
FieldTag privacy policy
Effective 12 September 2026 ยท HydroGeo Envi-Consultancy Services
Operator and contact
HydroGeo Innovations | FieldTag is operated for HydroGeo Envi-Consultancy Services. The configured backend owner and support contact is kenneth.fgc@gmail.com. Contact this address with privacy questions, access requests or requests to delete backed-up observations.
Information you provide
FieldTag stores original photos and the observation details you enter: project, observer name, title, category, notes, observation date and time, time zone, and coordinates. When you request device location and allow the browser permission, it records latitude, longitude, the location timestamp and reported accuracy. Manually entered coordinates are identified as manual. The app also keeps file names, types, sizes, photo checksums, record identifiers and backup status. Original photographs may contain embedded metadata because FieldTag preserves their original bytes.
Google identity and permissions
Ordinary Google sign-in requests OpenID, email and profile information. The server verifies your Google identity and uses the Google account identifier and email to associate submitted records with you and control cloud access. It may retain the profile name returned during sign-in. This identity is separate from the observer name you type into an observation.
The backend owner separately grants Google Sheets access and access to specific Drive files used with this app. The Sheets permission technically permits access to the owner's spreadsheets; FieldTag's implementation uses the single configured field database. The Drive permission is used to create and access the app's photo folder and original photo files. Ordinary users do not grant these Sheets or Drive permissions.
Local storage and sessions
Photos and notes are first saved in IndexedDB on your device. The offline app interface is cached by a service worker. The last verified account email and Google identifier are remembered locally for account selection and offline display; they are not credentials. The authenticated session uses an HTTP-only cookie. Original photos, observations and local account settings are not an encrypted per-user vault: anyone using the same unlocked browser profile can view local records. Signing out forgets the remembered account and pauses uploads, but does not delete local observations.
Cloud storage and who can access records
When backup succeeds, Google Drive holds the original photo and Google Sheets holds observation metadata, including your Google account identifier and email, coordinates, notes and photo links. Cloudflare hosts the application and its private backend storage for sessions, the backup journal, record metadata, rate-limit counters and the owner's Google connection tokens. OAuth client secrets and owner refresh tokens remain on the server and are not included in browser assets.
The configured owner can access and compile all backed-up field records. Through FieldTag, ordinary signed-in users can retrieve their own submitted cloud records. The central spreadsheet and photo folder are private to their configured owner unless that owner changes their sharing separately. A person who receives an exported report or device backup can access the information it contains; choose recipients and storage locations carefully.
Purpose and service providers
The app uses this information to capture observations, preserve original photos, authenticate users, retry and verify backups, enforce record access and generate field reports. Google and Cloudflare process data needed to provide their authentication, hosting and storage services under their own applicable policies. The application uses IP-derived rate-limit keys to protect the sign-in endpoint. It does not include advertising trackers or analytics scripts, sell Google user data, use it for advertising, or send it to AI models for training or analysis.
Retention, export, deletion and revocation
This version does not automatically expire or delete field observations. Local records remain until the browser removes site data or you clear it. You can export a device backup and daily reports from the app. Clearing local storage can permanently remove observations that have not been backed up. Backed-up records remain in the owner's Google storage and application journal until removed through owner administration; FieldTag does not currently provide a self-service cloud-deletion button.
To request access to or deletion of backed-up data, contact the owner and identify the relevant account and observations. Do not send passwords or access tokens. Signing out, uninstalling the app or revoking Google consent does not itself delete existing backups. You can review or revoke app access in your Google Account connections. Revoking the owner's Sheets/Drive access stops new backups until the owner reconnects; queued device observations remain local.
Google API user data
FieldTag's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google data is used for the user-facing functions described in this policy.
Policy updates
Material changes to the app's data handling will be reflected on this page and in the app's privacy information. The effective date above identifies this policy version.