Privacy Policy

Last updated: July 2026

1. Data We Collect

We collect information you provide when creating an account (email, username), activity data (GPS routes, finds, journal entries, photos), and technical data needed to operate the service (device/app version, error logs). We never sell your personal data to anyone.

2. Location Data

GPS coordinates are used to provide map features, route tracking, and (if you use AI features) regional context for identification. Precise find locations are never shared publicly by default — only approximate regional information is shown to other users unless you explicitly mark a find as public. You can manage this per-find and in Settings.

3. Find Locations & Storage

Find and route coordinates are stored in our database with the same infrastructure-level encryption (at rest and in transit) as the rest of your data — this is standard technical protection, not a special extra layer applied only to coordinates. Visibility control, not encryption, is what keeps your discoveries private: locations are hidden from other users by default (blurred to a regional level) unless you choose to share them.

4. Cookies

We use only essential cookies required for authentication and session management. We do not currently use any analytics, advertising, or tracking cookies.

5. Data Storage

Your data is stored on Supabase infrastructure (EU region) and Vercel (hosting). We rely on their standard encryption for data in transit and at rest; we do not apply additional application-level encryption beyond this.

6. Your Rights (GDPR)

You have the right to access, correct, export, or delete your data at any time. Go to Settings → Data & Privacy to export a complete copy of your data (JSON) or permanently delete your account and all associated data, instantly and without needing to contact us. You can also reach us at privacy@detectmap.app for any other request.

7. Third-Party Services (Sub-processors)

We share data with the following services, each strictly limited to what they need to do their job: Supabase (database, file storage, authentication — EU region); Vercel (application hosting); an AI vision provider — currently Google (Gemini API), which may be substituted with OpenAI — that processes photos and context you submit for AI identification, journal writing, and hunt strategy features (see the respective provider's API terms and privacy policy); Stripe (payment processing for subscriptions — we never see or store your card details); MapTiler (map tile rendering); Open-Meteo (weather forecasts — receives only coordinates, no personal identifiers). Each has its own privacy policy governing their processing.

8. AI Features

If you use AI-powered features (find identification, journal writing, hunt strategy), the photos, notes, and coordinates you submit for that specific request are sent to our third-party AI provider (currently Google's Gemini API; OpenAI may be used depending on configuration) for processing. This is optional — AI features are only triggered when you explicitly tap an "AI" button. Do not submit sensitive personal information beyond what's needed for the feature (e.g. a find photo, a location).

9. Heritage & Legal Compliance

DetectMap promotes responsible detecting. We do not facilitate illegal activity. Users are responsible for obtaining landowner permission and complying with local heritage laws. Protected zone and heritage-law data is provided for information only and is not a substitute for legal advice.

10. Children

DetectMap is intended for users aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, contact us at privacy@detectmap.app and we will remove it.

11. Contact

For privacy questions or data requests: privacy@detectmap.app For general support: support@detectmap.app

Questions about this policy? privacy@detectmap.app

Privacy Policy | DetectMap