← Back to My Map

Privacy notice

Last reviewed August 22, 2026.

My Map separates public saved-place information from private notes, collections, visits, home-relative commute data, and access capabilities. Private values are excluded from public map payloads, shared links, browser URLs, and the public cache.

Default production map

When its restricted runtime configuration is available, the production renderer defaults to Google Maps. Google’s JavaScript runs in this page; it is not isolated in a sandbox. The browser loads the script and map content from Google. Google may receive the browser IP address, user agent, referrer or origin, map ID, requested viewport and map interactions, cookies or similar data controlled by Google, and other request diagnostics. The application contract gives the renderer marker names, categories, stable app place IDs, coordinates, and derived marker meaning so it can draw the map. That contract reduces data; it is not a browser security boundary. Treat those values and coordinates as inside the Google renderer boundary.

MapLibre setting and fallback

MapLibre with OpenFreeMap remains available as an explicit setting and is used automatically when Google configuration or initialization is unavailable. OpenFreeMap basemap requests disclose requested tile coordinates and ordinary browser and network metadata to the tile provider. The app does not intentionally send private notes, collection names, visits, access capabilities, search text, or the private home origin to either map provider.

Raw visit records are excluded, but a derived visited marker state enters the active renderer. Raw private collection records are excluded, but applying a private collection or filter changes the subset of marker names and coordinates given to the renderer. An opened outing gives the renderer the named, ordered stop elements and stop coordinates. Private notes and their text, exact home origin and commute values, access capabilities, CSRF values, free-form search text, billing identifiers, and raw provider payloads are not intentionally supplied to the renderer.

Local evaluation timings contain only provider names, scenario labels, counts, durations, request totals, transfer totals, and browser-error totals. No public telemetry endpoint receives them.

Google processes data under the Google Privacy Policy. Google Maps Platform terms and regional requirements may also apply.

Storage and access

Public response summaries may be cached locally. Authorized private data may be held in browser memory during the active session, while private collections, visits, and notes are durably stored by the application’s private server-side database. A secure, HTTP-only session cookie authorizes access; it does not contain those private records. “Forget private access on this device” clears the browser’s authorized session and private preferences, but does not delete the durable server-side collections, visits, or notes.