The short version. We store your email address to sign you in and your map data to hand it back to you — encrypted, backed up, and never looked at, shared, or sold. There are no ads and no trackers, and the closest thing to analytics is our host’s anonymous page-view counter, named below. The plan is that you pay for the product one day; nobody monetizes your data in the meantime, or ever.
What we store
- Your email address. It is your account identity, and where sign-in codes go. Nothing else is ever sent to it except account notices — there is no newsletter and no marketing mail.
- Your map data. The waypoints, tracks, areas, folders and notes you create — which is location data by nature — plus any custom basemap or overlay entries you add (including API keys you put in them). It is encrypted at rest with a key unique to your account and used for exactly one thing: serving your map back to you.
- Backups of your map. Kept automatically so a mistake is recoverable: roughly the last ten saves, a daily snapshot going back a month, and a weekly one going back six months. Encrypted like the rest.
- Account records. When sign-ins and account events happened — the operational log that answers “was this me?” Recovery codes are stored only as one-way hashes; we could not read yours back if we wanted to.
What never leaves your device
Your GPS position. The locate button draws the blue dot and moves the camera on your device; your position is never sent to us. (A waypoint you choose to save is your map data, like any other.) The app also keeps a copy of your map and any downloaded offline areas in your browser’s storage, on your device, so it works without a signal.
What we don’t do
- No ad trackers, no third-party cookies, and one named exception on analytics. The app sets one cookie: the session that keeps you signed in; this website sets none at all. Cloudflare, our host, adds its own Web Analytics beacon to pages it serves for us — an aggregate page-view and page-speed counter with no cookies, no fingerprinting, and no tracking of you across sites. We see totals, never people. If we ever switch it off, this sentence leaves with it.
- No selling or sharing data. Not to advertisers, not to data brokers, not to anyone. There is no version of this where your campsites are a product.
- No reading your map. Administration works on account records — email, dates, counts — not map contents.
Who else is involved
Two service providers process data to make the service run: Cloudflare hosts everything (the app, the database, the map storage), and Resend delivers sign-in emails, so it sees your email address. Like any host, Cloudflare processes IP addresses and request logs as part of serving a website; we do not use them to identify or profile you, and the app stores no IP addresses of its own. If paid plans arrive, a payment provider will handle billing — we will never hold your card number — and this page will say so first.
Map layers you turn on
Some overlays — weather radar, fire data, land ownership — and any custom map sources you add are fetched from their publishers, in some cases directly from your device. Those services see the same basic request information every website you visit sees. What they do with it is governed by their policies, not this one.
Deleting your account
You can delete your account yourself, in the app, without asking anyone. There is a 30-day grace period in case you change your mind; after it, your account and map data are permanently deleted, and the encryption key is destroyed with them — which makes any remaining backups unreadable, by us or anyone. You can export everything, any time, in standard formats (GeoJSON, GPX, KML), whether or not you are leaving.
Children
The service is not directed at children under 13, and we don’t knowingly keep accounts for them.
Changes
If what the app does changes, this page changes with it — the date at the top is the record, and material changes will be called out here.
Questions
Reach us through starbuck.org ↗.