Pustaka BiodiversitasUser guide IDEN Download for macOS Download for Windows
Guide › Legal

Privacy policy

What data is stored, when the app connects to the internet, and where data is sent.

Effective 11 October 2026 · App version 0.3.0

In short: Pustaka Biodiversitas has no user accounts, installs no trackers, and does not send your project content to our server. All data is stored on your computer. The only data about you that we keep is the licence data needed for activation.

1. Data stored on your computer#

  • Projects: all project content (entities, topics, media, occurrences, glossary, backups) is stored in the .biodiv folder you choose.
  • App preferences: the recent projects list, theme, language and other settings, in the app's configuration folder in your user account.
  • Licence token: once a licence is activated, a digitally signed token is stored in the same configuration folder.
  • AI assistant API keys: stored in the Keychain (macOS) or Credential Manager (Windows), encrypted by the operating system.

We cannot access this data.

2. Automatic connections#

The app contacts the Pustaka Biodiversitas server (biodiversitas.id) unprompted only to:

  • Check for app updates, at most once a day. This can be turned off in Settings → App updates.
  • Update conservation status data (P.106/2018 and CITES), at most once per session when you check status.
  • Check whether a licence is still valid, once a day when the app opens and when the Licence dialog is opened, only once a licence has been activated. This request contains your licence token.

Update and status requests only contain the address of the file requested. As with any internet connection, the server and content delivery network (Cloudflare) receive your IP address and the app's name and version (User-Agent), and may record them in server logs for security and operational purposes. We do not combine this data with other information and do not use it for profiling or advertising.

3. Licence activation#

When you activate or release a licence code, the app sends our server:

  • the licence code;
  • a device identifier, which is a hash of the machine ID that cannot be turned back into the original ID;
  • the computer name (e.g. "Lab Laptop"), app version and operating system, so that you and we can recognise devices in the activation list.

The server stores the buyer's name and email given at purchase, the list of active devices with their activation and last-check dates, and the licence code in hashed form. The app checks the licence status at most once a day when it is online; at each check the server records the device's approximate location (province/region and country, estimated from the IP address by Cloudflare). Only the latest location is kept, the IP address itself is not stored, and we never record the city, address or coordinates. This data is used only to run the licence: limiting the number of devices, releasing devices and revoking misused licences. To prevent code guessing, the IP address of failed activation attempts is recorded for at most one day. Licence data is kept for as long as the licence is valid; ask for its deletion through the contact below.

Licence orders. When you send an order from the Buy a licence page, we store your name, email, institution, country, notes, cart contents and the sender's IP address (to limit spam orders), then email the details to us and a confirmation to you. This data is used only to process the purchase, send invoices and licence codes, and for bookkeeping.

4. Third-party services you use#

When you use the following features, the app sends requests directly from your computer to the service provider. The request only contains what the feature needs, usually a scientific name:

FeatureProviderData sent
Name checks, classification, IUCN status, photos & occurrencesGBIF, POWO/Kew, ChecklistBank, WoRMS, Catalogue of Life, iNaturalistScientific name, country code (if given)
Wikipedia summaries, Commons photosWikimedia FoundationScientific name
Online base mapsGBIF, OpenStreetMapThe map area shown
AI AssistantAnthropic, OpenAI or Google (your choice)Your questions and relevant project content, including text read by the assistant

Each provider processes data under its own privacy policy. With a local model (LM Studio/Ollama), AI assistant data never leaves your computer.

5. What we do not do#

  • No accounts, registration or login (licence activation only uses a code).
  • No analytics, telemetry or advertising trackers.
  • No sending of project content to our server.
  • No selling or sharing of personal data with third parties.

6. This website#

This guide uses no cookies or trackers. Its fonts and scripts are loaded from our own server. Your light/dark theme and macOS/Windows choices are stored in your browser (localStorage).

7. Your rights#

Because your data is stored on your own computer, you can view, change, copy or delete it at any time. To remove everything, release the licence from that computer, delete the .biodiv project folders, the app and its configuration folder, then remove the API keys from Keychain Access (macOS) or Credential Manager (Windows). For questions about server logs or licence data, contact us. This policy was written with Indonesia's Personal Data Protection Law (Law No. 27 of 2022) in mind.

8. Changes to this policy#

If this policy changes, the latest version will be published on this page with a new effective date.

9. Contact#

Privacy questions: pustaka@biodiversitas.id.

The Indonesian version of this policy is the authoritative one.

© 2026 Pustaka BiodiversitasPrivacyEULAPhoto & data licencesPhotos: Reza Saputra