Chickadee Privacy Policy
Effective date: July 2026 App: Chickadee, listed as “Camping Checklist & Meal Plan” (the “App”) Who we are: Cedar & Fog Labs, LLC Contact: trust@cedarandfoglabs.com
Summary
- The App is offline-first. By default, everything you enter (your gear, bins, trips, the people you camp with, meals, and recipes) lives only on your device. We cannot see it.
- Sync is an optional premium feature. If you turn it on, a copy of your household’s content is stored on our servers so your linked devices stay in step.
- We collect a small amount of diagnostics and usage data to keep the App working and to improve it. It is never tied to your name, only to a random ID, and you can turn it off in Settings.
- We do not sell your data, and we do not use it to build advertising profiles or track you across other apps.
- You can delete your data at any time.
How the App is built, and why it matters for your privacy
There are no usernames, passwords, or logins. When you enable Sync, your device creates a cryptographic key that stays locked to that device and acts as its identity. A “household” is simply the set of devices you have linked together (for example, your phone and your partner’s phone). Only devices in your household can reach your household’s data.
What data we handle, and where it lives
1. On your device (always). All of your App content is stored locally in a private database: bins and gear, trips, the people on your roster (including any names or details you choose to enter), clothing and packing lists, meals and recipes, grocery and restock lists, maintenance tasks, wishlist and capture notes, and your settings. If you never turn on Sync, this data never leaves your device, and deleting the App removes it. Reminders and notifications are scheduled on your device by the App itself; we do not use push notifications and never collect a push token.
A note on trip destinations: when you pick a campground from the App’s built-in directory, the App stores that campground’s name and its published map coordinates with your trip. The App never asks for or uses your device’s location — coordinates only ever come from the bundled directory, and only when you choose a campground from it. A destination you type yourself is stored as plain text, with no coordinates.
2. On our servers (only if you turn on Sync). Sync stores a copy of your household content (the same categories listed above, including trip destinations and their map coordinates) on our servers so your linked devices stay current. Alongside it we store the minimum needed to run sync: your devices’ public keys, a display name for each device (shown in Settings), a household identifier, timestamps, and a random per-install Diagnostic ID (see below). Your device’s private key is never uploaded.
3. Diagnostics and usage analytics. To keep the App stable and understand how it is used, we collect:
- Crash and error diagnostics through Sentry. We disable personal-data collection, so these reports do not include your IP address or your content, only technical details of the failure.
- Usage events through PostHog (for example, “a trip was created”). We do not use automatic capture, session replay, or location lookup, and we never send your name or email.
Both are tied only to a random Diagnostic ID created on your device at first launch. It is not your name and not your sync key. The same ID accompanies feedback you submit and your household’s sync records; it allows us to locate your data on request without knowing your identity. You can see this ID in Settings, and it is the reference to quote when you contact us.
You can turn all of this off. Settings → Privacy → Share usage data controls both crash diagnostics and usage analytics with a single switch. When it is off, neither is started and nothing is sent. It is on by default because the data contains no name, email address, or account identifier, only the random ID, and you can change it at any time.
4. Optional recovery email (premium). When you activate Sync, we offer (but never require) a recovery email so you can get your household back if you lose your devices. If you provide one, we store it solely to send you a recovery code. We do not use it for marketing. It is sent through Amazon SES.
5. Purchases. The premium unlock is sold and processed by Apple or Google. We use RevenueCat to confirm your purchase. We do not receive your card details. Your purchase is associated with your household identifier so it covers all your linked devices.
6. Feedback and support. If you send feedback from the App, we receive your message and its category, an optional reply email address if you choose to provide one (used solely to respond to you), your Diagnostic ID, the App version, and your platform (iOS or Android). Feedback is deleted from our servers automatically after 30 days. If you email us instead, we receive your email address and the contents of your message, and we retain the correspondence only as long as needed to assist you.
How we use your data
- To run the App and its features.
- To sync your content across the devices in your household, if you enable Sync.
- To keep the App reliable and to diagnose crashes.
- To understand, in aggregate, how the App is used so we can improve it.
- To provide and improve relevant gear and restock suggestions.
- To respond to your support requests and, if you opt in, to help you recover your household.
Analyzing content to improve the App
We may analyze App content and usage in aggregate and in de-identified form to understand how people use the App, to improve features, and to surface relevant gear and restock suggestions. This means we look at patterns across many households, not at you as an individual. We do not build personal advertising profiles and we do not sell your information. Today, your synced content is used only to keep your devices in step; this section reserves the ability to perform aggregate analysis as the product grows, always within the limits described in this policy. We never attempt to re-identify data that has been de-identified.
Security
Your data is encrypted in transit (HTTPS) and encrypted at rest on our servers using our cloud provider’s managed keys. Your device’s private sync key is held in your device’s secure keychain and is never uploaded or included in backups.
To be clear about what this does and does not mean: your synced content is not end-to-end encrypted. We can access it in order to operate the service and to perform the aggregate analysis described above. If you would rather no copy of your content leave your device, do not enable Sync. The App works fully offline without it.
Our servers and service providers maintain routine connection logs, which can include your IP address; our own server logs are deleted after 30 days. If a security incident affects your synced data, we will notify affected users promptly, as applicable law requires.
Who we share data with
We use a small number of service providers to run the App:
- Amazon Web Services (data storage and email delivery)
- Sentry (crash diagnostics)
- PostHog (usage analytics)
- RevenueCat (purchase validation)
- Apple and Google (app purchases)
We share only what each provider needs to perform its function. We do not sell your personal information, and we do not share it for cross-context behavioral advertising or with data brokers.
Where your data is processed
Our servers and service providers process your data in the United States (on Amazon Web Services, US East region). If you use the App from outside the United States, your data is transferred to and processed there.
How long we keep it
- On your device: until you delete it or uninstall the App.
- On our servers (Sync): until you delete your synced data or ask us to.
- Crash reports: deleted after 90 days.
- Usage analytics: retained while needed for trend analysis, identified only by the random Diagnostic ID, then deleted or aggregated.
- Feedback: deleted automatically after 30 days.
- Server logs: deleted after 30 days.
- Recovery email: until you remove it or delete your synced data.
Your choices and rights
You can:
- Keep everything local. Leave Sync off.
- Delete local data. Uninstalling the App removes it from your device.
- Delete synced data. Use “Delete the household’s synced data” in the App, or email us at trust@cedarandfoglabs.com with your Diagnostic ID and we will remove your household’s data from our servers.
- Access, correct, or object. Contact us and we will help you access, correct, or restrict the data we hold.
Depending on where you live, you may have specific rights:
- United States (including California): you may request access to or deletion of your data. We do not sell or share your personal information as state privacy laws define those terms, so opt-out signals such as Global Privacy Control have nothing to opt you out of, and our website sets no tracking cookies. We will not discriminate against you for exercising your rights.
- Mexico: you have ARCO rights (Access, Rectification, Cancellation, and Opposition) and the right to limit the use or disclosure of your data. Contact trust@cedarandfoglabs.com to exercise them.
- Brazil (LGPD): you have rights of access, correction, deletion, portability, and information about how your data is shared. We process diagnostics and usage analytics on the legal basis of legitimate interest; the switch in Settings → Privacy serves as your means to object. Our data protection contact is trust@cedarandfoglabs.com.
- Canada (including Quebec): you may access and correct your data, and Quebec residents also have data portability rights under Law 25. Our privacy contact (trust@cedarandfoglabs.com) serves as the person responsible for the protection of personal information.
- Australia and New Zealand: you may request access to and correction of your data and raise a privacy concern with us at trust@cedarandfoglabs.com. As noted above, your data is processed in the United States.
To exercise any right, email trust@cedarandfoglabs.com and include your Diagnostic ID (shown in Settings) so we can locate the correct records.
Children
The App is made for adults who manage their household’s camping gear. It is not directed at children, and we do not knowingly collect data directly from children. If you choose to record details about family members, including children, that information stays under your control on your device, and within your household if you enable Sync. Please enter only information you are comfortable storing.
Changes to this policy
If we make material changes, we will update the effective date above and notify you in the App before they take effect.
Contact
Cedar & Fog Labs, LLC trust@cedarandfoglabs.com