← Back to map

Privacy & Data Access

This page describes how your data is stored, who can access it, and what happens when you delete your account. It complements the short note on the signup page.

Administrator data access

Technical access

Site administrators have technical access to everything you upload. There is no application-level barrier between an administrator and the underlying storage. This includes raw GPX and .slopes files, processed GeoJSON, your account record, and any shares or tags you create.

When administrators will access your data

Administrators will only access user data to investigate a specific bug, to respond to a security incident, or to fulfill a data request you make about your own account.

There is no routine browsing of user content. If you'd prefer not to have admins able to see a particular track at all under any of those circumstances, don't upload it here.

Data retention & deletion

What's stored

For each account: your handle, your Google account identifier (used to sign you in), and any tracks, shares, and tags you create. For each track: the original uploaded file (GPX or .slopes), the processed GeoJSON used by the map, and metadata such as distance, duration, and bounding box.

Account deletion

Deleting your account starts a 30-day soft-delete window. During that window your account and data are hidden from the app but still recoverable: sign back in with the same Google identity and confirm, and everything is restored.

Once the 30-day window closes, the account can no longer be restored by signing in, and the data is purged from storage. After that it cannot be recovered.

Third-party services

Mapbox

Map tiles are rendered using Mapbox. When you pan or zoom the map, your browser fetches tiles directly from Mapbox, which means Mapbox sees the viewport coordinates you're looking at and your IP address.

Your uploaded tracks themselves are not sent to Mapbox — they're rendered on top of the tiles by your browser using data from this server.

Google Sign-In

Google Sign-In is used as the identity provider. Signing in tells Google that you visited this app. This server receives a Google-issued credential during sign-in and persists only the Google account identifier on your account record — no email, name, or profile picture is stored.