Privacy Policy
Effective July 20, 2026. Locsy is a mobile map and outdoor discovery app. You can explore public places without creating an account.
Information we process
If you sign in, Supabase Auth processes account identifiers and authentication information. Locsy stores profile details and content you choose to submit, including field notes, coordinates, descriptions, visibility choices, photos, comments, reactions, reports, and notification preferences.
Location is optional and is used to center the map and improve nearby discovery. Camera and photo-library access are requested only when you choose to add media. You can revoke permissions in system settings.
If you join the website waitlist, Locsy stores the email address you submit and the time you consented so we can send occasional launch news and early-access invitations. Waitlist addresses are not used for advertising or shared with data brokers. You can ask us to remove your address at any time.
Analytics and diagnostics
Firebase Analytics and Crashlytics may process app interactions, device information, and diagnostics to improve reliability only after you enable “Help improve Locsy” in Settings. This optional collection is off by default and can be disabled again at any time.
The Locsy website records aggregate page visits and waitlist conversion events without cookies. A random identifier kept only in your browser tab is converted server-side into a day-scoped cryptographic value. Approved campaign links may add coarse, allow-listed source, medium, campaign, and creative codes; Locsy does not retain the full query string or referrer. The original session identifier, full user agent, and IP address are not retained as analytics data. Analytics are skipped when your browser sends a Do Not Track signal.
Advertising and consent
Locsy uses Google Mobile Ads to display consent-gated banners on Discover. Explore remains ad-free so the map and safety controls stay unobstructed. Where required, Google’s consent form is shown before an ad request and privacy choices remain available in Settings. Locsy does not request Apple tracking permission or Android advertising-identifier and Privacy Sandbox ad permissions, and disables Google’s publisher first-party identifier on iOS before initializing Mobile Ads. Google may process device, advertising, interaction, fraud-prevention, and diagnostic information under your consent choices and regional rules.
Service providers
Locsy uses Supabase Auth for identity and Supabase for application data and media, Mapbox for maps and place search, OpenStreetMap contributors for place data, Firebase for analytics and diagnostics, Google Mobile Ads for consent-gated banner advertising, and Cloudflare for secure delivery. OpenStreetMap place data is © OpenStreetMap contributors and is available under the Open Database License (ODbL). Community field notes remain separate user-provided content.
Sharing and visibility
Public field notes and profile information are visible to other users. Private field notes are limited to their owner. Locsy does not sell personal information. Data may be shared with service providers only to operate the app, comply with law, protect users, or enforce product rules.
Retention, security, and deletion
Data is transmitted over HTTPS and retained while needed to provide the service or meet legal and security obligations. Waitlist addresses are retained until launch communications end or you request removal. Short-lived, cryptographically obscured abuse-prevention counters are kept separately from waitlist and analytics records. You can edit or delete field notes and delete your account from Settings. Account deletion removes the Locsy account and associated application data, subject to limited legal, fraud-prevention, and backup retention requirements.
Children and changes
Locsy is not directed to children under 13. Store age and regional requirements may impose a higher minimum age. We may update this policy as the service changes and will revise the effective date.