Pilot privacy notice
Dated
This is a test version
MyTravelMap is in a pilot. Features may change and your data may be reset. Testers will get notice before the pilot ends.
What we store
- Your Google account email address, name and profile picture link, through Supabase Auth, so you can sign in. Supabase Auth also records the IP address and browser of each sign-in, for security.
- Your visits: the places, dates, status and notes you add, plus any trip names and companion names.
- Up to 2 photos per visit. Our server re-encodes each photo and removes all of its metadata (EXIF, including GPS location) before storing it. The date the photo was taken is read on your device and saved with it.
- A copy of your visits on this device, so the map works offline. Signing out clears it.
Where it is stored
In Supabase (a Postgres database and file storage) in the ap-south-1 (Mumbai) region. The app runs on Google Cloud Run in asia-south1 (Mumbai). Like any website, Google Cloud keeps request logs for up to 30 days so we can run and secure the service. They contain your IP address, the time and the full address requested, which for place search includes the text you searched and for a long-press the map coordinates.
Who can see it
- Your map is private. The database only lets you read and change your own visits, trips and photos, and photos sit in a private storage bucket.
- Your public map link is off unless you switch it on in Settings (see Sharing below).
- When your public map link is on, anyone with the link can see your map at the level you chose (countries only, places, or places with dates), with no sign-in needed. It never includes notes or photos. The pilot has no friends feature.
Sharing
- Public map link is off by default. When you switch it on, anyone with the link (a random address) can see your map at the level you pick: countries only, places, or places with dates. It never shows notes, photos, planned trips, future visits, companions, trips, or dates you marked as hidden, and it is not listed in search engines. Switching the link off makes the page show “This map is private” to visitors at once, but the link itself is kept: if you switch it back on, the same link works again. To make the old link stop working for good, use New link. The page shows the name on your account (for example “Sam’s World”).
- A recap image is made on our server from your own visits at the level you pick for that image, sent to your device and not stored. Sharing it is up to you; once posted, it is outside our control. Images carry a small “MyTravelMap” mark and no account ID, and show the name on your account as their title (for example “Sam’s World”), as does the preview image of your public map.
- When a link to your public map is posted on a social network or chat app, that service fetches its preview image from us.
Other services
- Sign-in is through Google.
- Place search: the text you type is sent from our server to the Photon geocoder (by komoot), without any account details. Results are cached without a link to you.
- When you long-press the map, our server sends that point’s coordinates, without account details, to Photon, to OpenStreetMap’s Nominatim if Photon can’t answer, and to the Overpass API to find nearby sights.
- Map tiles load from OpenFreeMap straight to your browser, so OpenFreeMap sees your IP address, like any website.
- No ads and no analytics or tracking. Error reporting (Sentry) is optional and is switched off for the pilot. If it is switched on, it is set to collect no user details, cookies, headers or request content: each error keeps only a request ID and, for chat, a trace ID, with IDs, emails and numbers in the error text masked.
AI chat
- When chat is switched on for the pilot, what you type in Chat is sent from our server to Google’s Gemini API (a paid plan, under which Google does not use the content to improve its products), without your account details. The reply suggests places; nothing is saved until you tap the card.
- Your recent messages travel with each request so the AI has context. By default the conversation is kept only on this device. With Keep chat history on in Settings, it is stored in your account; turning it off, or deleting your account, deletes the stored chats.
- For each chat turn our server records a trace: which tools ran, the places found and their IDs, counts, timings, cost and the outcome, with a one-way code instead of your account ID. The text you typed, the replies and the details the AI passed to its tools are included (up to 300 characters each) only when chat history is on, with emails and phone, card and passport numbers masked. Friends’ data is never included. When Langfuse is switched on (its EU cloud region), that trace is deleted after 30 days, and when you delete your account. When Langfuse is not switched on, the same record goes to our server logs instead: those are kept for 30 days and arenot deleted earlier when you delete your account.
- If you rate a reply (👍 or 👎), the rating and any comment you add (up to 500 characters, with emails and numbers masked) are stored with that trace, also when chat history is off.
- We also note whether a suggested card was saved, edited or left to expire, to improve the suggestions.
- We count AI messages per day and their cost, to keep within free-use limits.
Deleting your data
Settings has Delete account and all data. It removes your photos from storage, then your account, which also deletes your profile, visits, trips and companions, and deletes your chat traces from Langfuse (any it cannot reach at that moment are still deleted after 30 days). You can download a copy first with Export my data. Places you looked up (such as “Rome”) stay in a shared place list that has no link to you.
Contact
Questions or requests: sandip.jadhav99@gmail.com