What we collect
Depending on how you use Barncom, we may collect:
- Contact and account details such as your name, email address, and organization information.
- Barn, horse, lesson, schedule, document, and operational records that you or your organization choose to store in the service.
- Photos, videos, and other media you upload or link, together with the details you enter about them.
- Support communications, attachments, screenshots, and troubleshooting details you send to us.
- Basic device, browser, log, crash, and usage data needed to secure and operate the website and app.
- If you connect a Google account, the Google account data described under Google services below.
- If third-party advertising is enabled, advertising-related data such as your IP address, device and advertising identifiers, app interactions, diagnostics, and general or approximate location derived from your IP address.
How we use information
- To provide, maintain, secure, and improve Barncom.
- To respond to support, billing, account, and legal requests.
- To operate customer organizations, permissions, and shared workflows inside the product.
- To publish, list, or link content on third-party services such as YouTube or Google Calendar only when you ask Barncom to do so.
- To comply with law, enforce our terms, and prevent abuse or unauthorized access.
- If advertising is enabled, to request, deliver, measure, limit the frequency of, and protect ads, subject to applicable consent and privacy choices.
How information may be shared
- With vendors and service providers that help us operate hosting, storage, analytics, crash reporting, communications, or support tooling.
- With Google, when you connect a Google account and ask Barncom to act on it — for example to upload a video to your YouTube channel, create a calendar, or export a spreadsheet. What is sent is described under Google services.
- If third-party advertising is enabled, with Google and participating advertising partners to deliver, measure, secure, and improve advertising as described below.
- Within your Barncom organization when access is granted by an account owner, admin, or other permitted role.
- When required by law or when reasonably necessary to protect rights, safety, property, or service integrity.
- As part of a financing, acquisition, or business transfer involving Barncom or its operator, after obtaining any consent applicable law requires.
We do not sell personal information, and we do not sell, rent, or share Google user data with data brokers or information resellers.
How we protect your information
We use technical and organizational security measures to protect the confidentiality, integrity, and availability of the information you entrust to Barncom. These measures apply to sensitive data and to all Google user data obtained through the Google APIs described below, on the same terms as the rest of your data.
- Encryption in transit. Traffic between the Barncom apps or website and our servers, and between our servers and Google's APIs, is encrypted with HTTPS/TLS 1.2 or higher. Plain, unencrypted connections are redirected to HTTPS or refused.
- Encryption at rest. Data held in our managed database and in our file and media storage is encrypted at rest with AES-256 by the hosting platform, backups included.
- Protection on your device. Session and credential material cached on a device is kept in the operating system's protected keystore — the Apple Keychain or the Android Keystore — rather than in ordinary app files. You can turn on an app lock that requires biometrics or a PIN; PINs are salted and hashed with PBKDF2 and are never stored in readable form, and Barncom covers its contents in the app switcher while locked.
- Access control and least privilege. Every table in our database enforces row-level security, so an authenticated request can only reach the records that account's role permits, and access inside an organization follows the roles its owner or admin assigns. Administrative access to production systems is limited to a small number of named, authorized people and is used to operate, secure, and support the service — not to browse customer content.
- Narrowest Google permissions. Each Google feature asks only for the scopes that feature needs, in its own separate consent. Barncom does not bundle scopes together, does not carry a permission granted for one feature into another, and does not request a broader permission where a narrower one exists.
- Server-side custody of Google credentials. Your Google refresh token is never sent to your device and is never stored in the app. It is held only on our server, in a store that is unreachable from the public API: direct access is revoked for every client role, row-level security admits the server alone, and the token can be read only by a single hardened server function, through routines that re-check that the caller owns the connection. That function hands the app nothing but a short-lived access token — valid roughly one hour — limited to the scopes of the one feature you invoked. The Google OAuth client secret exists only in that function's server environment and is not present in any published app binary or web bundle.
- Separation from advertising and analytics. Google user data is kept apart from our advertising and analytics systems. It is never shared with advertising partners, data brokers, or information resellers, and it is not used to develop, improve, or train generalized artificial-intelligence or machine-learning models.
- Deletion and revocation. Disconnecting a Google account revokes Barncom's authorization at Google and deletes the stored token immediately; a token you revoke from your Google account instead is deleted within 30 days. Deleting your Barncom account removes the associated records as described under Data retention.
- Monitoring and incident response. Access to production systems is logged and monitored, and platform and dependency security updates are kept current. If we become aware of a breach affecting personal data, we will investigate it, remediate it, and notify affected users and the relevant regulators where applicable law requires.
No service can promise perfect security, but these controls are in place today and are reviewed whenever the product changes. If you believe you have found a security problem in Barncom, write to info@barncom.com and we will respond.
Google services
Barncom offers optional features that use your Google account. Each one asks for your permission on Google's consent screen the moment you first use it, requests only the permissions that feature needs, and can be disconnected at any time (see Disconnecting Google and YouTube).
Barncom's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms: Google user data is used only to provide the Barncom feature you turned on and that is visible to you in the app. It is not used for advertising, is not sold, is not transferred to anyone except as needed to run that feature or as required by law, and is not read by Barncom staff except with your permission, for security, or to comply with law.
How your Google data is protected
Google user data receives the protections described under How we protect your information, and these in particular:
- Every request to a Google API travels over TLS 1.2 or higher, and anything Barncom stores from those APIs is encrypted at rest with AES-256.
- Your Google refresh token never reaches your device or the app. It is held server-side in a store that the public API cannot reach at all — client roles have no access, row-level security admits only the server, and one hardened server function reads it through owner-checked routines. The app receives only a short-lived, single-feature access token, valid about an hour.
- The Google OAuth client secret lives only in that server function's environment. It is not shipped in the app.
- Each feature consents to its own scopes only. Permissions are not pooled across features, and no broader scope is requested where a narrower one will do.
- Only the people operating the connected feature in your organization can see what it produced, enforced by row-level security on every table.
- Barncom staff do not read your Google user data except with your permission, for security, or to comply with law.
- Revoking access deletes the stored token — immediately when you disconnect in Barncom, within 30 days when you remove Barncom from your Google account.
Google Sign-In
If you sign in with Google, Barncom receives your name, email address, and profile picture to create and identify your Barncom account.
YouTube
Barncom uses YouTube API Services to let you upload videos from Barncom to your own YouTube channel and to let you pick videos already on your channel to show in your barn.
By using Barncom's YouTube features you also agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
What Barncom accesses, collects, and stores
- An authorization token for your YouTube account, so uploads can run in the background and be resumed if interrupted. Barncom does not receive your Google password.
- Your YouTube channel identifier.
- When you browse “My YouTube Videos”: the titles, thumbnails, IDs, privacy status, and publish dates of videos on your channel. These are shown to you and are not stored unless you attach one of them to your barn.
- When you upload from Barncom: the video file you chose, the title, description, tags, privacy setting, and other publishing options exactly as you set them in Barncom, and — once YouTube accepts the upload — the resulting YouTube video ID and URL.
- When you attach an existing YouTube video: its video ID and URL, together with the title and description you confirm in Barncom.
How that data is used and shared
- To perform the upload or attachment you asked for and to show the video in your barn, to you and to the people in your organization who have access to that barn.
- Barncom never publishes, edits, or deletes anything on your channel except the specific action you trigger, and never changes the title, description, or other values you entered before sending them to YouTube.
- YouTube data is not used for advertising and is not shared with advertising partners or any third party other than Google itself.
Retention and deletion
- Data obtained from the YouTube API about your channel is refreshed or deleted within 30 days.
- Your YouTube authorization token is deleted from Barncom when you disconnect, and within 30 days if you revoke access through your Google account instead.
- If you delete a video from Barncom, the stored YouTube ID and URL are deleted with it; the video itself remains on YouTube unless you remove it there.
- You can ask us to delete stored YouTube data at any time using the contact details below; we complete such requests within 7 days.
Google Calendar
If you connect Google Calendar, Barncom creates and manages calendars that Barncom itself created, and their sharing settings, so lessons and schedules can appear in your Google Calendar. Barncom does not read your other calendars. Barncom stores the identifiers of the calendars it created and an authorization token for that connection.
Google Sheets and Drive
If you export to Google Sheets, Barncom creates a new spreadsheet in your Google Drive containing the Barncom data you chose to export and fills it in. Barncom can only see and modify files it created for you.
Firebase
Barncom uses Google Firebase for crash reporting (Crashlytics), usage analytics, and push notifications (Cloud Messaging). These collect device, diagnostic, and usage information and a push-notification token. They do not receive your Google account data.
Disconnecting Google and YouTube
You can revoke Barncom's access to your Google account at any time, in either of two places:
- In Barncom: open Settings → Connected Accounts and choose Disconnect, or use Disconnect YouTube from Barncom on the YouTube upload screen. Barncom immediately revokes its authorization with Google and deletes the stored token.
- In your Google account: visit the Google security settings page and remove Barncom. Barncom deletes the corresponding stored token within 30 days.
Disconnecting does not remove videos, calendars, or spreadsheets already created on Google's services, and does not delete your Barncom account.
Advertising and Google Mobile Ads
Barncom may display first-party promotions or third-party ads. First-party promotions are served by Barncom. If Google Mobile Ads is enabled, Google and its advertising partners may collect, receive, and use information from the app to provide, personalize where permitted, measure, and protect advertising. This information may include IP address, device and advertising identifiers, app interactions, diagnostic information, and general location inferred from the IP address.
Google may use mobile advertising identifiers and similar technologies rather than browser cookies in mobile apps. Learn more about how Google uses information from sites or apps that use its services and review Google's Privacy Policy.
Barncom does not currently sell personal information for money. If our advertising or data practices materially change, we will update this policy and provide notice where required.
Advertising consent and privacy controls
Before requesting third-party ads, Barncom will use the privacy and consent process required for the user's region. Where required, the app will ask whether advertising partners may use personal data for personalized advertising. Users can decline personalized advertising and, when required, reopen the app's privacy options to change a prior choice. Declining personalized advertising does not necessarily remove all ads; contextual or limited ads may still be shown where legally permitted.
Device-level controls may also let you reset or limit an advertising identifier, restrict tracking, or change app permissions. Those controls are provided by your operating system and may affect more than Barncom.
Data retention
We retain information for as long as reasonably necessary to operate the service, meet legal or accounting obligations, resolve disputes, and enforce agreements. Retention periods may vary depending on the type of record and the role it plays in account history, billing, support, or security. Data obtained from Google APIs is subject to the shorter periods stated under Google services.
Your choices
- You can request support, corrections, or account deletion through our deletion page.
- You can choose what information you add to Barncom, subject to organizational requirements set by your team.
- You can disconnect Google and YouTube at any time as described above.
- You can contact us if you need a copy of the data associated with a support request or website inquiry.
Children
Barncom is not directed to children under 13. If you believe a child has provided personal information through the service without appropriate authorization, contact us and we will review the issue.
Barncom does not use third-party personalized advertising for an account we know is used by a child. Before third-party ads are enabled for such an account, Barncom will either suppress the ad request or apply the child-directed or under-age treatment required by the applicable platform and law.
Changes to this policy
We may update this policy from time to time. If we make material changes, we may update the date above and provide notice through the website, the product, or both. If the way we use Google user data changes, we will ask you to review and accept the updated policy before continuing.
Service operator
Barncom is a product operated by Darkel Capital. In this policy, "we," "us," and "our" refer to the operator of the Barncom service.
Contact
Privacy questions about Barncom, including questions about Google or YouTube data, can be sent to info@barncom.com.