Legal

Privacy Policy

Last updated: 3 October 2026

This Privacy Policy explains how Flocknest Limited (“FlockNest”, “we”, “us”) collects, uses and protects information when you use our mobile app for Android and iOS, our web app, the web console for farm owners and staff, this website and related services (together, the “Services”). It describes how the product actually works today.

Who we are

Flocknest Limited is a private limited company registered in Nigeria (CAC RC 9879525) under the Companies and Allied Matters Act. You can reach us at support@flocknest.co. We are the data controller for the personal information described in this policy. We handle it in line with the Nigeria Data Protection Act 2023 (NDPA) and, where they apply to you, the EU General Data Protection Regulation (GDPR) and the UK GDPR, as well as any other data protection law that applies where you live.

If you were invited to someone else’s farm, the farm owner decides which farm records are kept and who on the team can see them. Your own account details are ours to look after directly.

Information we collect

  • Account information. We collect your name, email address and farm name when you create an account. Your password is stored only as a secure one-way hash.
  • Farm records. We store the data you enter, including flocks, daily production, bird weights, feed and vaccine inventory, health checks, disease cases and treatments, sales, expenses, budgets, mortality and reminders.
  • Other people’s details in your records. Farm records can include information about other people, such as a buyer’s name, a vet’s name and phone number, or the email address of someone you invite. If you enter it, you are responsible for having a good reason to do so and for letting those people know where their details are kept.
  • Receipt photos. If you attach a photo to an expense, the app asks for access to your camera or photo library. The photo is saved only in FlockNest’s private storage on that device. It is not uploaded to our servers and does not sync to your other devices, so it is not covered by your cloud backup.
  • Device and usage information. We collect the basic technical data needed to run, secure and improve the Services, such as the app version, crash diagnostics and, with your agreement where it is required, in-app usage events and session replays. See “Analytics, session replay and crash reports” below.
  • Notification tokens. If you allow notifications, we store a device token so that reminders and alerts can reach the right phone. Removing the app or signing out retires the token.
  • Location. If you choose to set your farm’s location for weather advice, we store those coordinates: a single point, not a location history. This is optional and can be changed or cleared at any time.
  • Contact-form messages. If you write to us through this website, we receive your name, email address and message, which we email to our support inbox.

What we do not collect. Your fingerprint or face data never leaves your phone. The app lock is handled entirely by your device’s own biometric system, and we never see or store that data. We also never see your card details, because payments are handled by the app stores.

Analytics, session replay and crash reports

Usage analytics (Firebase Analytics) and session replay (Microsoft Clarity) are optional. In the EU/EEA, the UK and Switzerland, and wherever the app cannot tell your region, nothing is collected until you agree. Elsewhere they are on by default, and you can switch them off at any time in the app’s settings. Analytics records event names such as “flock added”, never the contents of your records. Clarity recordings are anonymised, and password, PIN and verification-code fields are masked and never captured.

Crash reporting (Firebase Crashlytics) runs even if you decline analytics. When the app crashes it sends the error details, device model, operating system and app version, so that we can fix problems that would otherwise stop the app working for you, including crashes at startup. It does not capture your farm records.

This website

This marketing website does not use analytics, advertising or tracking cookies, and it loads no third-party tracking scripts. Our hosting provider, Cloudflare, sees your IP address and request details to deliver and protect the site, and uses your approximate country to show prices in your local currency; we do not store it. If our contact form shows a Cloudflare Turnstile check, Turnstile processes signals from your browser to tell people from bots.

How we use your information

We use your information to provide and sync your records across your devices, generate insights and weather advice, send the reminders you ask for, process subscriptions, secure your account, answer your messages, and support and improve the Services. We do not sell your personal information, and we do not use your farm records to advertise to you.

Our lawful basis

We only process personal information where the law allows us to. For each purpose, the lawful basis we rely on under the NDPA and the GDPR / UK GDPR is:

PurposeLawful basis
Creating your account and keeping you signed inContract
Storing and syncing your farm records, team access and supportContract
Subscriptions and entitlement checksContract
Transactional emails (verification, password reset, invitations)Contract
Weather advice and insights from your farm locationContract; consent for using your device’s GPS
Push notifications and remindersContract; consent for notifications
Security, fraud and abuse prevention, server logs, backend error trackingLegitimate interests
Crash reports (Crashlytics)Legitimate interests
Usage analytics (Firebase Analytics) and session replay (Microsoft Clarity)Consent in the EU/EEA, the UK and Switzerland; elsewhere legitimate interests, with an opt-out
Answering contact-form messagesLegitimate interests
Keeping billing records and responding to lawful requestsLegal obligation

Where we rely on consent, you can withdraw it at any time by turning the feature off in the app or your device settings, without affecting the rest of the Services or anything we did before you withdrew it. Where we rely on legitimate interests, we do so only where those interests are not overridden by your rights, and you can object.

Who we share data with

We share data only with the service providers that make the Services work, and where required by law. They process it on our instructions under written agreements. Today those providers are:

ProviderPurposeData
RailwayHosting for our application servers and database, where synced records are stored.All server-side data: account details and synced farm records.
CloudflareHosting and delivery of this website and the FlockNest web app, DNS, and Turnstile bot protection on the contact form.IP address, browser details and request data; Turnstile challenge signals.
Google FirebaseCloud Messaging (push notifications), Crashlytics (crash reports) and Analytics (usage events, only with your agreement where required).Push tokens, crash diagnostics, device model and OS, app version, in-app event names.
Microsoft ClaritySession replay and usage analytics in the app, to see where it is confusing. Only with your agreement where required.Anonymised recordings of taps and screens. Password, PIN and code fields are masked.
RevenueCat, with Apple App Store and Google PlaySubscription status and entitlement checks. The app stores take the payment.Subscription status, plan and an app user ID. We never see card details.
ZeptoMail by Zoho (Brevo as an alternative provider)Transactional email: verification, password reset, invitations and messages sent through our contact form.Recipient email address and the message content.
OpenAIWriting farm insights in plain language.Aggregated farm metrics and our own draft wording only. No names, emails or farm names.
Open-MeteoLocal weather forecasts and weather advice.Your farm’s coordinates, only if you set a location.
OpenStreetMapMap tiles in the farm location picker.IP address and the map area being viewed, while the picker is open.
SentryError tracking for our backend, so we can find and fix faults.Error details and request metadata. Request bodies and authorisation headers are excluded.

About the AI insights. The analysis runs on our own servers. To phrase an insight in clearer language, we send OpenAI the figures behind it (for example a laying percentage, a mortality count or a spend total) together with the draft wording our own rules produced. We do not send your name, email, farm name, buyer or vendor names, vet details or your record history, OpenAI has no access to our database, and the request is not used to train their models.

Team members you invite to your farm can see records according to the role you give them. Expenses, budgets and profit figures are restricted to the farm owner and manager and are never sent to a worker’s or sales rep’s device. We may also disclose information where the law requires it, or to a buyer or successor if the business is sold, in which case this policy continues to apply.

International transfers

Our providers operate in countries that may be different from your own, including the United States and the European Union, so your information may be processed outside the country where you farm. We transfer personal data out of Nigeria only where the NDPA permits it. Where personal data from the EU/EEA or the UK goes to a country that does not have an adequacy decision, we rely on the European Commission’s standard contractual clauses (with the UK addendum for UK data) included in our providers’ data processing terms, or on another safeguard the law recognises. You can ask us for more information about these safeguards.

How your data is stored and protected

In the mobile app, your records are stored in an encrypted database on your device (SQLCipher) and backed up to secure servers when you sync. Sign-in tokens are kept in your phone’s secure keychain or keystore. We use industry-standard security measures, including encryption in transit, hashed and rotating sign-in tokens, rate limiting and account lockout, and every request is scoped to the farms you belong to. You can also protect the app with a biometric lock (fingerprint or face).

Receipt photos are the exception on mobile: they are held as ordinary image files in the app’s private storage on your device and are not encrypted, so avoid attaching photos showing information you would not want read by anyone with access to that phone.

Using FlockNest in a web browser. The web app keeps a copy of your farm records in your browser’s storage so that it works quickly and offline. Unlike the mobile app, this browser copy is not encrypted, and it stays there until you log out. On a shared or public computer, always log out when you finish.

Keeping and deleting your data

DataHow long we keep it
Account details and farm recordsWhile your account is active
Deleted accounts and solely owned farmsClosed immediately; permanently erased 30 days after deletion
Transactional emails, including contact-form messagesDeleted 30 days after sending
Sync logs90 days
Encrypted backupsExpire on their normal rotation after the periods above
Billing recordsAs long as accounting and tax law requires, without a link to your farm records
Crash reports, analytics and session replaysUnder the retention settings of Firebase and Microsoft Clarity

You can download a copy of your data at any time from App settings → Account → Download my data.

You can delete your account at any time from App settings → Account → Delete account, confirmed with your password, or without the app by following the steps on our account deletion page. When you do, we immediately close the account, end every signed-in session, and your records are no longer accessible through the Services. Farms you solely own are closed with the account; a farm you share with other members keeps working for them, and the records that farm’s team entered remain theirs.

Your personal data is permanently erased 30 days after you delete your account: we anonymise your user record and permanently delete the farms you solely owned, with all of their records. Copies in encrypted backups expire on their normal rotation after that. We keep billing records where we must for accounting and tax purposes, without a link to your farm, and we may retain the minimum information needed to meet other legal or fraud-prevention obligations. Deleting your account does not cancel an App Store or Google Play subscription, and it does not remove receipt photos already saved on your device. You can delete those from your phone directly.

Your rights and choices

Wherever you live, you can access and correct your records in the app, download a copy of your data, export your production records and reports, switch off optional features such as location, notifications, analytics and session replay, and delete your account and associated data at any time.

Under the NDPA, and under the GDPR and UK GDPR if you are in the EU/EEA or the UK, you also have the right to:

  • be told how we use your personal information (this policy);
  • get a copy of the personal information we hold about you;
  • have inaccurate information corrected;
  • have your information erased;
  • restrict how we use your information, or object to processing based on our legitimate interests;
  • receive your information in a portable format, or have it moved to another provider;
  • withdraw consent at any time, where we rely on it; and
  • not be subject to decisions based solely on automated processing that significantly affect you. We make no such decisions: our AI insights are advice only.

To make a request, email hello@flocknest.co. We will verify that the request comes from you and respond without undue delay, and in any case within 30 days. We will not charge you for a request unless the law permits it and the request is clearly excessive.

If you are unhappy with how we have handled your information, you can complain to the Nigeria Data Protection Commission (NDPC), the regulator for data protection in Nigeria. If you are in the EU/EEA, you can complain to the data protection authority in your country; in the UK, to the Information Commissioner’s Office (ICO). Elsewhere, you can contact the data protection authority where you live.

Security incidents

If a personal data breach is likely to put your rights at risk, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and any other regulator the law requires us to notify, such as an EU or UK supervisory authority. We will tell affected users without undue delay what happened, what it means for them and what we are doing about it.

Children

The Services are intended for adults aged 18 and over running or working on a farm business. We do not knowingly collect personal information from anyone under 18. If you believe a child has created an account, contact us and we will close it.

Changes to this policy

We may update this policy from time to time and will post the new version here with a new “last updated” date. If a change materially affects how we handle your information, we will tell you in the app.

Contact

Questions about privacy? Email us at hello@flocknest.co or, for account and data requests, support@flocknest.co.