Mappily

Privacy in the app

Last updated 15 September 2026

The Mappily app has no accounts and no analytics, advertising or tracking. It reports crashes to our own servers, and nothing in a report is about who you are. It reads your location only while you have asked to be shown where you are, and records nothing about where you have been. What you draw is held on your device and copied to our server, where an unguessable link is what reaches it. Accounts will probably arrive at some point, but only where they genuinely make the app better to use, and this page will say so when they do.

Nothing is counted

The website counts a handful of things about how the map is used, and its own privacy page lists them. The app counts none of them. There is no analytics in it: no events sent anywhere, no advertising identifier, and no third-party code running in the background to report on what you do.

Crashes are reported, to Bugsink (error-tracking software running on our own servers), the same one the website reports to. A report says what went wrong and where in the code, and nothing about who you are: no device identifier, no network address, and no content of any request.

What could contain a place is cleaned on the way out: the address of a request loses its query string and the numbered parts of its path, which are what name a search, a tile or a position. There is no session recording and nothing plays back what you did, and a crash report never draws a picture of your screen. One thing in the app does, and only when you ask it to — see 'Writing to us' below.

None of this is a promise about forever. Accounts are possible at some point.

Location, only when you ask for it

The app can show where you are on the map: a dot, with the map keeping it in view until you move the map yourself. The permission for that is asked for when you press the button that does it — never on opening the app — and refusing costs nothing: everything else in Mappily works without it.

What the permission allows is reading your position while the app is open, and nothing more. Nothing is written down: no track of where you have been is kept anywhere, and the position is drawn and let go. There is no background location at all — the app cannot read where you are while it is closed.

Android holds this to account rather than our word for it: the request comes in the system's own dialog, and a permission once given can be taken back in Settings. Recording tracks in the background is what a native app is eventually for. On the day that arrives, this page will say so.

What the app asks your device for

The camera, and only to scan the code a trip is shared with. The scanner reads one code and closes. Nothing is photographed, kept or uploaded, and refusing the permission costs you nothing but having to paste the link instead.

The file picker, when you import a GPX or KML file. Android hands over the one file you chose and nothing else, it is read on the device, and what is inside it is yours to keep or discard before anything is written.

The clipboard, when you copy a position or a trip link. That is the whole of it: the text goes to your clipboard and nowhere else.

Your location, when you press the button that shows where you are. What that means, and what it never does, is the section above.

What you draw is yours

Trips, and the waypoints, routes, tracks and areas in them, are stored in the app's own database on your device. That copy is the one the app works from, offline included, and it is the one that takes precedence when two devices disagree.

A copy is kept on our server as well, for every trip rather than only the ones you share. That is what makes a link open on somebody else's device, and what keeps a trip when a phone is lost. There are no accounts, so an unguessable link is what reaches one: anyone holding the view link can see it, and anyone holding the edit link can change it.

Removing the app removes what is on the device. The copy on the server stays, and whoever holds a link can still reach it.

What else stays on the device

A few small things, so that the app opens where you left it: the position and zoom you were last at, the layers you had switched on, the searches you have made recently, and the outline of any region you have looked at.

And the random identifier the app sets for itself, which is what the messages below are asked with, and what goes with anything you write to us. None of the rest of this leaves the device.

And an email address, if you have ever given one for a reply when writing to us. It is kept so you do not have to type it again, and it is sent only when you tick the box that asks for it.

Map imagery comes from other sources

The map itself is drawn from tiles served by OpenStreetMap, OpenTopoMap, Esri, Spain's IGN, Catalonia's ICGC, France's IGN and others, named under the map as you use them. The app fetches those directly, so those organisations see your network address and which squares of the world you asked for, which tells them roughly where you are looking.

This is unavoidable for any map that does not host its own imagery, and it is the largest single thing about using Mappily that is outside our control. Each provider has its own privacy policy.

Tiles you have already looked at are kept on the device so that they are still there without a signal, and the oldest are dropped once that store reaches its size. The app never downloads a region in advance: bulk fetching is against the terms of the services above, and there is no button for it.

What the app asks our server

Place search is answered by Photon, an OpenStreetMap geocoder. The app never contacts it: the request goes through our server, so Photon sees us asking and not you. Answers are cached there, so a search somebody else already made costs no request at all.

Elevation profiles, the horizon along a sight line, river and reservoir readings and the eclipse data are asked of our server too. Each of those requests carries the place it is about, because that is the question being asked — a profile means nothing without the line it runs along. None of it is counted, none of it is attached to you, and nothing joins one request to the next.

What a request does leave is a line in an ordinary web server log, as a request to any site does. That comes with running a server rather than being something the app decides.

Messages from us

When the app starts it asks our server whether there is a message to show: for example, release notes, or a warning that a map provider is down. Almost always there is nothing, and the app says nothing.

So that a message you have dismissed does not come back, the app makes up a random identifier for itself the first time it asks, and sends it with the question. It is not derived from your device or your network address, it cannot be turned back into anything about you, and it is sent with this one request and with nothing else. Removing the app forgets it.

The question also carries which version of the app you have, which platform it is running on and which language you read it in, so that a message meant for older versions, or written in Catalan, reaches the right people. Nothing about where you are is sent, and this identifier is never attached to anything that has a place in it.

Writing to us

There is a button on the map for sending us a message: what sort of thing it is, what you want to say, and Send. Nothing here happens unless you press it, and none of it is counted.

Two boxes under the message, both off until you tick them. One attaches a picture of the screen as it was when you pressed the button — which is mostly map, so it shows where you were looking. The other lets you leave an email address so we can answer. The app remembers the address so you do not have to type it again, and the box still starts off every time: being written to is something you agree to on each message rather than once.

Two things go with every message without a box asking. The first is where the map was — the position, the zoom, and which layers were switched on. It is what makes the feature worth having: most of what anybody writes about a map is about a particular place, and "the path over the pass is not there" cannot be answered without it. It does not include which trip you had open.

The second is the random identifier the app made up for itself, together with which version of the app you have, which platform it runs on, and which language you read it in. The identifier is what lets several messages from one person be read as one person rather than as unrelated complaints. This is the only place it sits beside a position, and it is kept as long as the message is.

A message is kept for a year and then deleted, and the screenshot and the address go with it. Nothing is published, nothing is passed to anybody else, and there is no page anywhere that shows it.

Where the app itself comes from

The app is installed from Google Play, which records the install under its own policy rather than ours. What we see of it is what Play shows every developer: counts by country, device and version, and nothing about a person.

Smaller updates arrive without a visit to the store. On launch the app asks Expo's update service whether the version it is running has been replaced, and it asks whether or not there is anything to send back. That request tells Expo your network address, which build you are running and which platform it is on, along with a random installation identifier of Expo's own, kept by their code and not by ours. Nothing about the map, and nothing you have drawn, goes with it.

How long any of this is kept

Nothing is counted, so there are no counted events to delete on a schedule. Crash reports are deleted after 90 days.

A record that you dismissed a message is kept until that message is deleted.

A message you sent us is kept for a year, and the screenshot and the email address, if you gave one, are deleted with it.

A trip's copy on the server is kept while the trip is. Deleting a feature leaves a marker saying it was deleted, so that a device which was offline at the time learns about the deletion instead of putting the feature back.

Asking about any of this

Questions about this page, or about anything the app records, can go to privacy [at] mappily.com.