Last updated: 3 August 2026
Sagala ("Sagala", "we", "us") is a skate-spot mapping app. This policy explains exactly what data the app handles, where it goes, and what stays only on your device. It is written to match how the app actually works.
We do not sell your personal data. We do not use it for advertising or cross-app tracking. We do not run third-party analytics or advertising SDKs.
Every spot and album you create has an audience you control:
| Audience | Where it is stored | Who can see it |
|---|---|---|
| Private (device-only) | Only on your device. Not uploaded to our servers. | Only you. |
| Friends | Uploaded to our backend (Supabase). | You and your mutual friends, plus anyone you explicitly share it with. |
| Public | Uploaded to our backend and reviewed by moderation. | Any signed-in Sagala user, after approval. |
Private spots never leave your device unless you change their audience or explicitly share them. If you make a private spot Friends/Public and later switch it back to Private, we delete the server-side copy (including its photos) once a full copy exists on your device again.
For private items, the following is stored locally and never transmitted: spot name, notes, exact GPS coordinates, category, and attached photos, plus your app preferences. This data is protected by your device passcode/biometrics.
Access is enforced by row-level security: other users can read your content only according to its audience. Your email is used for sign-in and account search and is not shown publicly.
Photos for Friends/Public spots are uploaded to Cloudflare R2 through our server using short-lived upload links. To display them, our server checks your access and issues a short-lived (5-minute) download link. Private-spot photos stay on your device.
We request location only while you are using the app. No background/always-on location. The app works if you deny location.
We access your photo library and camera only to attach photos to spots. If a photo contains GPS metadata we may use it to auto-fill a spot's location. We do not scan or upload your wider library and do not save photos back to it.
Text/semantic search is powered by Google Gemini, called from our server. Your search text — and the photos of cloud-synced (friends/public) spots — are processed server-side into numeric embeddings so spots can be matched to your search. Photos of private, device-only spots are never sent to Gemini. Results only include spots you are allowed to see; search never reveals other people's private spots or coordinates.
Public and shared spots are user-generated content. We provide tools to report content/users and to block users. Public spots are subject to moderation review. We may remove content or accounts that violate our Terms.
No advertising, no ad networks, no ad tracking/IDFA, no App Tracking Transparency prompt, no third-party product analytics SDKs, and no sale of personal data. When enabled for a release, Sentry receives only privacy-minimised crash diagnostics as described above.
When crash diagnostics are enabled for a release, we use Sentry to receive redacted error messages and crash stack traces so we can diagnose app failures. Reports first pass through our two-hop Cloudflare Worker privacy relay, which replaces the device network identity before making a new request to Sentry. The app does not attach your account, email, request data, breadcrumbs, device context, identifiers, real IP address, or location to those reports. It sends a non-routable placeholder solely to prevent Sentry from deriving a geographic location, and Sentry scrubs that placeholder. Crash diagnostics are not used for advertising, profiling, or tracking.
Sagala is not directed to children under 13 (or your country's minimum age). We do not knowingly collect children's data.
Our providers (Supabase, Cloudflare, Google, Mapbox, Sentry) may process data outside your country. By using Sagala you consent to this.
Depending on your jurisdiction (GDPR/UK GDPR, CCPA), you may request access, correction, or deletion. The in-app Delete Account flow satisfies most deletion requests; contact us for anything else.
We will update this policy as the app evolves and revise the "Last updated" date.
Email: support@sagalamap.app. You can also use the in-app report/support tools (Settings → Support) or the support page.