Legal

Privacy Policy

Product: Wildlost (also styled WildLost)
Effective date: October 2, 2026
Operator: WildLost LLC (“Wildlost,” “we,” “us,” or “our”)
Contact: support@wildlost.com · 1919 14th Street, Suite 700, Boulder, CO 80302

This Privacy Policy explains how we collect, use, share, and retain information when you use Wildlost’s websites, web app, and iOS app (together, the “Service”), including app.wildlost.com and related wildlost.com domains.

We do not sell your data for advertising purposes.


1. Who this applies to

This policy applies to visitors and users of the Service, whether you browse signed out (“Local” mode) or create an account.

If you are under 13 (or the minimum age of digital consent where you live), do not use the Service or create an account. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact support@wildlost.com and we will delete it.


2. Information we collect

2.1 Account information

When you register, we collect:

  • Email address
  • Password (stored as a one-way hash; we never store your password in plain text)
  • Email verification status and related tokens
  • Account and subscription status (for example Free vs Pro)

Sign-in uses email and password only (no third-party social login today).

2.2 Map content you create or import

If you sign in and sync, we store the content you choose to keep in the cloud, which may include:

  • Settings
  • Atlases, Routes, tracks, waypoints, polygons, notes, and related metadata
  • Photos and map-sheet files you upload
  • Named layer stacks, custom layer sources, and revision history
  • Collaboration settings (who can access an atlas, invite emails, share-link tokens)

Geometry and notes for synced objects are stored so the Service can sync across your devices.

In Local (signed-out) mode, map content stays on your device until you sign in and sync (or export it yourself).

2.3 Location

With your permission, the Service uses device location to:

  • Show your position on the map
  • Center the map / navigation
  • Record a track while you are actively recording in the app

On iOS, map locate uses when-in-use location access. When you start a track recording, the iOS app may request Always location access so GPS points can continue while the screen is locked or the app is in the background. Background location runs only during an active recording session and stops when you pause or end recording. We do not use Always location for advertising or to track you when you are not recording.

Location used for locate/record is not uploaded as a saved object unless you save a track (or other object) and sync it to your account. We may use location—including precise coordinates—and details from tracks you record or save to operate the Service and to improve it.

2.4 Sign-in and security data

When you sign in or verify email, we may record:

  • Approximate network location derived from Cloudflare (city, region, country)
  • IP address
  • Browser or device user-agent (and a short device label)
  • Sign-in method and time

We keep a limited recent history (on the order of tens of events) so you can review recent sign-ins on your account page.

2.5 Device and local data

On your device we may store:

  • Offline map packages and related files (typically in browser storage / OPFS)
  • Local copies of your map library for sync
  • Preferences (theme, units, layer choices, and similar)
  • A random device identifier for analytics indexing and sync metadata
  • Session tokens (including tokens stored for multi-account switching on the same browser)

Clearing site data, uninstalling the app, or removing offline packages deletes local copies on that device. Cloud copies remain until you delete them or delete your account (see §6).

2.6 Usage analytics

We collect first-party product usage events via our API into Cloudflare Workers Analytics Engine. Those events may include:

  • Feature usage (for example sign-in, import/export, layer changes, offline downloads)
  • Place / library search query text (truncated), result kind, result count, and duration
  • Coarse dimensions such as import format, layer catalog id, platform (web or ios), and counts
  • Performance and reliability signals (for example tile timing buckets)

We do not put precise GPS coordinates, track/route geometry, emails, or passwords in these analytics events. Location that appears in a saved track or other map object is stored as map content (§2.2 / §2.3), not as a separate analytics payload.

We use these events to understand how the Service is used and to improve it (including checking whether search returns useful results). We do not sell them for advertising. Analytics Engine retains samples on the order of months (see Cloudflare’s product limits).

If you choose Local Guest Mode and request guest access to cost-controlled map tiles, we send a Cloudflare Turnstile check so we can issue a short-lived tile credential. Cloudflare processes that check, including your IP address, under its own terms. We record the grant against the random device identifier above for usage and cost analytics. The check does not create an account, and it is not required to draw routes, tracks, or waypoints on this device.

2.7 Error reports

If the app crashes or hits an unexpected error, we may receive a truncated error message, truncated stack trace, URL path (query values stripped), platform, and related diagnostics. We keep these samples to diagnose and fix bugs.

2.8 Payments

Pro subscriptions on the web are processed by Stripe. Pro on the iOS app is processed by Apple via In-App Purchase. Stripe or Apple receives payment card and billing details according to its own privacy policy. We store subscription and customer/transaction identifiers needed to provide entitlements and billing management—not your full card number.

2.9 Communications

We send transactional email (for example email verification) from addresses such as noreply@wildlost.com. We do not currently operate a marketing newsletter. If that changes, we will update this policy and provide choices where required.

2.10 Automatically collected technical data

Like most online services, our hosting provider (Cloudflare) processes standard request logs (IP address, user-agent, timestamps, URLs) to operate and secure the Service.


3. How we use information

We use information to:

  • Provide, sync, and improve the Service
  • Authenticate you and protect accounts
  • Show recent sign-in activity
  • Process Pro subscriptions and entitlements
  • Respond to support requests
  • Monitor reliability and understand product usage so we can improve the Service
  • Comply with law and enforce our Terms

We do not sell your personal information for advertising purposes. We do not build advertising profiles from your tracks, location, or other data, and we do not sell that data to advertisers.


4. When we share information

We share information only as needed to run the Service:

Recipient Why
Cloudflare Hosting (Pages, Workers), database (D1), object storage (R2), email sending, analytics engine, Turnstile, security
Stripe Payment processing for Pro on the web
Apple In-App Purchase for Pro on iOS
Map / data providers Tile and data requests you trigger (for example USGS, OpenStreetMap-derived data, weather and imagery providers). Those providers see normal network request metadata for the requests your client or our proxy makes. Server-side API keys for some paid layers stay on our servers.
People you invite or link-share with If you share an atlas (invite or “anyone with the link”), recipients can see the content you chose to share
Professional advisors / authorities If required by law, or to protect rights, safety, and security

5. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict certain processing of your personal information, and to object to certain uses.

In the product today you can:

  • View and edit your synced map content
  • Review recent sign-ins
  • Cancel Pro via the Stripe customer portal (web) or App Store subscription settings (iOS)
  • Export your data using the app’s export tools
  • Schedule account deletion (password-confirmed), with a 30-day grace period you can cancel
  • Revoke location permission in your browser or iOS Settings
  • Use Local mode without creating an account

To exercise privacy rights, email support@wildlost.com. We may need to verify your request.

California / similar US state laws: We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are commonly defined. If that changes, we will update this policy and provide required opt-outs.

EEA/UK: Where GDPR applies, we process account and sync data to perform our contract with you; security and fraud prevention based on legitimate interests; and legal obligations where applicable. Contact support@wildlost.com for questions or complaints; you may also contact your local supervisory authority.


6. Retention

Data Typical retention
Account + synced library Until you delete it or your account is purged
Account deletion Scheduled purge after ~30 days (cancellable); then cloud account data, media, and related records are removed (Stripe cleanup is best-effort)
Device-only map data Remains on your devices after cloud deletion unless you remove it locally
Sign-in history Capped recent events
Product analytics While we use it to operate and improve the Service
Client error samples While we use it to diagnose and fix bugs
Backups / logs May persist for a limited additional period in infrastructure backups or security logs

7. Security

We use industry-standard measures appropriate to a small cloud service (HTTPS, hashed passwords, HttpOnly session cookies, access controls on our API). No method of transmission or storage is 100% secure. Protect your password and device access.


8. International transfers

We use Cloudflare and Stripe infrastructure that may process data in the United States and other countries. If you use the Service from elsewhere, you understand your information may be processed in countries with different data-protection laws.


9. Third-party sites and layers

The Service may link to or display data from third-party map, weather, and imagery sources. Their practices are governed by their own policies. Attribution for map layers appears in the product where applicable.


10. Changes

We may update this Privacy Policy. We will post the updated version with a new effective date and, for material changes, provide additional notice when appropriate (for example in-app or by email).


11. Contact

Questions about privacy: support@wildlost.com
Mail: 1919 14th Street, Suite 700, Boulder, CO 80302
Operator: WildLost LLC