Privacy and Terms
Last updated 14 September 2026
This covers PyxRanch (formally PyxRanch: Pyxel Ranch Operations), the ranch software, and this website. Pyxel AI is a sole proprietorship registered in British Columbia, Canada, and operated by Christopher Stoddard.
It is written to be read. Where something is uncomfortable to say plainly, it is said plainly anyway, because a policy nobody can understand is not consent.
1. Who holds your information
This is the part most policies skip, and it decides everything else.
The ranch is the customer. When a ranch uses PyxRanch, that ranch decides what is recorded, who works there, and what happens to those records. Pyxel AI runs the software and stores the data on the ranch’s behalf. In privacy law language, the ranch is the organisation responsible for the personal information and Pyxel AI is its service provider.
If you are a worker rather than an owner, your employer holds your records. Your account was created by your employer, and questions about what is recorded about you, or requests to see or correct it, go to them first. We will help them answer, and we will not hand your information to anybody else on our own initiative.
Each ranch has its own separate database. No ranch can see another ranch’s records, and there is no shared table anywhere in the system that would let that happen.
2. What is recorded
Depending on which parts of the software a ranch uses:
- People. Name, role, job title, work email and phone, the location you are based at, emergency contact details if your employer records them, and a hashed access code. We never store your access code itself.
- Work records. Equipment inspections, defect reports, work orders, hours and meter readings, feed and harvest records, livestock records, purchase orders and expense claims.
- Location. See section 3, which is its own section because it deserves one.
- Photographs. Machines, defects, animals, paperwork you photograph, and images from trail cameras a ranch has connected. From the phone app, only the photographs you choose to take and send; see section 4.
- Health information, in one place. Incident and injury reports can contain information about a person’s health, treatment and time away from work. It is restricted to people your employer has given the incidents permission to, it is never used for anything but the incident record and the legal logs an employer must keep, and it never reaches a paired phone in any form.
- Technical records. Sign-in times, the device a session came from, and an audit log of who changed what. This is how a ranch answers “who recorded this and when”, which is the point of keeping records at all.
3. Location, and being straight about it
Some parts of the software record where a machine or a person is. That is genuinely sensitive, so here is exactly what happens.
- Only while something is running, or at the moment you file. Location is recorded while a harvest shift is running and while a manager records a property line. It is also noted once, at the moment somebody files a pre-trip, pins or draws something in Yard Works, sites a pit, reports a defect, closes a chute session or adds a new place at a gate. Between those times nothing is recorded, and there is no always-on tracking.
- In two cases, the phone keeps recording with the screen off. The first is the point of the app. A driver should not have to hold a phone to have their loads counted, so once a harvest shift is started the recording continues with the phone locked or in a pocket, until the shift is paused or finished. The second is a manager recording a property line in Yard Works by walking or riding it, from starting the recording until they stop or leave the screen. Nothing else records in the background, and whenever something does, you can see it: an iPhone shows its own location indicator, and on an Android phone the app keeps a notification showing for as long as it records.
- Precise, and tied to a name. The position recorded is precise rather than approximate, because counting a load means knowing which pile a truck stopped at. It is stored against the person whose phone was paired, so the ranch can attribute the work. The app’s privacy label in the App Store says exactly that: precise location, linked to the person, used to make the app work, and not used for tracking.
- The app cannot ask to track you all the time. It asks only for permission to use location while you are using the app. The stronger permission, the one that would let software read your position when you have not started anything, is stripped out of the app when it is built, so it cannot be requested by accident or switched on later without a new version. On an iPhone that is the permission called Always; on Android, Allow all the time.
- The operator can see it. The screen shows the position it is using and how accurate it is. On a phone, the operating system shows its own indicator whenever an app is using location.
- Why. To count loads automatically so nobody tallies them by hand, to record where an inspection or another filing happened, to map a property line, and to keep equipment records accurate. Not to measure people.
- Who sees it. The operator, and managers at that ranch. Nobody else. It is never sold, never shared for advertising, and never used to build a profile of anybody.
- Where it goes. Positions are written to the phone first, so a truck out of signal loses nothing, and then to that ranch’s own database when a connection comes back. Every ranch has a separate database, so one ranch’s positions are not in the same place as another’s.
- The companion app is voluntary. Where a ranch uses the PyxRanch phone app on personal phones, using it is the operator’s choice, it asks before it uses location, and declining it does not stop the rest of the software working in a browser.
A note for employers. British Columbia’s Personal Information Protection Act sets rules for collecting employees’ personal information, including telling people before you do it and only collecting what is reasonable for the job. Turning on location features is your decision as the employer, and telling your crew is your obligation. We give you the tools; we cannot give you the conversation.
4. The phone app
PyxRanch has a companion app for phones. Section 3 covers its use of location; everything else it does with information is here. The app says the same things about itself under Help, in “What this app knows about you”, which links back to this page.
- No account of its own. When a manager pairs a phone for somebody, the ranch gives that phone a key, so the ranch knows whose phone it is, and what is filed from it is filed as that person. Unpairing takes the key off the phone, and a manager can take it back from the ranch at any time. What was already filed stays the ranch’s record.
- What it sends, and where. Location, as section 3 describes; photographs you choose to take; and what you file, such as loads, pre-trips, herd work, tasks and spares. All of it goes to your ranch’s own server and nowhere else. The app’s privacy label in each app store lists the same things, with the phone’s key as the user ID: each linked to you, used only to make the app work, and none of it used for tracking.
- The camera opens only when you tap to take a picture. Before your phone asks for the camera, the app says what the picture is for. The photographs it sends are the ones you choose to send: a defect, a fault on a machine checklist, a part on the shelf, or a paper pre-trip form.
- An ear tag photo never leaves the phone. If you photograph an ear tag to find an animal, the picture is read on your phone and deleted. It is never sent to the ranch or anyone else.
- Notifications, if you allow them. The phone gives its ranch an address for sending it notifications. A notification’s words travel from the ranch through Expo’s push service, then Apple’s to an iPhone or Google’s to an Android phone. Your location never goes that way, and everything else in the app works whether or not you allow notifications.
- It can speak, and it never listens. The app can say each counted load out loud, so a driver need not look at the screen. It never uses the microphone, has no voice input, and records no sound, and it does not ask for the microphone at all, on an iPhone or on Android.
5. What it is used for
Running the software for the ranch that entered it: showing records, producing the reports and legal documents a ranch asks for, sending the notifications a ranch has configured, keeping backups, and fixing faults when something breaks.
We do not sell information, ever, to anybody. There is no advertising in this product, no analytics sold on, and no sharing of one ranch’s records with another.
We may look at aggregate, de-identified counts - how many ranches use a module, how large a database is getting - to keep the service running and decide what to build. That never involves reading a ranch’s records for our own purposes.
6. Where a language model is involved
Some optional features use an AI model to summarise records or read scanned paperwork. These are off unless a ranch turns them on, they are limited to the parts of the record needed for the task, and the model provider does not use that content to train models. If a ranch never enables them, nothing is ever sent.
7. Who else touches it
- Hosting. The software and its databases run on infrastructure operated by Pyxel AI in Canada.
- Email delivery, for notifications and reports a ranch has asked to be sent.
- An AI model provider, only for the optional features in section 6, and only if enabled.
- Notification delivery, for the phone app, if you allow notifications: Expo’s push service, then Apple’s or Google’s depending on the phone, carry a notification’s words to it.
- Trail cameras. Where a ranch connects its own trail camera account, images and the credentials for that account are the ranch’s own arrangement with that supplier.
- Apple and Google, if the companion app is installed from their stores, on their own terms.
We do not add others without a reason, and a ranch can ask at any time who currently touches its data.
8. How long, and getting it back
Records are kept while a ranch is a customer, and for as long after as the law requires for the kind of record - inspection and incident records in particular have retention periods set by regulation, not by us.
A ranch can download everything it has, at any time, without asking us. The export is in the software, it lists exactly what it contains before you press it, and the only things withheld are hashed credentials, which are of no use to anybody. There is no gate on this and there never will be. When a ranch leaves, its data goes with it and we delete our copies on request.
9. Your rights
Under British Columbia’s Personal Information Protection Act you can ask to see the personal information an organisation holds about you, ask for it to be corrected if it is wrong, and ask how it has been used.
If you are a worker, ask your employer - they hold the record and we act on their instructions. If you are a ranch owner or operator, ask us and we will answer within the time the Act allows. If you are not satisfied, you can complain to the Office of the Information and Privacy Commissioner for British Columbia.
10. Security, honestly
Access codes are stored only as hashes and never in a form anybody can read. Connections are encrypted. Each ranch is a separate database and a separate running process. Sessions expire, and a lost phone can be cut off from a ranch’s own settings screen.
One limit worth stating rather than hiding: the field app is built to keep working with no signal, so a device that has been cut off keeps working until it next reaches the internet. That is true of every offline system. What limits it is that a phone is only ever given what the field jobs need - never money, purchasing, incident detail or cameras.
No system is perfectly secure. If something goes wrong that affects personal information, we will tell the affected ranch promptly and without being asked twice.
11. Ideas, feedback and suggestions
Much of this software exists because somebody working a ranch said “it should do this instead”. That is welcome, and we want more of it. So that suggestions can be acted on without anybody worrying later about who owns what, the following applies to any idea, suggestion, request, comment or feedback you send us about the product.
- You give it freely, and you are not owed payment, credit or a share of anything built as a result.
- You grant Pyxel AI a perpetual, irrevocable, worldwide, royalty-free and transferable licence to use, copy, modify and build on it in any product, without restriction and without any obligation to you.
- To the extent anything you send is capable of being owned, you assign it to Pyxel AI, and everything built from it - the design, the code, the finished feature - is owned entirely by Pyxel AI.
- Feedback is not confidential. Do not send us anything you need kept secret, or anything you do not have the right to give.
- We may already be working on the same idea, or may have had it independently, and nothing here stops us continuing.
This is about ideas for the product, and it is not a claim on your ranch’s records. Your data is yours. Section 8 says so and means it.
12. Terms of use
Using the software means accepting these terms. If a ranch signs a separate written agreement with Pyxel AI, that agreement wins wherever the two disagree.
Accounts. Access codes are personal. Do not share one. Tell the ranch if a device is lost. A ranch is responsible for who it gives accounts to and for what those people record.
You stay responsible for compliance. This is the important one. The software produces documents that regulators read - pre-trip inspection records, incident logs, livestock movement filings, burial records. It is a tool for keeping those records, not a substitute for knowing your obligations. Pyxel AI does not give legal, veterinary, safety or regulatory advice, and does not warrant that any record satisfies any particular regulator. Check what the law requires of you, and check what you file.
Fair use. Do not attempt to reach another ranch’s data, break the software, or use it against the law. We may suspend access that puts other customers or their records at risk, and we will say why.
Availability. We work to keep it running and we do not promise it never stops. Field features are built to keep working without a connection precisely because connections fail.
No warranty, and limited liability. The software is provided as it is, without warranties of any kind so far as the law allows. Pyxel AI is not liable for indirect or consequential loss, lost profit, or lost livestock, equipment or opportunity. Where liability cannot be excluded, it is limited to what that ranch paid Pyxel AI in the twelve months before the claim. Nothing here limits liability that cannot lawfully be limited.
Ownership. The software is Pyxel AI’s. A ranch’s records are the ranch’s. Neither becomes the other’s by using the product.
Where this is decided. The law of British Columbia and the courts of British Columbia.
13. Changes
When this changes, the date at the top changes with it. If a change matters - a new purpose, a new kind of information, a new company touching it - we will tell ranches directly rather than quietly editing this page.
14. Getting hold of us
Through the contact form on this site. Tell us which ranch you are with and we will get to the right person.
If you use the PyxRanch app on a phone, the support page is written for you: what to do about pairing, a lost phone, location and notifications, and a form that reaches a person.
Pyxel AI, British Columbia, Canada. PyxRanch is Pyxel Ranch Operations.