Privacy Policy
- Local-first: on the free plan your places never leave your device — with or without an account.
- No ads, no trackers: the app and website contain no advertising, no analytics SDKs, and we never sell data.
- Photos stay on your device unless you subscribe to Pro's cloud backup.
- Your device location is used on your device — it is not sent to our servers.
- With an account we store your email (in the EU). Your places reach our servers only on Pro, which is what cloud backup and sync are.
- You can export everything and delete your account at any time; deletion is immediate.
The full text below is the complete picture.
1. Who is responsible
Mapcove — the app for iOS, Android and the web, and the website at mapcove.app — is operated by Arvydas Bertašius, an independent software developer based in Lithuania, who is the data controller for the processing described here. Contact: [email protected].
Mapcove is built local-first on purpose: the app is designed so that as little of your data as possible ever needs to reach us.
2. Using the app without an account
The core app works fully without an account. In that mode your places, categories, tags, notes, lists and photos live in a database on your device only — we have no copy and no way to see them.
The app still talks to the network for two things:
- Map tiles: to draw the map, your device requests tiles from a map tile server (currently OpenFreeMap). Like any web request, the tile server technically receives your IP address and which map areas were requested. We don't receive anything.
- Place search: when you search by name, the text you type — and, if the app knows your position, your approximate location, used to rank nearby results first — is sent to the geocoding service (Photon by komoot). Search is optional; you can always pin places by long-pressing the map instead.
Your device location (the blue dot) is read by the app with your permission and used on the device — to centre the map and show distances. It is not sent to our servers or stored by us.
3. If you create an account
An account is optional, and on the free plan it is an identity, not a backup: it lets you join a shared list, post on the ideas board, and buy Pro. Signing in on the free plan does not send your collection anywhere — cloud backup and sync are exactly what Pro adds. When you sign up we store:
- Your email address, and — if you use a password — a salted one-way hash of it (PBKDF2). We never store passwords in readable form. If you sign in with Google or Apple, we store your email and the provider's stable account identifier instead, and no other profile details.
- Your place data — only if you subscribe to Pro: place names, coordinates, addresses, notes, categories, tags, lists, statuses and timestamps. On the free plan none of this is uploaded; it stays in the database on your device, and the free export and automatic backup are how you keep your own copy.
- Photos: photo files stay on your device. They leave it only if you subscribe to Pro's cloud backup, or when you yourself create a backup export.
- Signed-in devices: a short device summary (for example "Android 14 · Pixel 7 · Mapcove 1.3"), used to enforce the free plan's one-active-device rule and to let you see where your account is signed in. Not used for tracking.
4. Ideas board and bug reports
- Feature requests you post are stored on our server. They are visible only to you and the moderator until approved; once approved, the title and text are visible to other users. Votes are stored as counts per request.
- Bug reports stay private between you and us. They automatically include a one-line device summary (app version, OS, device model) — the exact text is shown to you before you send it.
5. Purchases (Mapcove Pro)
If you subscribe to Pro, the purchase is processed by Google Play or the Apple App Store. We never see or store your payment card details. To know which features to unlock, we and our subscription-management provider (RevenueCat) process a pseudonymous purchase identifier and the state of your subscription (active, expired, plan type). The store keeps its own purchase records under its own privacy policy.
6. The website and waitlist
- The website is a static page with no analytics and no advertising or tracking cookies.
- If you join the waitlist, we store your email address and the page it came from, so we can send you the launch announcement. That's the list's only purpose; you can ask to be removed at any time by emailing us.
- Our hosting provider (Cloudflare) processes standard technical request data (such as IP addresses) to serve and protect the site, as any host does.
- If you email us, your message and address are handled by our email provider (Zoho) and kept as long as needed to help you.
7. What we don't collect
- No advertising, no ad identifiers, no data brokers — we never sell your data.
- No third-party analytics or tracking SDKs in the app or on the website.
- No contact-list, calendar, microphone or browsing-history access.
- No location history on our servers — your position stays on your device.
- No profiling and no automated decision-making about you.
8. Where your data lives
Account and place data are stored on a server hosted with Hetzner in the European Union. A small number of service providers (processors) handle data on our behalf:
| Provider | What for |
|---|---|
| Hetzner (EU) | Server hosting — account and place data |
| Cloudflare | Website hosting, waitlist storage, object storage (offline map packs; Pro cloud backup) |
| Zoho | Email ([email protected]) |
| Google Play / Apple App Store | App distribution and payment processing, under their own privacy policies |
| RevenueCat | Subscription state (pseudonymous purchase identifier), when Pro is live |
| OpenFreeMap · Photon (komoot) | Map tiles and place search — contacted directly by your device, see section 2 |
Where a provider processes data outside the EU/EEA, transfers rely on the safeguards GDPR provides for (such as the European Commission's standard contractual clauses or an adequacy decision).
9. Legal bases (GDPR)
- Performance of a contract (Art. 6(1)(b)) — storing your account so you can sign in, and, on Pro, storing your place data to provide the backup and sync you signed up for; processing purchases.
- Legitimate interests (Art. 6(1)(f)) — keeping the service secure and abuse-free (for example technical logs and the signed-in devices list), and answering your messages.
- Consent (Art. 6(1)(a)) — the waitlist email, and any device permission you grant (location, photos, notifications), which you can revoke in your device settings at any time.
10. How long we keep data
- Account and place data: until you delete them. Deleting your account removes your data from the live database immediately — no soft-delete grace period, no retained copy of your places.
- Waitlist emails: until the launch announcement has been sent and the list has served its purpose, or immediately on request.
- Support emails: as long as needed to resolve your question.
- Technical server logs: short-lived, kept only for security and operations, then discarded.
11. Your rights
Under the GDPR you can:
- Access your data — the app's free export gives you everything, self-serve, in open formats (CSV, GPX, KML, JSON);
- Correct anything by editing it in the app;
- Delete everything — in the app, or by emailing us;
- Take your data elsewhere (portability) — the same export, in machine-readable formats;
- Object to processing based on legitimate interests, and withdraw consent at any time;
- Complain to a supervisory authority — in Lithuania, the State Data Protection Inspectorate (vdai.lrv.lt), or the authority of your own country.
For anything you can't do self-serve, email us — we answer, and we don't make you fill in forms.
12. Security
- All traffic between the app, the website and our servers is encrypted (HTTPS/TLS).
- Passwords are stored only as salted PBKDF2 hashes — never in readable form.
- Sign-in tokens are device-bound and can be revoked; you can sign a lost device out by signing in on a new one.
- The strongest protection is architectural: data we never receive — your photos on the free plan, your location — cannot leak from us.
13. Children
Mapcove is not directed at children. You must be at least 14 years old (or the minimum age of digital consent in your country, if higher) to create an account. If you believe a child has created an account, contact us and we'll delete it.
14. Changes to this policy
If this policy changes materially — for example a new processor, or a new kind of data — we'll say so in the app or by email before the change takes effect, and this page always carries the date of the current version.
15. Contact
Privacy questions and requests: [email protected]. Every email is read and answered by a real person.