Privacy Policy
1. Who we are and what this policy covers
MyLittleBigFarm is a livestock-records and farm-management app operated by MyLittleBigFarm, a sole proprietorship based in Saskatchewan, Canada. In this policy, “we,” “us,” and “our” mean MyLittleBigFarm.
This policy explains how we handle personal information when you use the MyLittleBigFarm mobile app and its connected services. It covers the information you provide, information generated while the app operates, and information processed by the service providers identified below. It does not cover information handled by a third party after you deliberately export, print, share, or send it outside the app.
2. Information we collect and why
| Category | What it includes | Why we use it |
|---|---|---|
| Account and authentication information | Your email address, password when you use email sign-in, one-time email codes, account identifier, display name, farm name, authentication-session information, and account-recovery information. If you choose Sign in with Apple or Google Sign-In, this can also include the provider identity token and provider-supplied name or email information where the provider makes it available. | Create and secure your account, sign you in, recover access, personalize your profile, and operate cloud sync. |
| Farm, animal, and operational records | Information you enter about your farm and animals, such as animal names, tags and official IDs, breed, birth and status information, notes, health, breeding, heat, weight, feed, milk, body-condition, movement, loss, pasture, task, inventory, expense, and related records. Some records may contain financial amounts, location labels, or free-form notes. | Provide livestock record-keeping, planning, reminders, reports, and optional cloud synchronization. |
| Contacts and visit information you enter | Names, business/contact details, notes, and visit, transport, equipment, or biosecurity details you choose to record about veterinarians, suppliers, customers, visitors, or other contacts. | Help you keep farm-related contact and operational records. You are responsible for having authority to enter another person’s information. |
| Photos, documents, and other content | Animal profile and gallery photos you select, photo captions and metadata, pasture/map images, and document information or text you import. A photo or document can contain personal information if you include it. | Display and organize the records you choose to keep. Only animal profile and gallery photos are designed to upload to the private cloud-photo bucket when cloud sync is active. |
| Weather location information | A place name you search for, the selected location label, latitude and longitude, and a locally cached weather forecast. | Find and show a farm weather forecast when you choose to use that optional feature. |
| Subscription information | Available subscription offerings, purchase and restore results, transaction/receipt-related information made available through Apple and RevenueCat, and resulting entitlement status. Apple processes payment-card information; the app does not collect payment-card numbers. | Offer, verify, restore, and provide paid subscription access. |
| Device and service information | App settings, local reminder preferences and notification content, technical authentication and sync information, and ordinary network-request information that service providers receive when the app connects to them, such as IP address and connection/device metadata. | Operate the app, maintain a local offline experience, schedule local reminders, troubleshoot service issues, and protect accounts and services. |
| Support communications | Information you include if you contact us by email, including your email address and message. | Respond to your request, provide support, and administer privacy requests. |
3. Choices and permissions
- You may use a local-only mode. In that mode, farm records remain on the device instead of being cloud-synced.
- The app asks for photo-library access only when you choose a photo, and camera access only when you choose to scan an ear tag or use a camera-enabled feature.
- The app does not request device GPS/location permission. Weather location is entered or selected by you.
- Notifications are optional. The app schedules farm reminders locally on your device and does not register you for remote push notifications in the reviewed code.
- You can sign out, remove optional permissions in device settings, stop using weather features, or delete your account as described below.
The app does not use advertising or behavioural-analytics services, and we do not sell or rent personal information or use it for cross-context behavioural advertising.
4. Where information is stored
The app is designed for offline use. It stores farm data, settings, selected files, and cached information on your device. Core cloud-synced farm records are also stored and synchronized through Supabase and PowerSync when you are signed in and cloud sync is active. Contacts/visit-operation records, weather settings, original imported document files, pasture map images, and locally created exports may remain only on your device in the current app design; document metadata or text may be synchronized even when the original imported file is not.
On native devices, the app uses the platform secure storage service (iOS Keychain) for its normal Supabase authentication-session storage and for the Apple refresh token used for account-deletion revocation. If secure storage is temporarily unavailable, the session may be kept in standard app storage on the device until it can be moved back into secure storage, and sessions saved by older app versions are moved into secure storage when the app next reads them. The app does not app-encrypt ordinary local farm records, local SQLite data, local files, or exports at rest. Protect your device with a passcode or other device security, and treat exports and backups as sensitive.
5. Service providers and disclosures
We use the following providers to operate the features you choose. They process information only for the services described here and under their own applicable terms and privacy practices.
| Provider | When used | Information involved |
|---|---|---|
| Supabase | Account authentication, database services, private cloud storage, and Apple-account deletion functions. | Email/authentication information; account identifiers; profile and farm information; cloud-synced core farm records; private animal-photo files and metadata; and the authentication token needed for service requests. |
| PowerSync (JourneyApps) | Cloud synchronization on supported native devices when cloud sync is active. | A current Supabase access token and the account-scoped core farm records that are synchronized between the device and cloud service. |
| Apple | Sign in with Apple, App Store purchases, and Apple-token revocation on account deletion. | For Apple sign-in, Apple identity/authorization information. For purchases, Apple ID billing and transaction information handled by Apple. For deletion, an available Apple refresh token is sent to Apple’s revocation endpoint by an authenticated server function. We do not collect payment-card numbers. |
| Only if you choose Google Sign-In. | Google authenticates you and provides an identity token; the app may use provider-supplied name fields to fill an empty profile name, then sends the identity token to Supabase for account authentication. | |
| RevenueCat | iOS subscription offerings, purchase/restore actions, and subscription-entitlement status. | Offering, purchase, restore, StoreKit/receipt-related, and entitlement information needed for subscriptions. The app does not pass your Supabase user ID or email to RevenueCat, but the RevenueCat SDK may process an anonymous app-user identifier and app/device or transaction information. According to RevenueCat, its SDK collects purchase history, device type and operating system, the time the app was last used, and the Apple receipt. RevenueCat stores this data on Amazon Web Services in the United States, and its subprocessors (including AWS, Snowflake, Google, Cloudflare, Elastic, and Sentry) are located in the United States. |
| Open-Meteo | Only if you search for a farm location or request a forecast. | The place-name search text and the selected latitude/longitude used in a forecast request. The app does not send your account email or Supabase ID in those requests, although Open-Meteo receives ordinary network-request information. Open-Meteo keeps web-server logs, which may include the request IP address and coordinates, for 90 days and then deletes them. |
We do not make your core farm records or private animal photos available to other MyLittleBigFarm users. The app’s supplied database/storage rules are designed to limit access to the account owner, and animal photos use a private, owner-prefixed storage path.
We may disclose information when required by law, to protect rights, safety, or security, or in connection with a business transaction such as a sale or reorganization. If you choose to export, print, email, or share a file, the recipient and sharing service you choose handle that copy under their own policies.
6. International and cross-border processing
We operate from Saskatchewan, Canada, while the providers above may process information in Canada, the United States, and other jurisdictions in which they or their subprocessors operate. Information handled outside your province or country may be subject to the laws, courts, law-enforcement agencies, or national-security authorities of that jurisdiction.
- Supabase: our project is hosted in the United States (US West / Oregon). Supabase’s Data Processing Addendum applies under its terms of service, and its current subprocessor list is published at supabase.com/legal/customer-resources/subprocessor-list. On our current Supabase plan there are no provider-managed daily database backups, and Supabase platform logs are retained for 1 day.
- PowerSync: PowerSync Cloud runs on Amazon Web Services with MongoDB Atlas storage in the United States. It keeps a synchronized copy of the records it syncs, including recent change history, for as long as needed to operate synchronization. PowerSync’s administrative subprocessors (SendGrid, Twilio, HubSpot, and Supabase) are located in the United States; its Data Processing Addendum and subprocessor list are published at powersync.com/legal/subprocessors.
- RevenueCat: subscription data is processed on Amazon Web Services in the United States by RevenueCat and its United States-based subprocessors under RevenueCat’s Data Processing Addendum. RevenueCat retains that data for as long as we hold a RevenueCat account and, on request after termination, destroys it within 30 days subject to its standard backup and archival practices.
We remain responsible for personal information under our control when we use processors and will use safeguards appropriate to the sensitivity of the information.
7. Retention and account deletion
We keep account and cloud-synced data while your account is active, and only as long afterward as necessary to operate the service, address security or support issues, meet legal obligations, or resolve disputes. Cloud-synced records and photos are kept until you delete them or delete your account. Copies may persist for a limited time afterwards: Supabase platform logs are retained for 1 day and there are currently no provider-managed database backups; PowerSync’s synchronized copy is updated to reflect deletions as part of normal sync and is retained only as long as needed to operate synchronization; Open-Meteo deletes its request logs after 90 days; RevenueCat keeps subscription records for as long as we hold a RevenueCat account; and support email is kept only as long as needed to handle your request and any follow-up or complaint, and to meet legal obligations.
You can delete your account in the app through More → Account → Delete account. The app asks you to confirm, then deletes the account through Supabase and removes account-scoped private animal-photo objects. It next attempts to wipe local app data, including local databases, local photos, imported files, caches, auth information, and the stored Apple refresh token. If local cleanup cannot complete, the app tells you so and you may need to remove the app or clear its data.
For an Apple-authenticated account with an available stored Apple revocation token, the app calls an authenticated server function to revoke Apple authorization before deleting the account. If revocation cannot be completed, deletion is not started so you can retry, and you can also remove MyLittleBigFarm from your Apple Account’s Sign in with Apple settings yourself. Older Apple sessions without a stored revocation token may be deleted with instructions to remove the app from your Apple Account’s Sign in with Apple settings. Deleting your MyLittleBigFarm account does not cancel an App Store subscription. Exports, printouts, shared files, and copies held by other services are outside our control and must be deleted separately.
8. Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information. The app communicates with the hosted providers named above over HTTPS. Its supplied Supabase schema uses account-scoped row-level-security rules, and its animal-photo bucket is designed to be private and owner-scoped. Native authentication and Apple revocation tokens are stored using platform secure storage as described above.
No system is perfectly secure. You should protect your device, account credentials, and exported files. Please do not enter passwords or unrelated secrets in free-form notes. If you believe your account or information has been compromised, contact the Privacy Officer promptly.
9. Your privacy rights and choices
Subject to applicable law, you may ask us to confirm whether we hold personal information about you; request access to it; ask that inaccurate or incomplete information be corrected; request deletion; request a copy or export where available; withdraw consent for optional processing; or complain about our privacy practices. We may need to verify your identity before responding. We will not discriminate against you for exercising rights available under applicable privacy law.
You can correct much of your farm information directly in the app. For account deletion, use the in-app process described above. For an access, correction, deletion, portability, or privacy complaint request, contact the Privacy Officer and identify the account email and request type. Quebec residents may request access and correction and, where applicable, a structured, commonly used copy of computerized personal information collected from them. Residents of the United States may have additional rights under applicable state law. We may take reasonable steps to verify your identity before acting on a request, will respond within the time required by applicable law, and will explain the reasons for any refusal.
You may also raise a concern with the Office of the Privacy Commissioner of Canada or, for Quebec matters, the Commission d’accès à l’information du Québec, as applicable.
10. Children’s privacy
MyLittleBigFarm is rated 4+ in the App Store but is a farm-management tool intended for adults and is not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information without appropriate authorization, contact us so we can review and delete it where appropriate. The minimum age to use MyLittleBigFarm is 13.
11. Privacy Officer and contact
Privacy Officer: the MyLittleBigFarm Privacy Officer (the owner of MyLittleBigFarm)
Email:
support@mylittlebigfarm.com
Mailing address: available on request via support@mylittlebigfarm.com
This contact is responsible for receiving and handling privacy requests and complaints. For Quebec users, the Privacy Officer is the person responsible for the protection of personal information unless that function has been validly delegated in writing.
12. Changes to this policy
We may update this policy when our practices, providers, or legal obligations change. We will post the revised policy here, update its effective date, and provide additional notice when required by law.