Privacy Policy
Last updated: 27 August 2026
Unmapped is a GPS-based app, allowing you to reveal the map by actually exploring the world. To make this work, the app has to know exactly where you are. Location data is among the most sensitive categories of personal data, so this policy explains exactly what we record, how precise it is, how long we keep it, how we protect it, and how you delete it.
The short version. Unmapped records your precise GPS position — full-resolution coordinates, with timestamps — for as long as tracking is on, including while the app is in the background if you allow that. You do not need an account to use the app, and that changes where the record lives. Without one, everything you explore is stored only on your device: it is never uploaded, we hold no copy of it, and it is lost for good if you delete the app. With an account, it is uploaded to us so it can sync across your devices and be restored — we keep your filtered track for as long as your account exists, but automatically delete the raw GPS data after 60 days. If you sign in after exploring without an account, what is on your device is uploaded and merged into that account at that moment. Whatever we do hold, we store separately from your account identity, under a pseudonymous ID whose link back to you is held outside our database — so a stolen database on its own cannot tie your movements to you. We never sell your data, use it for advertising, or share it with data brokers, and you can request a copy of what we hold, or permanently delete your data, at any time.
1. Who we are
When you read "Unmapped" in this policy, it refers to our iOS and Android apps, our backend service, and this website. The data controller for Unmapped is Artem Viacheslavovych Grishin, based in London, United Kingdom.
For any data-protection enquiry, contact privacy@getunmapped.app.
2. Location data — what we actually record
This is the core of the product and the most sensitive data we hold, so we describe it in full. Start with 2.1: whether any of it reaches us at all depends on whether you have an account.
2.1 Using Unmapped without an account
Unmapped is fully usable without signing in. The map reveals as you move, places appear and unlock as you reach them, and your level, experience and achievements are all worked out on your device.
Without an account, your exploration never leaves your device. Your positions, the map area you have revealed, and the statistics derived from them are written to storage on your phone and read back from there. We do not receive them, we hold no copy of them, and we back them up nowhere. If you delete the app, they are gone permanently — there is nothing for us to restore, because we never had it.
The rest of section 2, and sections 3 and 8, describe what we record and keep on our servers. Until you sign in, none of that applies to your location data. The only thing our backend sees is your device asking it for map and place information, which appears in our technical logs (section 3).
Signing in is the moment this changes. When you create an account or sign in, the exploration already stored on your device is uploaded and merged into that account. From that point it is data we hold, and everything else in this policy applies to it. If the account already holds exploration of its own, the two are combined — neither replaces the other.
2.2 Precision
We do not blur or round your coordinates. When tracking is active, your device reports its position and full-fidelity latitude and longitude are stored exactly as your device reported them — on your device always, and on our servers as well once you have an account. Alongside each position the app stores:
- The timestamp of the reading
- The reported accuracy of the reading
- The speed derived from it
- The inferred transport mode — walking, cycling, or travelling by vehicle
- A session identifier grouping the readings from one period of tracking
Taken together this is a detailed, time-stamped record of your movements. It can show where you were, when, how long you stayed, and how you travelled. Please read the rest of this policy with that in mind.
2.3 Two copies: the filtered track and the raw archive
The app applies quality filters before a position counts towards revealing the map — discarding readings that are too inaccurate, or that show you standing still. Once you have an account and your positions are uploaded, we store two things (without an account we store neither, because nothing is uploaded — see 2.1):
- The filtered track, which is what the app draws and what your statistics are computed from.
- A raw archive of every position your device sent us, including the readings the filters rejected, together with a flag recording whether each one passed. We keep this raw data solely to fix our own bugs. For example, if we need to re-process your history after fixing a bug that wrongly discarded movement.
The raw archive is more complete than the track you see in the app. Because we only need this raw data to temporarily debug filtering issues, it is automatically and permanently deleted after 60 days. If you delete your account before 60 days, any remaining raw data is destroyed immediately.
2.4 Background collection
If you grant background location permission, the app records your position while it is not on screen, so the map keeps revealing as you move without you having to hold your phone. This is optional. Unmapped works without it; you simply need the app open for the map to reveal. You can withdraw the permission at any time in your device settings; the app stops recording background positions immediately, and if you have an account we stop receiving them.
2.5 Consent
The timestamp at which you consented to location collection is recorded, so that consent can be demonstrated; without an account it is recorded only on your device, along with everything else. Withdrawing consent is always available: turn tracking off, revoke the permission in your device settings, delete your account if you have one, or — if you do not — use Delete in the app to wipe what is stored on your device (section 9).
2.6 We store your location apart from your identity
Because location history is so sensitive, we do not keep it in the same place, or under the same identifier, as your account. Your traces, coordinates, and the exploration statistics derived from them are stored under a separate, pseudonymous identifier, carrying no name or email. The link back to your account is never written down; it can only be recomputed with a key we hold outside the database. How this works, and its limits, is described in full in section 10.
This is pseudonymisation: your location history is still your personal data, with all the rights set out in this policy.
This describes location data we hold. Without an account we hold none of it, so there is nothing on our side to separate — see 2.1.
3. Other data we collect
This table describes data we hold on our servers. Most of it exists only once you have an account: without one there is no account record, no exploration data on our side, and no social or notification data. What still applies to you are the technical logs, because your device asks our backend for map and place information, and the two website rows, which are about this site rather than the app. A subscription bought without an account is held by Google Play or the App Store rather than by us; we record it if and when you sign in.
| Category | What it includes |
|---|---|
| Account | Your sign-in provider (Google, Apple, or Facebook) and the account identifier it gives us, your email address, your nickname, your unit preference, and whether your profile is public or private. Your nickname is assigned automatically when your account is created; you can change it in your profile. |
| Website storage | Only if you allow it: a note that you joined the waitlist, and the email address you used, kept in your browser so the form does not ask you twice. Refuse and nothing is stored beyond the record of your answer. See section 4. |
| Exploration | Derived from your location data: the map area you have revealed, your coverage of regions and territories, distance travelled, level and experience, achievements unlocked, and which points of interest you have discovered and when. We hold this only for signed-in accounts; without an account it exists on your device alone. |
| Social | Friend requests you send or receive, confirmed friendships, invite codes you generate, and your position on leaderboards. |
| Device & notifications | A push-notification token per device and its platform, used only to deliver notifications you have enabled. |
| Subscription | Your platform, plan, expiry date, and the purchase receipt from Google Play or the App Store. We never see or store your payment card — the app stores handle payment entirely. |
| Technical logs | Standard server logs of requests to our backend, including your IP address, timestamp, and the endpoint called. Used for security, abuse prevention, rate limiting, and debugging. |
| Waitlist | If you sign up on this website: your email address and which signup source it came from. |
4. Cookies and local storage on this website
We use no tracking or advertising cookies, and the site loads no analytics or third-party script. Fonts are served from our own servers, so opening a page contacts nobody but us.
What we do keep is one thing, and we ask first: a note that you joined the waitlist, together with the email address you used, so the signup form does not ask you again on your next visit. It is held in your browser's local storage rather than in a cookie, which makes no difference to your rights or to this policy. Nothing is written until you press Accept. Press Reject and the only thing kept is the record of that answer, which is what lets us honour it without asking on every page.
You can change your mind at any time: open the storage settings, or clear this site's data in your browser. Withdrawing permission deletes what was stored immediately.
The apps are separate. What they collect is described in the rest of this policy.
5. Analytics and crash reporting
We use Firebase (Google LLC) to catch crashes and understand how the app is being used. The apps send usage events and crash reports: screens viewed, onboarding steps completed or skipped, tracking sessions started and ended, places tapped and revealed, levels reached, friend requests sent and accepted, and similar interaction events. We also set a small number of properties describing your app state — subscription status, transport mode, level band, unit preference, and whether you are using the app with or without an account.
These events are pseudonymous, not anonymous. When you are signed in they are tied to your Unmapped account identifier so we can troubleshoot specific issues, though they carry no name or email.
Without an account, they carry no account identifier, and we do not create one for you. Usage without an account is counted only against the identifier Firebase's own SDK already assigns to the app's installation on your device. That identifier resets if you uninstall the app, is never joined to an advertising identifier, and is not used for advertising or cross-app tracking. Firebase remains the only analytics service we send anything to, with or without an account.
In either case we strictly exclude coordinates, addresses, and any other location content from analytics and crash payloads — the events record that you started a tracking session, not where.
Firebase's own privacy terms apply: firebase.google.com/support/privacy.
6. Why we process your data, and our legal bases
These bases cover the data we process on our servers. Exploration done without an account is processed only on your own device and never reaches us, so nothing below applies to it until you sign in.
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Revealing your map, computing coverage and statistics, syncing across your devices | Consent for location data; performance of our contract with you for the rest |
| Running your account, subscription, and support | Performance of a contract |
| Social features — friends, leaderboards, shared territories | Consent; you choose whether to participate and whether your profile is public |
| Security, abuse prevention, rate limiting, debugging | Legitimate interests in operating a safe, working service |
| Product analytics and crash diagnostics | Legitimate interests in improving the app |
| Waitlist and launch announcement | Consent |
| Correcting historical data after a fault in our processing | Legitimate interests in the accuracy of your records |
We do not use your data for advertising, profiling, or automated decision-making with legal effects, and we do not sell it.
7. Who we share it with
We do not sell personal data or share it with data brokers. We only share data with the specific services we need to keep the app running, and they are contractually bound to act only on our instructions:
- Fly.io — application hosting and the database holding your account, location, and exploration data
- Amazon Web Services (AWS KMS) — key management for our encryption and for the separation of your location data from your identity. AWS holds only key material. Keys are held in the EU (see section 11).
- Google Firebase — analytics, crash reporting, push notification delivery, and remote configuration
- Resend — transactional email (deletion confirmations, support replies, waitlist confirmations)
- LaunchList and Loops — waitlist signup and launch-announcement email
- Google Play and the Apple App Store — subscription billing and receipt validation
We also disclose data where we are legally required to, and to protect our rights or the safety of users.
6.1 Services your device contacts directly
To draw the map and describe places, the app requests data from third parties. These requests come from your device, so those providers receive your IP address and the map area or place being requested. They do not receive your account, your identity, or your recorded track.
- OpenFreeMap — base map tiles
- OpenStreetMap / Overpass — points of interest
- Wikimedia and Wikidata — descriptions and images of places
6.2 What other users can see
Without an account you have no profile, and nothing about you is visible to other users at all — the social features require an account.
If your profile is public, other users can see your nickname, your level and statistics, and your leaderboard position. If your profile is private, your identity is not visible anywhere, except to you and to friends whose requests you have accepted. Your location track is never visible to other users in any profile setting.
8. How long we keep it
These periods describe how long we keep data. They apply to what has been uploaded to us, which means to accounts — see the first row for the case where you have no account.
| Data | Retention |
|---|---|
| Everything explored without an account | Never reaches us, so we apply no retention to it and hold no copy. It stays on your device until you erase it with Delete in the app, or until you uninstall the app — and it is uploaded to us only if you sign in. |
| Filtered location track | For as long as your account exists. Deleted when you delete your account. |
| Raw location archive | Automatically deleted after 60 days, or when you delete your account, whichever is first. |
| Account, exploration, social, and content data | For as long as your account exists. |
| Analytics and crash data held by Firebase | Per Google's retention policy, up to 14 months. |
| Waitlist email | Until the launch invitation is sent or you unsubscribe, whichever is first. |
| Deletion and export audit record | Retained after erasure — see below. |
We keep a minimal audit record of account deletions and data exports, consisting of the event type, the timestamp, and the internal account identifier of the deleted account. It contains no name, email, location, or other content. We retain it to demonstrate that we honoured your request, which is itself a legal obligation. Because the account it refers to no longer exists, the identifier cannot be linked back to you.
9. Your rights
Under UK and EU GDPR, and comparable laws elsewhere, you have the right to:
- Access and portability — get a copy of your data. Send a request to privacy@getunmapped.app to obtain it. If you have never signed in, there is nothing for us to send: your exploration is on your device, where the app shows all of it.
- Erasure — permanently delete your data.
- With an account: Settings → Delete Account in the app erases the account and everything associated with it. If you have uninstalled the app, see Delete your account or email us.
- Without an account: the app's Delete control wipes everything stored on your device and resets the app to its first-run state. It reaches no server, because we hold nothing of yours to erase — and for the same reason it destroys the only copy that exists. We cannot recover it for you afterwards.
- Correction — fix inaccurate personal data.
- Withdraw consent — turn off tracking, revoke the location permission, or unsubscribe from waitlist email, at any time and without penalty to the rest of the service.
- Object or restrict — object to processing based on legitimate interests.
- Complain — to your local supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk).
To exercise any right, email privacy@getunmapped.app. We respond within 30 days.
10. Security
We hold precise, long-term movement data, so we have built the backend specifically to make that data hard to tie back to a person. This section is about the data we hold; exploration done without an account never reaches our servers in the first place (see 2.1).
9.1 Your location is separated from your identity
Your account details and your location history are stored in separate parts of our database, under different identifiers:
- Your identity and social data — sign-in provider, email, nickname, friends, subscription — are keyed to your account.
- Your location data — every trace and coordinate, and the exploration statistics derived from them — is keyed to a separate, pseudonymous identifier that is not your account ID and carries no name or email.
The value that connects the two is produced on demand from a secret key held in a dedicated key-management service (AWS KMS).
Your location history remains personal data — a detailed movement map can be re-identified from its own content — so we treat every part of it as personal data with all the rights set out in this policy.
9.2 Encryption
- Sensitive identity fields, such as your email address, are encrypted at rest.
- Where we need to find your account by email or sign-in ID, we match on a one-way keyed hash.
- All traffic between the apps and our backend is encrypted with TLS with certificate pinning.
- Session tokens are stored only as irreversible hashes, so a database compromise cannot yield a usable login.
9.3 Access, keys, and operations
- Our application connects to the database with least-privilege roles: the code serving your social features has no access to your location data, and vice versa.
- Encryption and linking keys are reached through short-lived, federated credentials.
- Database access is restricted to our application servers over private networking.
- Access to production data is limited to personnel who need it to operate the service, and use of the identity↔location linking key is logged and monitored.
Because we hold precise location data, we treat any breach of it as high-severity, and we notify affected users and the relevant supervisory authority as the law requires.
11. International transfers
Our processors operate infrastructure outside the UK and EEA, including in the United States. The key material that underpins our encryption and the separation of your location from your identity (AWS KMS) is held in the EU. Where data is transferred, it is protected by the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or an adequacy decision, as applicable.
12. Changes to this policy
If we make material changes — in particular any change to what location data we collect or how long we keep it — we update the date at the top of this page and notify you in the app or by email before the change takes effect.
13. Contact
Privacy and data-protection enquiries: privacy@getunmapped.app
Everything else: hello@getunmapped.app
We aim to respond within 5 business days.