Privacy
Useful data. Nothing more.
Picchu follows a simple principle: collect the minimum needed and let you decide when a sensitive feature is active.
Last updated: September 14, 2026Location and altitude
When permitted, Picchu uses location to show your position and altitude, find nearby wildlife and summits, record routes and optionally geotag an observation.
Precise coordinates may be sent and linked to your account when you use online identification, sync an observation or geotagged photo, or publish a route export. A published export makes its coordinates, dates and photos available to anyone who has its link.
Background altitude tracking stays off until you enable it. You can revoke permission in iOS Settings.
Camera and photos
The camera opens only from features that need it. Picchu never takes a photo automatically.
If you select an offline model (BioCLIP 2 or BioCLIP 1), the photo is analyzed directly on your device without being sent to Picchu or Modal for that analysis. A connection is needed to download the model and relevant data before using them offline.
In online BioCLIP 2.5 mode, a copy of your selected photo without EXIF metadata is sent to the Picchu server as soon as it is prepared, even before you start identification, to reduce waiting time. During analysis, this copy is sent to Modal, the provider hosting Picchu’s AI model. The Picchu server is hosted on Railway.
The preloaded copy is held temporarily in memory on the Picchu server, not in your account’s photo storage. It is automatically erased no later than 10 minutes after preload, or earlier after use or when the app requests removal. Photos sent for analysis are not automatically added to your observations.
Attaching a photo to an observation is a separate action. Photos you choose to save are re-encoded as JPEG and may be kept in private storage linked to your account until you delete them.
Account
Sign-in provides access to services linked to your account. Picchu stores your email address, a stable account identifier, sign-in providers, and information required for authentication and session security. Passwords are never stored in plain text.
Subscription
Apple processes purchases of the BioCLIP subscription. Picchu receives no payment-card data. To grant access to the correct account, Picchu stores the transaction identifier supplied by Apple, product identifier, subscription status, and its expiration or revocation dates.
Deleting a Picchu account does not automatically cancel the App Store subscription, which must be managed separately with Apple.
History and local storage
Altitude readings, routes and histories displayed in the app are stored locally by default. You can remove them from Picchu. Removing the app also removes data that has not been published or linked to an online service.
Online services
A connection is required for account creation, identification with online BioCLIP 2.5, downloading models or new data, and some saving, syncing and sharing features. Offline models that have already been downloaded can identify a photo without a connection.
For each online identification, Picchu stores in your account the supplied coordinates, country and taxonomic group, top result, prediction list and technical processing-time data. Clearing the history displayed locally in the app does not erase this server record; it is deleted with the account.
Synced observations, reports, private photos and published exports are also linked to your account. Picchu uses Railway for the server and database, Cloudflare R2 for photos and exports, Modal for online BioCLIP processing, Apple for subscriptions and Apple sign-in, and Google if you choose Google sign-in. Public export maps load OpenStreetMap tiles.
Species profiles may include public content and images from sources such as GBIF, iNaturalist, Wikimedia or Wikipedia, with attribution.
Website audience measurement
picchu.app uses a self-hosted Umami instance on Railway to measure viewed pages, traffic sources, approximate country and device type anonymously. It sets no analytics cookie, is not linked to Picchu accounts and is never used for advertising or personal profiling.
An IP address may be used briefly to produce a hashed technical identifier and approximate location, but it is not stored. Anonymous statistics are kept for no more than thirteen months. Search crawlers are counted separately from their technical signature.
Retention and deletion
Preloaded identification photo copies are deleted no later than 10 minutes after preload. Private photos and public exports remain until you delete them. Account data, synced observations, identifications, reports and subscription data remain until account deletion unless a legal duty requires otherwise.
You can delete local readings, photos, exports and your account in the app. Account deletion removes associated active data; temporary technical backups may remain only for the hosting provider’s recovery cycle before being overwritten.
Security
Network exchanges use encrypted connections. Private photos and account data are protected by authentication and short-lived links where appropriate.
Contact
For questions about your data or to exercise your rights, email [email protected].
Your audience measurement choice
Anonymous audience measurement is currently allowed in this browser.
