What we keep, and what we don't

Privacy is non-negotiable here. This is the plain-language version of how your data is handled — no dark patterns, no fine print.

Last updated 25 Jul 2026

Photos and location metadata

Photos carry hidden metadata (EXIF) — often including the exact GPS coordinates a shot was taken at. When you drop a spot, we strip that metadata from the file we store. The only location we keep is the pin you place, saved to plain database columns — so a spot lands where you put it, not where your camera secretly says.

Your identity

  • We never ask for your real name or phone number, and there's nowhere to enter one. You are your handle.
  • Artist credit is attached only to work that's publicly signed on the wall. We don't connect handles to real-world identities.
  • Sign-in is a magic link to your email. We use that address to log you in — not to sell, share or spam you.

Your location, in the moment

When you ask the map to show what's near you, your device location is used right then to centre the map. It is used in the moment and never logged historically— we don't build a trail of where you've been.

Doxxing and takedowns

Exposing a writer's real identity is the one thing we treat as an emergency. A doxxing report auto-hides the post immediately, before any human looks at it. See the code for how reporting works.

What we store

  • The spots, photos, comments and follows you create.
  • Your handle, avatar and the email you sign in with.
  • Basic counts (likes, saves) needed to make the app work.

Your control

You can delete your spots and your account. When you delete an account we remove your profile and the content tied to it. Want your data gone or have a privacy question? Reach us at privacy@graffitispot.app.

This page covers the essentials and will grow as the app does. Material changes get a new "last updated" date above.