Privacy Policy
Last updated: 12 June 2026
Unmapped is a fog-of-war map app that permanently records the places you walk, cycle, and travel. Because location data is inherently personal, we've written this policy to be plain and specific about what we collect, why, and how you can control it.
1. Who we are
Unmapped is operated by Unmapped Ltd (the "Company", "we", "us"). For data-protection enquiries, contact us at privacy@unmapped.app.
2. What we collect
Location data (app users only)
When you use the Unmapped app, your device's GPS sensor reports your position. We process this to determine which map tiles you have explored. We store the coordinates of explored tiles — not a raw GPS track of every second of your movement. A tile represents roughly a 95 × 95 m square; we cannot reconstruct your exact route from tile data alone.
Waitlist details
If you sign up on this website, we store your email address, and — if you choose to provide them — your name and city. Name and city are optional; you can join with just your email. We use these to send you a single launch invitation and, where you've told us your city, to note when Unmapped reaches your area. We do not send marketing emails without your explicit consent, and we never sell or share these details with third parties.
Usage analytics (app users only)
The Unmapped app sends anonymised event data directly to Firebase Analytics (Google LLC), which we use to understand feature usage and improve the app. This data is not tied to your name or email. Firebase's privacy terms apply: firebase.google.com/support/privacy.
Account data
When you create an account, we store your chosen display name, avatar (if set), and the tile coordinates of your explored map. Your level, distance walked, and discovery counts are derived from this data.
What we do not collect
- Continuous GPS tracks or movement history beyond tile coordinates
- Contacts, photos, or any data unrelated to map exploration
- Precise location when the app is in the background (unless you explicitly allow it for background tile sync)
3. How we use your data
- To provide the service — storing and syncing your fog-reveal map across devices
- To send your launch invitation — one email, then nothing unless you opt in
- To improve the product — aggregated, anonymised analytics
- To calculate statistics — distance, percentage explored, leaderboard positions (opt-in)
We do not use your data for advertising, profiling, or any purpose not described here.
4. How we share your data
We do not sell your personal data. We share data only with the following service providers, and only to the extent needed to operate Unmapped:
- Fly.io — hosting and database infrastructure (EU region available)
- Cloudflare R2 — avatar and image storage
- Google Firebase — anonymised in-app analytics
- Resend — transactional email delivery
- LaunchList — waitlist signup and referral management
- Loops — waitlist and launch-announcement email
All providers are contractually bound to process data only on our behalf and in accordance with applicable law.
5. Your rights
Under GDPR (if you're in the UK or EU) and similar laws, you have the right to:
- Access — request a copy of the data we hold about you
- Correction — fix inaccurate personal data
- Erasure — delete your account and all associated data permanently. In-app: Settings → Delete Account. By email: privacy@unmapped.app. We action deletion requests within 30 days.
- Portability — receive your explored tile data in a machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — unsubscribe from the waitlist at any time via the link in any email we send
To exercise any right, email privacy@unmapped.app. We'll respond within 30 days.
6. Data retention
- Waitlist emails — kept until launch invitation is sent, or until you unsubscribe, whichever comes first
- Account and map data — kept while your account is active. Deleted within 30 days of account deletion.
- Analytics data — retained by Firebase per their default policy (up to 14 months)
7. Security
All data is transmitted over TLS. Database access is restricted to application servers behind private networking. We do not store raw GPS coordinates, which limits the sensitivity of any data breach.
8. Children
Unmapped is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.
9. Changes to this policy
If we make material changes, we'll notify waitlist members by email and update the date at the top of this page. Continued use of the app after changes constitutes acceptance.
10. Contact
Questions or concerns: privacy@unmapped.app
We aim to respond within 5 business days.