Mapyx — Legal & Compliance Documents

Privacy PolicyTerms of ServiceData HandlingAI (Mapyx AI)GDPR / UK GDPRLGPDApple App PrivacyGoogle Play Data Safety
Operator (Individual Developer):
Douglas Pessoa
Country of Residence:
Ireland
Contact Email:
support@mapyx.app
Effective Date:
01/06/2026
Last Updated:
01/06/2026
Document Version:
1.0.0
Important. Mapyx is operated by an individual developer (Douglas Pessoa), not a company. References below to "we", "us", or "the developer" refer to that individual. The app includes a conversational AI feature (Mapyx AI) that transmits the user's prompt, the active session's prior turns, and minimal device context to a third-party large-language-model provider (OpenRouter, Inc.) for the sole purpose of generating an answer; this is described in detail in Section 1.13. This document covers all disclosures required by the Apple App Store, Google Play, the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Brazilian LGPD.

1.Privacy Policy

1.1 Who is the data controller

The data controller responsible for the processing of personal data within Mapyx is Douglas Pessoa, an individual developer based in Ireland. Contact: support@mapyx.app.

Because Mapyx is operated by a single individual and is not a company, no Data Protection Officer (DPO) is formally appointed. Where a DPO is required by law (for example, under LGPD Art. 41), the contact above acts as the privacy point of contact (Encarregado pelo Tratamento de Dados Pessoais).

1.2 Scope

This Privacy Policy applies to the Mapyx mobile application distributed on the Apple App Store and Google Play, and to the marketing website at https://mapyx.app. It also covers the developer's backend at https://api.mapyx.app, which receives chat requests for the Mapyx AI feature and proxies image queries. It does not apply to third-party services that the user may access through the app (see Third Parties).

1.3 Categories of data processed

CategoryDataSourceRetention
Approximate locationCoarse device location used once at startup to suggest a country; reverse-geocoded on-device to a country name onlyOperating system (with user permission via expo-location)Not stored; held in memory for the duration of the session and never transmitted to the developer's backend
App usage stateList of country IDs the user has explored or saved, daily streak counter, recently explored listUser actions inside the appStored locally on the device (AsyncStorage under @mapyx/* keys) until the user clears data or uninstalls
PreferencesTheme (light/dark), language preference, optional user display nameUser selectionStored locally (SecureStore for theme, AsyncStorage for the rest) until the user clears data or uninstalls
Mapyx AI promptsThe text the user types into the Mapyx AI chat, plus optional prior turns of the active sessionUser inputTransmitted to the developer's backend at https://api.mapyx.app and onward to OpenRouter, Inc. (tencent/hy3-preview). Today: not persisted server-side. Once planned conversation storage is enabled (see Section 1.14): retained for up to 90 days against the anonymous session ID, then automatically purged
Mapyx AI responsesThe model's textual replyOpenRouter, Inc. (tencent/hy3-preview)Same as Mapyx AI prompts above
Device context sent with chatTimezone, locale (BCP-47), theme, count and short list of saved-country IDs, optional user display nameDevice and user selectionTransmitted with each chat request to personalise the answer; retained server-side only under the planned conversation-storage feature (Section 1.14)
AI-inferred preferencesPreferences such as preferred language, preferred unit system, timezone, tone preference and display name, inferred from the user's prompts with a model-reported confidence of at least 0.7Derived from prompts by OpenRouter, Inc.Stored locally on the device (AsyncStorage key @mapyx/ai_prefs_v1) until the user clears data or uninstalls
Anonymous session IDOpaque string issued by the developer's backend on first chat request; not linked to any account, email or device identifierDeveloper's backendStored locally (AsyncStorage key @mapyx/chat_last_session_v1). Once planned storage is enabled, also stored server-side for the conversation retention period (Section 1.14)
Country name for image searchThe displayed country's name as a URL query parameterUser navigation inside the appSent to the developer's image-proxy host at mapyx.app (Vercel, Inc.); the proxy queries Unsplash and returns image URLs
Search queriesFree-text place searches typed by the user (where applicable)User inputSent to the OpenStreetMap Nominatim service; not stored by Mapyx
Network metadataIP address and standard request headers when contacting backend, map, image, or AI endpointsHTTPS requests sent from the deviceHeld by the relevant third-party service per its own policy. The developer's backend retains abuse-prevention logs for no more than 90 days; Mapyx does not retain network metadata against user identities
Diagnostic data (optional, currently not in use)Crash reports and basic performance metrics — only if a diagnostic provider is later added and the user opts inDevice, with user consentPer the diagnostic provider's retention policy. Mapyx currently uses no crash reporter (None — not in use)

Mapyx does not require an account, does not collect names, email addresses, phone numbers, payment data, contacts, photos, microphone audio, health data, biometric data, or any advertising identifier (IDFA/GAID), and does not sell personal data. The user-provided display name (an optional nickname used by Mapyx AI) is treated as personal data and is included in the user's rights of access, erasure and portability.

1.4 Purposes and legal bases

PurposeGDPR / UK GDPR Legal BasisLGPD Legal Basis
Provide the core functionality of the app (display country information, maps, images)Art. 6(1)(b) — performance of a contract with the userArt. 7, V — execution of a contract
Detect approximate location to suggest a countryArt. 6(1)(a) — consent (OS permission prompt)Art. 7, I — consent
Store explored/saved countries and preferences locally on the deviceArt. 6(1)(b) — necessary for the requested featureArt. 7, V — execution of contract
Process Mapyx AI prompts through OpenRouter, Inc. (tencent/hy3-preview) to generate a responseArt. 6(1)(b) — performance of a contract requested by the user (the user submitted the prompt to obtain an answer)Art. 7, V — execution of a contract
Send device context (timezone, locale, theme, saved-country IDs, display name) with chat requests so that responses are personalised and locale-awareArt. 6(1)(b) — performance of a contract; Art. 6(1)(f) — legitimate interest in producing relevant answersArt. 7, V — execution of contract; Art. 7, IX — legitimate interest
Store conversations server-side to cache prior turns and reduce response latency (planned — see Section 1.14)Art. 6(1)(f) — legitimate interest in providing a faster, more reliable service, balanced against the use of an anonymous session identifier and the 90-day retention capArt. 7, IX — legitimate interest
Operate abuse-prevention and rate-limiting on the backendArt. 6(1)(f) — legitimate interest in protecting the service from abuseArt. 7, IX — legitimate interest
Comply with the contractual obligations imposed by OpenRouter, Inc. on its API consumersArt. 6(1)(c) — legal obligation; Art. 6(1)(f) — legitimate interestArt. 7, II — legal obligation; Art. 7, IX — legitimate interest
Diagnose crashes and improve stability (only if a diagnostic provider is later added and the user opts in)Art. 6(1)(a) — consentArt. 7, I — consent
Comply with legal obligations and respond to user rights requestsArt. 6(1)(c) — legal obligationArt. 7, II — legal obligation

1.5 Third-party services and data sharing

Mapyx sends limited data to the following processors strictly to render the app and to operate the Mapyx AI feature:

  • OpenRouter, Inc. (registered at https://openrouter.ai) — receives the user's chat prompt, the prior turns of the active session, the device context (timezone, locale, theme, saved-country summary and optional display name) and the anonymous session ID. OpenRouter, Inc. routes the request to the selected large-language model (currently tencent/hy3-preview; see https://openrouter.ai/tencent/hy3-preview) and may further sub-process the request through the underlying model host. OpenRouter, Inc.'s privacy policy is available at https://openrouter.ai/privacy.
  • Vercel, Inc. — hosts the developer's image proxy at mapyx.app. Receives the country-name query and standard HTTPS request metadata (IP address, user agent, timestamp). Privacy policy: vercel.com/legal/privacy-policy.
  • OpenStreetMap Foundation (Nominatim) — receives the user's free-text search query (where applicable) and the device IP address to return geographic results. Privacy policy: osmfoundation.org/wiki/Privacy_Policy.
  • CARTO (CartoDB basemaps) — receives standard tile requests including the device IP. Privacy policy: carto.com/privacy.
  • Unsplash (via the developer's image proxy) — country names are sent to a server-side proxy (GET /api/images) which queries Unsplash and returns image URLs. The Unsplash API key is held server-side. Unsplash privacy policy: unsplash.com/privacy.
  • GitHub (raw GeoJSON) — public country boundary files are fetched over HTTPS; standard request metadata applies. Privacy policy: docs.github.com.
  • Apple and Google — distribute the app and may collect their own diagnostic data per their store policies.

Mapyx does not share personal data with advertising networks or data brokers, and does not engage in any cross-context behavioural advertising. The developer is not a controller of any social or analytics graph built outside the app.

1.6 International transfers

Some of the third parties listed above are located outside the European Economic Area, the United Kingdom and Brazil. In particular, OpenRouter, Inc. is incorporated in United States (Delaware), and large-language-model inference may take place on infrastructure located in the United States or in other jurisdictions chosen by OpenRouter, Inc.. Vercel, Inc. is incorporated in the United States. Where personal data is transferred internationally, the developer relies on (i) the European Commission's Standard Contractual Clauses (Decision 2021/914) where the processor offers them, (ii) the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, (iii) adequacy decisions where applicable, or (iv) the user's explicit consent for a specific feature — in compliance with GDPR Chapter V, the UK GDPR transfer rules and LGPD Art. 33.

1.7 Retention

Retention periods are set by category and by storage location

1.8 User rights

Subject to applicable law, the user may exercise the following rights free of charge:

  • Right of access — request a copy of personal data processed.
  • Right of rectification — correct inaccurate data.
  • Right of erasure ("right to be forgotten") — delete personal data, including via the in-app "Delete All Data" button. Once planned conversation storage (Section 1.14) is enabled, this action also triggers a server-side purge of the linked session.
  • Right of portability — receive a copy of locally stored data in a structured, commonly used, machine-readable format (JSON), available via the in-app "Export My Data" function. Where conversations are stored server-side under Section 1.14, an export of those conversations may also be requested by email.
  • Right to restriction and right to object to processing — including, where Section 1.4 relies on legitimate interest, the right to object to that processing on grounds relating to the user's particular situation.
  • Right to withdraw consent at any time, without affecting the lawfulness of prior processing. For Mapyx AI, this is exercised by ceasing to use the feature.
  • Right not to be subject to a decision based solely on automated processing — see Section 5.
  • Right to information about shared use (LGPD Art. 18, VII) — disclosed in Sections 1.5 and 3.6 of this document.
  • Right to lodge a complaint with a supervisory authority — in the EU, the local Data Protection Authority; in the UK, the Information Commissioner's Office (ico.org.uk); in Brazil, the ANPD (gov.br/anpd).

To exercise any of these rights, contact support@mapyx.app. Responses are provided within 30 days (GDPR / UK GDPR) or 15 days (LGPD). Because Mapyx processes no account-level identifier, the user may be asked to confirm the anonymous session ID stored under @mapyx/chat_last_session_v1 in order to identify any server-side records associated with the request.

1.9 Children

Mapyx is rated suitable for ages 4+ and does not knowingly collect personal data from children under 13 (or under 16 in jurisdictions that apply that threshold). The app does not include account creation, social features, or behavioural advertising. Mapyx AI is provided as a general-knowledge geography assistant; the developer does not direct it at children, does not enable any audience-targeted advertising of any kind, and instructs OpenRouter, Inc. to apply its standard safety filters. If the developer becomes aware that personal data from a child has been collected without verifiable parental consent, that data will be deleted promptly.

1.10 Security

All network communication uses HTTPS / TLS 1.2 or higher. Sensitive preferences are stored using expo-secure-store, which uses the iOS Keychain and the Android Keystore. The Unsplash and OpenRouter, Inc. API keys are not embedded in the client; they are held server-side at https://api.mapyx.app. Once planned conversation storage (Section 1.14) is enabled, stored conversations will be encrypted at rest using the backend's standard disk-level encryption, with access restricted to the developer. The developer takes reasonable technical and organisational measures to protect personal data, but no system is perfectly secure. Independent security review status: No independent security audit has been conducted. The developer implements industry-standard security practices including HTTPS/TLS encryption and secure storage mechanisms.

1.11 EU and UK representatives

Under GDPR Art. 27(1), the obligation to appoint an EU representative only applies where the controller is not established in the European Union. Mapyx is operated from Ireland, a Member State of the European Union, so this obligation does not apply.

  • EU representative — not required: the controller is established in Ireland (European Union).
  • UK representative — none currently appointed. While Mapyx remains a small-scale informational app, the developer relies on the exemption in UK GDPR Art. 27(2)(a) for occasional processing that does not include, on a large scale, special categories of personal data or personal data relating to criminal convictions and offences.

If the scope or scale of processing changes such that the above no longer applies, this Section will be updated and a representative will be appointed before Mapyx continues to be offered to users in the relevant jurisdiction.

1.12 Updates to this policy

Material changes — including activation of planned conversation storage (Section 1.14) or the introduction of advertising (Section 1.15) — will be announced through the app, the website, and the relevant store listing at least 14 days before they take effect. The "Last Updated" date at the top of this document always reflects the current version.

1.13 Mapyx AI processing (OpenRouter)

Mapyx includes a conversational AI feature called Mapyx AI that answers free-text questions about countries, geography, languages, economies, customs and similar subject matter. The AI inference is not performed on the device. Instead, when the user submits a prompt, the Mapyx mobile app transmits the request over HTTPS to the developer's backend at https://api.mapyx.app, which forwards the request to OpenRouter, Inc. — a US-incorporated large-language-model aggregator — for inference on the model currently configured (tencent/hy3-preview; see https://openrouter.ai/tencent/hy3-preview). The selected model may be changed in the future; any change will be reflected in this document on or before the change becoming live.

  • The prompt text typed into the chat input.
  • The prior turns of the active session, where the user has not cleared the thread.
  • Device context fields: timezone, locale (BCP-47), theme, the count and a short list of the user's saved-country IDs, and the optional user display name. These are sent so that the answer can be locale-aware and suitably personalised.
  • The anonymous session ID issued by the developer's backend, used to associate requests of the same conversation with one another and, once Section 1.14 is in force, with stored conversation records.

The following is not transmitted by the Mapyx app to OpenRouter, Inc.:

  • The user's device location (latitude, longitude, address). Location data is processed entirely on the device; only the resulting country name may be used as in-app context.
  • Contacts, calendar entries, photos, microphone audio, video, files, browsing history, health or biometric data — none of these are accessed by the app.
  • Any account or email identifier — there is no account.
  • Any advertising identifier (IDFA on iOS, GAID on Android) — these are not collected.

Mapyx AI's responses are generated probabilistically by a large-language model. They may be incomplete, out of date, or factually incorrect, and must not be relied upon for legal, financial, medical, immigration, travel-safety or any other consequential decision (see also Section 2.8). No automated decision producing legal or similarly significant effects on the user is taken by Mapyx or OpenRouter, Inc. on behalf of Mapyx; Mapyx AI generates content, it does not decide about the user. The user may refrain from using Mapyx AI at any time without affecting the rest of the app. The user's interaction with Mapyx AI is governed by OpenRouter, Inc.'s privacy policy (https://openrouter.ai/privacy) in addition to this document.

1.14 Planned conversation storage

Status: not yet enabled. The processing described in this section is a planned feature and is not yet active. When it becomes active, this Section will be updated, the "Last Updated" date will be bumped, and the change will be announced under Section 1.12 at least 14 days before the feature goes live.

The developer intends to introduce server-side storage of Mapyx AI conversations on the backend at https://api.mapyx.app for the sole purpose of caching prior turns so that repeated or follow-up questions can be answered more quickly and at lower cost. The processing will be operated as follows:

  • Identifier. Conversations are stored against the anonymous session ID already issued by the backend (Mapyx uses no email, account, device or advertising identifier).
  • What is stored. The prompts submitted by the user, the responses returned by OpenRouter, Inc., the device context fields described in Section 1.13, the model identifier in effect at the time, and timestamps.
  • Retention. Conversation records are retained for up to 90 days on a rolling basis from the date of each individual message, then automatically purged. Sessions inactive beyond the retention window are removed by an automated sweep.
  • User control. The in-app "Delete All Data" action invalidates the local session ID and, when network connectivity is available, calls the backend to purge the linked server-side conversation records. Uninstalling the app removes the session ID from the device, after which the orphan server record is removed by the next retention sweep.
  • Security. Stored conversations are protected in transit by HTTPS / TLS 1.2 or higher, are encrypted at rest using the backend's standard disk-level encryption, and are accessible only to the developer for the limited purposes of operating the cache, responding to user rights requests, and complying with law.
  • No secondary use. Stored conversations are not used to train any model, are not sold or made available to third parties (other than the inference call to OpenRouter, Inc. described in Section 1.13), and are not used for advertising.

The legal basis for this processing under the GDPR and the UK GDPR is Art. 6(1)(f) — the developer's legitimate interest in providing a faster and more reliable conversational service — balanced against the use of an anonymous identifier and the short retention window. The legal basis under the LGPD is Art. 7, IX — legitimate interest. A user who does not wish their conversations to be stored may abstain from Mapyx AI, or trigger the in-app deletion described above.

1.15 Advertising (reserved for future use)

Status: not currently used. Mapyx currently contains no advertising and integrates no advertising SDK; the App Tracking Transparency prompt (Apple) is therefore not presented and the Google Play Data Safety "data used for tracking" answers in Section 7 are "No".

  • If advertising is introduced in the future, the names of the relevant advertising providers, the categories of data processed by them, and the legal basis for that processing will be disclosed in this Section before any advertising SDK is shipped.
  • On iOS, where the relevant SDK requires it, the App Tracking Transparency prompt will be presented and tracking-related data will only be collected with the user's permission.
  • On Android, the Google Play Data Safety form will be updated to reflect any new collection and sharing of advertising data, and where required user consent will be obtained.
  • Behaviourally targeted advertising will not be served to children under 13 (or under 16 in jurisdictions that apply that threshold), to anyone below the local age of digital consent, or within any context designated as a children's experience.

Until this Section is updated to describe an active advertising programme, Mapyx does not allow advertising, profiling for advertising purposes, or onward sharing of personal data with advertising networks.

2.Terms of Service

2.1 Acceptance

By downloading, installing, or using Mapyx, the user agrees to these Terms of Service and to the Privacy Policy above. If the user does not agree, the app must not be used.

2.2 The service

Mapyx is free-to-use country exploration app providing maps, statistics, and informational content about countries. The service is provided "as is" and "as available", without warranties of any kind, except where such warranties cannot be excluded by mandatory consumer protection law.

2.3 License

The developer grants the user a personal, non-exclusive, non-transferable, revocable licence to install and use Mapyx on devices owned or controlled by the user, solely for personal, non-commercial purposes and in accordance with the Apple Media Services Terms and the Google Play Terms of Service.

2.4 Acceptable use

The user agrees not to:

  • Reverse engineer, decompile, or attempt to extract the source code, except as permitted by law.
  • Use the app to violate any applicable law or third-party right.
  • Bypass rate limits, abuse the developer's backend (https://api.mapyx.app), or interfere with the service's normal operation.
  • Distribute malware or use the app as a vector for any malicious activity.

2.5 Intellectual property

The app, its source code, design, and original content are the intellectual property of Douglas Pessoa. Country statistics are derived from public sources. Map tiles are provided by CARTO and OpenStreetMap contributors under their respective licences. Country images are provided by Unsplash photographers under the Unsplash License.

2.6 Third-party content

Some content is supplied by third parties (OpenStreetMap, CARTO, Unsplash). The developer is not responsible for the accuracy, legality, or availability of third-party content.

2.7 In-app purchases, payments and advertising

Mapyx is currently free of charge, contains no in-app purchases or subscriptions and, as confirmed in Section 1.15 of the Privacy Policy, contains no advertising and integrates no advertising SDK. If paid features are introduced in the future, billing will be handled exclusively by Apple or Google through their standard in-app purchase systems, and updated terms (including refund policies) will be presented before purchase, in accordance with Apple Guideline 3.1 and Google Play Payments policy. If advertising is introduced in the future, it will be disclosed in accordance with Section 1.15 of the Privacy Policy and the Apple App Store / Google Play store policies, including, where applicable, the App Tracking Transparency prompt on iOS and a refreshed Google Play Data Safety form on Android.

2.8 Disclaimer

Country information presented in the app is for informational purposes only and may contain inaccuracies. It must not be relied upon for legal, financial, immigration, travel, or safety decisions. The developer disclaims liability for decisions made based on the content of the app, to the maximum extent permitted by law.

2.9 Limitation of liability

To the maximum extent permitted by applicable law, the developer's total liability arising out of or related to the app shall not exceed the amount the user has paid for the app in the twelve (12) months preceding the event giving rise to liability, or fifty euros (€50), whichever is greater. Nothing in these Terms limits liability for fraud, gross negligence, death or personal injury caused by negligence, or any liability that cannot be excluded under applicable consumer law.

2.10 Termination

The user may stop using the app at any time and uninstall it. The developer may suspend or terminate access if these Terms are violated, or to comply with law.

2.11 Governing law and jurisdiction

These Terms are governed by the laws of Ireland, without regard to its conflict-of-laws rules. Any dispute arising from these Terms shall be brought before the competent courts of Ireland, except where mandatory consumer protection law grants the user the right to bring proceedings in the user's country of residence.

2.12 EU consumer dispute resolution

Consumers resident in the European Union may use the European Commission's Online Dispute Resolution platform: ec.europa.eu/consumers/odr. The developer is not currently obliged to participate in arbitration before a consumer arbitration board.

3.Data Handling & Storage Policy

3.1 Storage architecture

  • AsyncStorage (on-device, plaintext sandbox): non-sensitive app state — explored country IDs (@mapyx/explored_ids), recently explored (@mapyx/recently_explored), saved country IDs (@mapyx/saved_v2), the local chat thread cache (@mapyx/chat_thread_v1, up to the most recent 200 messages), the anonymous session ID (@mapyx/chat_last_session_v1), the AI-inferred preferences (@mapyx/ai_prefs_v1), the optional user display name (@mapyx/user_profile_v1), the language preference (@mapyx/locale_pref), the streak counter (@mapyx/streak_data), the onboarding completion flag (@mapyx/onboarding_v1), and cached translations (translation_cache_*).
  • SecureStore (on-device, OS-encrypted): theme preference (mapyx_theme_pref); reserved for future authentication tokens.
  • In-memory only: approximate device location returned by the OS; never persisted and never sent to the developer's backend.
  • Server-side (developer's backend at https://api.mapyx.app): the OpenRouter, Inc. and Unsplash API keys; a stateless image-proxy passthrough that does not store query parameters; the Mapyx AI chat passthrough (today: ephemeral — request and response are streamed to the user and not persisted; planned: persisted under Section 1.14 for up to 90 days against the anonymous session ID, encrypted at rest); and abuse-prevention logs retained for no more than 90 days, then automatically purged.

3.2 Encryption

Data in transit is protected by HTTPS / TLS 1.2 or higher. Data at rest in SecureStore is protected by the platform-provided Keychain (iOS) or Keystore (Android). AsyncStorage data is protected by the OS's standard sandboxing; it is not additionally encrypted because it does not contain account credentials or other sensitive personal data. Where planned conversation storage (Section 1.14) is enabled, server-side records are encrypted at rest using the backend's standard disk-level encryption.

3.3 Deletion

The user may delete all locally stored data at any time from Settings → "Delete All Data". This action clears all keys under @mapyx/* in AsyncStorage and the corresponding SecureStore keys, and is irreversible on the device. Once planned conversation storage (Section 1.14) is enabled, this action additionally calls the developer's backend to purge the server-side conversation records linked to the anonymous session ID; if the device is offline at the time of deletion, the orphan record is removed by the next automated retention sweep.

3.4 Export

From Settings → "Export My Data", the user may export all locally stored data as a JSON file via the standard share sheet, satisfying GDPR Art. 20 and LGPD Art. 18, V. Where planned conversation storage (Section 1.14) is enabled, a copy of the user's server-side conversation records may also be requested by email at support@mapyx.app, providing the anonymous session ID stored locally as proof of association.

3.5 Backups

Locally stored data may be included in OS-level backups (iCloud Backup, Google Drive backup) at the user's discretion and per the OS settings. The developer has no access to those backups.

3.6 Sub-processors register

The following sub-processors may process personal data on behalf of the developer in order to operate Mapyx. Where any of these is added, removed or materially changed, this Section and Section 1.5 will be updated.

  • OpenRouter, Inc. — large-language-model inference for Mapyx AI (https://openrouter.ai).
  • Vercel, Inc. — image-proxy hosting at mapyx.app (vercel.com).
  • OpenStreetMap Foundation — Nominatim geocoding (osmfoundation.org).
  • CARTO — basemap tiles (carto.com).
  • Unsplash — country imagery via the developer's image proxy (unsplash.com).
  • GitHub, Inc. — static hosting of public country boundary data (github.com).
  • Apple Inc. and Google LLC — app distribution, push notifications and platform diagnostics per their store policies.

4.Tracking & Analytics Disclosure

Mapyx does not use the Apple Identifier for Advertisers (IDFA), the Google Advertising ID (GAID), the Apple App_TransactionID, fingerprinting, SDK-based behavioural analytics, advertising SDKs, or any cross-app or cross-website tracking. As a result, the App Tracking Transparency prompt (Apple) is not presented and the Google Play Data Safety "data used for tracking" answers are "No". The anonymous session ID used by Mapyx AI (see Sections 1.3, 1.13 and 1.14) is internal to Mapyx and is not used to track the user across any other app, service or website; it qualifies as user-content infrastructure, not as a tracking identifier under Apple's or Google's definitions.

If diagnostic crash reporting is added in the future (for example, Firebase Crashlytics or Sentry), or if advertising is later introduced under Section 1.15, the change will be:

  1. Disclosed in this document before deployment, with at least 14 days' prior notice for material changes (see Section 1.12).
  2. Off by default and, where consent is the legal basis, enabled only with the user's explicit consent.
  3. For diagnostics: configured to scrub IP addresses and personally identifiable strings, and to operate only with explicit user opt-in.
  4. For advertising: subject to the App Tracking Transparency prompt on iOS where required, and reflected in a refreshed Google Play Data Safety form on Android.
  5. Reflected in the Apple Privacy Nutrition Label and Google Play Data Safety form.

5.GDPR / UK GDPR / LGPD Rights

This section is provided to satisfy GDPR Articles 13 and 14, the equivalent UK GDPR provisions, and LGPD Art. 9 and Art. 18.

RightHow to exercise
Access (GDPR Art. 15 / LGPD Art. 18, II)Use "Export My Data" in Settings for on-device data; email support@mapyx.app">support@mapyx.app for any server-side conversation records that may exist under Section 1.14.
Rectification (GDPR Art. 16 / LGPD Art. 18, III)Email support@mapyx.app">support@mapyx.app.
Erasure (GDPR Art. 17 / LGPD Art. 18, VI)Use "Delete All Data" in Settings (clears on-device data and, once Section 1.14 is in force, the linked server-side records), or email support@mapyx.app">support@mapyx.app.
Restriction (GDPR Art. 18 / LGPD Art. 18, IV)Email support@mapyx.app">support@mapyx.app.
Portability (GDPR Art. 20 / LGPD Art. 18, V)Use "Export My Data" in Settings; email for stored conversations once Section 1.14 is in force.
Object (GDPR Art. 21 / LGPD Art. 18, § 2º)Email support@mapyx.app">support@mapyx.app.
Withdraw consent (GDPR Art. 7 / LGPD Art. 8, § 5º)Toggle off in Settings; revoke OS permissions for location and notifications; cease using Mapyx AI.
Information about sharing (LGPD Art. 18, VII)See Section 1.5 and Section 3.6 of this document.
Lodge complaintContact your national supervisory authority. EU: your local Data Protection Authority. UK: ico.org.uk. Brazil: gov.br/anpd.

No decision producing legal or similarly significant effects on the user is taken on a solely automated basis. Mapyx performs no profiling. Mapyx AI generates content in response to the user's prompt; it does not decide about the user (see Section 1.13).

6.Apple App Store Compliance

This section discloses information required by Apple's Privacy and App Review guidelines, including App Privacy Details (Nutrition Label), Guideline 5.1.1 (Data Collection and Storage), and Guideline 5.1.1(v) (Account Deletion).

6.1 Privacy Nutrition Label (App Privacy Details)

Data CategoryTypeLinked to user?Used for tracking?Purpose
LocationCoarse LocationNoNoApp Functionality (suggest a starting country; reverse-geocoded on the device)
User ContentOther User Content (Mapyx AI prompts and responses)NoNoApp Functionality; Other Purposes (caching prior turns once Section 1.14 is enabled, to speed up replies)
IdentifiersNone collected (no account ID, no device ID, no IDFA, no advertising ID; an anonymous session ID is used internally and is not linked to any user identity)NoNoApp Functionality
Usage DataOther Usage Data (count of explored countries; device context fields sent with Mapyx AI requests — timezone, locale, theme, saved-country IDs, optional display name)NoNoApp Functionality
DiagnosticsCrash Data, Performance Data (only if user opts in to a future diagnostic provider; currently none in use)NoNoApp Functionality
Contact Info, Health, Financial, Browsing History, Search History, Photos, Audio, Contacts, Sensitive Info, Other Financial InfoNone

The "Data Used to Track You" section is empty. The "Data Linked to You" section is empty (no account; no user-identity-linked identifier). The "Data Not Linked to You" section contains Coarse Location, Other User Content (Mapyx AI prompts and responses), Other Usage Data (device context fields sent with Mapyx AI requests), and Diagnostics (only if enabled in the future).

6.2 Account deletion (Guideline 5.1.1(v))

Mapyx does not require account creation. The "Delete All Data" feature in Settings removes all locally stored personal data and satisfies Apple's account-deletion requirement for apps that store user-generated state on the device. Once planned conversation storage (Section 1.14) is enabled, this same feature additionally triggers a server-side purge of the conversation records linked to the user's anonymous session ID, satisfying the account-deletion expectation for off-device user content.

6.3 Sign in with Apple

Not applicable: Mapyx does not implement third-party login.

6.4 EU Digital Services Act — Trader status

Under the EU Digital Services Act, the developer is registered as a trader. Verified contact details are filed with App Store Connect and are also reproduced here for transparency:

6.5 Children's category

The app is not submitted to the Kids category; it does not contain advertising, third-party analytics, or external links targeted at children.

7.Google Play Data Safety

This section mirrors the Data Safety form in Google Play Console.

7.1 Data collection & sharing

Data typeCollected?Shared?Optional?Purpose
Approximate locationYes (in-memory only on the device, never transmitted to the developer's servers)NoYes (OS permission)App functionality
App activity (in-app actions: country selections, streak, recently explored)Stored on-device onlyNoNoApp functionality
App preferences (theme, language, AI-inferred preferences, optional display name)Stored on-device onlyNoNoApp functionality / personalisation
Messages — Other in-app messages (Mapyx AI prompts and responses)Yes — sent to the developer's backend at https://api.mapyx.app, then to OpenRouter, Inc. (tencent/hy3-preview) for inferenceYes — shared with OpenRouter, Inc. for the sole purpose of generating the AI responseYes (the user may simply not use Mapyx AI)App functionality. Currently not retained server-side; once retained under Section 1.14, retained for up to 90 days against an anonymous session ID
Other info — Device context sent with Mapyx AI requests (timezone, locale, theme, saved-country IDs, optional display name, anonymous session ID)YesYes — shared with OpenRouter, Inc. as part of the chat requestYes (avoid Mapyx AI)App functionality (personalising the AI response)
Diagnostics (crash logs)Only if opted in to a future diagnostic provider (none currently in use — None — not in use)Sent to the chosen provider if enabledYesApp functionality / analytics
Personal info, financial info, contacts, photos, audio, files, calendar, health, fitness, web browsing, device or other IDs, advertising IDsNoNo

7.2 Security practices

  • Data encrypted in transit: Yes (HTTPS / TLS 1.2 or higher).
  • Data encrypted at rest: Yes on the device via Keychain / Keystore for SecureStore items, and on the backend via standard disk-level encryption for any data persisted under Section 1.14.
  • Data deletion mechanism: Yes (in-app "Delete All Data"; once Section 1.14 is in force, this also purges the linked server-side conversation records).
  • Independent security review: No independent security audit has been conducted. The developer implements industry-standard security practices including HTTPS/TLS encryption and secure storage mechanisms.
  • Data is not used for tracking purposes as defined by Google Play.
  • Family-friendly: app does not target children, does not contain advertising, and does not include content unsuitable for general audiences.

7.3 Account deletion (Google Play policy)

No account is created. The on-device "Delete All Data" function is disclosed on the store listing as required by the Google Play Account Deletion policy. Once planned conversation storage (Section 1.14) is enabled, the same in-app action also purges the user's server-side conversation records, satisfying the Google Play account-deletion expectation for off-device user content. Where the user is unable to use the in-app action, deletion may also be requested by email at support@mapyx.app.

8.Contact & Requests

For privacy requests, legal notices, security disclosures, or general support, contact:

Brazilian users may also contact the privacy point of contact (Encarregado pelo Tratamento de Dados Pessoais) at the same email address. EU and UK users may contact the developer directly at support@mapyx.app; the current position on EU and UK representatives is set out in Section 1.11. Where the request concerns server-side conversation records under Section 1.14, please include the anonymous session ID stored locally on the device under @mapyx/chat_last_session_v1 so the request can be matched.

9.Changes to These Documents

Whenever the app's data handling, third-party services, or store disclosures change in a material way, this document is updated and the "Last Updated" field at the top is bumped. A summary of changes is kept in compliance_audit_protocol.md in the project repository. Continued use of the app after a material change constitutes acceptance of the updated documents.

© 2026 Douglas Pessoa. All rights reserved. Mapyx is an independent project; it is not affiliated with Apple Inc., Google LLC, OpenStreetMap, CARTO, or Unsplash.

Document version: 1.0.0 · Effective: 01/06/2026 · Last updated: 01/06/2026.

← Back to Mapyx