Skip to main content

Privacy Policy

How RestMap handles your data.

Last updated: August 2026

The short version: RestMap does not require an account and does not sell your data. RestMap does not store continuous precise device-location history on its servers. Nearby search and navigation can use third-party services as described below. Optional Premium reports run only when you ask and after you review the trip data being sent; their separate server and AI-provider handling is described below. RestRoom IQ scoring runs on device, and ratings you choose to submit are stored anonymously.

Our Privacy Principle

RestMap was built around a simple idea: you should not have to create an account or give up unnecessary personal data to compare restroom stops.

What We Do Not Collect

  • Personal account information - RestMap does not require accounts, email addresses, or sign-in.
  • Precise location history on our servers - We do not store continuous precise device-location history or movement tracks on RestMap servers. Optional Premium reports can retain the reviewed trip content described below.
  • Device profiles - We do not collect device IDs for cross-app profiles.
  • Cross-app tracking - We do not track you across other apps or websites.

On-Device Processing

  • Location - Your device location is used to find nearby restrooms and recommend stops along routes. We do not store your live device location as a server-side travel history. If you choose to grant "Always" location access, RestMap can use iOS's low-power, on-device visit detection to offer a quick rating reminder after you spend time at a place - this is optional, runs entirely on your device, does not use continuous background GPS, and is never stored on our servers. The optional Trip Report matching data described below identifies planned public places, not your live device location.
  • RestRoom IQ scoring - RestRoom IQ scores and recommendations are computed on your device using bundled data and on-device scoring logic.
  • Preferences, favorites, and trip history - These are stored locally on your device using Apple's secure storage. RestMap also syncs a copy through your iCloud account so that preferences, contribution stats, badges, and recent activity can move between your iPhone and iPad and survive reinstalling the app. This sync uses Apple's iCloud Key-Value Store; data stays within your iCloud account and the RestMap app sandbox.

Optional Premium Trip Report and Place Research

Trip Report runs only after you tap the request button and review the disclosure. AI report content can include opaque report stop and public-place IDs, public stop names and approximate public-place coordinates rounded to three decimal places, timing, RestMap grades, route weather, reduced city-level endpoints, and optional traveler context left in the reviewed field. OpenAI is RestMap's AI provider for v3.0.

When RestMap already holds a complete identity for a planned public stop, the app may send a separate same-place matching envelope to RestMap's server. The envelope repeats the report stop ID, place ID, public name, and type already included in the AI report data so RestMap can bind the two. It may additionally contain an Inspector locator, optional search and enclosing-place names, non-Unknown locality and region, address and exact public-place coordinates when held, and held provider anchors. RestMap uses the envelope only to decide whether an already-sourced Inspector record belongs to the same physical place. The additional exact matching fields are not included in AI prompts, web searches, or the Trip research cache and are not reused to improve future reports or Inspector records. Only compact Inspector facts authorized by the same-place match may be added to the report. The envelope expires with the temporary report job within seven days. Missing, legacy, synthetic, or ambiguous identity produces no Inspector evidence. Exact private start and end addresses remain excluded.

A signed StoreKit transaction proof is sent separately to RestMap to verify Premium access or one-free-report eligibility. It is not included in AI prompts or web searches. RestMap does not persist the raw proof or raw StoreKit transaction identifier; a one-way derived identifier is retained for quota, idempotency, and spend enforcement.

Trip Report request and result jobs are stored temporarily for up to seven days. Completed Trip Reports are saved on your device. Public-place research caches stop being used 30 days after their last research write. A daily deletion job removes expired cache documents, so physical deletion may occur the following day.

Unresolved public-place discoveries and destination-status observations may be held as candidates for up to 30 days after extraction. They cannot directly change public ratings or RestRoom IQ and do not retain the app's local trip identifier. A candidate transport envelope remains while processing is pending; after it succeeds or fails, it expires after seven days. The same daily deletion job removes expired candidates and terminal transport records.

Trip Report may ask our AI provider to search public information about places along the route. Inspector place research stores sourced facts about the public venue, with provenance and freshness information; it does not store your trip or traveler context in the venue record.

Anonymous Ratings and Contributions

When you choose to submit a rating, we store the following anonymously in our shared ratings database, Google Firebase:

  • The location of the place being rated, not your device location.
  • Your rating, such as Good, Okay, Poor, or No Restroom.
  • Optional amenity information you provide, such as changing table or accessibility details.
  • Optional review text you choose to write.
  • A random submission ID, UUID, so other travelers can thank your contribution.

Submissions are anonymous. They are not linked to an account, device identifier, or personally identifying information. Because submissions are anonymous, we cannot offer in-app deletion of individual ratings. You can request removal of a specific submission by emailing us with the location and approximate submission time.

Community Thanks

When another traveler thanks one of your ratings, reviews, or hours updates, we record an anonymous count next to that submission. To prevent duplicate thanks on the same item, we attach a one-way hashed key derived from a random per-install identifier. It is not your Apple ID, email, or device serial.

Thanks counts are stored alongside the contribution in Firebase. The hashed deduplication keys are visible only as opaque strings on individual contribution records. We do not aggregate them, build profiles from them, or share them with third parties.

Analytics

RestMap uses Google Firebase Analytics to understand app and feature usage. Firebase assigns a pseudonymous app-instance identifier to each installation and uses the IP address at collection time to derive coarse location; Google states that it discards the IP address before logging the event. RestMap does not link analytics to an account or collect Apple's IDFA or IDFV. The app is configured not to send ad-personalization signals, and RestMap does not use this data for cross-app or cross-website tracking.

During RestMap navigation, the app can send coordinate-free events showing whether a road-trip plan was saved, in-app navigation was started or completed, and approximate driving distance accumulated on-device. Driving distance is sent in five-mile checkpoints and a terminal remainder rounded down to one-tenth of a mile. These events do not include GPS coordinates, route geometry, origins or destinations, place names or IDs, or RestMap trip IDs. Debug, simulator, TestFlight, sandbox, and unverified builds are excluded.

You can stop future app analytics collection on this device in RestMap Settings > Privacy > Share App Analytics. Turning it off does not delete events already received. This setting does not control analytics on the restmap.io website, which can use a browser client identifier and cookies for aggregate website measurement.

Raw analytics events are retained according to RestMap's configured Google Analytics retention period while needed to measure product trends, then deleted or aggregated. Aggregate reports that no longer contain event-level records may be retained longer.

Third-Party Services

  • Apple Maps and Apple WeatherKit - Used for map display, search, directions, and the weather forecast shown for a planned route. When you query the map, request directions, or plan a route, that query is handled by Apple according to Apple's privacy policy.
  • OpenStreetMap - Used for public restroom and amenity data. RestMap sends a bounding box for the public place or map area being viewed directly from your device to a public OpenStreetMap Overpass service. The request includes ordinary network information, but RestMap does not attach an account, analytics identifier, or device identifier.
  • Refuge Restrooms - Used for community-contributed restroom locations, accessibility information, all-gender or unisex context, changing-table information, votes, comments, and directions. RestMap sends a search-area or public-place latitude and longitude directly from your device to Refuge's live API to find nearby records. The request includes ordinary network information, such as your IP address, but RestMap does not attach an account, analytics identifier, or device identifier.
  • Open Charge Map - Used for EV charging-station locations along a public route or near a requested location. RestMap sends route-sample or search-center coordinates directly from your device to Open Charge Map. The request includes ordinary network information, but RestMap does not attach an account, analytics identifier, or device identifier.
  • Google Maps Platform (Places API) - Used only to look up a place's opening hours, and only when you expand the hours section for a place RestMap has no other hours source for. RestMap's server sends that place's public name and coordinates to the Google Places API and returns the hours to your device; the request reaches Google from RestMap's server, not from your device, and carries no account, device identifier, analytics identifier, or your own location. Google's terms do not permit RestMap to store these hours, so each viewing is a fresh lookup.
  • Google Firebase - Used for anonymous community ratings, pseudonymous app-instance and website analytics, Premium access and quota enforcement, temporary report jobs and separate same-place public-place identity matching, public-place research caches, unresolved public-place candidates, terminal candidate transport, and sourced public-venue facts. Analytics are not linked to a RestMap account. Optional traveler context is stored only when you leave it in the reviewed report request.
  • OpenAI - RestMap's sole AI provider for v3.0 user-requested Trip Reports and public-place research. RestMap sends store: false, does not use Conversations or background mode, and disables prompt-cache writes at launch. OpenAI states that API data is not used to train its models unless the API customer explicitly opts in; default abuse-monitoring logs may retain content for up to 30 days, with limited legal and safety exceptions. No other AI provider receives this data in v3.0.

Data Sources

RestMap's restroom database combines public and app-specific data sources credited in the app:

  • OpenStreetMap - Public restroom and place data contributed by the OSM community.
  • Refuge Restrooms - Gender-neutral restroom and accessibility records contributed by the Refuge Restrooms community.
  • Open Charge Map - EV charging station locations.
  • MapKit/Apple Places - Business and place data from Apple Maps.
  • RestMap brand profiles and user-submitted ratings - RestMap-specific context used by the app.

RestMap's own brand profiles are bundled with the app. OpenStreetMap, Refuge Restrooms, and Open Charge Map records are fetched live as described under Third-Party Services above. RestMap does not attach an account, analytics identifier, or device identifier to these source lookups, but the providers receive the query coordinates and ordinary network information needed to return results. Apple Places results come from queries your device sends to Apple, and a place's opening hours may be fetched through RestMap's server from Google Maps Platform.

Data Storage

Your preferences, favorites, trip history, and Trip Reports are stored on your device, with limited preferences and activity data optionally synced through your iCloud account. Community ratings are stored anonymously in Google Firebase. Pseudonymous analytics events are stored in Google Analytics under the retention criteria above. Premium systems also retain one-way quota identifiers, temporary report jobs and any separate same-place public-place identity matching data, public-place research caches, unresolved public-place candidates, terminal candidate transport, and sourced public-venue facts as described above. We do not sell or share your data with third parties for marketing purposes.

Your Rights

  • Deny location access in Settings. The app will function with limited features.
  • Object to future app analytics by turning off Share App Analytics in RestMap Settings > Privacy.
  • Request removal of a submission you made by emailing us with enough detail to identify it.
  • Request deletion of Premium report data by emailing us with the completed trip and report details needed to identify it.
  • Report inappropriate content from within the app.

International Users

For users in the EEA and UK, RestMap processes device location when you grant system permission to provide requested nearby and navigation features. For pseudonymous analytics, RestMap currently relies on its legitimate interest in understanding and improving the app, balanced by data minimization and the in-app right to object. Any jurisdiction that requires opt-in consent must be addressed before this instrumentation is released there.

Anonymous review data, pseudonymous analytics, and optional Premium processing may be handled on servers in the United States by Google Firebase and OpenAI as applicable. You may request access, correction, deletion, restriction, or objection by contacting us; you can object to future app analytics immediately with the in-app toggle.

The optional Premium Trip Report and place research described above rest on a different basis: your consent, given the first time you use Trip Report and reviewed before every request. You can withdraw it at any time in RestMap Settings > Privacy > Trip Report & privacy. Withdrawing consent stops future requests; it does not undo a report already generated and saved on your device.

Children's Privacy

RestMap is rated 4+ on the App Store and does not require a child's name, email address, or account. A parent or guardian should review any optional traveler context before a Premium report is requested and remove personal details they do not want sent.

Changes to This Policy

We may update this privacy policy from time to time. We will post any changes here with an updated date. Significant changes will be highlighted in the app.

Contact Us

If you have questions about this privacy policy or wish to request data removal, contact us at flush.restmap@gmail.com.