Privacy Policy — Tairu Maps
1. In summary
Tairu Maps is a platform for collaborative mapping and geospatial data collection in the field. This policy explains what the application collects, what it does not collect, and — most importantly — what depends on a choice you make.
The central rule is this:
You decide, Expedition by Expedition, whether the data goes to the cloud.
Every Expedition has a "Sync to the cloud" switch. With it turned off, the Records, photographs, geometries, tracks and attachments of that Expedition remain exclusively on your device and are never transmitted to our servers.
1.1 What is collected, and when
| Category | Always | Depends on the plan | Depends on the Expedition switch |
|---|---|---|---|
| Name, e-mail, password (encrypted), profile picture | ● | ||
| Subscription and payment data | ● | ||
| Application access logs (Marco Civil da Internet — Brazil's Internet Civil Rights Framework, art. 15) | ● | ||
| Crash diagnostics and usage metrics | ● | ||
| Records, photographs, geometries, field attachments | ● | ||
| Tracks and location history | ● | ||
| Real-time location of the team | ● | ● | |
| Chat messages between Members | ● |
On the Offline plan there is no cloud synchronization under any circumstances: the application works entirely on the device, including Tracking, Records, offline base maps and the import/export of .tairudb, KML, GPX and GeoPackage files.
1.2 What we never do
- We do not sell personal data.
- We do not use your data for advertising, nor do we allow third parties to do so.
- We do not use the content of your Expeditions to train artificial intelligence models.
- We do not access the content of your Expeditions as an operational routine.
1.3 What we must state frankly
Tairu Maps does not use end-to-end encryption on synchronized data. Protection is by encryption in transit (TLS) and at rest, with access control by server rules. This means that the infrastructure administrator has technical access to the data stored in the cloud. There is no routine, process or purpose of accessing user content — but it would be dishonest to claim that such access is cryptographically impossible, because it is not.
If your use case does not admit this condition, use the cloud switch turned off, or talk to us about a dedicated instance (section 12).
2. Roles: who is the controller of what
This distinction is relevant for organizations that use Tairu Maps in institutional activity.
| Data | Controller | Processor |
|---|---|---|
| Registration, authentication, subscription, access logs, diagnostics | Tairu Maps | — |
| Expedition content: Records, photographs, geometries, tracks, Members, messages | You (or the organization you belong to) | Tairu Maps |
That is: regarding the data you produce in the field, you are the one who decides the purposes. We merely store and synchronize it according to your instruction, expressed through the application's settings. If you enter personal data of third parties (people involved, Contacts, photographs of individuals), responsibility for the legal basis of that processing lies with whoever enters it.
Organizations that need to formalize this relationship may request a data processing agreement (section 12).
3. Data processed
3.1 Identification and authentication
Full name, e-mail address, password (stored in encrypted form by Firebase Authentication, never in clear text), profile picture (optional), e-mail verification status. When you sign in with Google or Apple, we receive from those providers only name, e-mail and account identifier.
3.2 Location
- During active Tracking: high-precision GPS coordinates, collected continuously while you start and maintain a Tracking session, including with the application in the background, if authorized.
- Points and features marked manually.
- Tracking never starts on its own. It is started by an action of yours and can be ended at any time.
- Background location permission is requested separately and can be revoked in the operating system settings.
3.3 Field content
Expeditions (name, description, dates), Records with geometry (points, lines, polygons), photographs, observations, Members, Groups, record templates, Layers and imported files (.tairudb, PDF/GeoPDF, KML, GPX, GeoPackage).
Photographs may contain EXIF metadata with geographic coordinates, written by the device's camera. This metadata travels with the image.
3.4 Communication
Messages exchanged in the Expedition chat, including sender, recipients and time. Chat is a cloud feature: it does not exist in offline mode.
3.5 Technical and diagnostic data
Application access logs (date, time and IP address of connections), crash reports (Firebase Crashlytics), aggregated usage metrics (Firebase Analytics: screens visited, application version, device model and system), device identifiers for sending notifications and for synchronization, and synchronization metadata.
Diagnostics and metrics do not include map content: no coordinate, Record, photograph, message or imported file travels through those channels.
4. What does not leave your device
With the "Sync to the cloud" switch turned off on an Expedition, all of its content remains only in the device's local storage, in a database encrypted with AES, whose key is derived and kept in the operating system's secure storage (Keychain on iOS, Keystore on Android).
The same applies in full to the Offline plan.
Under that condition, we have no access to this data — not because we promise not to look, but because it never reaches us.
Caveat regarding the web version: in the browser, platform limitations prevent encrypting local storage in the same fashion. For sensitive data, prefer the mobile or desktop applications.
5. Purposes and legal bases (LGPD — Brazil's General Data Protection Law, art. 7)
| Purpose | Legal basis |
|---|---|
| Create and maintain your account; authenticate access | Performance of a contract (art. 7, V) |
| Synchronize and store the content of the Expeditions you chose to take to the cloud | Performance of a contract (art. 7, V) |
| Share data between Members of the same Expedition | Performance of a contract (art. 7, V) |
| Collect location during active Tracking | Consent (art. 7, I), expressed by granting the permission and starting the session |
| Send operational notifications (messages, Alerts, emergencies) | Performance of a contract (art. 7, V) |
| Process subscriptions and payments | Performance of a contract (art. 7, V) and legal obligation (art. 7, II) |
| Keep application access logs | Legal obligation — Marco Civil da Internet, art. 15 (art. 7, II) |
| Diagnose failures and improve the application | Legitimate interest (art. 7, IX) |
| Prevent fraud and abusive use | Legitimate interest (art. 7, IX) |
When the legal basis is consent, you may revoke it at any time — in the case of location, by ending Tracking or revoking the permission in the operating system. Revocation does not affect the lawfulness of prior processing.
6. Sharing
6.1 Between Members
The data of a synchronized Expedition is visible to its Members, according to each one's role (owner, administrator or user), defined by whoever administers the Expedition. A Member does not see Expeditions they do not take part in.
6.2 Processors and third-party services
| Service | What it receives | Where |
|---|---|---|
| Google Firebase / Google Cloud (authentication, database, files, notifications, diagnostics) | Registration data and all synchronized content | Database, files and server functions in São Paulo (southamerica-east1). Authentication, notifications and diagnostics are global Google services and may be processed outside Brazil |
| Base map providers (Google, Esri, Microsoft, MapTiler, EOX, OpenFreeMap and others you configure) | Tile requests, which reveal the map area being viewed | According to the provider |
| WMS/WFS services configured by you | Area requests and any credentials you provide | According to the server you choose |
| openrouteservice (FOSSGIS e.V.) — only in versions before 1.0.76 | The points of the requested route, including your position when the route started from it | Germany |
| Apple / Google (App Store, Google Play) | Purchase and subscription data | According to the provider |
As of version 1.0.76, land route calculation runs on your device, over OpenStreetMap data you download by region. No point of the route — including your position, when the route starts from it — is sent to third parties.
6.3 Authorities
We may share data upon court order or request from a competent authority, within the limits of the law. Whenever legally possible and not forbidden, we will notify the data subject.
6.4 What we do not do
We do not sell, rent or transfer personal data. We do not share it with data brokers, advertising networks, or for any third-party marketing purpose.
7. Where your data stays
The content of your Expeditions stays in Brazil. The database (Firestore), the storage of files and photographs (Cloud Storage) and the server functions operate in Google Cloud's São Paulo (southamerica-east1) region. Records, geometries, photographs, tracks and messages do not leave the national territory in normal operation.
Some Google support services are not region-bound and may process data outside Brazil:
- Firebase Authentication — your e-mail and access credentials.
- Firebase Cloud Messaging — sending notifications.
- Crashlytics and Analytics — crash diagnostics and usage metrics.
Outside Google, there is international transfer in a single case, under your control: the base map providers and WMS/WFS services you choose to use receive the requests you make to them.
Versions before 1.0.76. Up to that version, land route calculation could be performed by openrouteservice, in Germany, which received the points of the requested route — including your position, when the route started from it. We keep that service running only so as not to break users who have not updated yet. Updating the application ends that transmission.
These transfers occur to providers subject to contractual data protection clauses compatible with art. 33 of the LGPD.
8. Security
What we do:
- Encryption in transit (TLS) in all communication with the servers.
- Encryption at rest on the servers, managed by the cloud provider.
- Local database encrypted with AES in the mobile and desktop applications, with the key in the operating system's secure storage.
- Mandatory authentication, with an additional application integrity check (App Check).
- Access control by server rules, evaluated on every read and write, per Expedition and per role.
- Automatic backups.
What we do not do, and you should know:
- There is no end-to-end encryption. See section 1.3.
- The security of the content of a shared Expedition also depends on the Members you admit into it. Invitations grant real access to the content.
No system is immune to incidents. In the event of a security incident with relevant risk to data subjects, we will notify those affected and the ANPD (Brazil's national data protection authority), within the deadlines and in the manner of art. 48 of the LGPD.
9. Retention
| Data | Period |
|---|---|
| Content of synchronized Expeditions | For as long as the account exists and the data is not deleted by you |
| Local-only content | Under your exclusive control; it disappears when the application is uninstalled |
| Registration data and profile | For as long as the account exists |
| Data after account deletion | Removed from active systems within 30 days; purged from backups within 90 days |
| Application access logs | 6 months, as required by art. 15 of the Marco Civil da Internet |
| Tax and subscription records | 5 years, as required by tax legislation and the Consumer Protection Code (CDC) |
| Crash diagnostics and usage metrics | Up to 14 months, according to the provider's standard retention |
About data in shared Expeditions: when you delete your account, we remove your personal data and the Expeditions you own. Records you created inside third-party Expeditions remain with the owner of the Expedition, who is the controller of that data set — just as a document delivered to an organization does not vanish from it when its author leaves. Requests concerning those Records must be addressed to the owner of the Expedition.
10. Your rights (LGPD, art. 18)
You may request, at any time:
- Confirmation and access — to know whether we process your data and to obtain a copy of it.
- Correction of incomplete, inaccurate or outdated data.
- Anonymization, blocking or deletion of data that is unnecessary, excessive or processed in non-compliance with the law.
- Portability — the application already offers full export, with no need for a request: backup in JSON, and export to
.tairudb, KML, GPX and GeoPackage. - Deletion of data processed on the basis of consent.
- Information about whom we share your data with — section 6.2 answers this permanently and in an up-to-date manner.
- Information about the possibility of not consenting and the consequences of that.
- Revocation of consent.
How to exercise them: write to danielhsmartin@gmail.com. We will respond within 15 days. We may ask for identity confirmation before complying, to protect your account.
If you are not satisfied with our response, you may file a complaint with the ANPD — Autoridade Nacional de Proteção de Dados (Brazil's national data protection authority) (gov.br/anpd).
11. Account deletion
Deletion can be requested at tairumaps.com/delete-account or through the application's settings. It removes your registration data, profile, the Expeditions you own and the associated content, within the periods of section 9.
Before deleting, export whatever you want to keep. Deletion is permanent.
12. Institutional use
For agencies and organizations with their own information security requirements, we offer:
- Local mode, without any synchronization — available today, at no additional cost and with no contract.
- Data processing agreement / confidentiality agreement.
- Response to an information security questionnaire.
- Dedicated instance, with the cloud project under the organization's own control — in that arrangement, the organization becomes the administrator of the infrastructure and we cease to have access to the data.
Contact: danielhsmartin@gmail.com.
13. Minors
Tairu Maps is not intended for people under 18 years of age, and we do not intentionally collect data from minors. If we identify a minor's registration without a guardian's authorization, the account will be removed. Guardians who identify such a situation should contact us.
14. Local storage and similar technologies
The application uses local storage for caching, offline operation and performance; authentication tokens to keep the session; and device identifiers for notifications and synchronization. The institutional website does not use advertising tracking cookies.
15. Changes to this policy
We may update this policy. Relevant changes will be communicated in the application and by e-mail, with reasonable advance notice before they take effect.
Previous versions, kept for consultation: version of May 19, 2026.
Continued use after the new version takes effect implies awareness of it. When a change requires new consent, it will be requested specifically and prominently.
Languages. This policy is published in Portuguese, English and Spanish. The translations exist to make reading easier; in case of divergence between them, the Portuguese version prevails, as it is the only one entered into under Brazilian law.
16. Contact
Data Protection Officer (DPO): Daniel H. Saint Martin E-mail: danielhsmartin@gmail.com Supervisory authority: ANPD — gov.br/anpd
Tairu Maps · Developed by Daniel H. Saint Martin