Draft. This policy is pending legal review and may change before it is final. It describes what the product does today, in plain language.
Privacy policy
version 2026-08-05 · effective 5 August 2026
OutsiderMap exists to answer one question: where should you go, right now. To do that well it has to learn your taste, and that means holding some of your data. This page says exactly what we collect, why, how long we keep it, and how you get rid of it. It is written for the Digital Personal Data Protection Act, 2023 (DPDP) and for common sense.
What we collect
- Account details. Your email address and the profile you set up (name, username, photo if you add one). This is how you sign in and how other members see you.
- Your date of birth. Collected once when you join, and used for one thing only: checking that you are 18 or over. See Children below.
- Location, when you grant it. Used to center the map on you, find places near you, and verify spots you scout on-site. We store the area you are in, not your exact coordinates. The app works without it; the map is just less useful. You can revoke the permission in your device settings at any time.
- Your taste profile and interaction history. Your onboarding answers and what you do in the app (places you view, save, visit, skip). This is the raw material of the recommendation engine; without it we would be a generic list. Only collected if you agree to it, and it stops the moment you say so.
- Photos and camera uploads. Photos you attach to posts and the live photos you take to verify a spot. They are stored with your account and shown where you chose to share them. Uploads pass through moderation before they are public.
- Device push tokens. If you allow notifications, we store the token your device gives us so we can send them. Signing out releases the token.
We do not buy data about you, we do not sell data about you, and we do not run third-party advertising trackers.
Why we use it, and what you agreed to
When you join we ask separately about each of these. Only the first is required - it is the product itself. Everything else you can refuse at signup and switch off later from your profile, and refusing does not cost you access to anything else.
- Running your account. required Your email, profile and the things you explicitly save. This is the product itself - signing in, the map, saved places, and keeping members safe from abuse. You cannot switch this off and still have an account; deleting the account is how you withdraw it.
- Personalized recommendations. optional Your quiz answers and what you do in the app - places you view, save, visit and skip - used to work out what to show you. This is what makes the answers yours rather than a generic list.
- Remembering what you tell it. optional Durable facts you state in chat - vegetarian, hates rooftops, always with my partner - so you do not have to say them twice. Only things you actually said; nothing the app inferred on its own.
- Push notifications. optional The token your device gives us, so we can send the notifications you asked for. Signing out releases it.
- Using your location. optional Centring the map on you, finding places nearby, and verifying spots you scout on-site. While the app is open we also record where you have been, so we can tell which places you actually went to. Never in the background, and never when the app is closed. You can revoke the device permission at any time, and withdrawing here stops the recording even if the device permission stays on.
- Learning from where you go. optional Using the places you actually visited to teach the app what you like, so its recommendations get better instead of guessing from a quiz you took once. Withdrawing stops this without switching off the map or nearby search.
We keep a record of what you agreed to, when, and against which version of this policy - you can see that record in your data export. If we change this policy in a way that materially affects what you agreed to, we will ask you again before the change applies to you.
Children
OutsiderMap is for people aged 18 and over. The DPDP Act prohibits behavioural tracking and targeted advertising directed at children, and behavioural learning is how this product works - so rather than build a version we could not honestly operate, we do not accept under-18s at all. We ask for your date of birth once, at signup, and use it for nothing else. If it shows you are under 18 we refuse the account, keep no profile, quiz answers or history, and delete the record of the refusal after 30 days.
How long we keep it
For as long as you have an account, so the product keeps working for you - except for the operational records below, which are deleted on a schedule by a job that runs every night.
- What you tapped, saved and skipped. Deleted after 400 days. Thirteen months, so a full year of seasons still informs your recommendations, and nothing older does.
- Facts the concierge was told were temporary. Deleted as soon as it expires. Some remembered facts are stamped with an expiry when they are written - visiting from Bombay this week. They go when they expire.
- Full AI call records. Deleted after 180 days. The internal copy of a conversation must not outlive the conversation itself, so transcripts share chat's 180 days. Anything worth keeping longer is exported into a curated training set before it expires - curation is a decision, retention is a default.
- Your conversations. Deleted after 180 days. Six months. The concierge only ever reads the last twenty messages of one thread, so nothing older is doing any work.
- The conversations themselves. Deleted after 180 days. Six months, matching the messages inside them. Without this the messages went and an empty titled thread stayed behind forever.
- Your activity feed. Deleted after 180 days. Six months. The feed only shows recent activity.
- A log of notifications we sent you. Deleted after 90 days. Ninety days, kept only to avoid sending you the same thing twice and to debug a notification that did not arrive.
- The record of this cleanup running. Deleted after 400 days. Thirteen months of our own housekeeping log.
- Closed moderation decisions. Deleted after 1095 days. Three years, which is the retention the IT Rules 2021 require for moderation records. Open cases are never deleted.
- Resolved grievances. Deleted after 1095 days. Three years, as the statutory grievance register requires. Open grievances are never swept.
Where the law requires us to retain something for longer, we retain only that and only for as long as required.
Who else touches your data
We use the following companies to run the product. They process your data on our instructions and for no purpose of their own. Several of them operate outside India; the DPDP Act permits this except to countries the government has specifically restricted, and we do not transfer data to any restricted country.
- Supabase (Singapore / United States). Database, authentication and file storage - the primary store. Data shared: account details, profile, taste profile, interaction history, chat, photos.
- Vercel (United States). Application hosting and the scheduled jobs. Data shared: request metadata, anything in transit through the app.
- Anthropic (United States). The concierge - turning your question and taste profile into an answer. Data shared: chat messages, taste summary, remembered facts.
- OpenAI (United States). Embeddings for taste and place matching, and some chat generation. Data shared: taste summary, quiz-derived dimensions, chat messages.
- Open-Meteo (Germany). Current weather for your area, which is what the app takes its colours from. Data shared: an approximate area, rounded to roughly 11km, with nothing attached to it.
- Upstash (United States). Rate limiting - keeping the app usable and abuse-resistant. Data shared: hashed rate-limit keys derived from user id or IP.
- Resend (United States). Transactional email. We do not send marketing email. Data shared: email address.
- Google Cloud (United States). Sign in with Google, and the Places API used only to resolve a place id for navigation. Data shared: email address, place lookups.
- Apple (United States). Sign in with Apple, and push notification delivery on iOS. Data shared: email address (or Apple's relay address), device token.
- Google Firebase (United States). Push notification delivery on Android. Data shared: device token.
- Image moderation vendor (To be determined). Automated screening of uploaded photos before they are shown to anyone. Not yet engaged - every photo is reviewed by a person today. Data shared: uploaded photos.
- CSAM scanning vendor (To be determined). Detection of child sexual abuse material in uploads, as required by the IT Rules. Not yet engaged; the scanner interface is a documented no-op until credentials exist. Data shared: uploaded photo hashes.
Your rights
- See what we hold. Download everything, as a machine-readable file, from your profile settings. It includes your data, your consent history, who we share it with, and how long each thing is kept.
- Delete your account. In the app, from your profile settings. Deletion is immediate, requires a typed confirmation, and purges your personal data, not just the login. You do not have to email anyone or wait for an operator.
- Correct what is wrong.Your display name, bio and home area are editable directly. A fact the concierge has remembered can be deleted from your profile. Retaking the quiz rewrites your taste profile. For anything you cannot change yourself - your username, date of birth, or email - use “Request a correction” in your profile settings.
- Take back your consent. Every optional purpose above has its own switch in your profile. Turning one off deletes what it was holding - we do not simply stop looking at it.
- Nominate someone. You can name a person to exercise these rights for you if you die or become unable to. They cannot sign in or act on your account; they contact our grievance officer, who verifies their claim against what you recorded.
- Complain. See below.
What survives deleting your account
Almost nothing - but not quite nothing, and you should know which. Each of these is either a record the law requires us to keep, or something other members depend on. In every case your identity is removed from it.
- Grievances you filed. Statutory grievance register under the IT Rules 2021. reporter_id is ON DELETE SET NULL, so the case survives with you removed from it.
- Moderation decisions about your content. Moderation record required under the IT Rules 2021. author_id is ON DELETE SET NULL, so the decision survives de-identified.
- Photos you contributed to places. The photo is catalog content other members rely on to find the place. contributor_id is ON DELETE SET NULL, so it survives unattributed.
- AI answers we generated for you. Operational record of how the AI performed - latency, cost and error rates the service is run from. user_id is ON DELETE SET NULL, so what survives is that a call happened, not that it was yours.
- Spots you submitted. A submitted spot becomes part of the shared catalog. created_by is ON DELETE SET NULL, so the place stays and your name comes off it.
Grievances
If you believe we have mishandled your data, contact our grievance officer [grievance officer to be appointed]. We will acknowledge and respond within the timelines the DPDP Act requires. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
Changes
This is version 2026-08-05. If this policy changes in a way that materially affects what you agreed to, we will ask you to read and accept it again the next time you open the app - your existing choices about the optional purposes carry over untouched. Smaller corrections update this page without interrupting you. See also our terms of use.