Crowdmap service
Privacy Policy
This notice explains how this independently operated Crowdmap deployment processes personal data. It applies to this deployment only, not to the open-source project or other installations.
Last updated: 11 September 2026
Sponsorships through Ko-fi
If this deployment enables sponsorships, the sponsor link opens Ko-fi. Ko-fi processes contributions as an independent controller under its own privacy policy. The link does not send your name, email address, or other browser data to Ko-fi beyond what your browser normally sends when visiting a link.
Ko-fi sends this service a payment notification so it can show progress toward its monthly operating-cost goal. The notification may contain donor details, but this service discards them and retains only the payment amount, remaining sponsorship credit, currency, payment time, calendar month, and a hashed event identifier used to prevent duplicate counting. This processing is based on the controller’s legitimate interests under Article 6(1)(f) GDPR: showing funding progress and preventing duplicate records.
Controller and contact
The controller responsible for this deployment is keneanung. For privacy requests, contact keneanung@gmail.com.
Data processed and purposes
When you submit a map report, the service stores the reporter value you provide and the submitted map-change data: for example room and area identifiers, names, coordinates, exits, commands, and user-data fields. Use a pseudonym and do not include personal data in a report.
The reporter value is used to distinguish independent confirmations of the same map change; it is not published as part of a downloaded map. Changing to a new pseudonym does not rename or remove earlier reports.
To run and protect the service, request logs contain your IP address, request ID, request method and path, response status, and processing duration. Administrators may also process report details when reviewing, resolving, or incorporating changes.
This processing is based on the controller’s legitimate interests under Article 6(1)(f) GDPR: operating a reliable community map, assessing reports, and preventing abuse and security incidents. Map reporting is voluntary, but a reporter value is required to submit a report. The service does not use data for advertising, tracking, or automated decisions about people.
Retention
Pending reports are retained until an authorised administrator removes them or they are incorporated into the baseline map. The application does not automatically delete other pending reports. Request logs are retained for 30 days. Sponsorship payment records are retained while their credit is needed for a current or future monthly goal, then deleted. A hashed event identifier is retained for 30 days after deletion to prevent duplicate webhook notifications.
Recipients and international transfers
Authorised map administrators can access report details. The operator and providers acting on its instructions may process data where needed to host, store, back up, maintain, or secure this deployment. Hosted in the EU with no further service providers
Browser storage and cookies
This service does not set its own tracking or advertising cookies and does not persist explorer preferences in browser storage. The selected map-report threshold is kept only in the page URL. The review page keeps an administrator API key only in page memory while it is open.
Your rights
Subject to the GDPR and other applicable law, you can request access, rectification, erasure, restriction of processing, or a copy of your data, and you may object to processing based on legitimate interests. You can also lodge a complaint with the data-protection supervisory authority responsible for your habitual residence, place of work, or the place of the alleged infringement. To help locate a report, include its reporter pseudonym and any relevant report details in your request; for a sponsorship payment, include its amount, currency, and date.