Effective 21 June 2026
Privacy at mapf
mapf helps you discover where life is happening in the city. This policy explains, in plain terms, what information we collect, how we use it, who we share it with, and the choices you have. We aim to collect only what we need, and to handle it with care.
The short version
- We collect the details you provide, the things you save, and how you use the app — to run mapf and make it better.
- To us you are a set of random identifiers, not your name. Creating an account needs only an email address, and sign-in is passwordless — a one-time code, or a passkey.
- Precise location is used only with your consent, and you can turn it off at any time.
- We use trusted third-party providers — including infrastructure, mapping, and AI services — to operate mapf. We do not sell your personal information.
- We keep information only as long as we need it, honor Do Not Track, and let you request access to or deletion of your data.
01Who we are
mapf is operated by mapfAI (“mapf,” “we,” “us”) and lives at mapf.ai. We’re building a living map of where the energy is right now. This policy applies to the mapf website and app, and acts as our notice at collection. mapfAI is the controller of the personal information described here. For any privacy question or request, contact privacy@mapf.ai — or see how to contact us for the mailbox that fits your request.
02Information we collect
We collect the following categories of information:
- Account information. If you choose to create an account, we collect your email address — or, for accounts created earlier, a phone number — along with associated account identifiers and an optional display name if you add one. Sign-in is passwordless: a one-time code we send you, or a passkey (a device-based credential — we store the public key it creates, never your biometrics, and never a password). You can use much of mapf without an account.
- Business accounts. If you claim a venue, or subscribe to a paid plan for one, we collect what we need to check the place is yours and to manage the subscription — the contact details and the claim you submit, and the plan and billing status our payment provider reports back to us. Card details go to that provider directly; we never receive or store them.
- Content you provide. Information you give us through the app, such as places you save, text you enter into search, and photos you choose to upload — for example, a venue cover photo if you claim a place, or community photos of somewhere you’ve been. It also includes the optional traveller profile you can write into your settings to tune your recommendations: it is free text, so it holds whatever you decide to put in it, and it is stored on your account so it is there on every device you sign in to. You can edit or clear it at any time, and clearing it removes it from your account.
- Usage and interaction data. How you interact with mapf — for example, the features you use and the actions you take — which we use to measure and improve the experience.
- Device and technical data. Information such as your IP address, browser and device type, operating system, language, screen size, and time zone.
- Approximate location. A general, area-level location (such as country or city) derived from your IP address. This is not your precise position.
- Precise location. Collected only with your consent — see Precise location below.
03How we use information
We use the information we collect to:
- provide, operate, and maintain mapf and its features;
- understand and respond to your requests — including natural-language search and recommendations (see Personalization & automated processing);
- measure, personalize, and improve the quality of what mapf shows you;
- keep mapf secure — detecting, preventing, and addressing fraud, abuse, technical issues, and unauthorized access;
- communicate with you about the service; and
- comply with legal obligations and enforce our terms.
Where required by law, we rely on one or more legal bases to process your information — including your consent, the performance of our agreement with you, our legitimate interests in operating and improving mapf, and compliance with legal obligations. See the regional supplements below for details that apply where you live.
04Personalization and automated processing
mapf personalizes what you see and interprets what you ask for. To do this we use analytics, machine learning, and automated processing — for example, to rank places, tailor recommendations, interpret natural-language requests, and protect the service from abuse. Where we use third-party AI services to interpret your requests, we share only what is needed for that purpose (see How we share information).
These processes are designed to assist you. We do not use them to make decisions that produce legal or similarly significant effects about you solely by automated means.
05Precise location
Some features can use your device’s precise location — for example, to center the map on you and to make recommendations more relevant. We request precise location only with your consent:
- We ask for your permission within the app before any precise location is used, in addition to the permission prompt shown by your device or browser.
- We keep a record of your consent choices so we can honor them.
- You can withdraw consent at any time through the app’s settings or your device or browser permissions. mapf works without precise location.
- We do not infer your precise location from how you move the map.
06Cookies and similar technologies
We use cookies, local storage, and similar technologies on your device to keep you signed in, remember your preferences and privacy choices, maintain security, and measure how mapf is used. We do not use advertising cookies or third-party cross-site tracking. You can control these technologies through your browser settings, though some features may not work without the ones that are essential to the service.
07How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose information only to the following categories of recipients:
- Other people using mapf. A photo you upload for a place — a venue cover, or a community photo — is shown to everyone who looks at that place. We strip location, camera, and other embedded metadata from every image before we store it, but the picture itself is public, so upload only what you are happy for others to see.
- Service providers. Vendors that help us operate mapf — including hosting, content-delivery and security, mapping and map-tile, communications, payment, and AI and machine-learning providers — who process information on our behalf under agreements that limit their use of it to providing services to us. When your device loads maps, mapping providers may receive your IP address and the area you are viewing. When you use natural-language features, your input may be processed by AI service providers to interpret and respond to your request.
- Legal and safety. When we believe in good faith that disclosure is required by law or legal process, or is necessary to protect the rights, property, or safety of mapf, our users, or the public, or to detect and prevent fraud, abuse, or security issues.
- Business transfers. In connection with, or during negotiations of, a merger, financing, acquisition, reorganization, or sale of assets, in which case information may be transferred subject to this policy.
08International data transfers
We and our service providers may process and store information in countries other than the one in which you live, and laws there may differ from your own. Where required, we take steps to ensure such transfers are subject to appropriate safeguards and that your information remains protected as described in this policy. For transfers out of Europe, see the Europe, UK & Switzerland supplement.
09How long we keep it
We retain personal information only for as long as necessary for the purposes described in this policy. The period varies by the type of information and is determined by criteria such as how sensitive it is, whether it is needed to provide the service to you, and our legal, security, and operational requirements.
- Technical identifiers such as IP address are retained for a limited period and then removed or separated from the records they were attached to.
- Precise location information is kept only for a limited period.
- Usage and interaction data is retained for a limited period, after which it is deleted or kept only in aggregated or de-identified form that does not identify you.
- Account information is kept for as long as your account is active and is deleted when you delete your account.
When information is no longer needed, we delete it or de-identify it so it can no longer be associated with you.
10Security
We use reasonable technical and organizational measures designed to protect your information against unauthorized access, loss, misuse, and alteration. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. If you believe you have found a vulnerability, or something that looks like one, tell us at security@mapf.ai.
11Your choices and rights
- Location. Turn precise location off at any time in the app’s settings or through your device or browser permissions.
- Analytics. We honor your browser’s Do Not Track signal, and the app offers a private mode that limits measurement.
- Sign out or clear your data. Signing out removes your account session from your device; clearing your browser data removes the identifiers stored there.
- Access and deletion. Subject to applicable law, you may have the right to access, correct, delete, or receive a copy of your information, and to object to or restrict certain processing or withdraw consent. Signed-in users can access and delete their data in the app’s settings; you can also contact us at privacy@mapf.ai, and we may need to verify your identity before acting on a request.
We will not discriminate against you for exercising your rights. Depending on where you live, you may have additional rights — see the U.S. state and European supplements below.
12Aggregated and de-identified information
We may create and use aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you — for example, to understand trends, measure the quality of recommendations, and develop and improve mapf. We may retain and use such information without restriction, maintain it in de-identified form, and do not attempt to re-identify it except as permitted by law.
13Third-party services
mapf may link to or work with services we do not control, such as mapping providers and the venues and websites you discover through the app. Their collection and use of your information is governed by their own privacy policies, not this one. We are not responsible for their practices, and we encourage you to review them.
14Children
mapf is not directed to children under the age of 16 (or the minimum age required in your jurisdiction), and we do not knowingly collect their personal information. If you believe a child has provided us information, contact privacy@mapf.ai and we will take appropriate steps to delete it.
15Changes to this policy
We may update this policy from time to time. When we do, we will post the updated version here with a new effective date. If the changes are material, we will provide additional notice as appropriate or required.
16Artwork and featured artists
The artwork throughout mapf is curated by us — each piece chosen deliberately, and shown to celebrate the individual talent of the artist behind it. It stays theirs: artists retain every right in their work, and nothing in this product grants or transfers to you any right, title, or interest in it.
We work with emerging artists regularly, and we are always looking for the next one. If you would like to see your work featured in mapf — or to collaborate with us in some other way — write to curation@mapf.ai. A few pieces, or a link to your portfolio, is enough to start.
17How to contact us
We keep a separate mailbox for each kind of request so yours reaches the right people first time. Every one of them is read by a person.
- privacy@mapf.ai
- Questions about this policy, and requests to access, correct, delete, or port your information.
- compliance@mapf.ai
- Legal, regulatory, and law-enforcement requests — including copyright claims and requests to take down a photo or other content.
- security@mapf.ai
- Vulnerability reports and anything that looks like a security problem.
- curation@mapf.ai
- Artwork and featured artists — having your work featured, licensing, and collaborating with us.
- hello@mapf.ai
- Anything else — including if you are not sure where to start.
United States state privacy rights
This section applies if you are a resident of California or another U.S. state with a comprehensive privacy law. It adds to, and does not replace, the rest of this policy. The categories of personal information we collect, the purposes for using it, and the categories of recipients we disclose it to are described above.
No sale or sharing
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under these laws. We have not done so in the preceding 12 months.
Sensitive personal information
Precise geolocation is treated as sensitive personal information. We collect it only with your consent and use it only to provide the features you ask for — not to infer characteristics about you — and you can turn it off at any time.
Your rights
Subject to applicable law and verification, you may have the right to:
- know about and access the personal information we hold about you;
- delete it, and correct inaccurate information;
- opt out of any sale or sharing of your information (we do neither);
- limit our use of your sensitive personal information;
- not receive discriminatory treatment for exercising your rights; and
- where available, appeal our decision on your request.
How to exercise them
Signed-in users can access and delete their data in the app’s settings, or contact us at privacy@mapf.ai. You may use an authorized agent to submit a request, and we may need to verify your identity — and your agent’s authority — before we act.
Europe, the UK & Switzerland
This section applies if you are in the European Economic Area, the United Kingdom, or Switzerland, and adds to the rest of this policy. mapfAI is the controller of your personal information.
Legal bases
Where the GDPR or UK GDPR applies, we process your information on these bases:
- Contract — to provide mapf and the features you request;
- Consent — for precise location and certain other processing; you may withdraw consent at any time;
- Legitimate interests — to operate, secure, measure, and improve mapf, balanced against your rights; and
- Legal obligation — to comply with applicable law.
Your rights
You have the right to access, correct, delete, and port your personal information, and to object to or restrict certain processing and withdraw consent. To exercise these rights, contact privacy@mapf.ai.
International transfers
When we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses (with the UK and Swiss addenda) — or another lawful transfer mechanism.
Complaints and contacts
You have the right to lodge a complaint with your local data protection authority. You can also reach our privacy team at privacy@mapf.ai.