Privacy Policy

Effective June 15, 2026

This Privacy Policy describes how Stomped collects, uses, and protects your information when you use the Stomped mobile and web applications (the "Service"). We have written it in plain English.

In summary: we collect only what is needed to operate and improve the Service, we store it under your account, and we do not sell your data or share it with advertisers. Inside the iOS app we measure product usage with Google's Firebase Analytics — with no advertising and no advertising identifier — and also keep a first-party copy in our own database. Our public website uses Google Analytics to measure site traffic. You can export or delete your information at any time.

1. Who we are

The Service is operated by Stomped ("we," "us," "our"). For questions about this policy, contact us at privacy@stomped.app.

2. Information we collect

We collect the following categories of information:

We do not collect your phone number, date of birth, or physical address.

3. How we share information

Your information is shared only with the service providers required to operate the Service:

We do not use advertising networks, attribution platforms, or data brokers. The in-app usage analytics described above are kept in our own first-party database (hosted by Supabase) and, on iOS, are also processed by Google Firebase Analytics as described above; we use them solely to operate and improve the Service and never sell them. We do not sell your personal information.

4. Information visible to other users

Stomped is not a social network. Information is shared between users only in the following ways:

5. Data retention

6. Your rights and controls

Within the app's Settings screen you can:

You may also revoke location access, disable milestone notifications, or disable passive tile capture at any time.

You can also view your own explored map — your unlocked map tiles and saved tiles (their titles and notes, but not their photos), for your account only — by signing in at stomped.app, in addition to viewing it in the app.

To request access, export, or deletion by email, contact privacy@stomped.app from the address associated with your account. We will respond within thirty days.

California residents

If you are a California resident, you have the right to know what personal information we collect about you, to request its deletion, and to be free from discrimination for exercising these rights. We do not sell personal information.

7. Security

All communication between your device and our servers is protected by HTTPS. Passwords are stored as salted bcrypt hashes. Database access is restricted at the row level, so each user can only read and write data associated with their own account.

If a security incident affects your information, we will notify you by email and take reasonable steps to address it promptly.

8. Children

The Service is intended for users aged thirteen and older. If you are a parent or guardian and believe a child has created an account without your consent, please contact us at privacy@stomped.app and we will remove the account.

9. International users

Our servers are located in the United States, so if you use the Service from elsewhere your information is transferred to and processed in the United States. We take steps intended to protect your information when it is transferred. If you are in the EU or UK and have questions about this transfer or the basis for processing your information, contact us at privacy@stomped.app.

10. Changes to this policy

We may update this policy from time to time. When we do, we will update the effective date above, and for material changes we will provide notice within the app. Continued use of the Service after an update constitutes acceptance of the revised policy.

11. Contact

For questions about this policy or how we handle your information, contact us at privacy@stomped.app.