Skip to main content
Mapgram
  • Home
  • Privacy
  • Terms
  • Support
Draft for review

Privacy Policy

This review draft reflects facts confirmed from Mapgram's current implementation and by its operator. It is not the final Privacy Policy.

Review required before deployment

Privacy Policy content requires factual and legal review before deployment. The sections below intentionally do not fill gaps with assumptions.

Operator and contact

Mapgram is operated by Taiki Koyama. Questions about privacy can be sent to mapgram@tech-takolab.com.

Information Mapgram processes

Account information

Mapgram uses Supabase to create and authenticate accounts through Sign in with Apple or Sign in with Google. Account information may include an authentication identifier, email address, authentication-provider information, and profile information supplied by the provider.

Saved information

Mapgram stores information that a user chooses to save, including a Google place identifier, links to external posts, tags, notes, whether a place is marked as “want to go” or “visited,” and related creation and update dates.

The current product restricts a user's saved entries, including their links, tags, notes, and status, to that account owner. Mapgram also uses shared place records to avoid duplicating basic place references across accounts. A shared place record is separate from a user's saved entry.

Information stored on the device

The app stores the authentication session and language preference on the device so that the user can remain signed in and use their selected language.

Location information

If foreground location permission has been granted, Mapgram may use the device's current location to center the map, calculate distances on the device, and improve the relevance of place-search results. Place-search requests may send the search term and current coordinates to Google Places.

The current Mapgram implementation does not store the device's current location in its Supabase database. Coordinates associated with places a user saves are obtained from place services and are separate from the device's current location.

How Mapgram uses information

  • to create and authenticate an account and maintain the user's session;
  • to save, synchronize, organize, and display the user's places;
  • to provide maps, place search, place details, place photos, and distance calculations;
  • to provide account management and account deletion; and
  • to respond to support and privacy questions.

Service providers

  • Supabase provides account authentication, application data storage, and the account-deletion function. The production Supabase project is configured for the Northeast Asia (Seoul) region.
  • Apple provides Sign in with Apple.
  • Google provides Sign in with Google and Google Maps Platform features, including maps, place search, place details, and place photos. Google Places may receive a search term and current coordinates when location is used to improve a search. Google's processing is described in the Google Privacy Policy.

Analytics, advertising, and diagnostics

The current Mapgram source code does not intentionally integrate a dedicated product-analytics, advertising, attribution, session-replay, performance-monitoring, or crash-reporting SDK.

The service providers used for authentication, application data storage, maps, and place search may process operational request, device, location, diagnostic, security, or log information as necessary to provide and protect their services, subject to their own terms and Mapgram's provider-account settings.

Mapgram's account-deletion function records limited operational information for reliability and security. The current implementation is designed not to include user IDs, email addresses, authentication tokens, or external-provider error details in these audit events. The events are not used for product analytics.

Account deletion

A user can initiate account deletion from within the Mapgram app. The deletion process requires reauthentication and is designed to remove the Supabase authentication account and associated user-owned Mapgram data. A shared place record may remain after its association with the deleted account is removed.

Minimum age

Mapgram is intended only for people who are at least 18 years old.

Security

The current implementation uses Supabase authentication and database access controls, keeps administrative credentials in the server-side account-deletion function, and requires reauthentication before account deletion.

Mapgram Website

The Mapgram Website source does not include analytics or advertising scripts and does not set cookies or use browser storage. It does not provide account authentication or connect to the Mapgram application database.

The Website is planned to be hosted using Amazon S3 and Amazon CloudFront. The production access, security, and operational log settings have not yet been configured or verified.

Proposed data retention schedule

The following schedule has been selected for this review draft. It must be implemented and verified before it is stated as the final production policy:

  • account information and user-saved information are retained while the account is active and are removed from the live service when the user deletes the information or account;
  • saved-place coordinates are treated as a temporary cache for up to 30 days from the cache timestamp;
  • provider-managed database backups expire according to the production Supabase plan, and any manually created database export is deleted within 90 days;
  • closed support and privacy-request email is deleted within 12 months; and
  • if Mapgram enables Website access-log storage, those logs will be deleted within 90 days.

Operational logs created by service providers follow the production settings and retention available under the applicable provider plan. The exact production periods still require verification.

Items to finalize

Before publication, the final policy must accurately address:

  • confirmation that the production job for expiring cached saved-place coordinates is active;
  • the final Website hosting log settings and their retention configuration;
  • the production Supabase plan and provider-managed backup and log periods;
  • applicable user rights, legal bases, data transfers, and regional privacy requirements;
  • the effective date and how material policy changes will be communicated; and
  • production provider settings and the corresponding App Store privacy disclosures.

Contact

For a privacy question or a request to access, correct, or delete account data, email mapgram@tech-takolab.com from the address associated with the Mapgram account where possible. Mapgram may ask the requester to complete a new sign-in or provide limited account information when reasonably necessary to verify the request. Mapgram will not ask for an Apple or Google password, an authentication token, or a copy of a passport for a routine request.

Terms of Service Support

Mapgram · Operated by Taiki Koyama

  • Privacy Policy
  • Terms of Service
  • Support