MapPal Privacy Policy
Draft dated: August 28, 2026
This policy describes how MapPal handles information in the private Phase 1 iPhone app and this website. “MapPal,” “we,” and “us” refer to the operator that will be identified on MapPal’s final App Store listing. Public profiles, shared lists, collaboration, Community, Discover, advertising, analytics, and tracking are not part of this release.
Information MapPal handles
Account and security information
When you use Sign in with Apple, MapPal receives an Apple account identifier and, when Apple provides it, your email address or Apple private-relay address. We keep the MapPal account and session identifiers needed to authenticate you. App Attest provides device-key identifiers, counters, and security results that help prevent replay and abuse. MapPal does not request your full name, contacts, advertising identifier, or payment-card information.
Subscription information
Apple processes payments. MapPal receives and keeps verified product, transaction, entitlement, expiration, and revocation facts needed to provide MapPal Pro, restore purchases, prevent fraud, and meet accounting obligations.
Private places and device location
Your saved pins, folders, notes, private photos, links, and custom fields stay in MapPal’s local database and your private iCloud/CloudKit container. The MapPal backend does not receive that private library in Phase 1. If you grant location access, iOS uses it on your device for the map and nearby alerts. MapPal does not retain your current device location on its servers.
Information you choose to import
When you share a website, social post, map link, text, photo, or screenshot with MapPal, the app processes only what you selected for that requested import. Map links, photo GPS metadata, and screenshot text are handled on device when possible. A guarded hosted import may process the public URL and bounded public place, caption, address, or location evidence needed to return suggestions. It does not receive your private pin library, private notes, current device location, or an unselected photo merely because it appears in your photo library. Nothing becomes a pin until you review a suggestion, select a place, and tap Add Pin.
Operations and support
MapPal keeps limited account-bound security, purchase, import, deletion, rate-limit, and error outcomes required to run and protect the service. Ordinary service logs may include request time, route, IP address, user agent, and an opaque user or session identifier. If you email support, your email provider and ours process the address, message, and attachments you choose to send.
Why we use information
We use information only to authenticate accounts, protect requests, provide subscriptions, complete imports you initiate, return place suggestions for your review, operate nearby alerts on device, respond to support, delete accounts, prevent abuse, diagnose failures, and comply with law. MapPal does not sell personal information, serve advertising, build advertising profiles, or track you across other companies’ apps or websites.
Service providers
MapPal uses Apple for Sign in with Apple, App Attest, StoreKit, Maps/MapKit, and private iCloud/CloudKit; Supabase for authentication and the protected account database; and Cloudflare for the API boundary and bounded import workflow. When a public social source requires it, MapPal may use Apify to retrieve one user-selected public post and Anthropic to extract bounded place evidence. Apify run data is requested for deletion after settlement. Anthropic’s standard commercial API retention may be up to 30 days, subject to its safety, security, and legal exceptions. These providers process information only for the functions described here and under their own applicable terms and privacy commitments.
Retention and deletion
Account and security records remain while your account is active or for the record-specific period needed to operate and protect it. A hosted import unlinks its source from your account at terminal settlement; raw provider responses are not kept by MapPal. Ordinary Supabase operational logs and daily backups rotate after approximately seven days. After account deletion, minimized purchase and anti-fraud records may remain for up to 24 months. Provider, security, legal, backup, or fraud-prevention copies may remain until their ordinary protected retention periods end.
You can start account deletion inside MapPal under Settings → Account & Data. Deletion removes MapPal’s server account and eligible server data after the required checks complete. It does not automatically cancel an Apple subscription or erase the private pins stored on your device or in your private iCloud; the app explains those separate actions before confirmation. See Delete account for details.
Your choices
You can decline photo or location permission, choose manual pin entry, cancel an import, remove saved private content, manage or cancel subscriptions through Apple, remove MapPal from Sign in with Apple settings, and request account deletion in the app. You may contact us about access, correction, privacy, or deletion questions. We may need to verify the same signed-in account before changing protected account data.
Children
MapPal is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. Contact us if you believe a child supplied personal information.
Security and changes
MapPal uses authentication, App Attest, encryption in transit, restricted service roles, private storage, rate limits, and deletion controls. No system is completely secure. We may update this policy when the product or law changes; the page will show the new effective date, and material changes will be presented as required.
Contact
Privacy questions can be sent to support@getmappal.com.