Privacy Policy
Your travel history stays yours.
Last updated: August 24, 2026
The short version: Mapsake is a local-first, privacy-first app. Your authoritative travel record is stored on your device and, when available, in your private iCloud database. Optional sharing, feedback, enrichment, import, and Remote AI Access features are off or user initiated and are described below. The app has no advertising SDK, does not require a Mapsake account, and does not sell your data.
What the app stores, and where
Everything you create in the app - the places you mark as visited, lived, or next, along with dates, notes, trips, settings, and imported data - is stored locally on your device. When iCloud is available, Mapsake also synchronizes supported records through your private CloudKit database so your Apple devices can converge on the same record. Apple processes that data under Apple's terms.
Mapsake does not maintain a plaintext developer database containing every user's travel history. Device credentials and security preferences are stored using Apple platform storage such as Keychain and UserDefaults. Your device and iCloud remain the authoritative sources unless you deliberately use one of the optional sharing or service features below.
Photos & location
If you choose to import places from your photo library, the app reads the location info saved with your photos to figure out where they were taken. This happens on your device. We never receive your photos or their locations. Turning those locations into place names may use Apple's own services under Apple's privacy terms.
Remote AI Access
Remote AI Access is disabled by default. Before it can be enabled, Mapsake explains the data flow and asks for explicit permission. You must then create a one-time pairing code and use it to connect ChatGPT, Claude, or another compatible Model Context Protocol client.
While enabled, Mapsake creates a disposable read model containing the travel categories you selected. It encrypts that model on your device and stores the encrypted chunks in your iCloud public CloudKit database for up to 45 days, replacing older generations as the record changes. Relay metadata, encrypted requests, results, and connection grants remain only as needed to operate the connection, expire where practical, and are removed or invalidated when you turn access off or disconnect assistants.
For an authenticated request, the Mapsake relay decrypts the selected data in server memory only long enough to service that request, then sends the requested answer to the third-party AI provider you connected. Mapsake does not retain a second plaintext travel-history database. Once an answer reaches your chosen provider, that provider processes it under its own privacy terms. Passport chip data, passport images, original photos, and raw photo metadata are never included. Notes, photo counts and dates, passport stamps, edits, imports, and exports each have separate controls.
Remote writes are queued back to Mapsake and checked against the current authoritative record. Sensitive changes require an exact, fresh confirmation, imports show a native preview before saving, manual conflicts are preserved, and export PIN protection still applies. You can disable individual permissions, disconnect one client, disconnect every client, or turn Remote AI Access off from Settings.
Optional network services
Mapsake can request optional Wikipedia, OEC, and Open-Meteo information after you enable those features. Those requests contain the country, city, coordinates, or other place needed to return the requested article, economic facts, or weather, but do not send your complete atlas or photo library. Each provider processes ordinary network information under its own terms.
If you connect a self-hosted Immich server or a supported import provider, Mapsake contacts the service you selected only for the feature you requested. Access tokens and server credentials are kept in platform-protected storage where supported. Imported data is previewed and merged into the authoritative Mapsake record; the connected provider remains responsible for its own service and privacy practices.
Friends and public sharing
Friends and cross-device synchronization use Apple CloudKit. Public maps and Maplight pages are separate opt-in features and expose only the lenses, statistics, approximate areas, or other fields shown in their sharing screen. They never include original photos. Public links can be revoked and may be configured to expire.
In-app feedback
When you deliberately send feedback from Mapsake, our support service receives the category, message, optional contact address, app and device context, and only the attachments or diagnostic categories shown as enabled in the form. Diagnostic options can include logs, performance or thermal data, iCloud state, country resolution details, Friends state, or other material needed to reproduce the issue. Feedback uploads can resume after interruption. We use this information only for support, security, reliability, and product improvement, retain it only as long as reasonably needed for those purposes, and do not add it to a marketing list.
Maplight
Maplight turns photo locations into approximate illuminated origins. Before Maplight history is stored or synchronized, coordinates are reduced to an approximately 1 km geohash cell. Its private iCloud records contain only that approximate cell, the contributing source categories, and the earliest capture day. They never contain photo pixels or raw photo coordinates.
Removing a source photo does not remove a Maplight discovery. You can explicitly rebuild Maplight from sources currently available or erase its history. Friends sharing is off by default and sends totals only, never cells, dates, sources, or a footprint.
Public Maplight is a separate opt-in surface. When enabled, it publishes statistics and broader generalized cells without dates, sources, exact origins, photos, or private Maplight achievement history. The public page labels the result as generalized for privacy.
This website
This site uses Google Analytics to understand page visits, referral and campaign sources, general device and browser information, approximate geography, and actions such as opening an App Store link. Google may process identifiers, cookies, and IP-address information according to its own terms. We use this information to evaluate and improve the website and do not combine it with a Mapsake travel atlas.
You can limit cookies in your browser, use a content blocker, or use Google's browser add-on for opting out of Google Analytics. Standard server logs may also briefly record requests such as IP address and timestamp for security and reliability.
The free Photo Map Maker and Photo Location Finder read selected image metadata in your browser. Photo files, filenames, coordinates, dates, camera details, visited-map selections, airport itineraries, and radius coordinates are not sent to Google Analytics. Visited-map selections are saved in that browser's local storage until you clear them.
Website feedback
The text-only website feedback form stores the category, message, optional contact address, submission time, and a source label of Website. It does not accept files or collect app logs, photo data, Maplight data, or other in-app diagnostics. Feedback is used to answer support requests, reproduce problems, and improve Mapsake. It is not added to a marketing list.
The form uses Cloudflare Turnstile to prevent automated spam. Cloudflare processes browser and network information needed to evaluate the challenge under its privacy terms. Mapsake verifies the short-lived response and uses an IP address temporarily for rate limiting, but does not store that address with the feedback record.
Map search and tiles
The Map Radius Calculator sends location text to Mapsake only when you press Search. The server forwards that text to the OpenStreetMap Foundation's Nominatim service without forwarding your IP address, caches the returned place results for up to seven days, and does not include the query in Mapsake analytics. You can use map clicking or coordinates without place search.
The radius map loads map styles and tiles from OpenFreeMap. As with any remote tile service, the provider receives ordinary network request information such as IP address, user agent, and the tile areas requested. The other browser tools use geographic data bundled with this website and do not require a live tile provider.
What we don't do
- No ads. No ad networks. No ad tracking.
- No selling or renting of your data - ever.
- No account required to use the core app.
- No behavioral analytics on your in-app travel data.
- No hidden sharing with third-party AI providers.
Your control
You can export, back up, restore, and permanently delete Mapsake data from within the app. You can revoke public links, disconnect Friends, disable network enrichments, and revoke Remote AI Access. Deleting the app removes its local data from that device; private iCloud records and backups remain subject to your iCloud settings and Apple's retention controls. To request deletion of feedback or other data held by Mapsake support systems, contact us using the address below.
When Mapsake uses a service provider acting on its behalf, that provider is limited to the disclosed purpose and must protect the data consistently with this policy and applicable requirements. Services that you independently choose to connect, including a third-party AI assistant or a self-hosted server, also operate under their own terms. Mapsake never authorizes a connected service to use your travel data for advertising or unrelated profiling.
Children
The app is not directed at children under 13 and does not knowingly collect personal information from them.
Changes
If this policy changes, we'll update the date above and post the new version here. Material changes will be reflected in the app where appropriate.
Contact
Questions about privacy? Reach out via the support page or email [email protected].