Skip to content
Fugaji
FeaturesHow it worksPricingFAQAndroid app
Start free trial
FeaturesHow it worksPricingFAQDownload the Android appStart free trial

Privacy policy

What Fugaji records, why, who we share it with, how long we keep it and how you take control of it.

Last updated:September 16, 2026

Contents

  1. 1Who is responsible for your data
  2. 2What we do not do
  3. 3The data we process, and why
  4. 4What the mobile app does on your phone
  5. 5The assistant and voice-note transcription
  6. 6The providers involved
  7. 7Hosting and transfers outside your country
  8. 8Cookies and local storage
  9. 9How long we keep things
  10. 10Deleting an account and an organisation
  11. 11Your rights
  12. 12Security
  13. 13Children
  14. 14Changes to this policy
  15. 15Contact

1Who is responsible for your data

Fugaji publishes and operates the Fugaji service: the fugaji.com website, the app.fugaji.com web console and the Android and iOS mobile app. Fugaji is the controller of the data described in this policy.

For any question about your data, to exercise a right or to report a problem: contact@fugaji.com. We answer in French, English, Kinyarwanda or Swahili.

When you use Fugaji inside a farm organisation, that organisation decides what it records about its animals, its sales and its team; we process those records on its behalf and under our shared contractual instructions. For your personal account — your identity, your credentials, your devices — we are directly responsible.

2What we do not do

Three commitments apply across the whole service and do not depend on any setting:

  • No advertising. The service shows no adverts, neither our own nor anyone else's.
  • No advertising trackers and no analytics. There is no analytics SDK, no crash-reporting SDK, no advertising identifier, no tracking pixel and no third-party cookie — not in the mobile app, not on the website, not in the web console. We do not show Apple's tracking prompt because we do not track anyone.
  • No sale of data. We do not sell, rent or trade personal data, and we pass nothing to data brokers.

We do not profile people and we make no automated decision producing legal effects concerning you.

3The data we process, and why

Category by category, here is what is recorded, what it is for, and on what basis.

Account and identity
Name, email address and phone number when you provide them, a hash of your password, preferred language, profile photo, role and permissions in the organisation, creation date and deactivation date where applicable. Needed to create your account, sign you in and decide what you may see. Basis: performance of the contract.
Sign-in and devices
Open sessions, a hash of the refresh token, last use, expiry, revocation where applicable, and the device name sent by the client — typically the phone model. Needed to keep you signed in, to let you close a session remotely and to detect unusual access. Basis: performance of the contract and our legitimate interest in securing accounts.
Verification codes and invitations
The phone number attached to a one-time sign-in code and a hash of that code; for an invitation, the name, email address or phone number of the person invited, the intended roles and a hash of the invitation token. Codes and tokens are never stored in the clear. Basis: performance of the contract.
Livestock records
Animal files, identification and ear tags, pedigree, health events, treatments, vaccinations, breeding, weighings, milk production, feeding, movements and transactions. Every record keeps the identifier of the person who entered it, their free-text notes and any attached files. A transaction may carry the name of a counterparty. Basis: performance of the contract with the organisation, and its legitimate interest in keeping reliable records.
Photos and voice notes
Animal photos, listing photos, profile photos, task completion proofs, and voice notes recorded in the field. Photos are resized and re-encoded on the phone before they are sent, which in practice removes the metadata written by the camera, including any GPS position. In the rare case where the phone cannot process an image, the original file is sent as it is, with its metadata. Basis: performance of the contract.
Tasks and teamwork
Task titles and descriptions, assignments, checklists, comments, activity history, block and cancellation reasons, attachments. An attachment may carry the coordinates of the place where it was captured when the client supplies them. Basis: performance of the contract and the organisation's legitimate interest in organising its work.
Messages
The content of messages exchanged between members of an organisation, the sender's identifier, attachments, read receipts and dates. These messages are not end-to-end encrypted: they are stored on our servers so they can be delivered to all your devices and work offline. Basis: performance of the contract.
Shop and orders
Published listings — description, price, photos, linked animal — and, for each order, the buyer's name and phone number, the order lines, the amount, the status and, where applicable, the payment reference. An order can be placed without an account: the phone number is then the only thing that lets the buyer find it again. Basis: performance of the contract and pre-contractual steps at the buyer's request.
Collar positions and sensor readings
Positions sent by an organisation's connected collars, ear tags and boluses: device identifier, animal concerned, date and time, coordinates, speed, accuracy, battery level, and temperature readings. These are an animal's position, never a phone's. They do, however, reveal where a farm is and how it moves. Basis: performance of the contract with the equipped organisation.
Farm geography
Location and boundaries of farms and paddocks, virtual fences and their active hours, as the organisation draws them on the map. Basis: performance of the contract.
Alerts
Alerts raised by the fence, inactivity, battery or temperature rules, with their message, their underlying figures, their status, the person who handled them and their resolution note. Basis: performance of the contract.
Subscription and payments
Plan, status, current period, declared payment method, and for each payment the amount, currency, status, provider and transaction reference. We neither receive nor keep any card number or mobile money PIN. Basis: performance of the contract and the legal obligation to keep accounting records.
Push notifications
The device's notification token, the platform (iOS or Android), the device name and the date it was last seen. Needed to send you an alert or a message. Basis: consent, which you withdraw by turning notifications off in your phone settings.
Administration log
Sensitive actions: sign-in, password change or reset, account creation and modification, invitations sent (with the address or number invited), role changes, device registration and deletion, subscription and plan changes. Each entry keeps the author, the action, the object concerned and the date. Basis: legitimate interest in security, traceability and evidence.
Technical logs
Our servers and those of our hosting providers produce operational logs which may contain an IP address, a date and the request made. They keep the service running, limit abuse and help diagnose incidents. The IP address is also used as an in-memory key for rate limiting; it is not written to our database. Basis: legitimate interest in the security and continuity of the service.

4What the mobile app does on your phone

Camera
Used to photograph an animal, illustrate a listing or a task, and to read an identification code. Reading a code stores no image: only the decoded text is used.
Microphone
Used only while you hold the record button of a voice note. The app never listens in the background.
Photo library
Used when you pick an existing picture. The app reads no other photo.
Phone location
The app never reads your phone's location. It contains no geolocation library and calls no device location function. The points shown on the map come from animal collars and from the farm boundaries the organisation has recorded.
Offline copy
So that it works without a network, the app keeps in its private local database a copy of animals, breeds, herds, the calendar, alerts, the latest positions and the fences, along with a queue of entries not yet sent, including pending photos and voice notes. Your sign-in tokens and your profile are stored there too. This copy does not leave the device. It is erased when you sign out and when you uninstall the app.
Device information
The app sends the device model when you sign in, accept an invitation and register for notifications, so that you can recognise your own sessions. It sends no advertising identifier, no serial number and no unique hardware identifier.

The mobile app talks only to our own servers. Map imagery is relayed through our interface, so your phone does not contact the imagery provider directly.

5The assistant and voice-note transcription

When the assistant is enabled on the installation you are using, the question you ask is sent to our language-model provider, Anthropic, to obtain an answer. To answer, the model may query data belonging to your organisation alone — animal counts, animal lists, milk production, upcoming tasks, farm structure, open alerts — and those results are sent with the question. Assisted drafting of a monthly report sends, in the same way, the report's aggregated figures, the organisation name, the farm name and the period.

We do not keep a history of your conversations with the assistant: neither the question nor the answer is written to our database. Do not give the assistant information you would not want a third-party provider to receive.

When automatic transcription is enabled, a voice note is sent to the transcription service configured for the installation, together with a language hint. The resulting text is added to the notes of the record concerned; the audio stays attached to the file. When transcription is not enabled, a voice note remains a plain audio file and is sent to no one.

When no assistant provider is configured, the feature is hidden: nothing is sent anywhere.

6The providers involved

We share data only with the providers the service needs, for the purposes listed below, and none of them is allowed to use it for their own ends.

Vercel
Hosts the public website, the web console and the administration console. Receives browsing traffic and the associated technical logs.
The host of our application server
The programming interface, the PostgreSQL database and the file storage run on a dedicated server administered by Fugaji at an infrastructure provider. That server holds all the data described above, including photos, voice notes and reports.
Expo
Delivers push notifications. Receives the device's notification token, the notification title and its body. For a message, the body contains the sender's name and the beginning of the message; for an alert, its text and its type.
Resend, or the configured mail relay
Delivers the service's emails: invitations, password resets, welcome messages. Receives the recipient's address and the content of the message.
Esri (ArcGIS World Imagery)
Provides the satellite map imagery. On the public website and in the web console your browser contacts this service directly, so it sees your IP address and the area you are looking at. In the mobile app the same imagery is relayed by our server.
Anthropic
Provides the assistant's language model, when it is enabled. Receives the question asked and the results of the queries limited to your organisation, as described above.
Transcription service
Turns a voice note into text, when that feature is enabled. Receives the audio file and a language hint.
Onafriq (MFS Africa)
Collects mobile money payments, when that feature is enabled. Receives the payer's mobile money number, the amount and the reference. This integration is not active today; while it is not, no payment is processed by the service.

Sending codes by SMS is not active today: no SMS aggregator receives any data from us.

We may also disclose data where the law requires it, on a request from a competent authority, or to establish, exercise or defend a legal claim. If the business were transferred, the data would follow the service and you would be told before any transfer.

7Hosting and transfers outside your country

The database, the files you upload and the collar positions are hosted on a single server administered by Fugaji. The website and the web consoles are served by a global delivery network.

Several of our providers are established outside the African continent, in particular in the United States. Using Fugaji therefore means that some data is processed outside your country of residence. We choose providers that offer contractual confidentiality guarantees, and we limit each of them to the data its service strictly requires.

8Cookies and local storage

We use no advertising cookie and no analytics cookie. There is therefore no consent banner: there is nothing to consent to.

On this website
A single functional cookie remembers the display language you choose. No other cookie is set.
In the web console
Two functional cookies remember your language and your time zone so that dates display correctly. Your session, your light or dark theme and a few display preferences are kept in your browser's local storage, on your device.
In the mobile app
There is no cookie. The session and the preferences are kept in the app's private local database.

9How long we keep things

We keep data for as long as it is needed, then we delete it or detach it from your identity.

One-time sign-in codes
Valid for 5 minutes; expired records are deleted every night.
Password-reset tokens
Valid for 1 hour; deleted every night once expired. Using a reset link closes all your sessions.
Invitations
Valid for 7 days; deleted every night once expired or accepted.
Sessions
An access token lives 15 minutes; a session stays valid for 30 days and is extended each time it is used. You can close it at any moment by signing out.
Livestock records, tasks, messages, orders, alerts, files and collar positions
Kept for as long as the organisation exists and its administrator does not delete them. They are the organisation's memory: we do not erase them on our own initiative. They disappear when the organisation is deleted, under the conditions described below.
Accounting records attached to payments
Kept for as long as the applicable accounting and tax rules require, even after the account concerned has been deleted.
Administration log
Kept for as long as the organisation exists, for security and evidence. The author is detached from it when their account is deleted.
Backups
Backup copies of the database are taken regularly. Deleted data may survive in a backup until the backup holding it is replaced; it is then used only to restore the service after an incident.

Today, collar positions and sensor readings are not pruned automatically: they are kept for as long as the organisation exists. We prefer to write that plainly rather than announce a retention period the service does not yet enforce.

10Deleting an account and an organisation

You can delete your account yourself, from the mobile app settings or from your profile in the web console. Deletion is final and requires no step on our side.

Deleted: your account, your name, your email address, your phone number, the hash of your password, your profile photo, your sessions, your notification tokens, your preferences and the invitations you had sent.

Kept, but detached from your identity: the records, messages, comments and documents you created inside an organisation. They belong to the organisation's memory — a health register cannot lose its pages because an employee leaves. Your name is replaced there by « Deleted account » and the link to your account is broken.

The last administrator of an organisation that still has other members cannot delete their own account alone: they must first hand the organisation over to another administrator, or delete the whole organisation. If they are its only member, deleting their account also schedules the organisation's deletion, with the same grace period.

Deleting an organisation erases all of its data, for every member. It is preceded by a 30-day grace period: the organisation is disabled at once, then erased for good at the end of the period. An administrator can cancel the deletion during those 30 days.

The step-by-step instructions are on the « Delete your account » page.

11Your rights

Whatever your country of residence, we grant every Fugaji user the following rights:

  • to know what data we hold about you and to obtain a copy of it;
  • to have inaccurate or incomplete data corrected — your name, address and number can be changed directly in your profile;
  • to have your data erased, which you can trigger yourself by deleting your account;
  • to ask us to restrict a processing activity, or to object to it where it rests on our legitimate interest;
  • to receive your data in a machine-readable format, or to have us send it to another provider where that is technically feasible;
  • to withdraw a consent at any time, in particular for notifications, the camera and the microphone, without affecting what was done before;
  • to lodge a complaint with the competent data protection authority in your country.

Write to contact@fugaji.com from the address attached to your account, or tell us the phone number you sign in with. We answer within 30 days. We may ask for one further element to verify your identity, only where that is necessary, and that element is destroyed once the check is done.

Where your request concerns records belonging to an organisation you are a member of, we pass it to its administrator, who decides on the content of their records, and we tell you that we have done so.

12Security

These are the measures actually in place. We claim no certification and we do not claim absolute security.

  • Traffic between your devices and our servers goes over an encrypted connection (HTTPS/TLS).
  • Passwords are never kept in the clear: only a bcrypt hash is stored. One-time codes, invitation tokens, reset tokens and session tokens are stored as hashes too.
  • Separation between organisations is enforced by the database itself, row by row: a query run for one organisation physically cannot read another's rows. The service refuses to start if that separation is not active.
  • A user's rights are re-read on every request: removing a role or disabling an account takes effect immediately.
  • Sign-in attempts, code requests and resets are capped in number, and the service enforces an overall request ceiling.
  • Messages sent by collars must be signed with each device's own secret, within a five-minute replay window.
  • Changing a password closes your other sessions; resetting it closes them all.
  • Sensitive actions are logged.

Two points are worth knowing. Photos, audio files and attachments are served from an unguessable address and need no authentication to be displayed: anyone you pass such a link to will be able to see the file. PDF reports are the exception and require a signed link valid for ten minutes. Separately, we do not encrypt data at the database column level; protection rests on tenant separation, access control and server security.

In the event of a data breach likely to create a risk for you, we inform the people concerned and, where the law requires it, the competent authority.

13Children

Fugaji is a professional tool intended for adults. The service is not designed for children, is not offered to them and contains no content aimed at them.

We do not knowingly collect data about anyone under 18. If we learn that such an account exists, we delete it and its data. If you are a parent or guardian and believe a minor has given us data, write to contact@fugaji.com.

14Changes to this policy

This policy will change with the service: a new feature, a new provider or a new legal obligation may lead us to amend it. The date of the last update appears at the top of the page, and earlier versions remain available on request.

A substantial change — a new category of data, a new purpose, a new provider receiving your data — is announced at least 30 days in advance, by email to the administrators of the organisations and by a notice shown in the service the next time you sign in. If the change requires your consent, we will ask for it before applying it.

15Contact

Controller: Fugaji. For any question about this policy, to exercise a right or to report a security incident: contact@fugaji.com.

The French version of this policy is the reference version. If a translation differs from it, the French text prevails.

Fugaji

Livestock management for African farms: offline-first, in your language, paid by mobile money.

Product

  • Features
  • Pricing
  • FAQ
  • Android app

Company

  • About us
  • Contact

Legal

  • Privacy
  • Terms
  • Delete an account

© 2026 Fugaji. All rights reserved.

Fugaji