Legal // Privacy
Privacy Policy
BUFFMAP is a privacy-first field register for street art. This policy describes what the production Android app and buffmap.app actually handle today.
The short version
The app can be browsed without an account. Creating an account uses a public handle, a password proof, and a recovery-key proof; it does not require your real name, email address, or phone number. Photos are rebuilt on your device before upload. Location is optional and defaults to a displaced neighborhood cell. BUFFMAP has no ads and does not use the Android Advertising ID.
The Android app does include Google Maps. Google states that its Maps SDK automatically collects device and request metadata, crash metrics, IP address, a Maps-specific pseudonymous identifier, and, depending on use, map interactions such as panning and zooming. Those SDK practices are disclosed below.
Who is responsible
BUFFMAP is offered under the Google Play developer name Lot Foundry. For privacy questions or requests, contact privacy@buffmap.app. General support is available at support@buffmap.app.
Data the Android app handles
Account and authentication
If you create an account, BUFFMAP stores a public handle, server-side protected proofs derived from your passphrase and recovery words, the calendar day the account was created, and a trust tier. The service does not receive or store your passphrase in readable form. The recovery words are shown to you once; the service stores only a protected proof used to verify recovery.
An authentication token and local app state are kept in device-protected storage. Android cloud backup is disabled for the app.
Photos and submitted records
When you choose or take a photo, BUFFMAP decodes and re-encodes it on your device before upload. This is intended to remove embedded EXIF, GPS, capture-time, thumbnail, and camera metadata. If you apply a face or plate blur, the blur is burned into the derivative before upload. BUFFMAP uploads the rebuilt JPEG derivative, its integrity hash, and the record details you provide. The original photo is not uploaded by BUFFMAP.
A submitted record can include a location cell and precision choice, attribution choice, optional artist handle, description or alt text, style and surface tags, legal-wall flag, publication delay, uploader account linkage, and calendar-day dates. Published records and sanitized photos are visible to other users according to the choices made during filing.
Location
Location permission is requested only while you use a location-dependent feature. BUFFMAP does not request background location. The default filing choice is a displaced neighborhood cell. You may instead choose a block-level cell, Unmapped, or Exact.
- Neighborhood or Block: the device derives a displaced cell and sends that cell, not the raw device coordinate.
- Unmapped: no location cell is submitted.
- Exact: this is an explicit high-risk choice intended only for authorized legal walls. It sends a high-precision location cell to the BUFFMAP register and displays the record as an exact pin.
Status reports can use an on-device proximity check. The service receives the resulting pass/fail value, not the device's raw coordinate.
Community and moderation activity
BUFFMAP stores status reports, artist claims, safety flags, and their calendar-day status so it can operate the register and respond to removal or safety concerns. Claims and flags currently do not store the reporting account identifier. The service does not create a chronological “places visited” index for an account.
Google Maps SDK data
The Android app uses Google Maps SDK for Android to render and interact with the map. According to Google's current SDK disclosure, Google automatically receives device metadata, Maps SDK build/version and request metadata, stack traces and crash metrics from SDK code, IP address, and a Maps SDK-specific pseudonymous identifier. Map interaction events such as panning and zooming may also be collected. Google says it uses this information to maintain and improve Google services. BUFFMAP does not use this information for advertising.
Website data
buffmap.app does not set advertising or analytics cookies and does not run third-party analytics. Page assets are served through Cloudflare. Network providers necessarily process request information such as IP address to deliver and secure the site. The website also requests public aggregate register counts from api.buffmap.app; the application database does not store the visitor's IP address or browser user agent.
If you select an email link, your email provider handles the message and BUFFMAP receives the address and content you choose to send. Do not include a recovery phrase, passphrase, or sensitive location in support email.
How data is used
- Provide account creation, sign-in, recovery, and account management.
- Render the map, feed, records, sanitized media, and status history.
- Process submissions, delayed publication, status reports, artist requests, and safety flags.
- Protect the service, verify integrity, limit abuse, and respond to support or legal obligations.
- For Google Maps SDK data, maintain and improve Google mapping services and SDK stability as described above.
BUFFMAP does not sell personal information, show ads, use the Android Advertising ID, or use submitted data to build advertising profiles.
Who receives data
Other users can see records and sanitized photos made public through the filing flow. A handle or artist attribution is shown only when that option is selected.
Cloudflare provides network delivery, serverless compute, database, rate-limiting storage, and media storage for BUFFMAP. It processes data on BUFFMAP's behalf to provide those services.
Google receives the Maps SDK data described above as the provider of the map component.
BUFFMAP may disclose data when legally required or to protect users and the service. We can only provide data that the service actually holds.
Security
App traffic to BUFFMAP and Google services uses encrypted HTTPS connections. Authentication proofs are protected before storage, originals are excluded from the media pipeline, operational request logging is disabled on the BUFFMAP API, and account secrets are stored in Android protected storage with cloud backup disabled. No service can guarantee absolute security.
Retention and deletion
Account and submitted data remain until you delete the account, remove content through an available product flow, or ask BUFFMAP to act on a verified request. Calendar-day moderation records may be retained as needed to resolve safety issues, prevent abuse, or meet legal obligations.
The in-app Delete account & data control permanently deletes the account, its authentication material, status reports linked to the account, records filed by the account, associated timelines, claims and flags tied to those records, and their uploaded media. This action cannot be undone.
You can also request deletion without reinstalling the app at buffmap.app/account-deletion.html or by emailing privacy@buffmap.app. BUFFMAP may ask for limited information needed to verify control of the pseudonymous account. Never email your passphrase or twelve recovery words.
Your choices
- Browse without creating an account.
- Deny camera, photo-library, or location permission and continue using features that do not need it.
- Choose Unmapped, Neighborhood, Block, or Exact for each filed record.
- Choose whether a filed record is unattributed or associated with an artist handle.
- Request access, correction, deletion, coarsening, unmapping, or removal by contacting the privacy address.
Age and region
BUFFMAP is intended for people age 18 and older and is not directed to children. The current operational pilot is in San Diego, California. Cloudflare and Google operate global infrastructure, so data may be processed in locations outside your state or country.
Changes
We will update this page and its “Last updated” date when data practices materially change. The current policy is always available at this URL.
Contact
Privacy and data requests: privacy@buffmap.app
Security reports: security@buffmap.app
General support: support@buffmap.app