Privacy policy
The short version. You can use the map without an account and we store nothing about you on our servers beyond short-lived access logs. If you sign up we store what you give us (email, username, password hash, what you post) and, only while you turn on a live beacon, your position. We do not sell data, run adverts or use tracking analytics. Delete your account from the Me tab at any time.
1. Who is responsible
The data controller is Chamaps (Ed Freear, sole trader), Esher, Surrey, United Kingdom. Contact for anything in this policy: hello@chamaps.app. We are a small UK-based operator and we process personal data under UK GDPR and the Data Protection Act 2018.
2. What we store, why, and for how long
| Data | Why (legal basis) | Kept |
|---|---|---|
| Account: email, username, display name, avatar colour, bio, account type, the date you confirmed you are 18+ and the terms version you accepted | To run your account and meet our legal duties (contract; legal obligation) | Until you delete your account |
| Password | Stored only as a salted scrypt hash — we cannot read it (contract) | Until you delete your account |
| Sign-in tokens | Keep you signed in (contract) | 30 days from issue, then automatically invalid |
| Content you create: routes, activities (GPS tracks), photos, reviews, to-do lists, trips, guidebook entries, conditions reports | That is the service (contract). Public content is visible to anyone; friends-only content to your friends; private content only to you | Until you delete the item or your account. Items other people depend on (a route in someone else's trip) are kept anonymised |
| Messages in direct and group chats | Deliver chats (contract) | Until the chat is deleted by all members. When you delete your account, your messages stay in the chats but show "Deleted user" |
| Live beacon positions: latitude/longitude, altitude, accuracy, heading, speed | Only when you start a live beacon, and shared only with the friends or group chats you choose (consent — you can stop at any time) | Only the latest fix is kept; the beacon and its position are deleted automatically when the timer you set runs out (at most a few hours) or when you stop it |
| Friends, blocks, chat membership | Run the social features and let you block people (contract; legitimate interest in user safety) | Until you remove them or delete your account |
| Guide / operator verification: qualification body, certificate number, organisation, proof document | Verify guides and patrol before they can post conditions (legitimate interest; consent for the document) | The proof document is deleted as soon as an admin decides the application; the decision and note are kept with your account |
| Reports you make or that are made about your content: reason, details, a snapshot of the reported content, the reporter's and author's account ids, the decision and the moderator's note | Handle illegal and harmful content, and show we did so (legal obligation under the UK Online Safety Act 2023; legitimate interest in safety) | Reports are kept for 12 months after they are decided, then deleted. If your account is deleted your id is removed from the report but the snapshot and decision stay |
| Suspension: date and reason | Enforce the terms and stop banned users returning (legitimate interest) | While the account exists |
| Server access logs: IP address, requested URL, time, browser user-agent | Security, abuse prevention and debugging (legitimate interest) | Rotated automatically: at most about 60 MB of logs are kept, which in practice is days to a few weeks |
| Rate-limit counters keyed by IP address | Stop brute-force sign-in and report spam (legitimate interest) | In memory only, 10 minutes to 1 hour |
We do not use analytics or advertising trackers, we do not set third-party cookies, and we do not sell or rent personal data.
3. Stored on your device only
Your browser's local storage holds your sign-in token, your settings (language, appearance, layer choices, units), the places you have looked at, recordings in progress, and up to 20 locally-saved activities until you upload them. None of this leaves your device unless you sign in or upload. Clearing site data in your browser removes it.
4. Who else sees data
Our hosting
The Chamaps server and database run on a virtual machine in Oracle Cloud Infrastructure, UK South (London). Oracle is a processor acting on our instructions. Uploaded photos and proofs are stored on that machine, not on a third-party CDN.
Our admin assistant
Administrators can ask a text assistant in the cockpit to look things up or prepare moderation actions for them (every action still needs a human click). When they do, the text of their request and the minimum records needed to answer it — usernames, display names, account types, content titles, report reasons and similar — are sent to an AI model provider acting as our processor: not currently enabled. E-mail addresses, passwords and payment data are never included, and the provider is contractually barred from training on this data. We log that a request was made (who, when, which tools), not its text.
Services your browser talks to directly
To draw the map your browser fetches tiles and data straight from open providers, so they receive your IP address and the tile URLs (which reveal roughly where on the map you are looking), exactly as when you visit any website. We chose providers with open licences and clear policies:
- Map tiles: OpenFreeMap (OpenStreetMap data), OpenTopoMap; terrain: Mapterhorn (via AWS Open Data); night lights: NASA GIBS.
- Avalanche bulletins: EAWS / avalanche.report (Europe). Natural-hazard feeds: USGS, NASA EONET, GDACS. Point-to-point routing when you draw a route: BRouter. Place descriptions: Wikipedia.
- Fonts and libraries: Fontshare, Google Fonts, unpkg, jsDelivr.
Weather (MET Norway), snow models (DWD, NOAA), place search and reverse geocoding (Photon by komoot, with Nominatim by the OpenStreetMap Foundation as fallback), imagery from national mapping agencies and Copernicus, avalanche incident archives (LAWIS, regObs) and news (GDELT) are fetched by our server, cached, and passed to you — those providers see our server's address, not yours.
Other people
Other users see your username, display name, avatar colour, bio, account type and verification badge; whether you are online; the content you make public or share with them; and your live position only if you include them in a beacon. Admins can additionally see your email address and reports involving you.
Authorities
We disclose data only when the law requires it, for example a valid request from UK police or a court, or where we must report illegal content (such as child sexual abuse material) to the relevant authority.
5. Your rights and how to use them
- Delete everything: Me tab → Danger zone → Delete account. Your profile, friendships, blocks, beacons, proofs and photos are removed immediately; your messages and shared items stay, anonymised as "Deleted user"; report snapshots involving your content stay without your id.
- Export: routes and activities can be downloaded as GPX from the app at any time. For a full copy of your data, email us.
- Access, correct, restrict, object, withdraw consent: edit your profile in the Me tab, stop a beacon at any time, or email hello@chamaps.app. We answer within one month.
- Complain: you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local data-protection authority if you live outside the UK.
6. Children
Chamaps is for adults. You must confirm you are 18 or over to create an account, and we suspend accounts we reasonably believe belong to children. If you think a child has an account, email us and we will remove it.
7. Security
Connections use HTTPS. Passwords are hashed with scrypt. Proof documents are stored under random names and only downloadable by admins. The server keeps storage bounded and deletes temporary downloads. No system is perfectly secure; if we learn of a breach affecting you we will tell you and, where required, the ICO within 72 hours.
8. Changes
If we change this policy in a way that matters we will tell you in the app before it applies. The version date at the top shows when it last changed.