Skip to content

Privacy & telemetry

As a precision-agriculture data processor, DroneField takes privacy seriously. This page sets out exactly what data we store and transmit — and how you can control it.

This is the most important point. Your drone imagery, the orthomosaic, the DSM, the NDVI maps and the application maps are never sent to our servers in any form. Processing runs entirely on your own computer.

That means:

  • The exact coordinates of your field are known only to you.
  • The vegetation-index values stay with you.
  • The seeding and fertiliser doses we do not see.

Some data exchange is unavoidable for the product to work:

  • Email + password hash — for sign-in
  • Sanctum token — after successful sign-in
  • Device UUID + fingerprint hash — to identify the registered machines
  • Every 15 minutes your machine sends an “I’m here” ping
  • Contents: device UUID, application version, timestamp
  • Does not include geographic coordinates, project data or any user content
  • Every 5 minutes the app queries the server to confirm your subscription state
  • Contents: your account ID
  • Does not include processing data
  • Every 4 hours the app queries the latest stable build
  • Unauthenticated, asks only for the version number

Telemetry means anonymous usage statistics. It helps us understand which features are heavily used and where users get stuck.

Telemetry does NOT contain:

  • User content
  • Coordinates
  • Email addresses
  • Image data
  • Boundaries

Telemetry does contain:

  • “Processing started” event (just the fact, plus image-count bucket like “100–200”)
  • “Processing finished” event (success or failure, elapsed time in seconds)
  • “Error” event (just the error_code, e.g. MISSING_MRK)
  • “Feature opened” (e.g. “Application map opened”)
  • Device hardware model (M3 Pro, RAM bucket)
  • Application version

You can disable telemetry any time under Settings → Privacy. Licence validation and update checking continue to work even with telemetry off.

Server-side, we keep your account data on:

  • EU central servers (Frankfurt)
  • Stripe for payment data (PCI-DSS compliant)
  • AWS S3 (eu-central-1) for installer binaries

We are fully compliant with EU GDPR. The full data-handling detail is in the Privacy Policy.

DroneField writes local log files to ~/Library/Logs/DroneField/ (macOS) or the equivalent path on Windows / Linux. These stay only on your machine — we do not collect them automatically.

When you attach logs to a support ticket, they reach us — but logs never contain user content, only technical events.

Under GDPR you can request an export of all data we hold about you:

  1. Contact us through the portal support form.
  2. Within 30 days we deliver the export in JSON / CSV format.
  3. The export covers: profile, invoices, devices, subscription history, telemetry events.

If you want to leave DroneField:

  1. Portal → ProfileRequest account deletion
  2. We process the request within 7 business days
  3. Personal data is deleted; invoices are retained for 8 years under accounting law

See Profile → Account deletion for the full flow.

The my.dronefield.app and doc.dronefield.app sites use only these cookies:

  • Session — to keep you signed in
  • Remember me — optional, if you ticked it
  • CSRF token — to protect form submissions
  • Theme — light/dark preference on the docs site

We do NOT use marketing / tracking cookies, Google Analytics, Facebook pixel, or any third-party tracker.

If we change our privacy practices, we notify you by email and display a banner in the portal. See Legal documents for version history.