Hugs Map — Privacy Policy
Hugs Map is a private shared-memory app for you and the people you choose. This policy describes exactly what the app does with your information. It is written to match how the app actually behaves, not to cover things it does not do.
The short version: Hugs Map has no ads, no analytics, no trackers, and never sells or shares your data with anyone for their own purposes. What you save is yours and, if you share a memory with somebody, theirs to see. You can export everything at any time.
Who we are
Hugs Map is made by a solo developer in Oman. For any privacy question, contact: support@hugs-map.com.
What the app stores, and where
Everything you create is stored on your device first. What you choose to share with the people you have added (optional) is also stored in Google Firebase so they can see it: memories with their audience, the conversations on them, and your messages.
| What | Stored on device | Stored in the cloud |
|---|---|---|
| Memories (time, optional caption, mood, tags) | Always | Only within a connected space |
| Photos on a memory | Always (compressed) | Only within a connected space |
| Location on a memory (see below) | Only if you enable it | Only within a connected space |
| Comments and notes | Always | Only on memories you shared |
| Messages, pictures and clips in conversations | Always | Yes — a conversation exists to be delivered |
| Your contacts, and the private nickname you give each | Always | The list, yes; a nickname never leaves your phone |
| Your name, username, profile photo, status line, bio and link | Always | Copied to the people you have added so they can see who you are; name, username, photo and bio also shown to members who use "People on Hugs Map", unless you switch "Let people find me" off |
| Gender and year of birth (optional, asked once at the start) | Always | Never |
| The warmth map | — | One anonymous count per neighbourhood-sized cell, per hug you switch "Warm the map" on for; no id, no owner, no coordinates |
| Reports you file | — | Yes, for the developer to review |
| Settings | Always | Only if you turn on cloud backup |
| Google account (optional) | — | Used only to pair devices and, if enabled, back up |
If you use Hugs Map solo, nothing leaves your device except an optional, explicit cloud backup (below). Solo memories are never uploaded automatically.
Location
Location is the most sensitive thing an app like this could touch, so it is handled deliberately:
- Coarse only. The app requests
ACCESS_COARSE_LOCATIONand never fine location. - Read once, at the moment you save a memory. Never in the background, never while the app is closed, and never streamed. The app has no ability to locate you in real time. Two other single reads exist, each only when you ask for it: the map's "where I am" dot (kept in memory while the map is open, never stored), and the camera's place, temperature and weather stickers.
- The weather stickers ask one outside service. To show the temperature or the sky on a picture, the app sends your coordinates rounded to about five kilometres to Open-Meteo (open-meteo.com), once, when you tap the sticker, with no account, no key and no identifier of you. The reply is a number and a sky code. This is the only time any location leaves the phone for anything but a memory you chose to share.
- Approximate by default. Coordinates are snapped to roughly a 500-metre grid before they are stored. Choosing a lower precision destroys the original coordinates rather than hiding them; this cannot be undone.
- Optional. You can save memories with no location at all, and change or remove the setting at any time.
People nearby
If you open "Find people nearby", your phone announces your username and name to other phones within a few metres over Bluetooth and local Wi-Fi, and lists the phones it hears, for as long as that screen is open on both. No location is read or sent, and nothing is stored. Closing the screen stops it. It is offered only on Android 13 and newer, where this needs no location permission.
Photos
Photos you attach to a memory are compressed on your device and stored locally, encrypted. A memory you share is uploaded to private storage so the people you chose can see it; a public memory's pictures can be seen by anyone signed in, from the map. Original full-resolution files are never kept. EXIF metadata — including any GPS coordinates the camera embedded — is stripped. Every picture uploaded is compared, by a one-way hash, against pictures our moderation has removed before; a match holds the memory for a person to review (Terms §7.3). Nothing else is done to your pictures automatically.
Optional sign-in: Google or a phone number
Signing in is optional. It exists so your memories follow you to another phone and so only you can open them. With Google we receive a Google account identifier; we never receive or store your password. With a phone number we receive the number and send a one-time code through Firebase Authentication; the number is used for sign-in and is not shown to anyone. You can also choose "Not now" and confirm later, or use the app fully without ever signing in.
Optional cloud backup
If you turn on backup, a copy of your solo memories (words, feelings, places, times — not photos) and your settings is stored under your own account in Firebase, readable only by you, so a lost or replaced phone can restore them. Turning backup off deletes that copy.
Notifications
Two categories are on by default — a note from a contact, and a comment on a shared memory — because both are one person speaking to the other. Every other category is off until you switch it on. A notification only ever tells you *that* something arrived (for example, that a contact left a comment); the message never contains the content itself, which stays in the app. Every category can be switched off in Settings, and if you turn them all off, no messaging token is registered for your device at all.
Crash reporting
Crash reporting (Firebase Crashlytics) is off by default and collects nothing unless you turn it on. When on, it sends crash diagnostics to help fix bugs. It contains no memory content.
Who your data is shared with
- The people you have added, for the memories you chose to share with them and the conversations you have with them. Who sees a memory is your choice, per memory.
- Anyone signed in to Hugs Map, for a memory you mark Public: its pictures, words, feeling, place and your name and picture, from the map. A public memory can be made private again from the memory itself.
- Everyone who uses Hugs Map, but only two things and neither is personal: the warmth map (anonymous counts per neighbourhood, if you switch "Warm the map" on for a hug) and, unless you switch "Let people find me" off, your name, username, photo and bio under "People on Hugs Map", so that people can send you a request. Nobody sees your memories, your places or your conversations that way.
- Google Firebase, which stores and transfers your data on our behalf as a processor. It is not permitted to use your data for its own purposes. Firebase's handling is governed by Google's privacy terms.
- Open-Meteo, only the rounded coordinates described under Location, only when you tap a weather sticker.
We do not share your data with advertisers, data brokers, or any other third party, and we do not sell it.
Security
On your device, the app's database — memories, messages, contacts, settings — is encrypted at rest (AES-256), with the key sealed in your phone's secure hardware. It is never included in a cloud backup. Since 1.3.0 every memory photo, chat picture and clip on the device is encrypted the same way, under its own sealed key.
In transit, everything is encrypted (HTTPS/TLS).
On the server, access is enforced by security rules: a shared memory can be read only by the people it was shared with (or by anyone signed in, if you marked it Public), and a conversation only by its members. Requests must come from the genuine app on a genuine device (Play Integrity). Chats and shared memories are not end-to-end encrypted: they are encrypted at rest and in transit, but the service itself could read them. That is what makes abuse reports and getting your chats back on a new phone possible; the app says so under You → Privacy → Your data.
An optional on-device PIN (with biometric unlock) can lock the app. A username can be changed once every 49 hours.
Records we keep about decisions. When somebody looks up an account for support, or a report is decided, or an appeal is filed or answered, a record is written — who acted, on what, when; never the content. These records are kept for one year and then deleted. Reports themselves are kept, because the enforcement ladder in the Terms (§7.4) depends on history; the hash of a picture is deleted with the picture.
Server backups. The server database is backed up once a day and each backup is kept for 14 days; the database also keeps its own history for 7 days so that a fault can be undone. Backups hold the same data the server already holds — never a "just me" memory, which is only on your phone — in the same region, under the same access controls, and nobody reads them except to recover from a failure. Something you delete is gone from the live service at once and from every backup within those 14 days; Terms §4.2 says 30, which is the outer bound we promise.
Your rights and controls
- Export everything, any time, as a plain, readable file — free, no account needed.
- Delete. A memory is yours: you can put it away or delete it for everyone at any time. A line you sent in a conversation can be taken back for everyone. You can delete your account and everything it holds in the cloud from You → Your data → Delete my account, or by email; see the "Delete your account" page.
- Block and report. Anybody can be blocked from You → People; they are never told. A person, a memory, a comment or a message can be reported from where it appears. Reports are reviewed by the developer, who may remove content or suspend an account.
- Read receipts are a switch, off by default. Off means you send none and see none.
- Turn off location, notifications, crash reporting, backup, and presence individually at any time.
Children
Hugs Map is not directed to children under 13 (or the equivalent age in your country) and does not knowingly collect their data.
Changes
If this policy changes materially, the app or this page will say so. Continued use after a change means you accept the updated policy.
Contact
support@hugs-map.com