Privacy Policy
Last updated: August 2026
Overview
Someday Map (“we”, “us”, “our”) helps you turn saved social media posts into an interactive map of places. You can import content from Instagram, TikTok, YouTube, Yelp, web pages, and uploaded files. This policy explains what data we collect, why we collect it, how we use it, and your rights regarding that data.
Information we collect
We collect only what is necessary to provide the service:
- Account information — when you sign in with Google or Apple, we receive the account identity information you authorize, such as your name, email address, and profile photo when supplied. We use this to create and identify your account.
- Imported content — post captions, URLs, usernames, thumbnails, collection names, accessibility text, subtitles, and other information from content you choose to import from Instagram, TikTok, YouTube, Yelp, web pages, PDFs, images, and pasted text. Selected source photos, carousel images, audio, or video may be downloaded or decoded while an import or rescan is processed. Saved records, uploaded files, generated thumbnails, extracted results, and processing logs may be stored with your account when the feature requires it.
- Location data — if you enable the “Near You” feature, we request your browser or device location, cache it on your device when that client supports caching, and send the coordinates to our authenticated nearby endpoint to sort and filter your saved places by distance. That endpoint does not write the coordinates to our database. If you choose to detect and save a default map center, its coordinates and resolved city are stored in your account preferences and the coordinates may be sent to Google for geocoding. In the mobile app, map requests can also be handled by the device's native map provider and can include the viewed coordinates or your device location when you choose to show it on the map.
- Payment information — if you subscribe to a paid plan or purchase add-ons, payment details such as card number and billing address are collected and processed by Stripe. We do not receive or store your full card number. To create and manage billing, we send Stripe your account email, an internal account identifier, and the selected plan or add-on. Stripe returns customer, checkout, subscription, price, invoice, payment-status, event, and cancellation information; we store the identifiers, amounts, status, and timing needed to provide entitlements, purchases, billing support, and reconciliation.
- Usage and technical data — server and hosting logs may include request paths, timestamps, IP or network information, browser or device information, essential session metadata, provider-operation receipts, and errors. We use this information to operate, secure, diagnose, and enforce limits for the service; we do not attach advertising identifiers to these records.
What we do not collect
- Your Instagram, TikTok, or YouTube passwords or login credentials
- Posts you have not explicitly chosen to import
- Direct messages, private conversations, or follower lists
- Browsing history on websites other than those you import from
- Social posts or media you have not explicitly chosen to import or process
How we use your data
- Place extraction — captions, descriptions, pasted text, document text, selected carousel images, and extracted video frames may be analyzed to identify place names, cuisines, and context. Anthropic's Claude models receive text for ordinary extraction and may receive selected images or extracted frames for vision-based extraction. Anthropic processes this data subject to their privacy policy.
- Places, maps, routes, and weather — place queries, identifiers, addresses, coordinates, trip dates, and route endpoints may be sent to Google services to resolve places, geocode locations, calculate routes, and obtain map imagery. MapTiler supplies browser map styles and tiles. The mobile app uses the device's native map service, normally Apple Maps on iOS or Google Maps on Android when configured, for map rendering and optional device-location display. A dropped pin's coordinates may be sent to OpenStreetMap Nominatim to look up its address. Coordinates, dates, and unit preferences may be sent to Visual Crossing to obtain weather forecasts. Returned forecast payloads and their accounting receipts may be cached on our servers. Google processes data subject to its privacy policy.
- Currency conversion — when a saved expense needs a historical exchange rate and no saved rate is available, its date and currency pair may be sent to Frankfurter. The returned rate may be cached; the expense amount, trip, and account identity are not included in that request.
- Media processing — selected source URLs, photos, carousel images, audio, and video may be processed on Modal compute. Audio may be sent to OpenAI's Whisper model for transcription. Extracted frames and related caption context may be sent to Google's Gemini models or Anthropic's Claude models for automated image analysis. When a source blocks ordinary server access, a selected source URL and its response traffic may pass through Evomi's residential proxy service.
- Photos and generated covers — place names, coordinates, provider identifiers, and photo references may be sent to Google, Tripadvisor, Unsplash, Wikimedia Commons, or source websites to find and retrieve place imagery. A trip or collection name and related destination context may be incorporated into an image-generation prompt sent to Fal to generate a trip or collection cover. Selected or generated images may be stored in our configured storage service when the product saves them.
- Payment processing — paid subscriptions and add-on purchases are processed by Stripe. We use your Stripe customer ID to manage your subscription and enforce usage limits. We do not have access to your full card details.
- Account management — profile information supplied by Google or Apple is used to identify your account and display your profile within the app.
Data retention and deletion
Your imported content (captions, place data, notes) is stored in our database for as long as you maintain an account. Resolved-place, geocoding, weather, and provider- response caches may retain search queries, addresses, coordinates, provider results, and accounting metadata to reduce duplicate requests and support durable replay. Some cache entries are shared across accounts, while operational receipts can be linked to the account that initiated the request. These records are not intended to contain account profile fields, but location queries and addresses can themselves be personal information.
Processing may create temporary media files, decoded frames, provider responses, thumbnails, and logs. What is retained depends on the active path: account records, user uploads, saved thumbnails, generated covers, references, extracted results, and usage receipts can persist until removed under the product's deletion rules. Other processing artifacts are handled by the relevant service under its own retention and privacy terms. We do not make a blanket claim that every provider immediately deletes raw request data.
Provider and accounting receipts used for durable replay can include raw Google Places Autocomplete suggestions, terminating place-detail responses, or reverse- geocoding responses. These operational records may remain stored after a request is settled and require a bounded retention-and-cleanup review before deployment.
- Deleting places or collections — when you delete a place or collection, the account-scoped database records associated with that item are removed under the product's deletion rules. Shared resolved- place or cache records, provider and accounting receipts, and independently stored files may follow separate retention and cleanup processes and are not guaranteed to be removed by the same database operation.
- Deleting your account — you can delete your account from the Settings page. An account-deletion request attempts to remove the primary account record and related database records configured to be deleted with it. Deletion is complete only after the service confirms success. Shared caches, operational or billing records, independently stored objects, and records held by third-party providers may follow separate retention or deletion processes. Contact us if you need confirmation or follow-up deletion assistance. These deletion and storage-cleanup paths require founder review before deployment.
- Data export — you can export all of your saved place data from the Settings page before deleting your account.
We do not sell, rent, or trade any personal data.
Third-party services
Someday Map uses the following third-party services to operate:
- Google — sign-in; Places, Geocoding, Routes, Maps, Street View, and place-photo services using place queries, identifiers, addresses, coordinates, route endpoints, and map requests; and Gemini models using trip text, imported text, selected images, or extracted video frames for generation and automated image analysis. Deep Review and grounded description paths can send dates, stop names, coordinates or locality, and other trip facts to Gemini with Google Search grounding; returned source URLs and research catalogs can be stored with the result. A fixed Google Fonts asset is fetched when the server renders certain generated collection images; that asset request does not include the collection's content. Google Privacy Policy.
- Anthropic Claude — place extraction from captions, pasted or document text, selected carousel images, and extracted video frames. The active vision paths can send images as well as text. Anthropic Privacy Policy.
- OpenAI — Whisper model for audio transcription during selected video rescans; the audio prepared for transcription is sent to this service. OpenAI Privacy Policy.
- Fal — generated trip and collection covers. A trip or collection name, destination context, and generation prompt may be sent, and the returned image may be stored with that trip or collection. Fal Privacy Policy.
- Visual Crossing — weather forecasts. Coordinates, trip dates, and unit preferences are sent when forecast data is not already cached. Returned forecast payloads, query-cost data, and accounting receipts may be stored in the weather cache and usage ledger. Visual Crossing Privacy Policy.
- Tripadvisor, Unsplash, and Wikimedia Commons — place-photo discovery and retrieval using place names, coordinates, search terms, or provider identifiers. Returned photo references and attribution may be saved with a place. Some images are requested directly by the browser, which sends ordinary network and device request metadata to the image host. Tripadvisor Privacy Policy, Unsplash Privacy Policy, and Wikimedia Privacy Policy.
- MapTiler — browser map styles, tiles, sprites, and glyphs. Browser requests can include map viewport, network, and device information normally sent with web requests. MapTiler Privacy Policy.
- OpenStreetMap Nominatim — reverse geocoding for map pins. The browser sends the dropped pin's latitude and longitude to look up a display address, along with ordinary browser network and device request metadata; the returned address may be saved with the place. OpenStreetMap Foundation Privacy Policy.
- Frankfurter — historical currency conversion. An expense date and source/destination currency codes are sent only when a saved rate is unavailable; returned rates may be cached. Expense amounts, trip details, and account identifiers are not sent in this request. Frankfurter documentation.
- Native mobile map providers — the mobile map uses the platform's default map provider, normally Apple Maps on iOS or Google Maps on Android when configured. Map viewport coordinates, searched or saved-place coordinates, and your device location when you choose to display it can be included in native map requests. If you choose “Open in Apple Maps”, “Open in Google Maps”, or “Open in Waze”, the selected place name, address or coordinates, and available place identifier are passed to that navigation provider. A separately billed native Google Maps key is not enabled under the current accounting scope; enabling one requires accounting review before dispatch.
- Stripe — subscription and add-on checkout, billing-portal access, and payment lifecycle processing. Depending on the flow, Stripe receives your account email, an internal account identifier, and the plan, price, package type, or quantity selected. Stripe sends billing events and customer, checkout, subscription, invoice, payment-status, and cancellation data back to us. We do not receive or store your full card number. Stripe Privacy Policy.
- Supabase — database hosting. Your account data, collections, saved places, uploaded files, saved thumbnails, references, and generated covers may be stored in Supabase-hosted database or object-storage services. Supabase Privacy Policy.
- Vercel — hosts the web application and server functions. When you use the web product, Vercel infrastructure may process request URLs, IP and network information, browser or device information, headers and essential cookies, and content submitted to hosted endpoints as needed to serve and secure the product. Request, runtime, and error logs may be retained according to our configured platform settings and Vercel's terms. Vercel Privacy Policy.
- Modal — serverless compute for video and carousel processing. Selected source URLs and media, downloaded page or media responses, decoded audio, extracted frames, prompts, and internal user/job identifiers used for accounting attribution may be handled during a job; results and operational records return to Someday Map. Modal Privacy Policy.
- Evomi — residential proxy service used when selected Instagram, TikTok, YouTube, or content-delivery URLs cannot be retrieved directly. The full selected URL and proxied page, subtitle, image, audio, or video response traffic can pass through the proxy. We do not intentionally add your Someday Map account identifier or social-login credentials to those requests, but source URLs can contain public creator identifiers or signed resource tokens. Evomi Privacy Policy.
- Selected source websites and content-delivery networks — Instagram, TikTok, YouTube, Yelp, and other source sites or CDNs may receive server or worker requests for the URL you selected and for related URLs discovered from that page or its public metadata, including oEmbed or public API endpoints, carousel items, subtitles, thumbnails, and signed or direct media URLs. Requests can include service-generated browser headers or cookies and ordinary network information; we do not intentionally send your Someday Map session, password, or social-login credentials. Returned public content can include captions, accessibility text, page metadata, thumbnails, subtitles, images, audio, or video needed for the requested import.
- Apple — optional mobile sign-in and Apple Maps on supported devices. Apple supplies the account identity claims you authorize; map or navigation requests can contain the map viewport, device location when enabled, or the selected place name, address, and coordinates. Apple Privacy Policy.
Chrome extension
The Someday Map Chrome extension supports quick saves and bulk imports on Instagram, TikTok, and YouTube. Its declared site scope and data handling are described below.
- Content scripts run on instagram.com, tiktok.com, and youtube.com. TikTok resource permissions also cover tiktokcdn.com and tiktokcdn-us.com so selected subtitle or media resources can be retrieved during an import.
- On Instagram and TikTok, the content scripts inspect the page structure and relevant site responses to detect collections and assemble content you choose to import or quick-save. Depending on the source, this can include post or video IDs and URLs, captions, usernames or display names, collection names and identifiers, thumbnails and carousel URLs, accessibility captions, durations, location tags, addresses or coordinates, and subtitle URLs, text, or VTT data.
- On YouTube, the content scripts run on playlist, library, watch, and Shorts pages. They inspect the page structure, embedded playlist data, and relevant browse, player, and timed-text responses. They may make authenticated YouTube player or caption requests in the page context to collect playlist and video information. That information can include video IDs and URLs; titles, channel names, durations, thumbnails, descriptions; playlist names, identifiers, and source URLs; and subtitles or VTT data.
- When you confirm an import or quick save, the chosen import payload is sent to your authenticated Someday Map account at somedaymap.com. We do not intentionally send your social-media password or session cookie to Someday Map. Source-site requests made in the page context can use the browser session you already have with that source site.
- Chrome local storage can hold collection or playlist selections, pending navigation, progress, extracted import results, subtitle-request coordination, and recent import markers so an import can continue across popup closes or page navigations.
- The extension does not request your social-media password, direct messages, private conversations, or follower lists. Its source-site scripts can still process the page data and responses needed for detection and import, including a current video you choose to quick-save or a playlist you choose to import.
Cookies
Someday Map uses only essential cookies required for the application to function (for example, session authentication). We do not use advertising cookies or track you across other websites.
Your rights
Depending on your location, you may have the following rights under applicable data protection laws (including GDPR and CCPA):
- Access — request a copy of the personal data we hold about you. You can export your place data from the Settings page at any time.
- Deletion — request deletion of your personal data. You can delete your account from the Settings page, or contact us to request deletion.
- Correction — request correction of inaccurate personal data.
- Portability — receive your data in a structured, machine-readable format via data export.
- Opt out of sale — we do not sell your personal data to third parties. There is nothing to opt out of.
To exercise any of these rights, contact us at the address below. We will respond within 30 days. California residents may also designate an authorized agent to make requests on their behalf.
Changes to this policy
We may update this policy as the product evolves. When we do, we will update the date at the top of this page. Continued use of Someday Map after a change constitutes acceptance of the revised policy.
Contact
Questions or requests about this privacy policy can be sent to privacy@somedaymap.com.