Privacy Policy
Last updated: March 16, 2026
Mapinlay ("we", "us", or "our") operates the Mapinlay web application. This Privacy Policy explains how we collect, use, and protect your information when you use our service.
Information We Collect
Account Information
When you create an account, we collect your name, email address, and password. If you sign in with Google, we receive your name, email address, and profile picture from Google. We do not store your Google password.
Content You Create
We store the tours, waypoints, text overlays, and media (images, videos) that you upload to the platform. Media files are stored securely on Amazon Web Services (AWS) S3.
Automatically Collected Information
We collect standard server logs including IP addresses, browser type, and request timestamps to maintain service quality and security.
How We Use Your Information
- To provide, maintain, and improve Mapinlay
- To authenticate your identity and secure your account
- To store and serve your tour content
- To enable AI-powered tour generation (prompts are sent to the Anthropic API)
- To display published tours on the explore feed
Third-Party Services
We use the following third-party services to operate Mapinlay:
- Google Identity Services— for Google sign-in authentication. Subject to Google's Privacy Policy.
- Amazon Web Services (S3, CloudFront) — for media file storage and delivery.
- Anthropic API— for AI-powered tour generation. Tour generation prompts are sent to Anthropic for processing. See Anthropic's Privacy Policy.
- MapLibre GL— for map rendering (open-source, self-hosted). Map tiles are fetched from third-party tile providers.
Data Retention
We retain your account information and content for as long as your account is active. If you delete your account, we will delete your personal data and uploaded media within 30 days, except where we are required to retain it for legal or legitimate business purposes.
Data Security
We use industry-standard security measures to protect your data, including encrypted connections (HTTPS), secure password hashing (Argon2id), and token-based authentication with short-lived access tokens.
Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and data
Cookies
We use essential cookies for authentication (refresh tokens stored as HttpOnly cookies). We do not use tracking or advertising cookies.
Children's Privacy
Mapinlay is not directed to children under 13. We do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on this page with a new "Last updated" date.
Contact Us
If you have questions about this Privacy Policy, please contact us at [email protected].