Last updated: 29 August 2026
Arachnid League is operated by Xander Labs LLC ("we", "us"). You can reach us at xander@xanderlabs.io.
This policy says what the app collects, why, who sees it, and how to get rid of it. It describes the app as it actually behaves; where something is not collected, that is stated rather than left out.
Your account. An email address, used to sign you in with a one-time code and to reach you about your account. A display name you choose. Optionally a Venmo handle, which you provide so leaguemates can pay you when you win — we never see, hold or process a payment.
Photographs. Every find is a photograph you submit. It is stored so the members of the league you submitted it to can see it. A photograph submitted to three leagues is stored three times, once under each league, because access is controlled per league.
Precise location, when you allow it. With your permission, the app reads the capture time and the GPS coordinates recorded inside the original photograph in your device's photo library, and stores them with the find. This is precise location data. It is used to record when and where a find was made, to check a find against the week it was submitted to, and to detect two members photographing the same specimen.
You can refuse. Every find still counts; it is marked as having no verified time or place, and the app says so on the card. You can change the permission at any time in your device settings, and finds submitted before you refuse keep what was already recorded until you delete them.
Before any location is shown to anyone else it is blurred by at least the radius your league has set. You may choose to be vaguer than that; you cannot be more precise. No precise coordinate ever appears in a link, a share, or anything the app sends outside itself.
An image fingerprint. The app computes a short numeric fingerprint of each photograph — 64 bits, derived from a 72-pixel reduction of the image — so it can match a shared image back to the original in your library, and so it can tell when the same photograph has been submitted twice in one league. The fingerprint cannot be turned back into a picture. Nothing in this app searches the web for your photographs, and no reverse image search is performed.
Photo library access. When you allow it, the app reads recently captured photographs from your library in order to find the original of a shared image. That reading happens on your device. Only the photograph you submit, its capture time and its coordinates leave the device — never your library, never a list of what is in it.
What you write. Messages you post in a league channel, species names, flair, reasons on contests, cards and rulings, and anything else you type into the app.
Reports you file. When you report content, we receive what you reported, your reason, and who you are. Your league is not told.
Device notification token. If you turn on notifications, a token identifying your device for Apple's or Google's push service.
Basic technical records. Our hosting provider keeps ordinary server logs — IP address, timestamp, and what was requested — which are used to run and secure the service.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Members of a league you are in see: your display name, your Venmo handle if you set one, your finds and their photographs, the blurred location and the date of a find, your messages, and rulings and cards that involve you. Nothing crosses between leagues: a member of one league cannot read anything belonging to a league they are not in, and this is enforced by the database rather than by the app.
A commissioner of a league you are in additionally administers that league — certifies weeks, rules on flags, and issues cards. Blocking someone hides the two of you from each other everywhere in the app, except that a commissioner still sees finds submitted to the league they run, because a find nobody can see cannot be certified.
We can see what is stored, and read reports. Content that is removed is hidden from every member, including the person who posted it.
Nobody else, other than the service providers in the next section.
Finds, weeks, rulings and results are kept for as long as the league exists. Results in a league you competed in were decided partly by your finds, and a certified week is never rewritten.
Reports and removals are kept while we may need them to enforce our terms.
When you delete your account, your sign-in is destroyed and your display name, Venmo handle and messages are removed. Your past finds remain so that other members' results still make sense, but what remains does not identify you.
Arachnid League is not for children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child has an account, write to us and we will remove it.
Access is controlled row by row in the database: every league-owned record is readable only by that league's members, and photographs are stored under a per-league key that resolves to membership. Data is encrypted in transit. No system is perfectly secure, and we do not claim otherwise.
We may update this policy. If we make a material change we will tell you in the app before it takes effect, and the date at the top will change.
Xander Labs LLC — xander@xanderlabs.io