Privacy Policy
Summary
CatMap does not require an account. Your device is identified by a random token stored in the browser. You may optionally create an account (email/password or Google) to sync your cats and hearts across devices and to receive email notifications. Some optional fields (such as a contact method on a missing-cat post, or your account email) are personal data if you choose to provide them.
What we store
-
Device token — a random UUID generated in your
browser's
localStorage. It is sent as theX-Device-Tokenheader so you can confirm sightings once, report content, edit or delete your own posts, send private tips, heart cats, and manage watches. Clearing site data generates a new token and you lose access to “my cats” unless you exported a backup or linked an account. Anyone who obtains the token (for example by scanning or screenshotting the backup QR) can act as you. - Optional account — email address (lowercased), password hash (argon2id) when you set a password, linked Google subject id, private display name used only in emails/settings, email notification preferences, and opaque session tokens. Accounts do not publish a public author name on the map.
- Hearts — which sightings or cat profiles you have hearted (server-side), so they sync when you are signed in.
- Sightings you submit — photo (EXIF metadata is stripped before storage), optional description, map coordinates, and optional attributes (color, ear-tipped, stray).
- Missing-cat contact — optional phone, email, or handle stored with the post. It is shown publicly only if you opt in; otherwise finders can send a private in-app tip to you.
- Comments and tips — text (and optional tip location) stored with the device token of the author. IP addresses are not persisted with comments.
- Watches — which sightings or cat profiles this device follows, so we can send activity alerts.
- Push subscriptions — a Web Push endpoint (and, on Android, an FCM token) stored against your device token so we can deliver nearby-missing and watch alerts. Unsubscribe from Settings to remove it.
- Email notifications — if you verify an email on your account and leave email alerts enabled, we may email you about activity on your posts, cats you follow, nearby alerts, and moderation. Every email includes an unsubscribe link.
-
Error tracking (Sentry) — if configured by the
operator, crash reports may be sent to Sentry. Personal information
is not attached by default (
send_default_piiis off). - Anonymous analytics (optional) — if you accept the consent banner, Google Analytics 4 may collect aggregated usage data (page views, feature interactions). IP addresses are anonymized.
What we do not collect
- Names, email addresses, or login credentials as account data
- Precise hardware identifiers beyond the anonymous device token
- Photo EXIF after upload (GPS and camera metadata are removed)
Moderation
Users can report sightings and comments. Content may be hidden automatically after multiple reports. Uploaded photos are checked for cat-like content before being published. Device tokens may be blocked from posting.
Third parties
- OpenStreetMap — map tiles and place search (Nominatim)
- Google Analytics — only when you opt in via the consent banner. Google Privacy Policy
- Sentry — error monitoring, only when the site operator has configured a DSN
- Firebase Cloud Messaging — Android push delivery when native notifications are enabled
Contact
Questions or concerns: open a GitHub issue or visit drytrix.com.