Privacy Policy
Last Updated: September 22, 2026
The short version
- We use the photos you upload to estimate where they were taken. Before a photo leaves our servers we shrink it if it is large and remove its embedded metadata (including GPS coordinates). We then send it to AI providers that analyse it for us: PPQ (ppq.ai), which passes the photo to the vision model that reads it; TypeSafe, which receives text about the photo but never the photo itself, and picks between the candidate places; and a fallback service if our main engine fails.
- For the free demo we keep a record of each analysis, including your IP address. After 90 days we shorten the IP address so it no longer points to a single address. We also keep a reduced-resolution copy of the photo for 30 days.
- If you have an account, we keep your analyses until you delete them or your account. Each analysis includes a small thumbnail of the photo, not the full photo.
- We don't sell your personal information or use it for advertising. Analytics run only if you allow them in the cookie banner, and you can change that choice at any time.
- You can access, download, correct or delete your data. Signed-in users can download their data and delete their account in Settings. For anything else, email contact@geolocator.app.
Who we are
GeoLocator Technologies Inc (“GeoLocator,” “we,” “us”) operates geolocator.app, including the free demo, the dashboard, the newsletter and our support channels (together, the “Services”). We are the controller responsible for the personal data described in this policy.
For any privacy question or request, email contact@geolocator.app.
This policy covers website visitors, demo users, account holders, newsletter subscribers, people who contact us, and people who appear in photos that others upload.
What we collect
When you visit the website
Our hosting provider (Vercel) receives technical information with every request, as it would for any website: your IP address, your browser and device type (user agent), the page requested, the referring page and the time. This information ends up in the hosting provider's request and server logs. Our application does not write it to its own database. Error messages in those logs can occasionally include something you submitted, such as a form field.
When you use the free demo
- The photo you upload. See What happens to your photos.
- A record of each analysis: your IP address (for IPv6, only the first 64 bits), your browser user agent, the photo's file size and format, the result (estimated country, region, city, coordinates, confidence and the AI's written explanation) and the time.
- A reduced-resolution copy of the photo (at most 1,600 pixels, metadata removed). It is kept in private storage for 30 days and then deleted automatically.
- Demo allowance. To show how many free analyses you have left, we look up your IP address in our rate-limit records.
When you create an account and use the dashboard
- Account details: your email address, your name if you provide it, your password (stored only in hashed form by our authentication provider, Supabase) and the date you created the account. Our authentication provider also keeps sign-in security records, which include IP addresses.
- For each analysis: the estimated location and coordinates, confidence, the AI's explanation and supporting evidence, which engine and model produced the result and how long it took. We also keep a small thumbnail of the photo (at most 400 pixels and 100 KB), a fingerprint (SHA-256 hash) of the original file, and the file's original name, size and dimensions. We do not keep the full-size photo. File names can contain personal information, so rename a file before uploading it if that matters to you.
- What you add: case names and descriptions, notes, tags, verdicts and the true coordinates if you record them.
- Maps: the dashboard map, the place search and PDF reports with a map load data from Mapbox (see Who receives your data). CSV, JSON and PDF exports are generated in your own browser.
When you subscribe to the newsletter
We use double opt-in. When you submit the form we record the address as awaiting confirmation and email you a confirmation link, which is valid for 48 hours. We only start sending you the newsletter once you click it. If you never do, nothing is sent.
We keep your email address, your subscription status, and the dates you subscribed, confirmed and unsubscribed. So that we can show that you agreed, we also keep which form you subscribed from and the exact wording of the notice shown next to it. Each record holds two random tokens: one for your confirmation link, and one used in the unsubscribe link and the unsubscribe header in every newsletter email we send you. The unsubscribe token is never changed, so unsubscribe links in older emails keep working.
To check that an address can receive mail, we look up its domain in DNS (the domain only, not the full address). Your IP address goes into a short-lived rate-limit record.
When you contact us
- Contact form: your first and last name, email address, company (optional), subject and message. We also keep our replies and internal notes about the conversation. We email you a confirmation that repeats your message.
- Emails you send us: the sender's name and address, the recipients, the subject and the text of the message. Emails that reach our support system become support conversations there. Attachments are not copied into it.
- Access requests: your first and last name, email address, company, phone number, intended use, our decision and the conversation that follows.
For the contact form and access requests, we check that the email address's domain can receive mail by looking it up in DNS (the domain only, not the full address).
Security, rate limiting and bot protection
- Rate-limit records. To limit how often analyses and forms can be used, we keep counters with timestamps. Each counter is keyed by your IP address (for IPv6, the first 64 bits), your account ID or, for access requests, the email address you submitted.
- hCaptcha. hCaptcha's bot check runs on the contact, sign-in and sign-up pages, on the admin sign-in page, and when you start a demo analysis. It does not run on the newsletter forms. It collects information from your browser and device, such as your IP address, browser characteristics and how you interact with the page. To verify the check for the demo and our forms, we send hCaptcha the resulting token and your IP address (only when it is a public address). For sign-in and sign-up, the token is passed to our authentication provider, Supabase.
Analytics, only if you accept
If you allow analytics in the cookie banner — with “Accept analytics”, or by turning Analytics on under “Customize” and saving — we use Vercel Web Analytics and Speed Insights. They measure page views, referring pages, browser, operating system and device type, a country derived from your IP address, and page-performance metrics. These tools do not set cookies. If you reject them, or make no choice, they do not load. You can change your choice at any time from the Cookie Policy; turning analytics off reloads the page so they stop straight away.
What you have to give us
You don't have to give us any personal data. But we can't analyse a photo you don't upload, create an account without an email address and password, send the newsletter without an email address, or answer you without a way to reply. The website cannot work without the technical request data described above.
What happens to your photos
- Your photo is handled in our server's memory for the length of your request. We do not store the file you upload.
- First, we turn the photo upright, resize it to at most 2,048 pixels on its longest side and strip its embedded metadata (EXIF, including any GPS coordinates).
- We send that processed copy to PPQ (ppq.ai), which forwards it to the vision model that identifies visual clues and candidate locations. We do not send your name, email address or IP address with it. PPQ states that it does not store the prompts it receives, but says that any retention beyond that depends on the model provider it routes to, which is outside its control. We have not confirmed which legal entity operates PPQ, in which country it processes data, or which model providers receive your photo (see international transfers).
- TypeSafe (api.typesafe.ai) then helps choose between the candidate countries, regions and cities. It receives text only: the vision model's notes, which can include text visible in the photo (such as signs), plus candidate place names and our reference lists. It never receives the photo. We have not yet confirmed in which country TypeSafe processes data (see International transfers).
- If our primary engine fails or is unavailable, for example during a provider outage, the processed photo is sent instead to a third-party fallback geolocation service at api.videomaker.cool. We have not yet confirmed how long that service keeps photos, or whether it uses them for any other purpose (see International transfers).
- Demo: we keep a reduced-resolution copy (at most 1,600 pixels, metadata removed) for 30 days, for abuse prevention and quality review. It sits in private storage that only our servers and administrators can access, and is then deleted automatically.
- Dashboard: we keep a thumbnail with your analysis, as described above, until you delete the analysis or your account.
- We do not use your photos to train AI models. The system is built to estimate where a photo was taken, not to identify the people in it. Our providers handle the data we send them under their own terms and policies (see Who receives your data).
Why we use your data (legal bases)
The GDPR and UK GDPR require a legal basis for each use of personal data. These are ours:
| Purpose | Legal basis |
|---|---|
| Running the analysis you ask for (demo or dashboard) and showing you the result | Performance of a contract (Art. 6(1)(b)): providing the service you requested. |
| Processing the personal data of people who appear in uploaded photos | Legitimate interests (Art. 6(1)(f)). The interest is providing the photo geolocation our users ask for. We limit the impact on the people shown: the system does not identify people, and our Terms forbid using it to locate, track or harass anyone. |
| Creating and running your account, and saving your analyses, cases and notes | Performance of a contract (Art. 6(1)(b)). |
| Showing maps, place search and map images in the dashboard (Mapbox) | Performance of a contract (Art. 6(1)(b)). |
| Keeping demo analysis records and short-term demo photo copies | Legitimate interests (Art. 6(1)(f)). Our interests are investigating misuse of a tool that can locate places (for example, attempts to track down a person) and checking the quality of results. |
| Rate limiting, bot protection (hCaptcha) and server logs | Legitimate interests (Art. 6(1)(f)). Our interests are protecting the Services and their users from abuse, automated attacks, fraud and overload, and enforcing the free demo allowance so the demo stays available to everyone. |
| Answering the contact form, support emails and access requests, and sending the related emails | Performance of a contract or steps you ask for before one (Art. 6(1)(b)) when the message is about using or getting access to the Services. Otherwise, legitimate interests (Art. 6(1)(f)): answering people who write to us. Keeping the conversation afterwards, so we can handle follow-up questions and possible legal claims, is also based on legitimate interests. |
| Sending the newsletter | Consent (Art. 6(1)(a)). You can withdraw it at any time with the unsubscribe link. |
| Keeping a record of addresses that have unsubscribed, so we don't email them again | Legitimate interests (Art. 6(1)(f)): respecting your choice not to receive the newsletter. |
| Analytics (Vercel Web Analytics and Speed Insights) | Consent (Art. 6(1)(a)), given with the cookie banner. You can withdraw it at any time. |
| Complying with the law, answering valid legal requests and handling your privacy requests | Legal obligation (Art. 6(1)(c)). |
| Enforcing our Terms and establishing, exercising or defending legal claims | Legitimate interests (Art. 6(1)(f)): protecting our rights and those of others. |
Where we rely on legitimate interests, you have the right to object (see Your rights). Withdrawing consent does not affect processing that happened before you withdrew it.
Who receives your data
We use the following service providers. Each receives only what it needs to do its job for us.
| Provider | What it does for us | What it receives |
|---|---|---|
| PPQ / ppq.ai (operator and processing location not confirmed) | Routes your photo to the AI vision model that runs the first step of our geolocation engine (demo and dashboard) | Your photo, resized with its metadata removed, plus our fixed instructions. No name, email or IP address. PPQ forwards it to a model provider we do not separately name. |
| TypeSafe (api.typesafe.ai; we have not yet confirmed where it processes data) | AI decision model that chooses between candidate countries, regions and cities | Text only: the vision model's notes about the photo (which may include text visible in it), candidate place names and reference lists. No photo, IP address or account details. |
| Fallback geolocation service (api.videomaker.cool) | Fallback geolocation, used only when our primary engine fails or is unavailable | Your photo, resized with its metadata removed, plus an instruction prompt. No name, email or IP address. |
| Supabase | Database, user authentication and private file storage | Everything we store, as described in this policy. It also receives the hCaptcha token at sign-in and sign-up. |
| Vercel | Website hosting, servers and logs; analytics if you accept | Every request to the site (IP address, browser, page, uploaded files in transit, form contents) and server logs. With your consent: analytics and performance data. |
| Resend | Sending and receiving email | Email addresses and names, and the content of emails we send (newsletter, confirmations and replies, which may quote your message or request) and emails you send us. |
| hCaptcha (Intuition Machines, Inc.) | Bot protection on forms and the demo | IP address, browser and device information and interaction signals collected by the widget, plus the verification token. |
| Mapbox | Maps, place search and static map images (dashboard only) | IP address and browser information with each map request, the map area you view, text you type into the dashboard search box, an analysis's coordinates when you create a PDF report, and usage events with a random identifier. |
| Upstash (if enabled) | Rate-limit counters | Short-lived counters keyed by IP address (for IPv6, the first 64 bits), account ID or, for access requests, email address. |
Other disclosures
- Authorities: when the law or valid legal process requires it, or when it is necessary to protect someone's life or safety.
- Professional advisers (for example lawyers or accountants), under duties of confidentiality.
- Business transfers: to a buyer or successor if our business is merged or sold. If that happens, this policy will continue to apply to your data unless you are told otherwise.
- Map links: if you click “view on map,” the estimated coordinates are placed in a link to Google Maps, OpenStreetMap or Bing Maps. Those services' privacy policies apply once you open the link.
We do not sell personal information. We do not share it with anyone for advertising.
International transfers
Most of the providers listed above are based in the United States. Your data may be processed there or in other countries where they or their subprocessors operate.
Personal data from the EEA, the UK or Switzerland may be transferred to a country that does not have an adequacy decision. The safeguards available for such transfers are the European Commission's Standard Contractual Clauses (with the UK Addendum), which providers can include in their data processing terms, and the EU-US Data Privacy Framework (with its UK Extension and the Swiss-US framework) for providers certified under it. We have not yet confirmed, for each provider, which of these safeguards applies to our use of its service. You can ask us about a particular provider.
We have not confirmed which legal entity operates PPQ, in which country it processes the photos we send it, or which model providers it forwards them to. PPQ does not publish a data processing agreement. You can ask us about this, and you can ask us to delete anything we hold about you.
We have not yet confirmed in which country TypeSafe processes the text we send it.
We have not yet confirmed where the fallback geolocation service processes data, or which transfer safeguard applies to it. It is used only when our primary engine fails or is unavailable.
How long we keep it
| Data | How long we keep it |
|---|---|
| Photos you upload (demo and dashboard) | We do not store the uploaded file. We process it in memory during your request. |
| Reduced-resolution copies of demo photos | 30 days, then deleted automatically by a daily clean-up job. |
| Demo analysis records | After 90 days we shorten the IP address to its network prefix (the first three parts of an IPv4 address, or the first 48 bits of an IPv6 address), so it no longer points to a single address, and we delete the user agent. The rest of the record (result, file size and format, time) is kept with no fixed end date. |
| Rate-limit records (keyed by IP address, account ID or email address) | Counters reset after 1 or 24 hours. Records are deleted automatically, at the latest about 9 days after your last request. |
| Account details | Until you delete your account. We do not currently delete inactive accounts automatically. Sign-in security records held by our authentication provider, Supabase, follow its retention. |
| Dashboard analyses (thumbnail, file fingerprint, file name, results, notes) and cases | Until you delete them or your account. |
| Newsletter subscription | Until you unsubscribe. After that we keep the record marked unsubscribed — the address, the dates and the record of the consent you originally gave — so we don't email it again. If you ask to subscribe and never click the confirmation link, the unconfirmed record is deleted automatically by a daily clean-up job once the link has been expired for 30 days. Ask us if you want the unsubscribed record deleted. |
| Contact form messages, support emails, access requests and our replies | No fixed end date. We keep the conversation, including our replies, so we can answer follow-up questions and deal with legal claims, and we keep it even if you delete your account in the meantime. It is not deleted automatically or on a schedule. If you want yours deleted, email contact@geolocator.app: we look at the request and delete the conversation, unless we still need it for a legal claim, and we tell you what we did. |
| Hosting and server logs | For the period set by our hosting provider, Vercel, under its log retention. We do not copy these logs into our own database. |
| Analytics (only if you accepted) | Held by Vercel under its own retention terms. |
We may keep specific data longer when the law requires it or when we need it to deal with a legal claim or a security incident. When that need ends, we delete it. Deleted data can remain in our providers' backups for a limited period, until those backups expire.
Your rights and how to use them
Depending on where you live (including in the EEA and the UK), you have the right to:
- Access your personal data and get a copy of it
- Rectification: have inaccurate data corrected
- Erasure: have your data deleted
- Restriction: ask us to limit how we use your data
- Portability: receive the data you gave us in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Withdraw consent at any time, for the newsletter and for analytics
How to exercise them
- Account holders: you can download a copy of your data and delete your account from Settings in the dashboard. Deleting your account permanently deletes your account, analyses and cases, and, if your account's email address is confirmed, unsubscribes that address from the newsletter. Messages you have sent us are kept, with no scheduled deletion, as described in How long we keep it; email us if you want them deleted. You can also delete individual analyses and cases, and export your analyses as CSV, JSON or PDF, at any time.
- Newsletter: use the unsubscribe link in any newsletter email, or open the unsubscribe page. If you no longer have one of those links, enter your address there and we will email you a fresh unsubscribe link.
- Analytics: change your choice as explained in our Cookie Policy.
- Everyone else, or for anything not covered above: email contact@geolocator.app. We identify demo records only by IP address, so for those, include the IP address(es) you used and roughly when. We may ask for information to confirm your identity, or that you used that IP address, so that we don't disclose someone else's data.
We respond within one month. If a request is complex, or you send several, we may extend this by up to two further months; if so, we will tell you why within the first month. Exercising your rights is free, unless a request is clearly unfounded or excessive.
Complaints
If you think we have mishandled your data, please contact us first at contact@geolocator.app and we will try to fix it. You also have the right to complain to a data protection supervisory authority. In the EEA, that is the authority in the country where you live, where you work or where the problem happened. In the UK, it is the Information Commissioner's Office (ico.org.uk).
AI and automated processing
The Services use AI models to estimate where a photo was taken. That estimate is about the photo. It is not a decision about you, and we do not use it, or anything else, to make decisions that have legal or similarly significant effects on you. We do not build advertising profiles. AI estimates can be wrong; treat them as a starting point to verify.
If you appear in someone else's photo
People who use the Services may upload photos that show other people. We receive those photos from the person who uploads them, and we process them only as described above: to estimate where the photo was taken. The system is not built to identify the people in a photo. Our Terms forbid using the Services to locate, track or harass anyone, and require users to have a lawful basis for any personal data in what they upload. If you think a photo of you has been processed, you can exercise the rights above by emailing contact@geolocator.app. You can also report misuse to that address.
Children
The Services are not directed at children under 16, and you must be at least 16 to use them. We do not knowingly collect personal data from children under 16. If you believe a child has given us personal data, contact us at contact@geolocator.app and we will delete it.
Security
We protect personal data with measures that include:
- Encryption in transit: the site is served over HTTPS, and our servers connect to our providers over HTTPS.
- Access controls. Database row-level security limits each signed-in user to their own records, admin tools are limited to designated administrator accounts, and demo records and demo photo copies can be reached only by our servers and administrators.
- Bot protection (hCaptcha) on the demo, the contact form and sign-in, and rate limits on demo and dashboard analyses and on newsletter sign-ups
- Removing embedded metadata (such as GPS coordinates) from photos before they reach AI providers
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach is likely to put your rights at high risk, we will tell you without undue delay.
California privacy notice
If you are a California resident, the California Consumer Privacy Act (CCPA) may give you additional rights. In the past 12 months we have collected these categories of personal information:
- Identifiers: name, email address, IP address, account ID
- Internet or network activity: pages requested, browser and device information, logs
- Visual information: photos you upload and thumbnails of them
- Professional information: company name and phone number, if you give them to us
- Inferences: AI estimates of where a photo was taken
We collect this information from you, your browser and device, and the service providers listed above. We use it for the purposes described in this policy and disclose it only to those service providers and in the other cases listed above. We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use sensitive personal information to infer characteristics about you. We keep each category for the periods in How long we keep it.
You have the right to know what personal information we collect, use and disclose, and to access, correct and delete it. You also have the right not to be treated differently for using these rights. To make a request, email contact@geolocator.app. An authorised agent may make a request for you with your signed permission. We will verify requests before acting on them.
Changes to this policy
We will update this policy when our practices change, and we will revise the “Last Updated” date at the top. If we make a material change, we will give notice on the site or by email before it takes effect, where the law requires it.
Contact us
For questions about this policy or to exercise your rights, contact GeoLocator Technologies Inc at:
Email: contact@geolocator.app