Last updated: pilot draft, subject to change
The short version: we don't store your location history. We store that you checked in at a specific park at a specific time, not a trail of where your phone has been.
What we collect
- Account info: your email address (for sign-in) and a display name/username.
- Profile details you choose to add: avatar icon/color, interests, an equipped title.
- Check-in records: which park, when, which activity (if any), and whether your proximity to the park was GPS-verified at that moment. Your device checks distance to the park locally. Only the yes/no result is sent to us, never your raw coordinates.
- Home base (optional): if you choose to set one, we reverse-geocode a single GPS reading into a city/state (e.g. "St. Charles County, Missouri") and store only that, never the coordinates themselves. You control whether this is shown on your profile at all, and if so, at what level of detail (state only vs. city and state).
- XP, streaks, and achievements earned through the app.
- Anything you submit voluntarily: photos, ratings, written reviews, park submissions, or issue reports. Photos have location and device metadata stripped before upload.
What we don't do
- We read your location at two moments only: when you open the map, so it can centre on you and show the parks nearby, and when you check in, to verify you are actually at the park. Never in the background, never while the app is closed, and never on a schedule.
- To show you nearby parks, the app has to ask our database which parks are in your area. It does not send your position to do this. Your location is first rounded to a grid roughly three and a half miles across, and only that rounded area is sent — so the request narrows you to a cell of that size and no further. The precise fix stays on your device, which filters the results down to your real search radius locally.
- We don't sell your data or share it with advertisers.
- We don't build a movement history from your check-ins. The record is "you visited this park," not a timeline of where you've been throughout the day.
Who else touches your data
- Supabase hosts our database, authentication, and backend functions.
- OpenStreetMap/Nominatim is used only at the moment you set a home base, to convert a single GPS reading into a city/state. It never receives your check-in locations.
- Map tiles are served by OpenStreetMap and CARTO, the same way any map in any app works.
Your controls
- Edit or remove your profile details, home base, and title at any time from Edit Profile.
- Delete your account entirely from Settings → Delete Account. This permanently removes your check-ins, XP, streaks, badges, and profile, and revokes your sign-in. It can't be undone.
Children's privacy
thicket isn't directed at children under 13, and we don't knowingly collect information from them.
Changes
As a pilot, this policy may change as the app develops. Meaningful changes will be reflected here with an updated date.
Questions
Questions about this policy: hello@getthicket.app