Legal

Privacy Policy

Last updated August 4, 2026.

summarize The short version

UrbanLens is built and run by one person, not a company. The site collects only what's needed to run: your account info, the content you create, and (if you sign in with Google or Discord) the basic profile details those providers share. Your content is private by default and only visible to people you choose to share it with. We don't sell your data, we don't run ads, and we don't track you with analytics. Read the full policy below for the details.

1

Who this policy covers

This policy explains what information UrbanLens ("the site", "we", "us") collects when you use the site, why we collect it, and how it's stored and shared. It applies to everyone who creates an account or otherwise uses UrbanLens. See also our Terms of Service and Values, which describe the principles this policy is built around.

2

Information you give us directly

When you create an account, we store your username, email address, and password (hashed, never in plain text). As you use the site, we store the content you create: pins, notes, photos, trip plans, wiki edits, messages, reviews, and similar content. This is the core information the site is built to hold, and it stays private to you unless you explicitly share it. We encrypt as much of it as we can, while keeping the site functional.

3

Signing in with Google or Discord

If you sign in using Google or Discord instead of a password, that provider shares basic profile information with us to create and authenticate your account - typically your name, email address, and profile picture from Google, or your username, user ID, and email address from Discord. We use this information only to set up and sign you into your UrbanLens account. We never post to your Google or Discord account, request access beyond basic profile information, or use this data for anything other than authentication. Our use of information received from Google APIs adheres to the Google API Services User Data Policy.

4

Who can see your content

Pins, notes, photos, and other content you create are private by default. Nothing you create is visible to another user, including the site owner, until you take an explicit action to share it - by inviting a friend, posting to a trip, or otherwise changing a sharing setting. Even friend requests don't reveal whether an account exists until the request is accepted.

5

Information sent to research APIs

Many of the site's research tools (search, imagery, elevation, weather, wildlife data, historical records, and similar lookups) work by sending a location's coordinates or a place name to third-party APIs and returning what they know about that spot. These requests only ever include the coordinates or search terms needed to answer the lookup - never your name, account, or other identifying information. You can turn these lookups off entirely from onboarding or your account settings.

6

Connected photo services

If you connect a third-party photo service (such as Flickr, Immich, or Google Photos) to import media, we store the access token needed to talk to that service, encrypted at rest. We only use that connection to import the photos you request - we don't browse or sync your library in the background beyond what you ask for, and you can disconnect a service at any time from your settings, which removes the stored token.

7

Cookies and tracking

We use a session cookie to keep you signed in and a CSRF cookie to protect forms - that's it. We don't run third-party analytics, advertising, or tracking scripts, and we don't store your IP address. There's nothing on this site designed to track you across the web.

8

How we store and protect data

Your data is stored in a database we control, accessed over encrypted connections. Sensitive values, like third-party API tokens, are encrypted at rest. No system is perfectly secure, but we design every feature to limit what a breach could expose - for example, by not collecting data we don't need in the first place.

9

How long we keep data

We keep your data for as long as your account is active. You can delete your account at any time from Settings; deletion starts a 7-day grace period (during which signing back in cancels it), after which your account and its associated data are permanently removed. Your data may still be present in automated backups that are only used in the event of a server failure, until those backups are aged out. This process typically takes another 7 to 30 days.

10

We don't sell your data

We don't sell or rent your personal information or your content to anyone, and we don't share it with third parties except where this policy already describes - the research and photo-import APIs you choose to use, and the sign-in providers you choose to authenticate with.

11

Children's privacy

UrbanLens is not directed at children, and per our Terms of Service, you must be at least 18 (or the age of majority where you live) to create an account. We don't knowingly collect information from children.

12

Your rights and choices

Any data we store about you is visible to you on pages like your profile page. You can update or delete your content at any time, disconnect any third-party service, and delete your account entirely from Settings. If you'd like a copy of your data or have a question about what we hold, reach out using the contact info below.

13

Changes to this policy

We may update this policy as the site grows. Material changes will be reflected here. Continuing to use UrbanLens after a change means you accept the updated policy.

14

Contact

Questions about this policy, or want to request your data? Reach out through the Github page.

Attach a Map
Layer:
Draw:
Attach a Photo
Are you sure?