Privacy, plainly

Privacy Policy

Last updated: July 12, 2026

What we collect

Accounts contain an email address, username, a password hash or Google account identifier, saved preferences, and contributions. Authentication uses an HTTP-only cookie that can last up to 30 days and is marked Secure in production. Basic server and abuse-prevention logs may include IP address, request path, browser details, and timestamps.

Photos and listing location

Photos are optional. When you upload one, the service screens it for people, reads any GPS metadata to suggest a pin, rotates and resizes it, and re-encodes it without the original metadata. Automated screening can make mistakes, so do not upload a photo containing a person or sensitive material.

Accepted uploads are held in private quarantine until they are attached to a listing and published. Unattached quarantined uploads are scheduled for deletion after 24 hours. A listing stores the coordinates you confirm; published photos do not contain the original EXIF metadata.

Location and recommendations

Finder pages can ask your browser for location. You can deny that request; the Now flow also accepts latitude and longitude entered directly. The Now and submission flows can send an address or landmark search to Mapbox and receive possible coordinates; direct coordinate entry remains available without that lookup. Recommendation requests send the current coordinates and selected functional requirements to the API to rank nearby listings, but recommendation sessions do not store raw coordinates or a route history.

Starting directions sends your selected origin and the recommended bathroom destination to OpenStreetMap so it can open a walking route. Mapbox and OpenStreetMap process those lookup or route details under their own privacy terms.

The random recommendation capability token stays in this tab's session storage and expires after 24 hours. Recommendation records can include the selected listing, requirement-match flags, whether directions were requested, and one structured outcome. Account links are removed after 30 days and recommendation records are scheduled for deletion after 180 days.

Analytics

When configured, PostHog receives manually sent page views and a small set of named product events. Automatic click and form capture is off. Signed-in accounts are identified by an internal user ID and role; form contents, access codes, raw coordinates, recommendation capability tokens, and photo metadata are not intentionally sent as analytics properties.

How information is used

The application uses account and contribution data to authenticate users, operate moderation and trust features, personalize results, prevent abuse, and deliver password-reset messages. The current implementation has no personal-data sale integration.

Removal requests and account control

Anyone can request photo review or removal without an account. The form requires a photo ID, category, contact email, typed full name, and good-faith attestation; it also accepts up to 700 characters of optional detail. The email is used to support review and is not shown in the public receipt. The service returns a private receipt token used to authenticate status access, and the receipt can be re-entered later without an account.

Requests enter a staff queue. Reports involving a person in a photo or a sensitive location receive priority for staff review. Staff move each request through reviewing to actioned or rejected; the photo remains unchanged during review and media changes happen only after staff action. Submitting a report does not itself guarantee removal. For actioned requests, the contact email, typed attestation, and submitted detail are scheduled to be purged 30 days after resolution. Receipt status and moderation audit records may be retained, and rejected-request contact and attestation data are not currently subject to that automatic 30-day purge.

From account settings, signed-in users can download an export containing their account profile, reviews, submitted listings, photo records, status reports, corrections, ownership claims, and saved spots. The export applies listing visibility and access-code rules, so it omits non-public codes and hides or rounds listing coordinates as configured. Account deletion removes reviews and saved spots and anonymizes account credentials. Listings and published photos may remain as community records without the former email or public identity, unless they are separately removed through moderation or a removal request.

Service providers

A production deployment may use Vercel for the site, Railway for the API and database, Cloudflare R2-compatible storage for photos, Resend for email, Google for optional sign-in, Mapbox for maps and optional location lookup, OpenStreetMap for directions, and PostHog for configured analytics. Those providers process data for their service role.

Contact and changes

Use the public removal form for photo concerns. Other privacy requests can be sent to the project maintainers. Material changes update the date above. See the Terms of Service for service rules.