Privacy Policy

Last updated: July 31, 2026  |  Version 1.1

Short version: We collect only what’s needed to make the map work. We never sell your data. You can delete your account any time from your Profile — your personal details go, and anything you contributed stays only with your name removed.

Overview

Flagstone is a community tool for mapping accessibility barriers. This policy explains what we collect, why, and how to control your information.

What We Collect

When you browse the map (no account needed)

Nothing. You can view flags without logging in and we don’t track you.

When you create an account

When you report or verify a flag

Automatically collected

Almost nothing. There is no usage analytics and no crash reporting in the app: nothing about how you use it is collected, transmitted, or stored.

What we never collect

How We Use Your Data

Your DataWhat We Do With ItWho Sees It
EmailSign-in, password reset, optional notificationsOnly you (never visible on the map)
Display nameShown on flags you report/verifyOther app users
Flag locationPlaced as a marker on the mapOther app users
Flag description + categoryShown on the map when people tap the markerOther app users
PhotosDisplayed in flag details (public-readable in Storage)Other app users
Usage dataFixing bugs, improving the app, understanding feature adoptionInternal team only

We do not:

Your Rights & Controls

Manage Your Account

Data Access & Portability

Privacy by Region

GDPR If you’re in the EU/EEA:

CCPA If you’re in California:

PIPEDA If you’re in Canada:

How We Store & Protect Your Data

Storage Location

Data Retention

Type of DataHow Long We Keep It
Account (email, display name, avatar)Until you delete your account
Flags you submitUntil resolved + 90 days (then archived)
Flag photosUntil the flag is deleted
Audit logs (for security)30 days

Third-Party Services

Supabase (Cloud Database & Storage)

We use Supabase to host our database and file storage. Supabase is contractually bound to protect your data under GDPR/CCPA. Supabase Privacy Policy (opens in new tab)

Expo / EAS (App Distribution)

We use Expo Application Services to build and distribute the app. Expo may receive your device type and app version during updates. Expo Privacy Policy (opens in new tab)

OpenStreetMap Nominatim (Address Search)

When you type into the address-search field, the text you type is sent to OpenStreetMap’s Nominatim service to look up the place. That search text is the only thing Nominatim receives — no account details, no device identifiers, and never your GPS location. OSM Foundation Privacy Policy (opens in new tab)

No Other Sharing

We do not share data with advertisers, analytics companies, or data brokers. We will not sell your data under any circumstance.

Photo Privacy Details

When you upload a photo:

  1. We re-process the image to strip all EXIF metadata (GPS coordinates, timestamps, camera model, lens info)
  2. On iOS/Android: we use the device’s native media library for re-processing
  3. On web: we use canvas to re-render, which naturally strips all metadata
  4. Photos are stored in Supabase Storage with public read access — anyone on the map can see them
  5. Only you can delete your photos

Children & Minors

Flagstone is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn that we’ve collected data from a child under 13, we’ll delete it immediately. If you believe a child under 13 has created an account, please contact us at support@skypistudio.com.

Changes to This Policy

If we make material changes, we will update the “Last updated” date, notify you via in-app message and email, and ask you to re-accept the new policy if required.

Contact & Data Requests

For data subject requests (GDPR / CCPA / PIPEDA), include one of the following in your email subject line: