Privacy Policy
Last updated: 15 August 2026
1. Data We Collect
We collect information you provide when creating an account (email, username), activity data (GPS routes, finds, journal entries, photos), and technical data needed to operate the service (device/app version, error logs). We never sell your personal data to anyone.
2. Location Data
GPS coordinates are used to provide map features, route tracking, and (if you use AI features) regional context for identification. Precise find locations are never shared publicly by default — only approximate regional information is shown to other users unless you explicitly mark a find as public. You can manage this per-find and in Settings.
3. Find Locations & Storage
Find and route coordinates are stored in our database with the same infrastructure-level encryption (at rest and in transit) as the rest of your data — this is standard technical protection, not a special extra layer applied only to coordinates. Visibility control, not encryption, is what keeps your discoveries private: locations are hidden from other users by default (blurred to a regional level) unless you choose to share them.
4. Cookies
We use only essential cookies required for authentication and session management. We do not currently use any analytics, advertising, or tracking cookies.
5. Data Storage
Your data is stored on Supabase infrastructure (EU region) and Vercel (hosting). We rely on their standard encryption for data in transit and at rest; we do not apply additional application-level encryption beyond this.
6. Your Rights (GDPR)
You have the right to access, correct, export, or delete your data at any time. Go to Settings → Data & Privacy to export a copy or permanently delete your account. The live DetectMap account and its app content under our direct control are removed immediately and any active subscription is cancelled first. Restricted-access disaster-recovery backups may contain a copy for up to 30 days and are subject to our documented retention review and explicit removal procedure. Short-lived operational logs use random request identifiers — not raw account IDs, email addresses or coordinates — and Better Stack retains them for 3 days; Vercel applies its runtime-log plan limit. Billing and tax records are retained only where and for as long as required by law. Except for these limited cases and data held by sub-processors under Sections 7 and 8, DetectMap does not retain deleted account data in its active systems. You can also reach us at privacy@detectmap.app.
7. Third-Party Services (Sub-processors)
We share data with the following services, each strictly limited to what they need to do their job: Supabase (database, file storage, authentication — EU region); Vercel (application hosting and short-lived runtime logs); Better Stack (EU-region operational logs and alerts, with 3-day log retention); an AI vision provider — currently Google (Gemini API), which may be substituted with OpenAI — that processes photos and context you submit for AI identification, journal writing, and hunt strategy features (see the respective provider's API terms and privacy policy); Stripe (payment processing for subscriptions — we never see or store your card details); Esri (satellite imagery tiles); OpenFreeMap (base map tiles); Open-Meteo (weather forecasts — receives only coordinates, no personal identifiers). Each has its own privacy policy governing their processing.
8. AI Features
If you use AI-powered features (find identification, journal writing, hunt strategy), the photos, notes, and coordinates you submit for that specific request are sent to our third-party AI provider (currently Google's Gemini API; OpenAI may be used depending on configuration) for processing. This is optional — AI features are only triggered when you explicitly tap an "AI" button. Do not submit sensitive personal information beyond what's needed for the feature (e.g. a find photo, a location). Provider retention continues independently after account deletion: Google states that Gemini API abuse-monitoring data may be retained for 55 days; OpenAI states that API abuse-monitoring logs are retained for up to 30 days by default and may be kept longer where legally required. DetectMap has no direct control over those provider periods.
9. Heritage & Legal Compliance
DetectMap promotes responsible detecting. We do not facilitate illegal activity. Users are responsible for obtaining landowner permission and complying with local heritage laws. Protected zone and heritage-law data is provided for information only and is not a substitute for legal advice.
10. Children
DetectMap is intended for users aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, contact us at privacy@detectmap.app and we will remove it.
11. Contact
For privacy questions or data requests: privacy@detectmap.app For general support: support@detectmap.app
Questions about this policy? privacy@detectmap.app