private images are delivered using signed links; an animal's profile photo is visible to visitors when you publish that animal on a public Animals For Sale page.

Cloudflare R2 -- stores database backup files used for disaster recovery. Backups are transferred over HTTPS/TLS and R2 encrypts stored objects at rest. A backup can contain the database information that existed when the backup was made.

Stripe -- processes web subscription payments when paid billing is enabled. Stripe receives your email, billing name and address, payment credentials, customer and account identifiers, selected product and price, subscription state, transaction information, and refund or dispute information needed to provide billing and reject non-US billing countries.

Apple App Store and Google Play -- process native-app purchases when enabled and receive payment and store-account information directly. Herpository receives product, transaction, subscription, and entitlement information but not complete store payment credentials.

RevenueCat -- connects native purchases to the correct Herpository account and validates, restores, and reports Apple and Google entitlements. It receives a pseudonymous Herpository account identifier and app, device-platform, store, offering, product, transaction, subscription, trial, renewal, expiration, and entitlement information.

Sentry -- receives technical error and performance diagnostics such as stack traces, affected app or server route, app/browser/device and operating-system details, release and environment, and in some server reports the internal Herpository user identifier. Sentry is configured not to collect default personal information, but diagnostic context can still contain information needed to investigate a failure.

Expo/EAS -- delivers app updates and build infrastructure.

Expo Push Service, Apple Push Notification service, and Firebase Cloud Messaging -- route notification messages to devices when push notifications are enabled.

Resend -- sends account-verification, password-reset, listing-report, moderation, and other service emails. Resend receives the destination email address, message content, and delivery metadata needed to send those messages.

Atlassian (Jira) -- when you submit feedback through the in-app or public website feedback form and the Developer has configured this integration, your feedback message, category, follow-up email address, and basic app, device, operating-system, or browser context are forwarded to the Developer's Jira workspace for tracking.

These providers handle information under their applicable agreements and privacy terms. Some providers, particularly payment platforms and app stores, may also process limited information for their own legal, fraud-prevention, security, tax, and platform-administration purposes.

5. Data Retention

We retain your account, active sign-in sessions, animal-care data, and uploaded images for as long as your account is active. Expired or revoked sign-in sessions are periodically removed. Replacing or deleting an image removes the corresponding cloud image. User blocks are removed when the blocking or blocked account is deleted.

Listing reports and a limited moderation audit record may be retained for up to two years after resolution, including after an associated account or animal is deleted, when reasonably needed to prevent repeat abuse, document our response, resolve an appeal, address fraud or animal-welfare concerns, or comply with law. We minimize retained snapshots and do not use them for advertising.

Database backups are created for disaster recovery and are automatically deleted when they are more than 30 days old. Deleting an account removes it from active systems after connected-provider cleanup completes, but information already present in a backup may remain until that backup expires. Backups are not restored except for disaster recovery and any restored deletion request will be reapplied where reasonably possible.

Authenticated deletion from the Account tab permanently removes the account and associated data from Herpository's active systems after connected service-provider cleanup completes. This includes uploaded images, animal and care records, breeding records, public listings, shared documents, feedback submissions, usage events, reminders, push tokens, user blocks, and ordinary local subscription-entitlement records. Limited moderation and payment records may be retained as described above or when required by law. If a Stripe customer exists, deletion removes that customer and cancels any active Stripe-processed Herpository subscription. Apple and Google control subscriptions purchased through their stores, so deleting a Herpository account does not itself cancel an App Store or Google Play subscription. Cancel a store subscription through the applicable store before deleting your account. Stripe, Apple, and Google may retain limited transaction records for financial reporting, fraud prevention, refund or dispute handling, or other legal obligations.

You can also request deletion at https://herpository.app/delete-account or by contacting support@herpository.app. Support requests are completed within 30 days after identity verification. We may retain limited information where required by law or necessary for security and fraud prevention, and will not use retained information for other purposes.

6. Your Rights

Depending on the state where you live, you may have rights to access, obtain a portable copy of, correct, or delete personal information and to appeal a denied request. California residents may also have rights to know the categories and sources of personal information collected and how it is used. We do not sell personal information or share it for cross-context behavioral advertising, and we do not discriminate against a person for exercising an applicable privacy right.

To exercise any of these rights, visit https://herpository.app/delete-account or contact us at support@herpository.app. We may need to verify your identity (e.g., confirm you control the account's email address) before acting on a request.

7. Children's Privacy

Herpository is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at support@herpository.app and we will delete it.

8. Security

We use industry-standard measures to protect your data, including encrypted transmission (HTTPS) and secure password hashing. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

9. Processing Locations

Herpository is a United States service. Our providers may process support, diagnostic, security, or payment information from facilities or personnel in other locations as part of operating their global services. Provider access remains limited to the purposes described above and their applicable contractual and legal obligations.

10. Private Listings and Transactions

The app's public for-sale listing feature is provided solely as an advertising and contact tool. The Developer is not a marketplace operator, broker, seller, buyer, auctioneer, payment processor, escrow service, shipping provider, inspector, veterinarian, or party to any private transaction arranged through a listing.

User-provided information is not verified. We do not verify a user's identity, ownership or legal right to sell an animal, or the accuracy of statements about an animal's species, sex, age, morph, genetics, health, temperament, provenance, condition, price, availability, or other listing details. Displaying a listing does not constitute an endorsement, certification, warranty, or guarantee by the Developer.

Buyers and sellers are solely responsible for conducting appropriate due diligence; agreeing to payment, delivery, and refund terms; complying with all applicable animal-welfare, wildlife, import/export, transport, permit, and sales laws; and determining whether a transaction is safe and appropriate. Prospective buyers should independently verify material claims and consider obtaining relevant records or an examination by a qualified reptile veterinarian before completing a sale.

To the fullest extent permitted by law, the Developer is not responsible for private-user conduct or for fraud, scams, misrepresentation, payment or chargeback disputes, shipping problems, injury, disease transmission, escape, loss, death, illegal sales, or any other damage or dispute arising from a listing, communication, meeting, or transaction between users.

11. Changes to This Policy

We may update this policy as the app changes. If we make a material change, we will require you to review and acknowledge the updated policy the next time you open the app before you can continue using it. The effective date at the top of this policy reflects the most recent version.

12. Contact Us

Questions about this policy or your data can be sent to support@herpository.app or mailed to Herpository LLC, 146 Woodside Rd, Simpsonville, SC 29680, United States.