Privacy Policy
Last updated: August 27, 2026
Disco is a walking tracker and private exploration map. As you move through the world, you reveal a map for yourself and, if you choose, add anonymous areas to a shared atlas. This page explains what we collect, why we collect it, and how you can remove it.
Information we collect
- Location data. While tracking is on, Disco reads precise GPS location in the foreground and, if you allow it, in the background. Your detailed trail and personal atlas stay on your device. If you enable contribution to the shared atlas, Disco sends visited map-cell identifiers (roughly 100 meter areas), timestamps, and coarse movement context to our server. Discoveries made before you enabled contribution stay private unless you separately choose to include them. These records are linked to your pseudonymous account so you can restore shared discoveries and delete them later. Location is also sent when you choose to post or view a location-locked field note.
- Motion and fitness data. Step counts and coarse motion-sensor signals are processed to confirm movement is genuine. When shared-atlas contribution is enabled, these signals accompany a discovery for anti-cheat checks; they are not kept as a personal fitness history.
- Account information. Disco creates a pseudonymous user ID on first launch. You may choose a public explorer name and may keep it off the leaderboard. If you link Apple or Google for recovery, we receive the provider identifier and any email address the provider supplies for account management.
- Photos you choose to post. Disco's optional "field notes" feature lets you post a photo tied to your current map hexagon, visible to other explorers standing in that same hexagon. Before upload, we strip the photo's embedded GPS and EXIF metadata. Only the coarse hexagon you posted from is attached, not the exact coordinates a raw phone photo would otherwise carry.
- Other content you submit. Feedback messages and field-note reports are stored with your pseudonymous account so we can respond, maintain safety, and prevent duplicate abuse reports.
- Diagnostics. Disco automatically sends a capped error message, stack trace, platform, and pseudonymous user ID when an unhandled app error occurs. These error reports are deleted after 30 days. Android also keeps a bounded, app-private tracking-health journal containing service timestamps, closed error codes, restart and queue counters, and whether tracking recovered after the app was dismissed. It contains no coordinates, route, map cells, place names, or text you wrote. You can copy this local diagnostic summary from Settings; it is not uploaded automatically. If you explicitly upload a debug log or include diagnostics with feedback, it may also contain app version, build, platform, battery state, tracking state, and queue counts. It never contains coordinates or your route. Uploaded debug logs are deleted after 7 days.
- Usage analytics. If you turn on Usage analytics in Settings, the app sends a limited set of product events to Disco's own backend, such as completing onboarding, starting an outing, revealing your first area, opening a feature, posting a field note, or observing a coarse Android tracking-health transition. A tracking-health event can say that Android recreated the service, a direct permission/provider/storage issue occurred or recovered, a normal Recent Apps dismissal later received a fix, a moved trip had a confirmed gap, or encrypted queue records were lost. It uses allowlisted reasons and coarse count/duration buckets, never the route or exact fix count. An event includes its time, a random session ID, app version, platform, your pseudonymous Disco account ID, and a small set of controlled values such as a boolean, count, or coarse duration. Nothing is stored or sent for product analytics before you opt in. Usage analytics never contains coordinates, map-cell identifiers, routes, place searches, quest or district IDs, photos, device model, free-form tracking errors, feedback text, or other content you create. Events are deleted after 180 days and are removed when you delete your account.
- Device integrity data. Apple App Attest or Google Play Integrity tokens and related device-bound identifiers help prove that shared contributions came from a genuine app rather than an automated or modified client.
What we don't do
- We don't include advertising SDKs, cross-app trackers, or third-party analytics SDKs in the app. Product events go to Disco's own backend and are used only to understand and improve Disco.
- We don't access your contacts, photo library, or files beyond a photo you explicitly take or choose to post.
- We don't sell your data to anyone, for any reason.
- We don't publish your exact route, the times you visited a place, or anything that identifies you personally on the shared map.
How the shared map works
If you turn on "contribute to the shared atlas," map cells you've physically visited are added to a map everyone can see. The public cell has no name, timestamp, or route attached. Separately, your contribution record remains linked to your pseudonymous account so it can be restored to you and removed if you delete your account. Server-side speed, continuity, motion, and device-integrity checks exist to stop fake locations, not to advertise to you or build a marketing profile. You can turn contribution off at any time; your personal map keeps working on your device.
Who we share data with
We use a small number of service providers to run Disco. None of them are permitted to use your data for their own purposes:
- Supabase hosts our database, authentication, file storage, and server functions.
- Apple and Google provide device-integrity verification (App Attest / Play Integrity) and, only if you opt in, account sign-in.
- OpenStreetMap / Nominatim powers place search when you look up a location by name.
- Map tile providers (CARTO, Esri/ArcGIS) supply the base map imagery you see.
- Plausible provides cookie-free, aggregate traffic analytics for Disco's public website. Website analytics are not linked to your Disco account or in-app activity.
How long we keep data
- Automatic client-error reports are deleted after 30 days; debug logs you explicitly upload are deleted after 7 days.
- First-party usage analytics events are deleted after 180 days.
- Your profile, shared contribution history, field notes, feedback, and safety records are kept until you delete your account or the content is removed through moderation.
- When an account is deleted, a public map cell remains only if another explorer also contributed that same cell; it no longer contains a record connected to the deleted account.
Delete specific data without deleting your account
Delete a field note: open Here → My posts, open the field note, choose Delete, then confirm Delete permanently. This removes the post, its stored photo, and its view records from our servers without deleting your Disco account.
Reset data stored only on your device: open Settings → Account → Account & data removal → Reset local footprint. This clears the personal atlas and related local history on that device without deleting your account or previously accepted shared-map contributions.
Delete your account and data
In the app: open Settings → Account → Account & data removal → Delete account & shared contributions, type DELETE, and confirm. This removes the authentication account, profile, shared contribution history, field notes and their stored photos, feedback, blocks, reports, view records, device-attestation records, and diagnostic logs. Personal map data stored only on that device is cleared by the app.
Without the app: email marvin.maerz@gmail.com with the subject “Disco account deletion.” Include the Explorer ID shown in Settings → Account. If you linked Apple or Google, send the request from the linked email address when possible. We may ask for additional proof before deleting data to avoid deleting another person's account.
Your other privacy choices
- Turn off sharing anytime in Settings. Your personal map keeps growing, but nothing new is added to the shared map.
- Turn off usage analytics anytime under Privacy in Settings. This stops future product events and clears events waiting on your device. Delete your account to remove events already received by Disco.
- Protected places. You can mark specific areas, such as home, as private in Settings. Visits there are never queued for the shared map, regardless of your sharing setting.
Children's privacy
Disco is not directed at children. We do not knowingly collect data from children under 13 (or the relevant minimum age in your region).
Changes to this policy
If this policy changes in a way that affects how your data is used, we'll update the date at the top of this page and, for significant changes, notify you in the app.