Infrared Explorer Privacy Policy
This Privacy Policy describes how Institute for Future Intelligence, Inc. (“IFI”, “we”, “us”) collects, uses, and shares information when you use Infrared Explorer: the mobile app for Android and iOS (shown on your device as “IR Explorer”) and the companion website at ie.intofuture.org (together, the “Service”). IFI is a non-profit educational research organization based in Natick, Massachusetts, USA.
Infrared Explorer is a scientific instrument for thermal imaging with a FLIR ONE camera and a citizen-science tool for building the crowd-sourced Infrared Street View. It is not a medical device and is not intended for measuring body temperature or for any medical, health, or veterinary purpose.
The short version
- You can use the app without an account. Everything you capture stays on your device unless you choose to share, export, or upload it.
- Signing in (Google, or Apple on iOS) gives us your name, email address, and profile picture, and lets you upload recordings and street views to the cloud.
- Uploads are meant to be seen. Recordings are “link only” by default; street views are public on the shared map and include the precise location where you captured them.
- Location is used only while the app is open, never in the background, and is sent to us only inside a street view you upload.
- AI lab reports are written only when you ask for one. The app tells you what it will send to the AI provider you pick, asks you to agree the first time, and never sends your name, email address, or account identifier.
- No ads, no tracking, no analytics SDKs, no sale of personal information.
- You can delete your account in the app, on the website at ie.intofuture.org/delete-account, or by asking us. Deletion removes your account and everything it uploaded; section 6 lists the few things that can remain.
1. Information we collect
1.1 Account information (optional)
The app works fully as a guest, offline. If you sign in so you can upload to the cloud, join class activities, or use the website, we receive from your sign-in provider:
- Google Sign-In (Android, iOS, web): your name, email address, profile picture URL, and a Google account identifier used to authenticate you.
- Sign in with Apple (iOS): your name (Apple provides it once, at first sign-in) and either your email address or, if you choose “Hide My Email”, an Apple private-relay address that forwards to you.
We create an internal account identifier for you and keep an account record containing your email address, display name, profile picture URL, sign-in provider identifier, account creation time, and (on the website) the time of your most recent sign-in and your notification preferences. A separate public profile — display name, profile picture, the short bio you may write, and the month you joined — is visible to anyone on the website, signed in or not, together with the content you have made public.
On your device the app keeps a list of the accounts you have signed in with (name, email, picture URL, identifiers) so you can switch between them, and keeps each account’s captures and settings separate.
1.2 Content you upload
Nothing is uploaded automatically. When you choose Upload in the app (or save, copy, or annotate an experiment on the website), we store:
- Thermal recordings: the radiometric thermal frames, the rendered thermal images, and the visible-light photographs taken at the same instants. The app always records the visible-light photographs alongside the thermal frames, and there is no setting to leave them out of an upload. Visible-light photographs may show people, homes, vehicles, and other identifiable details of the scene you filmed.
- Photo sets: still photos you tick in the gallery and upload together as one experiment. A photo that carries temperature data uploads that data together with its rendered images; a photo without it — a screenshot-style capture, a chart, or a picture you brought in from your phone’s photo library — uploads as the picture alone. A picture brought in from your photo library is uploaded as it stands: we do not strip metadata your phone wrote into it (see Location).
- Street views: the same kinds of images, plus the precise location (latitude and longitude) where the panorama was captured, the compass heading and tilt of each shot, and the capture time.
- Descriptions: the title, description, subject, temperature unit, palette, and other settings you choose, and your display name shown as the author.
- Website additions: temperature probes, transects, annotations and notes, key-moment captions, chart settings, and the reports you generate for an experiment.
A still photo is uploaded only when you select it and choose Upload yourself. Photos you do not upload stay on your device, and leave it only if you share them or turn on the System gallery setting, which copies captures into your phone’s photo library.
Who can see uploads. A recording you upload is link only (“unlisted”) by default: it does not appear in public lists, but anyone who has its link can open it, and it can appear as a “related” item next to other experiments made from the same recording. You can change it to private or public on the website. A street view you upload is public: it appears on the shared Infrared Street View map for everyone, with its location, your display name, and its capture time. You control it afterwards: in the app, Account › Street View › My street views lets you make any of your street views private or delete it outright. If another user reports one of yours, it may be taken off the map automatically while we look at it, and its image files are moved at the same time to a location that is not publicly readable; we tell you when that happens, and you can appeal. Image and data files that are still published are served from web addresses that do not require sign-in; anyone who has such an address can open the file until it is deleted or moved.
1.3 Website activity
- Comments you post on experiments, shown publicly with your display name and profile picture.
- Ratings you give to experiments. Ratings are recorded under your account identifier and are publicly readable, so it is possible to tell which accounts rated an experiment.
- Viewing history: a private record of the experiments you open, visible only to you.
- Notifications about comments and ratings on your experiments, which name the person who left them. You can turn these off in Settings.
- Contact and deletion-request forms: the email address and message you type (and, on the contact form, your name), which are also emailed to us.
1.4 Classroom features (website and app)
If you join a class with a class number and password, your display name and email address are added to the class roster, which is visible to the teacher and to the other members of that class. The teacher’s name and email address are visible to class members. Your submissions to assignments are visible to the teacher; grades are written by the teacher and visible to you; work the teacher promotes to the class showcase is visible to the whole class; your private workspace is visible only to you.
1.5 AI lab reports (app) and AI analysis tools (website)
AI lab reports in the app. Any signed-in user can ask the app to write a draft lab report for a recording they have uploaded. Each time, the app shows what will be sent and to which provider, and before your first report it asks you to agree. When you generate a report, the recording’s thermal data, its rendered thermal images, the visible-light photographs in it, its title, description, and annotations, and any notes you type for the AI are sent to the AI provider you choose from those offered in the app (OpenAI, Google, xAI, or DeepSeek) to produce the report. Your name, email address, and account identifier are not included in these requests. The report, the notes you typed, and any temperature probes the AI places on the recording are stored with the experiment and visible to anyone who can view that experiment.
Personal accounts — every account other than an IFI staff account — can generate a limited number of reports each hour and each day. The counts behind these limits are kept under your account identifier and expire about a day after your last report. When you agree to send your data to an AI provider, we keep a record of that agreement (which version of the notice you agreed to, when, and the platform and app version you used) until you delete your account.
AI analysis tools on the website (currently limited to IFI staff). The website includes AI-assisted analysis tools (lab-report drafts, questions about an experiment, and a lab assistant). At present they can be used only by IFI staff accounts. When a staff member uses them on an experiment they are permitted to view, the experiment’s thermal data, its rendered thermal images, any visible-light photographs in the recording, its title, description, and annotations, the question typed, and a screenshot of the viewer are sent to a third-party AI provider (OpenAI, Google, xAI, DeepSeek, or Anthropic) to produce the response. Your name, email address, and account identifier are not included in these requests. A generated report, and the instructions typed to produce it, are stored with the experiment and visible to anyone who can view that experiment. If you own the experiment, each question you ask and the answer you receive (with the model used and the moments you attached) are also stored with the experiment, readable and deletable only by you; on someone else’s experiment the thread is kept only in your browser. A follow-up question is sent to the provider together with the earlier questions and answers in that thread and any existing report for the experiment.
1.6 Diagnostic and technical information
- Website error reports. If a page of the website crashes, the browser sends us the error message and stack trace, the page address, your browser type, and your account identifier if you are signed in. We keep these reports for 90 days; deletion runs as an automatic sweep, so a report can remain for up to a day after that.
- Abuse prevention. To rate-limit view counting we store, for two hours, a one-way hash of your account identifier if you are signed in or of your IP address if you are not; to rate-limit the contact form we store a one-way hash of your IP address with a message count, for two hours; to rate-limit class joins and AI requests we store counts under your account identifier (the AI counts expire about a day after your last request). We do not store raw IP addresses in our database. These hashes are rate-limit keys, not anonymised data: an IP address is drawn from a small enough set of possibilities that we do not claim a hash of one cannot be reversed — what we do claim is that it is short-lived and is never attached to what you sent. Two details apply to every period named here and in section 5: the clock on a record restarts each time a new request is counted against it, and the deletion itself runs as an automatic sweep, so a record can persist up to a day beyond the period stated.
- View counts on experiments are aggregate numbers; your own views of your own experiments are not counted.
- The mobile app sends no analytics, crash reports, advertising identifiers, or device identifiers. Neither the app nor the website uses advertising or analytics SDKs, and we do not track you across other companies’ apps or websites.
- Server logs. Our hosting provider (Google Firebase) keeps standard infrastructure logs, including IP addresses and request timestamps, for a limited period to operate and secure the Service.
1.7 Information stored on your device or in your browser
The app stores your captures, settings, account list, pending uploads, and — if you use a wireless FLIR camera — the camera’s Wi-Fi password, in its own storage on your device. On iOS the capture folder is also visible in the Files app. The website keeps your sign-in session, display preferences, and unsent drafts in your browser’s local storage; it does not set advertising or tracking cookies.
1.8 Reports, flags, and blocks
The Infrared Street View map has no review before publication, so it is moderated by the people looking at it; the experiments people share, and what is posted in a class, can be reported the same way; and an AI lab report can be flagged by the people who read it. Three features record information as a result.
- When you report a street view, an experiment, an author, or something in a class, we store what you reported (the street view or experiment identifier, its title and its author’s account identifier at the time, or the reported author’s account identifier), the reason you picked, anything you typed in the description box, when you sent it, and how it was resolved. A report on a person in a class is filed against that person’s account, and a report on a class as a whole against its teacher’s. The app adds one line to the end of the description when the report needs more context: where a report on an experiment is filed against the experiment’s author, that line gives the experiment’s title and web address, and where a report is made from inside a class, it gives the class number, the class name, and the class’s web address. If you were signed in, your account identifier is stored with it, so that we can tell you what happened and so that reporting the same thing twice does not count twice. For a report filed against a person’s account, “the same thing” means the same person. While a report you filed is still open, reporting the same thing again does not create a second report and cannot hide anything a second time — but if you have something new to say, what you type is kept on that open report as an addition, with the reason you picked and the time you sent it. A report holds up to ten additions; after that, or if you only repeat what you said last time, nothing further is stored and we ask you to write to us instead. Additions are deleted together with the report they were added to (section 5). Once a report has been resolved, reporting the same thing again starts a new report in place of the old one, additions and all. If you were not signed in, no identifier for you is stored on the report — neither your IP address nor anything derived from it. With no identifier there is nothing to match a later report against, so a report sent while signed out always stands on its own and never becomes an addition to an earlier one. A short-lived hash of your address is kept separately from the report, and only to limit how many reports can be sent in an hour; it expires about a day after your last report. Section 1.6 says what that hash is and is not.
- When you flag an AI lab report (in the app, from the report’s ⋮ menu), we store the experiment’s identifier and title, its owner’s account identifier, a copy of the flagged report’s text as it stood when you flagged it, which model wrote it and when, the reason you picked, anything you typed in the description box, your account identifier, whether the experiment is yours, when you sent it, and how it was resolved. Flagging the same version of a report again replaces your earlier flag. A flag does not hide the report, and the experiment’s owner is not told about it. We keep the copy of the report so that we can judge what was flagged even if the report is later regenerated or cleared. If a flag is upheld, IFI staff may remove the report from the experiment and may stop the owner’s account from uploading and from using AI reports.
- When you hide an author, we store that author’s account identifier and display name in a private list under your account, which only you and IFI staff can read. The author is never told. Removing them from the list deletes the entry.
- What the author is told. If your street view or your experiment is hidden or removed after a report, you get a notification and an email saying which one and what happened. Neither ever names who reported it.
2. Location
The app asks for permission to use your precise location, and only while the app is open. It never collects location in the background. Location is used to:
- geotag a street view panorama so it appears in the right place on the shared map;
- save a small location file next to each recording on your device, so a recording can later be placed on a map; this file stays on your device and is not uploaded or included in exports;
- show your coordinates in the optional sensor overlay on the live view; and
- center the street view map on where you are.
Your location reaches us only through something you upload, and there are two such ways. The first is a street view you choose to upload, where the capture location becomes part of a public map pin; if a street view has no saved capture location, the app asks before using your current position instead. The second is a picture you brought in from your phone’s photo library and then uploaded: the app never writes location into a photo it takes, but it does not remove metadata a picture already carries, so if your phone geotagged that picture and hands the tag over when you pick it, the tag is part of what you upload. Two things to know as well: a photo the app takes is a picture of what the screen shows, so if you have turned on the optional Sensor data overlay, the coordinates it displays are part of any photo you take while it is on, and travel with that photo if you share or upload it; and files you upload are served from web addresses that do not require sign-in. You can decline or later revoke the location permission in your device settings; the app keeps working, but street views cannot be placed on the map.
Camera hardware and connections
To operate a FLIR ONE camera the app uses USB, and for wireless FLIR ONE Edge cameras it uses Bluetooth, local-network discovery, and joins the camera’s own Wi-Fi network (only after you turn on the Wireless camera setting). The app does not take pictures with your phone’s own camera: the visible-light detail blended into thermal images comes from the FLIR camera’s built-in visible-light sensor (iOS may still list a camera entry for the app because the flashlight toggle drives the camera’s LED). These capabilities are used solely to talk to the camera and to capture images; nothing about your Bluetooth or Wi-Fi surroundings is collected by us, and we do not send your data to Teledyne FLIR. The camera’s serial number is recorded in a capture’s local information file and is not uploaded.
3. How we use information
- to operate, secure, and improve the Service and provide the features you use;
- to authenticate you and associate your uploads, comments, and class memberships with your account;
- to display your public content, profile, and street views to other users, as described above;
- to run the classroom features for teachers and students who use them;
- to respond to your messages and deletion requests;
- to enforce rate limits and prevent abuse;
- to review reports about street views, experiments, authors, or anything in a class and flags on AI lab reports, to moderate content, and to act on violations of the Terms — including hiding or removing content and suspending accounts;
- to conduct education research and report on the National Science Foundation grants that fund this work, using data in aggregate or de-identified form; and
- to comply with law and protect the rights, safety, and property of users and IFI.
We do not sell personal information, use it for advertising, or use your content to train AI models of our own.
4. How we share information
| Who | What and why |
|---|---|
| Other users and the public | Content you make public or link-only, your display name and public profile, your comments and ratings, public street views with their locations, and — within a class — your name and email address on the roster. |
| Google Firebase (service provider) | Authentication, database, file storage, cloud functions, and hosting for the whole Service, operated on our behalf in the United States under Google’s data-processing terms. |
| Google and Apple (sign-in) | When you sign in, Google or Apple learns that you are signing in to Infrared Explorer and issues the identity we receive. If you sign in with Google, your profile picture is served from Google’s image servers: whenever the app or the website displays it — including to other people viewing your public profile or comments — the viewing device fetches it from Google, which then sees that device’s IP address. Their own privacy policies govern these steps. |
| Map providers | The app’s home screen shows a small street view map preview, and the full street view map opens on demand; both load map tiles from the OpenStreetMap Foundation (the full map also from Esri, and its map library from a public content-delivery network). Those servers see your device’s IP address and the map area shown — for the home preview that is a fixed starting area or your saved default map location, not where you are — and this happens whenever the app opens, including as a guest. Place searches you type in the map are sent to OpenStreetMap’s Nominatim geocoding service. The website’s street view map uses Google Maps Platform, which receives your IP address and map interactions under Google’s privacy policy. |
| AI providers | Experiment data and images as described in section 1.5, only when an AI lab report or another AI tool is used, and without your name, email address, or account identifier. We access the providers through their developer APIs; each provider’s API terms and privacy policy govern how it handles submitted data, including whether it may use that data to improve its models. |
| IFI staff | IFI staff accounts can read the private account record described in section 1.1 (including your email address, last sign-in time, account role, the preference toggles in Settings, and the identifiers of any classes you have joined), all uploaded experiments and street views regardless of visibility, and all comments, in order to moderate content, curate featured work, support users, and operate the Service. Staff also read the reports and flags users file, including the reporter’s account identifier and description and the copy of a flagged AI report, and the lists of authors users have hidden. Staff can remove content that violates the Terms, including AI reports, and stop an account from uploading anything further or using AI reports. |
| Researchers | Aggregate or de-identified data about how the Service is used may be shared with research collaborators and funders. We do not share your identity with them. |
| Email delivery | Messages you send through the contact and deletion-request forms are relayed to us by email. |
| Legal and successors | We may disclose information if required by law, to enforce our Terms, or to protect rights, property, or safety; and if IFI merges with or transfers the Service to another non-profit or entity, your information may transfer subject to this Policy. |
We do not share personal information with advertisers or data brokers, and there is no advertising in the Service.
We share user data only with third parties that provide the same or equal protection of that data as described in this Policy. The service providers that process information on our behalf — Google Firebase, the AI providers named in section 1.5, and the email service that delivers form messages to us — handle it under the terms that govern our use of their services: Google Firebase and the email service may use it only to provide their service to us, and the AI providers receive only the data described in section 1.5 and handle it under their developer API terms, as described in the table above. The map, geocoding, and content-delivery servers listed above receive only the technical information any web request carries (your IP address and what was requested) and handle it under their own published privacy policies.
5. How long we keep information
- Account and uploaded content: for as long as your account exists, or until you delete the content or the account.
- Experiments you move to the trash remain stored (and, if they were public or link-only, remain reachable by link) until you delete them permanently or delete your account.
- Website error reports: 90 days, plus up to a day for the sweep that deletes them.
- Abuse-prevention records: hashed view-counting records (account identifier or IP address) and hashed contact-form records expire two hours after the last request counted against them; AI request counters expire about a day after your last AI request; other per-account rate-limit counters are deleted with your account. As section 1.6 explains, the sweep that carries out these deletions can lag the stated period by up to a day.
- Reports about street views, experiments, authors, or anything in a class, and flags on AI lab reports: 12 months from when they were filed, resolved or not, then deleted automatically. Anything added to a report that was still open (section 1.8) is deleted with the report it was added to, so an addition can be kept for less than 12 months and never for more. The rate-limit records behind them (a hash of an account identifier or IP address) expire about a day after the last report counted against them.
- Lists of authors you have hidden: until you remove the entry or delete your account.
- Your agreement to AI lab reports: until you delete your account.
- Contact and deletion-request messages: for as long as needed to respond and to keep a record that a request was honored.
- Guest data never reaches us: it lives only on your device until you delete it or uninstall the app.
- Backups: deleted data may persist in our provider’s backups for a limited period before it cycles out.
6. Deleting your account
You can delete your account, and everything it uploaded, in three ways:
- In the app: open the Account screen (from the menu or your avatar on the home screen) and choose Delete account. You will be asked to sign in once more to confirm.
- On the website, without the app: ie.intofuture.org/delete-account.
- By request: use the form on that page, or email xiaotong@intofuture.org from the account’s email address. We delete the account and confirm by email, normally within a few days.
Deletion is immediate and permanent. It removes:
- your account record, sign-in, profile, and public profile page;
- every recording, experiment, and street view you uploaded, including thermal frames, images, and locations;
- comments and ratings you left on other people’s experiments, together with any replies other users made to those comments;
- the reports you filed about street views, experiments, authors, or class content, and your list of hidden authors; entries pointing at you in other users’ hidden-author lists are deleted too, so your account identifier does not survive as a bare string in a stranger’s list;
- the flags you filed on AI lab reports, the flags anyone filed on AI reports about your experiments, and the record that you agreed to AI lab reports;
- your class memberships, submissions, grades, and workspace items; and
- classes you created, together with everything inside them (your students’ own experiments are not affected).
Four things can remain, and we tell you so here rather than quietly:
- if another user copied one of your recordings into their own experiment, the recording’s image files stay online so their work is not blanked out; your name, title, and account are still removed;
- reports other users filed about you or about your experiments — including your account identifier and the experiment titles and class names written into them — are kept until they expire, 12 months after they were filed (section 5); reports about your street views are deleted with them;
- your display name, and the title and description of experiments you published, may remain in other users’ notification history and in their private viewing history;
- if you cancelled an upload, or it was interrupted before it finished, the files it had already sent were never linked to your account, so deletion cannot find them; they sit at an unguessable address, are shown nowhere on the Service, and we will remove them if you ask.
Anything already downloaded, shared, or exported by you or by others before deletion is outside our control. Deleting your account does not delete captures stored on your own device; they are kept there and move to the guest library.
7. Children’s privacy
Infrared Explorer is a general-audience science tool. It is not directed at children under 13, and you must be at least 13 to create an account. Users under 18 should use the Service with the involvement of a parent, guardian, or teacher.
The Service is used in schools. Teachers who use the classroom features are responsible for enrolling only students who meet the age requirement above and for obtaining any consent their school or district requires. We do not knowingly collect personal information from children under 13, we do not use student information for advertising or to build commercial profiles, and on request from a school we will describe the information held about its students, let the school review it, and delete it. If you believe a child under 13 has provided personal information to us, contact xiaotong@intofuture.org and we will delete it.
8. Your choices and rights
- Use the app without an account. Sign-in is needed only for cloud features.
- Control visibility. Recordings can be private, link-only, or public; you can move experiments to the trash or delete them permanently on the website. A street view is public when you upload it, and you can make any of yours private again or delete it outright in the app under Account › Street View › My street views; deleting your account (section 6) removes all of them at once. If you cannot reach the app, email xiaotong@intofuture.org and we will remove it for you.
- Report what should not be there, or hide who published it. Both are in the ⋮ menu on a street view, in the app and on the website. In the app, a card showing someone else’s experiment outside a class has Report experiment and, where a person published it, Report author and Hide this author; reporting needs no account. Inside a class, the ⋮ menus on the class’s experiments and on roster rows let its members report what they see, and a student can also report the class as a whole from the class’s own ⋮ menu. In the app you can also flag an AI lab report from its ⋮ menu. Section 1.8 says what each of them records.
- Manage permissions for location, Bluetooth, local network, and the photo library in your device settings at any time. The System gallery and Wireless camera features are off until you turn them on.
- Edit your profile and notification preferences in Settings on the website.
- Delete your account as described in section 6.
- Access, correction, portability, objection. Email xiaotong@intofuture.org. Residents of California, the European Economic Area, the United Kingdom, and other jurisdictions with privacy laws may have additional rights; we honor verified requests to the extent required by applicable law, and we do not discriminate against you for exercising them.
9. Security
All traffic between the app or website and our servers uses TLS (HTTPS). Data is stored with Google Firebase, which encrypts it at rest, and access is governed by identity-based security rules and staff access limited to the purposes above. Uploaded media files are protected by long, unguessable addresses rather than sign-in; treat a link to an unlisted experiment like a key. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
10. International users
The Service is operated from the United States. If you use it from elsewhere, your information is transferred to and processed in the United States and in other countries where our service providers operate, which may have different data-protection laws from your own.
11. Changes to this Policy
We may update this Policy. The “Last updated” date above reflects the current version. Material changes will be announced in the app or on the website, or by email where practical, before they take effect.
12. Contact
Privacy questions or requests:
xiaotong@intofuture.org
Institute for Future Intelligence, Inc., Natick, Massachusetts, USA
Terms of Service: ie.intofuture.org/terms