Unmapped
Back to Unmapped

Privacy Policy

Last updated: 27 August 2026

Unmapped is a GPS-based app, allowing you to reveal the map by actually exploring the world. To make this work, the app has to know exactly where you are. Location data is among the most sensitive categories of personal data, so this policy explains exactly what we record, how precise it is, how long we keep it, how we protect it, and how you delete it.

The short version. Unmapped records your precise GPS position — full-resolution coordinates, with timestamps — for as long as tracking is on, including while the app is in the background if you allow that. You do not need an account to use the app, and that changes where the record lives. Without one, everything you explore is stored only on your device: it is never uploaded, we hold no copy of it, and it is lost for good if you delete the app. With an account, it is uploaded to us so it can sync across your devices and be restored — we keep your filtered track for as long as your account exists, but automatically delete the raw GPS data after 60 days. If you sign in after exploring without an account, what is on your device is uploaded and merged into that account at that moment. Whatever we do hold, we store separately from your account identity, under a pseudonymous ID whose link back to you is held outside our database — so a stolen database on its own cannot tie your movements to you. We never sell your data, use it for advertising, or share it with data brokers, and you can request a copy of what we hold, or permanently delete your data, at any time.

1. Who we are

When you read "Unmapped" in this policy, it refers to our iOS and Android apps, our backend service, and this website. The data controller for Unmapped is Artem Viacheslavovych Grishin, based in London, United Kingdom.

For any data-protection enquiry, contact privacy@getunmapped.app.

2. Location data — what we actually record

This is the core of the product and the most sensitive data we hold, so we describe it in full. Start with 2.1: whether any of it reaches us at all depends on whether you have an account.

2.1 Using Unmapped without an account

Unmapped is fully usable without signing in. The map reveals as you move, places appear and unlock as you reach them, and your level, experience and achievements are all worked out on your device.

Without an account, your exploration never leaves your device. Your positions, the map area you have revealed, and the statistics derived from them are written to storage on your phone and read back from there. We do not receive them, we hold no copy of them, and we back them up nowhere. If you delete the app, they are gone permanently — there is nothing for us to restore, because we never had it.

The rest of section 2, and sections 3 and 8, describe what we record and keep on our servers. Until you sign in, none of that applies to your location data. The only thing our backend sees is your device asking it for map and place information, which appears in our technical logs (section 3).

Signing in is the moment this changes. When you create an account or sign in, the exploration already stored on your device is uploaded and merged into that account. From that point it is data we hold, and everything else in this policy applies to it. If the account already holds exploration of its own, the two are combined — neither replaces the other.

2.2 Precision

We do not blur or round your coordinates. When tracking is active, your device reports its position and full-fidelity latitude and longitude are stored exactly as your device reported them — on your device always, and on our servers as well once you have an account. Alongside each position the app stores:

Taken together this is a detailed, time-stamped record of your movements. It can show where you were, when, how long you stayed, and how you travelled. Please read the rest of this policy with that in mind.

2.3 Two copies: the filtered track and the raw archive

The app applies quality filters before a position counts towards revealing the map — discarding readings that are too inaccurate, or that show you standing still. Once you have an account and your positions are uploaded, we store two things (without an account we store neither, because nothing is uploaded — see 2.1):

The raw archive is more complete than the track you see in the app. Because we only need this raw data to temporarily debug filtering issues, it is automatically and permanently deleted after 60 days. If you delete your account before 60 days, any remaining raw data is destroyed immediately.

2.4 Background collection

If you grant background location permission, the app records your position while it is not on screen, so the map keeps revealing as you move without you having to hold your phone. This is optional. Unmapped works without it; you simply need the app open for the map to reveal. You can withdraw the permission at any time in your device settings; the app stops recording background positions immediately, and if you have an account we stop receiving them.

2.5 Consent

The timestamp at which you consented to location collection is recorded, so that consent can be demonstrated; without an account it is recorded only on your device, along with everything else. Withdrawing consent is always available: turn tracking off, revoke the permission in your device settings, delete your account if you have one, or — if you do not — use Delete in the app to wipe what is stored on your device (section 9).

2.6 We store your location apart from your identity

Because location history is so sensitive, we do not keep it in the same place, or under the same identifier, as your account. Your traces, coordinates, and the exploration statistics derived from them are stored under a separate, pseudonymous identifier, carrying no name or email. The link back to your account is never written down; it can only be recomputed with a key we hold outside the database. How this works, and its limits, is described in full in section 10.

This is pseudonymisation: your location history is still your personal data, with all the rights set out in this policy.

This describes location data we hold. Without an account we hold none of it, so there is nothing on our side to separate — see 2.1.

3. Other data we collect

This table describes data we hold on our servers. Most of it exists only once you have an account: without one there is no account record, no exploration data on our side, and no social or notification data. What still applies to you are the technical logs, because your device asks our backend for map and place information, and the two website rows, which are about this site rather than the app. A subscription bought without an account is held by Google Play or the App Store rather than by us; we record it if and when you sign in.

CategoryWhat it includes
Account Your sign-in provider (Google, Apple, or Facebook) and the account identifier it gives us, your email address, your nickname, your unit preference, and whether your profile is public or private. Your nickname is assigned automatically when your account is created; you can change it in your profile.
Website storage Only if you allow it: a note that you joined the waitlist, and the email address you used, kept in your browser so the form does not ask you twice. Refuse and nothing is stored beyond the record of your answer. See section 4.
Exploration Derived from your location data: the map area you have revealed, your coverage of regions and territories, distance travelled, level and experience, achievements unlocked, and which points of interest you have discovered and when. We hold this only for signed-in accounts; without an account it exists on your device alone.
Social Friend requests you send or receive, confirmed friendships, invite codes you generate, and your position on leaderboards.
Device & notifications A push-notification token per device and its platform, used only to deliver notifications you have enabled.
Subscription Your platform, plan, expiry date, and the purchase receipt from Google Play or the App Store. We never see or store your payment card — the app stores handle payment entirely.
Technical logs Standard server logs of requests to our backend, including your IP address, timestamp, and the endpoint called. Used for security, abuse prevention, rate limiting, and debugging.
Waitlist If you sign up on this website: your email address and which signup source it came from.

4. Cookies and local storage on this website

We use no tracking or advertising cookies, and the site loads no analytics or third-party script. Fonts are served from our own servers, so opening a page contacts nobody but us.

What we do keep is one thing, and we ask first: a note that you joined the waitlist, together with the email address you used, so the signup form does not ask you again on your next visit. It is held in your browser's local storage rather than in a cookie, which makes no difference to your rights or to this policy. Nothing is written until you press Accept. Press Reject and the only thing kept is the record of that answer, which is what lets us honour it without asking on every page.

You can change your mind at any time: open the storage settings, or clear this site's data in your browser. Withdrawing permission deletes what was stored immediately.

The apps are separate. What they collect is described in the rest of this policy.

5. Analytics and crash reporting

We use Firebase (Google LLC) to catch crashes and understand how the app is being used. The apps send usage events and crash reports: screens viewed, onboarding steps completed or skipped, tracking sessions started and ended, places tapped and revealed, levels reached, friend requests sent and accepted, and similar interaction events. We also set a small number of properties describing your app state — subscription status, transport mode, level band, unit preference, and whether you are using the app with or without an account.

These events are pseudonymous, not anonymous. When you are signed in they are tied to your Unmapped account identifier so we can troubleshoot specific issues, though they carry no name or email.

Without an account, they carry no account identifier, and we do not create one for you. Usage without an account is counted only against the identifier Firebase's own SDK already assigns to the app's installation on your device. That identifier resets if you uninstall the app, is never joined to an advertising identifier, and is not used for advertising or cross-app tracking. Firebase remains the only analytics service we send anything to, with or without an account.

In either case we strictly exclude coordinates, addresses, and any other location content from analytics and crash payloads — the events record that you started a tracking session, not where.

Firebase's own privacy terms apply: firebase.google.com/support/privacy.

6. Why we process your data, and our legal bases

These bases cover the data we process on our servers. Exploration done without an account is processed only on your own device and never reaches us, so nothing below applies to it until you sign in.

PurposeLegal basis (UK/EU GDPR)
Revealing your map, computing coverage and statistics, syncing across your devicesConsent for location data; performance of our contract with you for the rest
Running your account, subscription, and supportPerformance of a contract
Social features — friends, leaderboards, shared territoriesConsent; you choose whether to participate and whether your profile is public
Security, abuse prevention, rate limiting, debuggingLegitimate interests in operating a safe, working service
Product analytics and crash diagnosticsLegitimate interests in improving the app
Waitlist and launch announcementConsent
Correcting historical data after a fault in our processingLegitimate interests in the accuracy of your records

We do not use your data for advertising, profiling, or automated decision-making with legal effects, and we do not sell it.

7. Who we share it with

We do not sell personal data or share it with data brokers. We only share data with the specific services we need to keep the app running, and they are contractually bound to act only on our instructions:

We also disclose data where we are legally required to, and to protect our rights or the safety of users.

6.1 Services your device contacts directly

To draw the map and describe places, the app requests data from third parties. These requests come from your device, so those providers receive your IP address and the map area or place being requested. They do not receive your account, your identity, or your recorded track.

6.2 What other users can see

Without an account you have no profile, and nothing about you is visible to other users at all — the social features require an account.

If your profile is public, other users can see your nickname, your level and statistics, and your leaderboard position. If your profile is private, your identity is not visible anywhere, except to you and to friends whose requests you have accepted. Your location track is never visible to other users in any profile setting.

8. How long we keep it

These periods describe how long we keep data. They apply to what has been uploaded to us, which means to accounts — see the first row for the case where you have no account.

DataRetention
Everything explored without an accountNever reaches us, so we apply no retention to it and hold no copy. It stays on your device until you erase it with Delete in the app, or until you uninstall the app — and it is uploaded to us only if you sign in.
Filtered location trackFor as long as your account exists. Deleted when you delete your account.
Raw location archiveAutomatically deleted after 60 days, or when you delete your account, whichever is first.
Account, exploration, social, and content dataFor as long as your account exists.
Analytics and crash data held by FirebasePer Google's retention policy, up to 14 months.
Waitlist emailUntil the launch invitation is sent or you unsubscribe, whichever is first.
Deletion and export audit recordRetained after erasure — see below.

We keep a minimal audit record of account deletions and data exports, consisting of the event type, the timestamp, and the internal account identifier of the deleted account. It contains no name, email, location, or other content. We retain it to demonstrate that we honoured your request, which is itself a legal obligation. Because the account it refers to no longer exists, the identifier cannot be linked back to you.

9. Your rights

Under UK and EU GDPR, and comparable laws elsewhere, you have the right to:

To exercise any right, email privacy@getunmapped.app. We respond within 30 days.

10. Security

We hold precise, long-term movement data, so we have built the backend specifically to make that data hard to tie back to a person. This section is about the data we hold; exploration done without an account never reaches our servers in the first place (see 2.1).

9.1 Your location is separated from your identity

Your account details and your location history are stored in separate parts of our database, under different identifiers:

The value that connects the two is produced on demand from a secret key held in a dedicated key-management service (AWS KMS).

Your location history remains personal data — a detailed movement map can be re-identified from its own content — so we treat every part of it as personal data with all the rights set out in this policy.

9.2 Encryption

9.3 Access, keys, and operations

Because we hold precise location data, we treat any breach of it as high-severity, and we notify affected users and the relevant supervisory authority as the law requires.

11. International transfers

Our processors operate infrastructure outside the UK and EEA, including in the United States. The key material that underpins our encryption and the separation of your location from your identity (AWS KMS) is held in the EU. Where data is transferred, it is protected by the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or an adequacy decision, as applicable.

12. Changes to this policy

If we make material changes — in particular any change to what location data we collect or how long we keep it — we update the date at the top of this page and notify you in the app or by email before the change takes effect.

13. Contact

Privacy and data-protection enquiries: privacy@getunmapped.app
Everything else: hello@getunmapped.app
We aim to respond within 5 business days.