How Pila Studio UG (haftungsbeschränkt) handles personal data in the Livestock Manager app, website and related services.
Version 2.0 · In effect from 31 July 2026
This policy explains, in plain terms, what personal data we collect when you use Livestock Manager, why we collect it, who else sees it, how long we keep it and what you can require us to do about it. It is our notice to you under Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”).
The controller responsible for the processing of your personal data within the meaning of Article 4(7) GDPR is:
Pila Studio UG (haftungsbeschränkt)
Berlin, Germany
Registered at Amtsgericht Charlottenburg, HRB 289822 B
Email: hello@livestockfarm.co
Full provider details are set out in our Legal Notice (Impressum).
We have assessed our processing activities against § 38 of the German Federal Data Protection Act (BDSG) and Article 37 GDPR and are not currently required to appoint a data protection officer. All data protection enquiries are handled directly by our management at hello@livestockfarm.co. If this assessment changes, we will appoint an officer and publish their contact details here.
This policy applies to:
(together, the “Services”). It does not apply to third-party websites or services we link to, each of which operates under its own privacy policy.
We do not ask for, and the Services are not designed to hold, special categories of personal data within the meaning of Article 9 GDPR (such as health, biometric, religious or political data about individuals). Please do not enter such data into free-text fields. If you do, you are responsible for having a lawful basis under Article 9 for doing so.
We only process personal data where the GDPR gives us a legal basis to do so. The table below sets out each purpose and the basis we rely on.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and administering your account; authenticating you; providing the core record-keeping, reporting and farm management features you signed up for | Account, farm and operational data | Art. 6(1)(b) GDPR — performance of our contract with you |
| Processing subscriptions, purchases, renewals, refunds and entitlements | Account and purchase data | Art. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation for tax and accounting records |
| Sending service messages: password resets, receipts, order and invoice notifications, security alerts, and notices of material changes | Account data, email address, push token | Art. 6(1)(b) — contract |
| Optional reminders and alerts you have switched on (daily record reminders, task, mortality, feed, medicine and production alerts) | Push token, notification preferences, farm data | Art. 6(1)(a) — your consent, given through your device permissions and in-app notification settings, which you may withdraw at any time |
| Keeping the Services secure: preventing fraud, abuse, automated attacks and unauthorised access; rate limiting | IP address, device data, request metadata, logs | Art. 6(1)(f) — our legitimate interest in the integrity and security of our systems and our users |
| Diagnosing crashes, errors and performance problems, and improving reliability | Diagnostic data, device data, pseudonymous user ID | Art. 6(1)(f) — legitimate interest in a functioning, reliable product |
| Product analytics, session replay, feature experiments and understanding how the Services are used | Usage data, device data, pseudonymous user ID | Art. 6(1)(a) — your consent, where the technology stores or accesses information on your device (§ 25 TDDDG) |
| Advertising, remarketing, measuring campaign effectiveness and affiliate attribution | Cookie and advertising identifiers, hashed email, conversion events | Art. 6(1)(a) — your consent |
| Serving advertisements in the free tier of the mobile app | Advertising identifier, device data, ad interactions | Art. 6(1)(a) — your consent, requested through the app tracking permission prompt on iOS and the consent dialog on Android |
| Providing the in-app AI assistant, summaries and suggestions | Your prompts and the farm context needed to answer them | Art. 6(1)(b) — contract, where you choose to use the feature |
| Handling support requests, feedback and disputes; establishing, exercising and defending legal claims | Account data, correspondence, relevant records | Art. 6(1)(f) — legitimate interest in supporting users and defending our rights |
| Moderating community content and enforcing our Terms, including notice-and-action under the Digital Services Act | User-generated content, account data, reports received | Art. 6(1)(c) — legal obligation under Regulation (EU) 2022/2065; Art. 6(1)(f) — legitimate interest in a safe platform |
| Complying with tax, accounting, commercial and other statutory retention duties | Transaction and invoice records | Art. 6(1)(c) — legal obligation under the German Fiscal Code (AO) and Commercial Code (HGB) |
Where we rely on legitimate interests, we have carried out a balancing test weighing our interest against your rights and freedoms. You may request a summary of that assessment at hello@livestockfarm.co.
On our website and web application, cookies and comparable technologies that are not strictly necessary are only set after you have given consent through our cookie banner, in accordance with § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Article 6(1)(a) GDPR. You can change or withdraw your choice at any time via the “Cookie settings” link in the footer of every page.
Session replay
Where you consent to analytics, our analytics provider PostHog may record a reconstruction of your interactions with the interface — the pages you view, and where you click, scroll and type. We configure this feature to mask text entered into input fields, and we do not use it to read the contents of your farm records. We use it solely to find and fix usability problems. If you would prefer not to be recorded, decline analytics cookies in the banner or in “Cookie settings”.
A full breakdown of every cookie and tracking technology we use, its purpose, its provider and its storage duration is set out in our Cookie & Tracking Policy.
In the mobile apps, analytics and advertising identifiers are used only where you have granted the corresponding permission. On iOS this is requested through Apple’s App Tracking Transparency prompt. You can change your decision at any time in your device settings.
We do not sell personal data, and we never have. We share it only in the following circumstances:
| Service | Purpose | Data | Location |
|---|---|---|---|
| DigitalOcean DigitalOcean, LLC | Application hosting, managed PostgreSQL database and object storage (Spaces) for uploaded files. | All account, farm and uploaded file data. | European Union |
| Vercel Vercel, Inc. | Hosting and delivery of the website and web application; aggregate, cookieless traffic measurement. | IP address, request metadata, user agent. | European Union / United States EU Standard Contractual Clauses |
| Arcjet Arcjet, Inc. | Bot detection, rate limiting and abuse prevention. | IP address, request fingerprint, user agent. | United States EU Standard Contractual Clauses |
| Better Stack BetterStack, s.r.o. | Server and application log aggregation for reliability and security monitoring. | Log records, which may contain IP address and user identifiers. | European Union |
| PostHog PostHog, Inc. (EU Cloud) | Product analytics, feature flags, A/B testing and session replay, to understand how the Services are used and to diagnose faults. | Pseudonymous user ID, events and screen views, device and browser metadata, approximate location derived from IP address, and — where session replay is active — a reconstruction of your interactions with the interface. | European Union (Frankfurt) |
| Google Analytics Google Ireland Limited | Website traffic and audience measurement. | Cookie identifiers, IP address (truncated), pages viewed, device metadata. | European Union / United States EU–US Data Privacy Framework and EU Standard Contractual Clauses |
| Firebase (Analytics, Crashlytics, Performance, Cloud Messaging) Google Ireland Limited | Mobile app analytics, crash reporting, performance monitoring and delivery of push notifications. | App instance ID, device model and OS, crash stack traces, performance traces, push token. | European Union / United States EU–US Data Privacy Framework and EU Standard Contractual Clauses |
| Meta Pixel and Conversions API Meta Platforms Ireland Limited | Measuring the effectiveness of our advertising and showing you relevant ads. | Cookie identifiers, hashed email address, event data such as sign-ups and purchases, IP address. | European Union / United States EU–US Data Privacy Framework and EU Standard Contractual Clauses |
| Google AdMob Google Ireland Limited | Serving advertisements within the free tier of the mobile app. | Advertising identifier, device metadata, approximate location, ad interaction data. | European Union / United States EU–US Data Privacy Framework and EU Standard Contractual Clauses |
| GoMarketMe GoMarketMe, Inc. | Attribution of affiliate and creator referrals. | Pseudonymous install and purchase identifiers, referral codes. | United States EU Standard Contractual Clauses |
| RevenueCat RevenueCat, Inc. | Managing subscription entitlements and validating purchase receipts. | App user ID, purchase and subscription history, store receipts, country. | United States EU Standard Contractual Clauses |
| Apple App Store Apple Distribution International Ltd. | Distribution of the iOS app and processing of in-app purchases. Apple is the seller of record for in-app purchases. | Purchase and subscription records; payment details are handled solely by Apple. | European Union / United States EU Standard Contractual Clauses |
| Google Play Google Ireland Limited | Distribution of the Android app and processing of in-app purchases. Google is the seller of record for in-app purchases. | Purchase and subscription records; payment details are handled solely by Google. | European Union / United States EU–US Data Privacy Framework |
| Stripe Stripe Payments Europe, Ltd. | Processing card payments made directly through our website, including gift purchases. | Name, email address, billing country, payment token, transaction records. Full card numbers never reach our servers. | European Union / United States EU–US Data Privacy Framework and EU Standard Contractual Clauses |
| Paystack Paystack Payments Limited | Processing card and local payment methods for users in supported African markets. | Name, email address, transaction records, payment token. | Nigeria / United States EU Standard Contractual Clauses |
| OneSignal OneSignal, Inc. | Delivery and scheduling of push notifications. | Push token, device metadata, notification interaction data, time zone. | United States EU Standard Contractual Clauses |
| SendGrid Twilio Inc. | Delivery of transactional and service emails. | Email address, name, message content, delivery and open events. | United States EU–US Data Privacy Framework and EU Standard Contractual Clauses |
| Resend Resend, Inc. | Delivery of transactional emails, including order and invoice notifications. | Email address, name, message content, delivery events. | United States EU Standard Contractual Clauses |
| Slack Slack Technologies Limited | Internal routing of user feedback and support requests to our team. | Content of feedback you submit, and the email address associated with it. | European Union / United States EU–US Data Privacy Framework |
| Sign in with Google Google Ireland Limited | Optional single sign-on. | Name, email address, profile picture and Google account identifier, only where you choose this sign-in method. | European Union / United States EU–US Data Privacy Framework |
| Sign in with Apple Apple Distribution International Ltd. | Optional single sign-on. | Apple user identifier and the email address you elect to share, which may be a private relay address. | European Union |
| OpenAI OpenAI Ireland Ltd. | Powering the in-app assistant and generating written summaries and suggestions. | The content of the prompts you submit and the relevant farm context needed to answer them. | European Union / United States EU Standard Contractual Clauses |
We keep this list current. If you would like to be notified of additions before they take effect, write to hello@livestockfarm.co.
Our own infrastructure — our application servers, our database and the files you upload — is hosted within the European Union.
Some of the service providers listed above process data in the United States or other countries outside the European Economic Area. Those countries may not offer a level of data protection equivalent to the GDPR, and in particular may permit access by public authorities in circumstances broader than EU law allows. Where such a transfer takes place, we rely on one or more of the following safeguards under Chapter V GDPR:
You may request a copy of the relevant safeguards from hello@livestockfarm.co.
When you enter personal data about other people into the Services — your customers, suppliers, employees or farm team members — you are the controller of that data and we act as your processor, processing it only on your instructions in order to provide the Services.
As controller, it is your responsibility to:
Our processing on your behalf is governed by the data processing terms in section 17 of our Terms & Conditions, which form a data processing agreement meeting the requirements of Article 28(3) GDPR. If you need a separately signed agreement, contact hello@livestockfarm.co.
Some features use large language models to answer questions, summarise records and suggest actions. When you use them, the content of your prompt and the farm records needed to answer it are transmitted to our AI provider (currently OpenAI) for the sole purpose of generating a response.
We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22(1) GDPR.
We do perform limited profiling in the ordinary sense: we group users by behaviour to decide which features to build, which experiment variant to show, and which onboarding tips or offers to surface. These decisions do not affect your legal position, your pricing, or your access to the Services. You can object to profiling for direct marketing purposes at any time, as described below.
We keep personal data only as long as necessary for the purpose it was collected for, or as long as the law requires us to.
| Data | Retention period |
|---|---|
| Account and farm data | For as long as your account is active, and then for 30 days after you request deletion, during which the deletion can be reversed if requested in error |
| Invoices, transactions and tax-relevant records | 10 years from the end of the calendar year in which they arose, as required by § 147 AO and § 257 HGB. During this period the data is blocked from ordinary use and retained for tax purposes only |
| Commercial and business correspondence | 6 years, as required by § 257 (4) HGB |
| Server, security and access logs | Up to 90 days, then deleted or irreversibly anonymised |
| Analytics and session replay data | Up to 12 months, in pseudonymous form; session recordings are deleted sooner where our provider’s retention settings so provide |
| Support correspondence | 3 years from the end of the year the matter was closed |
| Community content you posted | Until you delete it or your account is deleted; content removed for a Terms violation, and the reasons for removal, may be kept for up to 12 months for enforcement and legal defence |
| Consent records | 3 years after consent is withdrawn, in order to demonstrate compliance |
Where data must be retained for a statutory period, we restrict its processing under Article 18 GDPR rather than continuing to use it.
You can delete your account at any time from within the app, or via our account deletion page.
We maintain technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. These include:
No system connected to the internet can be made perfectly secure, and we do not claim otherwise. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours under Article 33 GDPR and, where the risk is high, notify you without undue delay under Article 34 GDPR.
Under the GDPR you have the following rights in relation to your personal data. Exercising them is free of charge and we will respond within one month, extendable by two further months for complex requests.
To exercise any of these rights, write to hello@livestockfarm.co. We may ask you for information to confirm your identity — this is to protect you against someone else obtaining your data.
Right to object under Article 21 GDPR
Where we process your personal data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. If you object, we will stop processing that data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims.
Where we process your data for direct marketing purposes, you have an unconditional right to object at any time. We will then stop such processing immediately, with no need to give reasons. An objection can be sent informally to hello@livestockfarm.co.
Without prejudice to any other remedy, you have the right under Article 77 GDPR to lodge a complaint with a data protection supervisory authority — in the Member State of your habitual residence, your place of work, or the place of the alleged infringement.
The authority competent for us is: Berliner Beauftragte für Datenschutz und Informationsfreiheit.
We would ask you to raise the matter with us first at hello@livestockfarm.co — but that is a request, not a condition, and your right to complain is entirely unaffected by whether you do.
The Services are intended for use by adults in a farming or business context and are not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact hello@livestockfarm.co and we will delete it promptly.
We may update this policy to reflect changes in our Services, our service providers, or the law. The version number and effective date at the top of this page always identify the current version.
Where a change is material — for example, a new purpose of processing or a new category of recipient — we will notify you in advance by email or through a prominent in-app notice, and, where the change requires it, ask for your consent. Immaterial changes take effect on publication.
For any question, request or concern about how we handle your personal data, write to hello@livestockfarm.co . Our postal address is provided on request and is recorded in the commercial register (Amtsgericht Charlottenburg, HRB 289822 B). We aim to reply to every privacy enquiry within five working days.
This policy is published in English, which is the authoritative version. Any translation is provided for convenience only; in the event of a discrepancy, the English text prevails, save where mandatory law provides otherwise.