← Back
Português · English · Español

Privacy Policy — Tairu Maps

Version 2.0 · Effective as of the publication date · Supersedes the version of May 19, 2026

Controller: Daniel H. Saint Martin — CPF (Brazilian individual taxpayer number) 001.627.811-99
Data Protection Officer (DPO): Daniel H. Saint Martin — danielhsmartin@gmail.com


1. In summary

Tairu Maps is a platform for collaborative mapping and geospatial data collection in the field. This policy explains what the application collects, what it does not collect, and — most importantly — what depends on a choice you make.

The central rule is this:

You decide, Expedition by Expedition, whether the data goes to the cloud.

Every Expedition has a "Sync to the cloud" switch. With it turned off, the Records, photographs, geometries, tracks and attachments of that Expedition remain exclusively on your device and are never transmitted to our servers.

1.1 What is collected, and when

CategoryAlwaysDepends on the planDepends on the Expedition switch
Name, e-mail, password (encrypted), profile picture●
Subscription and payment data●
Application access logs (Marco Civil da Internet — Brazil's Internet Civil Rights Framework, art. 15)●
Crash diagnostics and usage metrics●
Records, photographs, geometries, field attachments●
Tracks and location history●
Real-time location of the team●●
Chat messages between Members●

On the Offline plan there is no cloud synchronization under any circumstances: the application works entirely on the device, including Tracking, Records, offline base maps and the import/export of .tairudb, KML, GPX and GeoPackage files.

1.2 What we never do

1.3 What we must state frankly

Tairu Maps does not use end-to-end encryption on synchronized data. Protection is by encryption in transit (TLS) and at rest, with access control by server rules. This means that the infrastructure administrator has technical access to the data stored in the cloud. There is no routine, process or purpose of accessing user content — but it would be dishonest to claim that such access is cryptographically impossible, because it is not.

If your use case does not admit this condition, use the cloud switch turned off, or talk to us about a dedicated instance (section 12).


2. Roles: who is the controller of what

This distinction is relevant for organizations that use Tairu Maps in institutional activity.

DataControllerProcessor
Registration, authentication, subscription, access logs, diagnosticsTairu Maps—
Expedition content: Records, photographs, geometries, tracks, Members, messagesYou (or the organization you belong to)Tairu Maps

That is: regarding the data you produce in the field, you are the one who decides the purposes. We merely store and synchronize it according to your instruction, expressed through the application's settings. If you enter personal data of third parties (people involved, Contacts, photographs of individuals), responsibility for the legal basis of that processing lies with whoever enters it.

Organizations that need to formalize this relationship may request a data processing agreement (section 12).


3. Data processed

3.1 Identification and authentication

Full name, e-mail address, password (stored in encrypted form by Firebase Authentication, never in clear text), profile picture (optional), e-mail verification status. When you sign in with Google or Apple, we receive from those providers only name, e-mail and account identifier.

3.2 Location

3.3 Field content

Expeditions (name, description, dates), Records with geometry (points, lines, polygons), photographs, observations, Members, Groups, record templates, Layers and imported files (.tairudb, PDF/GeoPDF, KML, GPX, GeoPackage).

Photographs may contain EXIF metadata with geographic coordinates, written by the device's camera. This metadata travels with the image.

3.4 Communication

Messages exchanged in the Expedition chat, including sender, recipients and time. Chat is a cloud feature: it does not exist in offline mode.

3.5 Technical and diagnostic data

Application access logs (date, time and IP address of connections), crash reports (Firebase Crashlytics), aggregated usage metrics (Firebase Analytics: screens visited, application version, device model and system), device identifiers for sending notifications and for synchronization, and synchronization metadata.

Diagnostics and metrics do not include map content: no coordinate, Record, photograph, message or imported file travels through those channels.


4. What does not leave your device

With the "Sync to the cloud" switch turned off on an Expedition, all of its content remains only in the device's local storage, in a database encrypted with AES, whose key is derived and kept in the operating system's secure storage (Keychain on iOS, Keystore on Android).

The same applies in full to the Offline plan.

Under that condition, we have no access to this data — not because we promise not to look, but because it never reaches us.

Caveat regarding the web version: in the browser, platform limitations prevent encrypting local storage in the same fashion. For sensitive data, prefer the mobile or desktop applications.


5. Purposes and legal bases (LGPD — Brazil's General Data Protection Law, art. 7)

PurposeLegal basis
Create and maintain your account; authenticate accessPerformance of a contract (art. 7, V)
Synchronize and store the content of the Expeditions you chose to take to the cloudPerformance of a contract (art. 7, V)
Share data between Members of the same ExpeditionPerformance of a contract (art. 7, V)
Collect location during active TrackingConsent (art. 7, I), expressed by granting the permission and starting the session
Send operational notifications (messages, Alerts, emergencies)Performance of a contract (art. 7, V)
Process subscriptions and paymentsPerformance of a contract (art. 7, V) and legal obligation (art. 7, II)
Keep application access logsLegal obligation — Marco Civil da Internet, art. 15 (art. 7, II)
Diagnose failures and improve the applicationLegitimate interest (art. 7, IX)
Prevent fraud and abusive useLegitimate interest (art. 7, IX)

When the legal basis is consent, you may revoke it at any time — in the case of location, by ending Tracking or revoking the permission in the operating system. Revocation does not affect the lawfulness of prior processing.


6. Sharing

6.1 Between Members

The data of a synchronized Expedition is visible to its Members, according to each one's role (owner, administrator or user), defined by whoever administers the Expedition. A Member does not see Expeditions they do not take part in.

6.2 Processors and third-party services

ServiceWhat it receivesWhere
Google Firebase / Google Cloud (authentication, database, files, notifications, diagnostics)Registration data and all synchronized contentDatabase, files and server functions in São Paulo (southamerica-east1). Authentication, notifications and diagnostics are global Google services and may be processed outside Brazil
Base map providers (Google, Esri, Microsoft, MapTiler, EOX, OpenFreeMap and others you configure)Tile requests, which reveal the map area being viewedAccording to the provider
WMS/WFS services configured by youArea requests and any credentials you provideAccording to the server you choose
openrouteservice (FOSSGIS e.V.) — only in versions before 1.0.76The points of the requested route, including your position when the route started from itGermany
Apple / Google (App Store, Google Play)Purchase and subscription dataAccording to the provider

As of version 1.0.76, land route calculation runs on your device, over OpenStreetMap data you download by region. No point of the route — including your position, when the route starts from it — is sent to third parties.

6.3 Authorities

We may share data upon court order or request from a competent authority, within the limits of the law. Whenever legally possible and not forbidden, we will notify the data subject.

6.4 What we do not do

We do not sell, rent or transfer personal data. We do not share it with data brokers, advertising networks, or for any third-party marketing purpose.


7. Where your data stays

The content of your Expeditions stays in Brazil. The database (Firestore), the storage of files and photographs (Cloud Storage) and the server functions operate in Google Cloud's São Paulo (southamerica-east1) region. Records, geometries, photographs, tracks and messages do not leave the national territory in normal operation.

Some Google support services are not region-bound and may process data outside Brazil:

Outside Google, there is international transfer in a single case, under your control: the base map providers and WMS/WFS services you choose to use receive the requests you make to them.

Versions before 1.0.76. Up to that version, land route calculation could be performed by openrouteservice, in Germany, which received the points of the requested route — including your position, when the route started from it. We keep that service running only so as not to break users who have not updated yet. Updating the application ends that transmission.

These transfers occur to providers subject to contractual data protection clauses compatible with art. 33 of the LGPD.


8. Security

What we do:

What we do not do, and you should know:

No system is immune to incidents. In the event of a security incident with relevant risk to data subjects, we will notify those affected and the ANPD (Brazil's national data protection authority), within the deadlines and in the manner of art. 48 of the LGPD.


9. Retention

DataPeriod
Content of synchronized ExpeditionsFor as long as the account exists and the data is not deleted by you
Local-only contentUnder your exclusive control; it disappears when the application is uninstalled
Registration data and profileFor as long as the account exists
Data after account deletionRemoved from active systems within 30 days; purged from backups within 90 days
Application access logs6 months, as required by art. 15 of the Marco Civil da Internet
Tax and subscription records5 years, as required by tax legislation and the Consumer Protection Code (CDC)
Crash diagnostics and usage metricsUp to 14 months, according to the provider's standard retention

About data in shared Expeditions: when you delete your account, we remove your personal data and the Expeditions you own. Records you created inside third-party Expeditions remain with the owner of the Expedition, who is the controller of that data set — just as a document delivered to an organization does not vanish from it when its author leaves. Requests concerning those Records must be addressed to the owner of the Expedition.


10. Your rights (LGPD, art. 18)

You may request, at any time:

How to exercise them: write to danielhsmartin@gmail.com. We will respond within 15 days. We may ask for identity confirmation before complying, to protect your account.

If you are not satisfied with our response, you may file a complaint with the ANPD — Autoridade Nacional de Proteção de Dados (Brazil's national data protection authority) (gov.br/anpd).


11. Account deletion

Deletion can be requested at tairumaps.com/delete-account or through the application's settings. It removes your registration data, profile, the Expeditions you own and the associated content, within the periods of section 9.

Before deleting, export whatever you want to keep. Deletion is permanent.


12. Institutional use

For agencies and organizations with their own information security requirements, we offer:

Contact: danielhsmartin@gmail.com.


13. Minors

Tairu Maps is not intended for people under 18 years of age, and we do not intentionally collect data from minors. If we identify a minor's registration without a guardian's authorization, the account will be removed. Guardians who identify such a situation should contact us.


14. Local storage and similar technologies

The application uses local storage for caching, offline operation and performance; authentication tokens to keep the session; and device identifiers for notifications and synchronization. The institutional website does not use advertising tracking cookies.


15. Changes to this policy

We may update this policy. Relevant changes will be communicated in the application and by e-mail, with reasonable advance notice before they take effect.

Previous versions, kept for consultation: version of May 19, 2026.

Continued use after the new version takes effect implies awareness of it. When a change requires new consent, it will be requested specifically and prominently.

Languages. This policy is published in Portuguese, English and Spanish. The translations exist to make reading easier; in case of divergence between them, the Portuguese version prevails, as it is the only one entered into under Brazilian law.


16. Contact

Data Protection Officer (DPO): Daniel H. Saint Martin E-mail: danielhsmartin@gmail.com Supervisory authority: ANPD — gov.br/anpd


Tairu Maps · Developed by Daniel H. Saint Martin