Last updated: June 2026

Privacy Policy

1. What data we collect

When you use Footprint, we collect:

  • Google account information — your display name and email address, provided by Google when you sign in.
  • Location history — GPS coordinates, timestamps, and inferred place names from the Google Timeline JSON files you upload.
  • Uploaded files — the raw JSON files you upload, stored temporarily for processing.

We do not collect payment card details (handled entirely by Stripe), passwords, or any data you do not explicitly provide.

2. How we use your data

Your data is used solely to provide the Footprint service — rendering your personalised travel map, computing statistics, and displaying your visit history. We do not:

  • Sell or share your data with third parties for advertising
  • Use your location data to profile or track you outside the app
  • Train AI or machine-learning models on your data

3. Data storage

Your data is stored in two places:

  • Cloudflare R2 — raw uploaded JSON files are stored in a private, access-controlled bucket. Files are only readable by the server during processing.
  • PostgreSQL database — processed visit records (coordinates, timestamps, city/country names) are stored in a private database accessible only to your account.

Both stores are access-controlled. No other users can see your data.

4. Google Firebase Authentication

We use Google Firebase Authentication to handle sign-in. When you sign in with Google, Firebase receives your Google account token and returns your name and email to us. Firebase also stores authentication metadata on their infrastructure, subject to Google's privacy policy.

We store a secure session cookie (__session) in your browser to keep you signed in for up to 14 days. This cookie contains no personal data — only a cryptographic session token.

5. Cookies and analytics

We use two types of cookies:

  • Essential: __session — required for authentication. Cannot be disabled without breaking sign-in.
  • Analytics: Firebase Analytics (_ga, _ga_*) — optional, used to understand aggregate usage patterns. Only set if you click "Accept all" in the cookie banner.

See our Cookie Policy for full details.

6. Your rights (GDPR)

If you are in the European Economic Area, you have the right to:

  • Access — request a copy of the data we hold about you
  • Deletion — delete your account and all associated data via Settings → Delete Account
  • Portability — your raw uploaded files can be re-downloaded from the Uploads page
  • Correction — contact us to correct inaccurate account information
  • Restriction — contact us to pause processing of your data

To exercise any right, email us at [email protected].

7. Data retention

We retain your data for as long as your account is active. When you delete your account, all associated visit records, uploads, and account information are permanently deleted within 30 days. Backups are purged on the same schedule.

8. Changes to this policy

We may update this policy to reflect changes in our practices or applicable law. Material changes will be notified by email or an in-app notice at least 14 days before taking effect.

9. Contact

Questions or requests: [email protected]