Legal
Privacy Policy
Product: Wildlost (also styled WildLost)
Effective date: August 6, 2026
Operator: WildLost LLC (“Wildlost,” “we,” “us,” or “our”)
Contact: support@wildlost.com · 1919 14th Street, Suite 700, Boulder, CO 80302
This Privacy Policy explains how we collect, use, share, and retain information when you use Wildlost’s websites, web app, and iOS app (together, the “Service”), including app.wildlost.com and related wildlost.com domains.
We design Wildlost around a simple rule: your map data stays yours unless you choose to share it. We do not sell personal information, and we do not put precise location or track geometry into analytics.
1. Who this applies to
This policy applies to visitors and users of the Service, whether you browse signed out (“Local” mode) or create an account.
If you are under 13 (or the minimum age of digital consent where you live), do not use the Service or create an account. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact support@wildlost.com and we will delete it.
2. Information we collect
2.1 Account information
When you register, we collect:
- Email address
- Password (stored as a one-way hash; we never store your password in plain text)
- Email verification status and related tokens
- Account and subscription status (for example Free vs Pro)
Sign-in uses email and password only (no third-party social login today).
2.2 Map content you create or import
If you sign in and sync, we store the content you choose to keep in the cloud, which may include:
- Atlases (projects), folders, and settings
- Routes, tracks, waypoints, polygons, notes, and related metadata
- Photos and map-sheet files you upload
- Named layer stacks, custom layer sources, and revision history
- Collaboration settings (who can access an atlas, invite emails, share-link tokens)
Geometry and notes for synced objects are stored so the Service can sync across your devices. Precise coordinates in your tracks and routes are part of your content, not analytics.
In Local (signed-out) mode, map content stays on your device until you sign in and sync (or export it yourself).
2.3 Location
With your permission, the Service uses device location to:
- Show your position on the map
- Center the map / navigation
- Record a track while you are actively recording in the app
On iOS we request when-in-use location access. We do not currently request always-on / background location for continuous recording when the app is not in use.
Location used for locate/record stays on the device unless you save a track (or other object) and sync it to your account. We do not send precise coordinates to our product analytics.
2.4 Sign-in and security data
When you sign in or verify email, we may record:
- Approximate network location derived from Cloudflare (city, region, country)
- IP address
- Browser or device user-agent (and a short device label)
- Sign-in method and time
We keep a limited recent history (on the order of tens of events) so you can review recent sign-ins on your account page.
2.5 Device and local data
On your device we may store:
- Offline map packages and related files (typically in browser storage / OPFS)
- Local copies of your map library for sync
- Preferences (theme, units, layer choices, and similar)
- A random device identifier for analytics indexing and sync metadata
- Session tokens (including tokens stored for multi-account switching on the same browser)
Clearing site data, uninstalling the app, or removing offline packages deletes local copies on that device. Cloud copies remain until you delete them or delete your account (see §6).
2.6 Usage analytics (coarse)
We collect first-party product usage events (for example sign-in, import/export actions, feature usage counts) via our API into Cloudflare Workers Analytics Engine.
These events use coarse dimensions only (such as event name, platform web or ios, format or catalog id, counts). We intentionally do not include:
- Precise coordinates
- Track/route geometry (GPX/KML bodies)
- Search query text
- Email addresses
- Offline download bounding boxes
2.7 Error reports
If the app crashes or hits an unexpected error, we may receive a truncated error message, truncated stack trace, URL path (query values stripped), platform, and related diagnostics. We retain these samples for a limited period (on the order of 30 days) to fix bugs.
2.8 Payments
Pro subscriptions are processed by Stripe. Stripe receives payment card and billing details according to its own privacy policy. We store subscription and customer identifiers needed to provide entitlements and the customer portal—not your full card number.
2.9 Communications
We send transactional email (for example email verification) from addresses such as noreply@wildlost.com. We do not currently operate a marketing newsletter. If that changes, we will update this policy and provide choices where required.
2.10 Automatically collected technical data
Like most online services, our hosting provider (Cloudflare) processes standard request logs (IP address, user-agent, timestamps, URLs) to operate and secure the Service.
3. How we use information
We use information to:
- Provide, sync, and improve the Service
- Authenticate you and protect accounts
- Show recent sign-in activity
- Process Pro subscriptions and entitlements
- Respond to support requests
- Monitor reliability (errors and coarse product metrics)
- Comply with law and enforce our Terms
We do not sell your personal information. We do not use your tracks or precise location to build advertising profiles or sell location intelligence.
4. When we share information
We share information only as needed to run the Service:
| Recipient | Why |
|---|---|
| Cloudflare | Hosting (Pages, Workers), database (D1), object storage (R2), email sending, analytics engine, security |
| Stripe | Payment processing for Pro |
| Map / data providers | Tile and data requests you trigger (for example USGS, OpenStreetMap-derived data, weather and imagery providers). Those providers see normal network request metadata for the requests your client or our proxy makes. Server-side API keys for some paid layers stay on our servers. |
| People you invite or link-share with | If you share an atlas (invite or “anyone with the link”), recipients can see the content you chose to share |
| Professional advisors / authorities | If required by law, or to protect rights, safety, and security |
Wildlost has no public activity feed and no public discovery of other users’ tracks. Sharing is intentional (link or invite).
5. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict certain processing of your personal information, and to object to certain uses.
In the product today you can:
- View and edit your synced map content
- Review recent sign-ins
- Cancel Pro via the Stripe customer portal
- Export your data using the app’s export tools
- Schedule account deletion (password-confirmed), with a 30-day grace period you can cancel
- Revoke location permission in your browser or iOS Settings
- Use Local mode without creating an account
To exercise privacy rights, email support@wildlost.com. We may need to verify your request.
California / similar US state laws: We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are commonly defined. If that changes, we will update this policy and provide required opt-outs.
EEA/UK: Where GDPR applies, we process account and sync data to perform our contract with you; security and fraud prevention based on legitimate interests; and legal obligations where applicable. Contact support@wildlost.com for questions or complaints; you may also contact your local supervisory authority.
6. Retention
| Data | Typical retention |
|---|---|
| Account + synced library | Until you delete it or your account is purged |
| Account deletion | Scheduled purge after ~30 days (cancellable); then cloud account data, media, and related records are removed (Stripe cleanup is best-effort) |
| Device-only map data | Remains on your devices after cloud deletion unless you remove it locally |
| Sign-in history | Capped recent events |
| Product analytics | On the order of ~3 months (Cloudflare Analytics Engine) |
| Client error samples | On the order of ~30 days |
| Backups / logs | May persist for a limited additional period in infrastructure backups or security logs |
7. Security
We use industry-standard measures appropriate to a small cloud service (HTTPS, hashed passwords, HttpOnly session cookies, access controls on our API). No method of transmission or storage is 100% secure. Protect your password and device access.
8. International transfers
We use Cloudflare and Stripe infrastructure that may process data in the United States and other countries. If you use the Service from elsewhere, you understand your information may be processed in countries with different data-protection laws.
9. Third-party sites and layers
The Service may link to or display data from third-party map, weather, and imagery sources. Their practices are governed by their own policies. Attribution for map layers appears in the product where applicable.
10. Changes
We may update this Privacy Policy. We will post the updated version with a new effective date and, for material changes, provide additional notice when appropriate (for example in-app or by email).
11. Contact
Questions about privacy: support@wildlost.com
Mail: 1919 14th Street, Suite 700, Boulder, CO 80302
Operator: WildLost LLC