MapRoute

Privacy

Map Route is operated from our own server. Account data is stored in a database on that server. The browser never connects to the database directly. We do not sell personal data.

Accounts

Registration is optional for browsing and for up to three Generate Journey uses as a visitor. An account is required to download images or videos, and to continue generating after the visitor limit.

When you register, we store the email address you provide and a password hash. Passwords are hashed with Argon2id. We do not store the password itself. We send a verification email from noreply@maproute.org so we can confirm you control that address. Temporary or disposable email addresses are not accepted. Password reset in this release is handled manually: please contact our team.

Session cookies

After you log in, we set a secure HttpOnly session cookie so the server can recognize your account. Session tokens are stored as hashes. A longer-lived visitor cookie may also be set so anonymous Generate Journey uses can be counted if you return without an account. These cookies are not used for advertising.

Hashed IP addresses and usage limits

We use HMAC-hashed IP addresses, not raw IP addresses, for abuse controls and usage limits. Logged-out visitors may generate a journey up to three times, counted by hashed IP and visitor cookie. After that, registration or login is required. We do not ask visitors to pay at that stage.

Registered free accounts have a combined limit of five uses per UTC day. Generate Journey, Download Video, and Export Image each count as one use. Paid accounts also have a daily limit (five by default) which we can change for an individual account. Paid status is set manually after we receive payment. There is no automatic card charge or in-app checkout. If a paid subscription expiry date has passed, the account is treated as free until it is renewed from our admin area.

Usage events are stored against your account id so logging out and back in does not reset the daily counter. Invalid or failed server requests are not counted.

How long we keep data

Account records, hashed passwords, session hashes, and usage events are kept while the account exists and as needed to enforce limits and security. Login attempt records are kept to slow down password guessing. You may contact our team to ask about closing an account.

Third-party map and routing services

When you search for a place, the query is sent from our server to a third-party geocoder. Photon by Komoot is the primary geocoder. Nominatim (OpenStreetMap) is the fallback adapter. Those services receive the search text in order to return matching places.

Road path requests are sent to an OSRM routing engine. Railway geometry may be requested from the OpenStreetMap Overpass API. Map tiles and styles come from OpenFreeMap / OpenMapTiles (OpenStreetMap data). Air corridor and geodesic lines are computed locally and are not sent to a travel operator. Video and image export is rendered in your browser, not on our server.