PRIVACY
Your data. Your record.
How Metal Detecting Log handles account information, finds, precise location, land permissions, events and the optional Night Watch feature.
Effective date: 7 October 2026. Metal Detecting Log ("MDL") is currently in beta. This Privacy Policy explains how personal data is handled by the MDL website, mobile application and connected operational services.
1. Who controls your data
The data controller for Metal Detecting Log is Adam Antonowicz, United Kingdom. Privacy enquiries can be sent to privacy@metaldetectinglog.co.uk. General support enquiries can be sent to support@metaldetectinglog.co.uk.
2. Age requirement
MDL accounts are intended for people aged 18 or over. We do not knowingly provide child accounts. If we become aware that an account has been created by a person under 18, we may restrict or close the account and take appropriate steps in relation to the associated personal data.
3. Information we process
Depending on the features you use, MDL may process:
- Account and profile information, including your account identifier, name, email address, telephone number, account type or operational role, NCMD number where supplied, profile image and account timestamps.
- Find records, including titles, descriptions, categories, material and period information, photographs, date found, findspot, National Grid Reference, measurements, reporting status, potential-treasure status, PAS references, notes and permission information.
- Precise location information, including coordinates attached to finds, detecting sessions, farms, fields, permissions, events, navigation points and other location-based records you choose to create.
- Photo and media information. If you choose an image from your device, MDL may read available metadata, including location metadata, when needed to support the feature you selected.
- Land and permission records, including farms, fields, mapped boundaries, permission relationships, field status and operational information.
- Detecting-session information, including start/end time, duration, location, associated farm/field or event and linked finds.
- Hosted Event and Rally information, including event membership, organiser/participant roles, event fields, sessions, operational locations, meeting or infrastructure points and event-linked finds.
- Notification and security information, including notification preferences/tokens, account-security information and device/app attestation used to protect the service.
- Support and reporting information that you choose to submit when contacting us or using a reporting/export workflow.
4. Why we use personal data
We use personal data to create and secure accounts; provide finds, mapping, permissions, sessions, event, portal and reporting features; preserve provenance; provide location-based functionality requested by the user; send operational notifications; prevent abuse; maintain service security; respond to support requests; and comply with legal obligations. Depending on the activity, our lawful basis may be performance of our contract with you, our legitimate interests in operating and securing MDL, your consent where a feature specifically asks for it, or compliance with a legal obligation.
5. Precise location and Exact GPS Visibility
Precise coordinates can reveal sensitive information about a findspot or a person's activity. MDL is designed to limit exact GPS to the account owner and relevant verified operational scopes. A landowner, Farm Manager or authorised Estate role may access operational records within the land scope they manage. An event organiser may access event-linked locations for joined participants within that event. Other participants and public-facing views are not intended to receive another person's exact GPS merely because they use MDL.
Location permissions are requested when required for a feature. Denying a location permission may prevent that feature from working but should not prevent unrelated parts of MDL from being used.
6. Night Watch and background location
Night Watch is optional. If you enable it for eligible live events, MDL may ask the operating system for background location permission so registered event-field areas can be monitored while the app is closed. When an entry into a registered area is triggered during the relevant protected period, the current location point, account identifier, event identifier, trigger information and timestamp may be sent securely to MDL for server-side verification and to support an organiser alert.
Night Watch is designed around geofence entry events and does not continuously record your route. You can disable Night Watch and remove its registered monitoring areas. Background location is not required for ordinary find recording or unrelated MDL features.
7. Protected Area Safety, maps, LiDAR and heritage data
Protected Area Safety and MDL's mapping, historical and LiDAR features may use a location or planned area to provide contextual information. These tools are informational and do not create permission, determine legality or replace current official designation records. Map tiles, geocoding, imagery and heritage datasets may be supplied by third parties and may receive technical network information necessary to deliver requested content.
8. Who may receive or access information
MDL uses role-based access. Data may be accessible to you, authorised land-management roles, event organisers or other operational roles only where the relevant relationship and scope require it. We also use service providers that process data on our behalf or provide infrastructure. The current mobile application uses Google Firebase services for authentication, database storage, file storage, cloud functions, application integrity/security and messaging. Mapping or imagery providers may process network requests when their content is loaded.
The public launch-list website is prepared to use Supabase to store launch-list sign-ups if that backend is enabled. Supabase is separate from the Firebase-backed mobile application. We do not sell personal data and we do not use MDL data for third-party advertising.
9. MDL Reports and official find reporting
MDL Reports are operational records generated from information stored in MDL. Detecting Reports, Land Reports and Event Reports are not official archaeological or treasure reports.
Where MDL provides an official find-reporting workflow, you choose whether to initiate it. A report prepared for the Treasure Trove Unit in Scotland or the Portable Antiquities Scheme / a Finds Liaison Officer in England and Wales may contain finder details, contact information, find details, photographs, findspot information and precise coordinates. Review the information before sending it. MDL does not automatically submit every recorded find to an archaeological authority.
10. Notifications
MDL may use push notifications for account, permission, session, event, land-management, Night Watch, inactivity or other operational messages. You can control notification permissions through your device and, where available, MDL settings. Some essential service or security communications may still be sent by email.
11. Retention and inactive accounts
MDL applies an inactivity-retention schedule to reduce unnecessary storage of personal data. After approximately 11 months without opening MDL, one inactivity warning may be sent where notifications remain available. If the account remains unused for 12 months, sign-in may be disabled and a final 90-day retention period begins. If the account remains inactive, private account data is scheduled for permanent deletion after that period.
Where another member still reasonably relies on shared operational history, limited records may be retained only in a form intended to be anonymised so they no longer identify the deleted user. Opening MDL while signed in before deactivation resets the inactivity period. This schedule does not replace a shorter deletion process following a valid manual deletion request.
12. Deleting your account
You can start account deletion from Account Details in the MDL app. You can also use our web account-deletion page. Account deletion is different from temporary deactivation. We will delete or anonymise associated personal data as appropriate, except where limited retention is necessary to comply with law, establish or defend legal claims, prevent fraud/security abuse, or preserve genuinely anonymised shared operational records.
13. Website launch list, cookies and analytics
If you join the launch list, we may process your email address and limited sign-up context to send release and availability communications. You can ask to be removed at any time. The current website package does not intentionally include advertising trackers. If non-essential analytics, advertising pixels or similar cookies are introduced, this policy and the site's consent controls will be updated before they are enabled where consent is required.
14. International processing
Some technology providers may process data in, or make data accessible from, countries outside the United Kingdom. Where UK data-protection law requires safeguards for an international transfer, we rely on appropriate contractual or other lawful transfer mechanisms provided by the relevant service provider.
15. Security
We use technical and organisational measures intended to protect MDL data, including authenticated access, role-based data access, application-integrity controls and secured cloud infrastructure. No online service can guarantee absolute security. Do not send passwords, recovery codes or unnecessary precise find-location exports to support by email.
16. Your UK data-protection rights
Depending on the circumstances, you may have rights to request access to your personal data, correction, erasure, restriction, portability, or to object to certain processing. Where processing relies on consent, you can withdraw that consent without affecting processing that was lawful before withdrawal. To exercise a right, contact privacy@metaldetectinglog.co.uk.
You also have the right to raise a concern with the UK Information Commissioner's Office (ICO). We would appreciate the opportunity to address your concern first.
17. Beta service and policy changes
MDL is currently in beta, so features and data flows may change as testing continues. We will update this policy where a change materially affects how personal data is used. The effective date at the top identifies the current version.
18. Contact
Controller: Adam Antonowicz, United Kingdom
Product: Metal Detecting Log
Privacy: privacy@metaldetectinglog.co.uk
Support: support@metaldetectinglog.co.uk
Website: metaldetectinglog.co.uk