Privacy Policy
Last updated: 2 Oct 2026
1. What we collect
- Account data: username, email, password (stored as a one-way hash, never as plain text), farm name.
- Operational data: houses, flocks, daily production, feed, prices, and the notes you enter yourself.
- Technical data: sign-in times, browser type in hashed form, and IP address. For long-term records the IP is stored hashed; the raw IP appears only in the sign-in attempt log and is discarded after 30 days.
- Google sign-in (if you use it): your Google account identifier, email, name, and profile photo. We never receive your Google password.
2. What we use it for
- Running the service: storing your records and calculating farm indicators.
- Securing your account: detecting repeated sign-in attempts and suspicious activity.
- Contacting you about the service, billing, or an outage.
- Improving the interface: counting how often each button is seen and clicked per day, without names, emails, accounts or IP addresses.
We do not sell your data, and we do not use your farm data for advertising.
3. Separation between users
Every record is tied to your own account. Every data request is filtered by the account that owns it, so other users cannot see your records. The service operator may open account data for support, security and aggregate statistics; every access is logged and never shared with third parties.
4. How long we keep it
- Operational data is kept for as long as the account is active.
- Items moved to the trash are deleted permanently after 30 days.
- Sign-in attempt logs (which contain raw IP addresses) are discarded after 30 days.
- Security event logs (with the IP already hashed) are kept for auditing, then trimmed periodically.
- Once an account is closed, its data may be deleted permanently. Export it before closing.
5. Third parties
- Hosting provider — stores the database and the application files.
- Cloudflare — filters traffic and absorbs attacks.
- Google — only if you choose to sign in with Google.
- Google Sheets — only if you connect a spreadsheet link yourself.
6. Google Sheets sync — what you need to know
To pull data in, you have to open access to the sheet (publish it as CSV, or share it with anyone who has the link). A link like that can be opened by anyone who holds it. So publish only your daily report sheet — never one containing wages, purchase prices, or personal data. This limitation comes from Google, not from us.
7. Security
- Connections are encrypted with HTTPS.
- Passwords are stored as a one-way hash, and passwords known from public breaches are rejected at sign-up.
- Sessions live in the database, not in a shared temporary directory, and can be revoked. Only a fingerprint of the session is stored, never the identifier itself.
- Third-party secrets are encrypted with a key held outside the database.
No system is completely secure. If you find a weakness, please tell us.
8. Your rights
- View and correct your account details from the Settings page.
- Export your operational data to CSV at any time.
- Request deletion of your account and its data.
- Disconnect Google and go back to using a password.
9. Cookies
We use cookies only for what is necessary: keeping you signed in, remembering your language, and remembering your theme. There are no advertising cookies and no third-party trackers.
10. Children
This service is for business use and is not directed at children under 18.
11. Changes to this policy
Changes are announced on this page, with a new last-updated date.
12. Contact
Email: [email protected] · WhatsApp: +628127654321