Most of the feedback we received so far is related to Privacy of users and security concerns, so I though it would be best to just put this out there: Security and Privacy of WeedLog users is our top concern!
We are very open about the measures we employ to make everyone secure and protect the privacy of our users. In fact, you can read about most of them here: Privacy and also here: FAQ
But here are the top concerns we have been noticing from potential and actual users:
Q1: Because the Mobile App runs on my phone, can it access my phone number and other sensitive data?
A1: In short : No . When an App is being installed, the store (Google Play Store, for example) will display a notice saying exactly what permissions the App is requesting from the phone. In the description of the App we explain exactly what each mean, and what they are used for. To get access to, for example the IMEI, GSM, etc of a phone, the permission necessary is: “Read Phone State and ID” , which, is never requested by the Mobile App.
Q2: How is my data stored on my mobile phone?
A2: All the photos , descriptions, grow logs inserted on the Mobile App are stored on a encrypted database on the mobile phone. This database is password protected, but for convenience the password is saved on an application file. Users who wish can modify the default password and not save it to memory, and that way everytime the Mobile App is started a prompt will show asking for the user to put in the password. Losing that password means losing everything you have stored, and there is no way to get it back. The software we use for the encrypted database is SQLCypher.
Q3: Could anyone intercept what I am doing on the Web browser and uploading?A3: All communications to and from the WeedLog servers (both by User browsers and Mobile App) are performed through SSL (same as when one buys anything online with credit card) making use of a certificate issued by a credited and valid certificate authority, which means that no one can read the data coming and going. The easiest way to know that all is working fine in regards to this check for the Green Lock on your web browser:
Q4: What about the information WeedLog stores about the users?A4: The only personal information we store about users is their email address (to allow for password recovery), apart from that, we only store the photos and descriptions inserted by our users. We even go further and never log any IP addresses on our logs and just disregard them on normal usage of WeedLog. This makes our work of finding bugs a lot harder but ensures the privacy of our users.
Q5: Where are you and your servers located?A5: We, WeedLog are located in Portugal, all servers are located in The Netherlands on a datacenter in Amsterdam.
Any concerns you may have, please do get in touch trough our Feedback Platform , through the contacts on our Contacts page or just leave a comment here.