Last updated 4 September 2026. Bunting is operated by Rivolu LLC.
Your account. An email address, and a display name if you set one. An account exists so your journal reaches your other devices and survives a lost phone.
Your sightings. The species, count, date and time, any notes you write, any photographs you attach, and the location where you logged them. This is the journal itself — it is the thing the app is for.
Your outings. If you record a trail, the route you walked. Trails are recorded only while a session is running and only if you turn the option on.
The waitlist. If you join the list on this website, the name, email address, city and birding frequency you type into that form. They are used to send you an invite when Bunting is available in your area, and to decide which areas to open next — the phone you tell us about decides whether that invite is an App Store or a Google Play link. We ask for a city, not a street address. Joining the list does not sign you up to a newsletter, and your email address is not passed on.
Usage counts. How many birds and species you log, whether each was entered by voice or by typing, and how long the app is open each day. These are counts and durations, used to understand which parts of the app are worth improving. They contain nothing about which birds you saw or where.
Voice recordings. Only if you use “Report a Bug” in voice mode and leave the audio switched on in that report, which sends the recordings from the attempts that went wrong, once, because you asked. Set out below.
Speech is turned into text by Apple's or Android's on-device recognition. No recording leaves your phone unless you file a bug report in voice mode with the audio left switched on.
If you connect an eBird API key, it stays on your phone. It is never sent to our servers, so we cannot read it, recover it for you, or use it on your behalf; requests to eBird are made from your device, with your key, against your own quota. Removing it in the app is the whole of it — there is nothing on our side to delete.
We do not use advertising identifiers, and there are no third-party analytics or advertising SDKs in the app.
Recordings leave your phone in one case only: when you use Report a Bug in voice mode and leave the audio switched on in that report. Voice mode listens in order to work, and what it hears is turned into text on the device; none of it is sent anywhere unless you file a report, and a report with the audio switched off sends no recordings at all.
A report sends the attempts since the last bird you logged successfully — the run that went wrong — together with whatever you write about what you expected. Nothing is sent until you tap Send, it is sent once, and you can turn the recordings off in the report and send only the words.
Recordings are stored against your account. That is what makes “delete my recordings” work from anywhere, and what makes deleting your account take them with it.
A voice is identifying in itself. Anyone holding these recordings and a separate sample of your speech could match them. That is true of any voice recording, and is why nothing is sent unless you file a report, and why what you have sent can be emptied whenever you want.
Recordings are used to measure and improve speech recognition. They are not used to build a profile of you, are not shown to other birders, and are not shared outside the people working on the app.
“Delete my voice data” in the app’s settings removes every recording on your account, whichever device sent it, along with any report on the phone that has not gone yet.
You can do it from any device you are signed in on, and it does not matter whether you have reinstalled the app since. Deleting your Bunting account removes them too, without a separate step.
Location is used to place your sightings on a map, to record a trail when you ask for one, and to find birds reported near you. Precise coordinates are stored in your own journal and shown only to you.
When you choose to share an outing, the location published with it is coarsened to approximately one kilometre. Photographs are re-encoded on upload, which strips the GPS coordinates cameras embed in them. A nest site or a roost stays where you found it.
Other birders see only what you publish, and publishing is always a separate, deliberate step from writing your journal. Nothing you log is shared by default.
We use Apple (sign-in, push, App Store), Google (Play distribution), Railway (hosting and database), Cloudflare R2 (photo storage), Vercel (this website) and Resend (email delivery) to run the service. They process data on our behalf and are not permitted to use it for anything else. We do not sell data, and there is nothing to sell it to.
Your journal is kept until you delete it. Deleting your account removes your sightings, outings, photographs and account record from our systems.
Voice recordings from a bug report are kept until you delete them, either on their own or by deleting your account, which removes them with everything else.
Waitlist entries are kept until Bunting opens in your area and we have written to you, or until you ask us to remove you — whichever comes first.
Export everything you have logged from within the app, at any time, in a form other software can read. Ask us to delete your account and we will. Location permission can be withdrawn in your phone's settings; the journal continues to work without it, with sightings simply carrying no coordinates.
Recordings are sent only when you file a bug report, and only if you leave the audio switched on in it, so there is nothing running in the background to switch off. Deleting what you have already sent is a button in Settings, under Delete my data.
Bunting is not directed at children under 13 and we do not knowingly collect their information.
If this policy changes in a way that affects what we collect or who sees it, we will say so in the app rather than only here.
Privacy questions and deletion requests: admin@rivolu.com. Anything else: support@heybunting.com.