Overview
Flagstone is a community tool for mapping accessibility barriers. This policy explains what we collect, why, and how to control your information.
What We Collect
When you browse the map (no account needed)
Nothing. You can view flags without logging in and we don’t track you.
When you create an account
- Email address — for sign-in and optional notifications only
- Display name — shown on flags you verify or report (you choose this)
When you report or verify a flag
- Location — the latitude/longitude where you submit the flag (placed on the map)
- Description — the text you write about the accessibility barrier
- Category — which type of barrier (ramp, parking, etc.)
- Severity — how much of a problem it is (1-5 scale)
- Photos — if you choose to add them
- GPS metadata is automatically removed from all photos before they’re stored
- Camera metadata, timestamps, and other EXIF data are stripped before upload
- We keep only the image itself, not the metadata
Automatically collected
Almost nothing. There is no usage analytics and no crash reporting in the app: nothing about how you use it is collected, transmitted, or stored.
- Timestamps — when you created your account and when you take actions
What we never collect
- Analytics about how you use the app, or which screens you visit
- Crash or error reports
- Your device’s location in the background
- Contacts, camera roll, or other device data
- Payment information (we don’t charge)
- GPS coordinates or camera metadata from your photos
How We Use Your Data
| Your Data | What We Do With It | Who Sees It |
|---|---|---|
| Sign-in, password reset, optional notifications | Only you (never visible on the map) | |
| Display name | Shown on flags you report/verify | Other app users |
| Flag location | Placed as a marker on the map | Other app users |
| Flag description + category | Shown on the map when people tap the marker | Other app users |
| Photos | Displayed in flag details (public-readable in Storage) | Other app users |
| Usage data | Fixing bugs, improving the app, understanding feature adoption | Internal team only |
We do not:
- Sell or share your data with third parties (except our cloud provider, Supabase, which is contractually bound)
- Use your data for advertising
- Share your email with other users
- Analyze your flag history to profile you
Your Rights & Controls
Manage Your Account
- Edit your profile — change display name or avatar anytime in Settings
- Delete a flag — remove any flag you submitted via the flag’s detail screen
- Manage notifications — opt in/out anytime in Settings
- Delete your account — Profile > Delete Account
- Your account and personal details go — email, display name, avatar
- Reports and comments you contributed may stay in the app with your name removed, so the community’s record of barriers stays whole
- Photos attached to your reports may remain unless you delete the report itself first
- This action cannot be undone
Data Access & Portability
- See your data — all your personal data is visible in the app (profile, flags, activity)
- Export data — contact us at support@skypistudio.com to request a copy of all your data
Privacy by Region
GDPR If you’re in the EU/EEA:
- Right to access — request a copy of your data via the contact email below
- Right to erasure (“right to be forgotten”) — use Delete Account in-app, or contact us
- Right to restrict processing — contact us to restrict how we use your data
- Right to portability — request your data in a portable format (CSV, JSON)
- Right to object — contact us to object to certain data uses
CCPA If you’re in California:
- Right to know — request what personal information we collect about you
- Right to delete — use Delete Account in-app, or contact us
- Right to opt-out — we do not sell personal information
- Right to non-discrimination — we won’t discriminate for exercising your rights
PIPEDA If you’re in Canada:
- Right to access — request a copy of your personal data
- Right to correction — ask us to correct inaccurate data
- Right to complaint — contact the Privacy Commissioner of Canada if you believe we’ve violated PIPEDA
How We Store & Protect Your Data
Storage Location
- Your data is stored by Supabase, our cloud database provider
- Data is encrypted at rest (AES-256) and in transit (TLS 1.2+)
- Passwords are never stored — managed by Supabase Auth
Data Retention
| Type of Data | How Long We Keep It |
|---|---|
| Account (email, display name, avatar) | Until you delete your account |
| Flags you submit | Until resolved + 90 days (then archived) |
| Flag photos | Until the flag is deleted |
| Audit logs (for security) | 30 days |
Third-Party Services
Supabase (Cloud Database & Storage)
We use Supabase to host our database and file storage. Supabase is contractually bound to protect your data under GDPR/CCPA. Supabase Privacy Policy (opens in new tab)
Expo / EAS (App Distribution)
We use Expo Application Services to build and distribute the app. Expo may receive your device type and app version during updates. Expo Privacy Policy (opens in new tab)
OpenStreetMap Nominatim (Address Search)
When you type into the address-search field, the text you type is sent to OpenStreetMap’s Nominatim service to look up the place. That search text is the only thing Nominatim receives — no account details, no device identifiers, and never your GPS location. OSM Foundation Privacy Policy (opens in new tab)
No Other Sharing
We do not share data with advertisers, analytics companies, or data brokers. We will not sell your data under any circumstance.
Photo Privacy Details
When you upload a photo:
- We re-process the image to strip all EXIF metadata (GPS coordinates, timestamps, camera model, lens info)
- On iOS/Android: we use the device’s native media library for re-processing
- On web: we use canvas to re-render, which naturally strips all metadata
- Photos are stored in Supabase Storage with public read access — anyone on the map can see them
- Only you can delete your photos
Children & Minors
Flagstone is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn that we’ve collected data from a child under 13, we’ll delete it immediately. If you believe a child under 13 has created an account, please contact us at support@skypistudio.com.
Changes to This Policy
If we make material changes, we will update the “Last updated” date, notify you via in-app message and email, and ask you to re-accept the new policy if required.
Contact & Data Requests
- Email: support@skypistudio.com
- Response time: We aim to respond within 30 days
For data subject requests (GDPR / CCPA / PIPEDA), include one of the following in your email subject line:
- Data Subject Access Request — to see your data
- Data Deletion Request — to delete your data
- Data Portability Request — to export your data